Method for generating twiddle factor table for number-theory transformation

By generating a rotation factor table on the polynomial ring, the problem of slow calculation speed of number theory transformation is solved, more efficient number theory transformation is achieved, and the performance of grid-based cryptographic scheme is improved.

CN120389865APending Publication Date: 2025-07-29SPACE STAR TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510305827.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

The prior art fails to describe in detail the generation method of the rotation factor table, resulting in a slow calculation speed of number theory transformation, and the research on the form of polynomial number n is a power of 2, making it difficult to select appropriate granularity and range at a given security level.

Method used

A rotation factor table generation method for number theory transformation is proposed, including generating key data on the polynomial ring, decomposing the polynomial layer by layer, selecting negative values of constant terms, calculation of inverse number theory transformation data and Montgomery domain transformation, and generating a rotation factor table of positive number theory and inverse number theory transformation.

Benefits of technology

It significantly accelerates the implementation efficiency of number theory transformation, provides finer granularity and wider range, improves the efficiency of quantum encryption, decryption and signature algorithms, and solves the problem of confusing data items in the rotation factor table.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389865A_ABST
    Figure CN120389865A_ABST
Patent Text Reader

Abstract

The invention discloses a twiddle factor table generation method for number theory transformation, which is mainly based on decomposition of a polynomial on a finite field and comprises the steps of key data generation, polynomial decomposition and data selection, inverse number theory transformation data calculation, Montgomery domain conversion and the like. The method comprises the following steps of: decomposing five types of polynomials of an original three-term expression, square difference, square sum, cubic difference and cubic sum according to levels and a specific sequence, then selecting negative values of constant term parts of partial polynomials to form a rotation factor table of positive number theory transformation, and then calculating a rotation factor table used by inverse number theory transformation according to the rotation factor table of the positive number theory transformation, and finally, converting the twiddle factor table data to the Montgomery domain to obtain a final twiddle factor table. According to the technical scheme, the implementation efficiency of number theory transformation can be remarkably improved, and finer granularity and a wider range are provided for selection of lattice-based password parameters; and the efficiency of anti-quantum encryption, decryption and signature algorithms is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a method for generating a rotation factor table for number-theoretic transformation. Background Art

[0002] The development of quantum computers has opened the post-quantum cryptography era. Lattice-based cryptography is a public-key cryptosystem that resists quantum computing and has attracted much attention. Due to its outstanding balance in terms of security, communication bandwidth, and computing efficiency, it has become the most promising post-quantum cryptography scheme. In most lattice-based cryptography schemes, number-theoretic transformation (including forward number-theoretic transformation and inverse number-theoretic transformation) calculations play an important role.

[0003] The existing technologies mainly focus on the overall circuit structure design, data flow and memory access design, and butterfly transformation design for forward number-theoretic transformation and inverse number-theoretic transformation. Moreover, in order to improve the speed of number-theoretic transformation calculations, they are all completed under the condition that the rotation factor table has been pre-calculated, but the specific generation method of the rotation factor table has not been described in detail.

[0004] In addition, since the polynomial degree n involved in most lattice cryptography schemes is often in the form of a power of 2, the research on number-theoretic transformation in the form of a power of 2 is sufficient. However, the number of n in the form of a power of 2 with appropriate size is limited. In order to select more detailed parameters suitable for number-theoretic transformation under a given security level, the research on number-theoretic transformation with n = 2 u 3 v and the corresponding method for generating the rotation factor table are of great significance for the rapid implementation of lattice-based cryptography schemes. Summary of the Invention

[0005] The technical problem solved by the present invention is: for the number-theoretic transformation on the polynomial ring a method for generating a rotation factor table for this number-theoretic transformation is proposed to improve the performance of number-theoretic transformation in software implementation and hardware implementation.

[0006] The technical solution of the present invention is: a method for generating a rotation factor table for number-theoretic transformation, which is used to generate the rotation factor tables for forward number-theoretic transformation and inverse number-theoretic transformation on the polynomial ring where the modulus q is a prime number and satisfies the condition q ≡ 1 mod m, m = 2 u 3 v:1 , u ≥ 1, v ≥ 1, and both are integers, is the Euler's totient function, Z represents the ring of integers, Z q represents the finite field with q elements, x is the independent variable in the polynomial, is a polynomial, is a polynomial ring with coefficients in Z q , is Zq The unit group of; including the following steps:

[0007] Step 1: Key data generation: including generating the following data, An m-th primitive root of unity ζ in, the expression of -1 with respect to ζ, the 6-th primitive root of unity η and η 5 The expression of ζ, the 3-th primitive root of unity μ and μ 2 The expression of ζ, the Montgomery transformation constant R, for direct use in subsequent steps;

[0008] Step 2: Polynomial decomposition and data selection: Layer-by-layer decompose the original trinomial During the decomposition process, according to the decomposition result of the previous layer, use the difference of squares, sum of squares, difference of cubes or sum of cubes decomposition method for this layer of decomposition, and select the negative value of the constant term in the first binomial after each decomposition to form the positive number theory transformation rotation factor table;

[0009] Step 3: Inverse number theory transformation data calculation: According to the positive number theory transformation rotation factor table, first take the inverse of the elements in the table and then obtain the inverse number theory transformation rotation factor table in the order of inverse order between layers and positive order within layers;

[0010] Step 4: Montgomery domain conversion: Convert the elements in the positive number theory transformation rotation factor table and the inverse number theory transformation rotation factor table to the Montgomery domain to obtain the final rotation factor table.

[0011] Furthermore, in the said Step 1, key data generation, includes the following sub-steps:

[0012] Step 1-1: Use the calculation method of integer modulo prime order to obtain An element of order q - 1 in, then this element is The generator g of;

[0013] Step 1-2: Calculate The m-th primitive root of unity of Then the following formula holds:

[0014] ζ m ≡1 mod q

[0015]

[0016] ζ i ≠ζ j mod q, 0 ≤ i < j ≤ m - 1

[0017] Step 1-3: The 6-th primitive root of unity of and

[0018] Step 1-4: The 3rd primitive root of unity μ 2 ≡ζ 2n mod q;

[0019] Steps 1 - 5: Select the Montgomery transformation constant R according to the bit width of q, requiring R > q and gcd(R, q) = 1; often select R = 2 16 or 2 32 .

[0020] Furthermore, in step 2, polynomial decomposition and data selection include the following sub - steps:

[0021] Step 2 - 1: First - layer decomposition and selection, decompose the initial trinomial into two binomials,

[0022]

[0023] Select the negative value of the constant term in the first binomial, that is

[0024] Step 2 - 2: Second - layer to u - th layer decomposition and selection. If the degree of the binomial obtained from the previous - layer decomposition is odd, go to step 2 - 3; if it is even, perform the following operations on each newly obtained binomial in order from left to right:

[0025] If the binomial is in the form of (x 2d -ζ 2f ), that is, the sign of the constant term is negative, then decompose it according to the difference - of - squares decomposition method,

[0026] (x 2d -ζ 2f )≡(x d -ζ f )(x d +ζ f ) mod q

[0027] Select the negative value of the constant term in the first binomial, that is ζ f ;

[0028] If the binomial is in the form of (x 2d +ζ 2f ), that is, the sign of the constant term is positive, then decompose it according to the sum - of - squares decomposition method,

[0029]

[0030] Select the negative value of the constant term in the first binomial, that is

[0031] After completing the decomposition and selection of the polynomial for this layer, return to step 2 - 2 to enter the next layer;

[0032] Step 2-3: Decomposition and selection from the (u + 1)-th layer to the (u + v)-th layer. If the degree of the binomial obtained from the decomposition of the previous layer is a multiple of 3, then perform the following operations on each newly obtained binomial in sequence from left to right:

[0033] If the binomial is in the form of (x 3d - ζ 3f ), that is, the sign of the constant term is negative, then decompose it according to the method of difference of cubes,

[0034] (x 3d - ζ 3f ) ≡ (x d - ζ f )(x d - μζ f )(x d - μ 2 ζ f ) mod q

[0035] ≡ (x d - ζ f )(x d - ζ n · ζ f )(x d - ζ 2n · ζ f ) mod q

[0036] ≡ (x d - ζ f )(x d - ζ f:n )(x d - ζ f:2n ) mod q

[0037] Select the negative value of the constant term in the first binomial, that is, ζ f ;

[0038] If the binomial is in the form of (x 3d + ζ 3f ), that is, the sign of the constant term is positive, then decompose it according to the method of sum of cubes,

[0039]

[0040] Select the negative value of the constant term in the first binomial, that is,

[0041] After completing the decomposition and selection of the polynomial of this layer, return to Step 2-3 to enter the next layer;

[0042] After completing the entire Step 2, form a rotation factor table for the positive number theory transform from the selected values in the selection order:

[0043]

[0044] where ζ i,j represents the j-th value selected in the i-th layer, and the number of values selected in the i-th layer are respectively:

[0045]

[0046] Furthermore, for the inverse number-theoretic transform data calculation, in step find the inverse element of each element in the table in , and arrange them in the order of reverse order between layers and positive order within layers to obtain the rotation factor table used in the inverse number-theoretic transform:

[0047]

[0048] Furthermore, for the Montgomery domain conversion, multiply each element in the rotation factor tables of the positive number-theoretic transform and the inverse number-theoretic transform in by the Montgomery transformation constant R to obtain the final rotation factor table used:

[0049]

[0050] The present invention also provides a method for quickly implementing lattice-based cryptography. The cryptography implementation process includes three steps: key generation, plaintext encryption, and ciphertext decryption. When performing multiplication operations on the polynomial ring in these three steps, use the rotation factor table generation method for number-theoretic transform as described above to perform number-theoretic transform.

[0051] The present invention also provides a communication system, including four modules: a source and a destination, a transmitting device, a channel, and a receiving device. When performing encoding, encryption operations in the transmitting device and decoding, decryption operations in the receiving device, use the rotation factor table generation method for number-theoretic transform as described above to perform number-theoretic transform.

[0052] The present invention also provides an image processing system, including five modules: image preprocessing, frequency domain transformation, compression coding, feature extraction and recognition, and security encryption. In the security encryption module, when performing image encryption or digital watermark embedding, use the rotation factor table generation method for number-theoretic transform as described above to perform number-theoretic transform.

[0053] The present invention also provides a rotation factor table generation system for number-theoretic transform, which is used to generate rotation factor tables for positive number-theoretic transform and inverse number-theoretic transform on the polynomial ring where the modulus q is a prime number and satisfies the condition q ≡ 1 mod m, m = 2 u 3 v:1 , u ≥ 1, v ≥ 1, and both are integers, is the Euler's totient function, Z represents the integer ring, Zq Denote \( \mathbb{Z}_q \) as the \( q \)-ary finite field, where \( x \) is the independent variable in the polynomial, and \( \mathbb{Z}_q^* \) q is the multiplicative group of units of \( \mathbb{Z}_q \); it includes the following modules:

[0054] A key data generation module, which is used to generate the following data, an \( m \)-th primitive root of unity \( \zeta \) in \( \mathbb{Z}_q^* \), the expression of \(-1 \) with respect to \( \zeta \), a 6-th primitive root of unity \( \eta \) and the expression of \( \eta \) 5 with respect to \( \zeta \), a 3-th primitive root of unity \( \mu \) and the expression of \( \mu \) 2 with respect to \( \zeta \), and the Montgomery transformation constant \( R \), for direct use in subsequent steps;

[0055] A polynomial decomposition and data selection module, which is used to decompose the original trinomial layer by layer During the decomposition process, according to the decomposition result of the previous layer, use the difference of squares, sum of squares, difference of cubes or sum of cubes decomposition method for this layer of decomposition, and select the negative value of the constant term in the first binomial after each decomposition to form the positive number theory transform rotation factor table;

[0056] An inverse number theory transform data calculation module, according to the positive number theory transform rotation factor table, first takes the inverse of the elements in the table and then arranges them in the order of inverse order between layers and positive order within layers to obtain the inverse number theory transform rotation factor table;

[0057] A Montgomery domain conversion module, which converts the elements in the positive number theory transform rotation factor table and the inverse number theory transform rotation factor table to the Montgomery domain to obtain the final rotation factor table.

[0058] The advantages of the present invention compared with the prior art are as follows:

[0059] (1) The present invention proposes a method for generating a rotation factor table in the Montgomery domain for the number theory transform on the polynomial ring when \( n = 2 \) u 3 v This can significantly improve the implementation efficiency of the number theory transform, and provide a finer granularity and a wider range for the selection of lattice-based cryptographic parameters. The present invention improves the efficiency of quantum-resistant encryption, decryption, and signature algorithms, and also has important applications in communication systems, image processing, and cryptographic devices.

[0060] (2) The present invention proposes a method for decomposing polynomials and selecting data in layers and categories, clearly and systematically describes the generation process of the elements in the rotation factor table, and arranges the elements in the inverse number theory transform rotation factor table by first taking the inverse of the elements in the positive number theory transform rotation factor table and then arranging them in the order of inverse order between layers and positive order within layers, which solves the problem of chaotic data item order and error-proneness in the rotation factor table, and greatly reduces the generation difficulty. Brief Description of the Drawings

[0061] Figure 1 Calculation step diagram of rotation factor table;

[0062] Figure 2 Schematic diagram of polynomial factorization and data selection;

[0063] Figure 3 Trinomial factorization and data selection diagram;

[0064] Figure 4 Difference of squares factorization and data selection diagram;

[0065] Figure 5 Sum of squares factorization and data selection diagram;

[0066] Figure 6 Difference of cubes factorization and data selection diagram;

[0067] Figure 7 Sum of cubes factorization and data selection diagram. Specific implementation manner

[0068] In order to better understand the technical solution of the present invention, the specific implementation manner of the present invention will be described below.

[0069] The present invention discloses a method for generating a rotation factor table for number-theoretic transform. The generation method is mainly based on the factorization of polynomials over a finite field to generate rotation factor tables for positive number-theoretic transform and inverse number-theoretic transform on a specific polynomial ring where the modulus q is a prime number and satisfies the condition q≡1 mod m, m = 2 u 3 v:1 , u≥1, v≥1, and both are integers, and φ is the Euler's totient function.

[0070] In this example, referring to Figure 1 , the specific implementation process is as follows:

[0071] First, specific parameter values are given: u = 3, v = 2

[0072] m = 216 = 2 3 ·3 3

[0073] n = 72 = 2 3 ·3 2

[0074] q = 433

[0075] Step 1, key data generation:

[0076] Step 1-1: Obtain the generator g = 5 of

[0077] Step 1-2: Calculate The 216th primitive root of unity

[0078]

[0079] Step 1-3: The 6th primitive root of unity

[0080]

[0081] η 5 ≡ζ 180 mod 433

[0082] Step 1-4: The 3rd primitive root of unity μ≡ζ n ≡ζ 72 mod 433, μ 2 ≡ζ 144 mod 433;

[0083] Step 1-5: Select the Montgomery transformation constant R = 2 according to the bit width of q 16 ;

[0084] Step 2, polynomial decomposition and data selection, the overall process is as Figure 2 , first for Figure 2 The content description is as follows: (1) The first layer decomposes the original trinomial into two binomials, and the degree of the decomposed binomial is 1 / 2 of the degree of the original trinomial; (2) For the 2nd to u-th layers, each binomial of the previous layer is decomposed into two binomials, and the degree of the decomposed binomial is 1 / 2 of the degree of the original binomial; (3) For the u+1-th to u+v-th layers, each binomial of the previous layer is decomposed into three binomials, and the degree of the decomposed binomial is 1 / 3 of the degree of the original binomial; (4) The blue part is the polynomial position where the data is selected after decomposing the polynomial.

[0085] Step 2 is specifically carried out according to the following steps:

[0086] Step 2-1: The first layer decomposition and selection are as Figure 3 shown, decompose the initial trinomial into 2 binomials,

[0087] (x 72 -x 36 +1)≡(x 36 -η)(x 36 -η 5 )≡(x 36 -ζ 36 )(x 36 -ζ 180 )mod q Select the negative value of the constant term in the first binomial, that is, ζ 36 , at this time Step 2-2 First Round: Decomposition and Selection of the Second Layer. The two binomials obtained from the first-layer decomposition have an even degree of 36 and are processed in the order from left to right:

[0088] (1) For the first binomial (x 36 -ζ 36 ), decompose it according to Figure 4 the difference-of-squares decomposition method,

[0089] (x 36 -ζ 36 ) ≡ (x 18 -ζ 18 )(x 18 +ζ 18 ) mod 433

[0090] Select the negative value of the constant term in the first binomial (x 18 -ζ 18 ), which is ζ 18 ;

[0091] (2) For the second binomial (x 36 -ζ 180 ), decompose it according to Figure 4 the difference-of-squares decomposition method,

[0092] (x 36 -ζ 180 ) ≡ (x 18 -ζ 90 )(x 18 +ζ 90 ) mod 433

[0093] Select the negative value of the constant term in the first binomial (x 18 -ζ 90 ), which is ζ 90 ;

[0094] After the second-layer decomposition, the following 4 binomials of degree 18 are obtained and can continue the decomposition in Step 2-2:

[0095] (x 72 -x 36 +1) ≡ (x 18 -ζ 18 )(x 18 +ζ 18 )(x 18 -ζ 90 )(x 18 +ζ 90 ) mod 433 At this time Step 2-2 Second Round: Decomposition and Selection of the Third Layer. The 4 binomials obtained from the second-layer decomposition have an even degree of 18 and are processed in the order from left to right:

[0096] (1) For the first binomial (x 18 -ζ 18 ), decompose it according to Figure 4 the difference - of - squares decomposition method,

[0097] (x 18 -ζ 18 )≡(x 9 -ζ 9 )(x 9 +ζ 9 ) mod 433

[0098] Select the negative value of the constant term in the first binomial (x 9 -ζ 9 ), that is, ζ 9 ;

[0099] (2) For the second binomial (x 18 +ζ 18 ), decompose it according to Figure 5 the sum - of - squares decomposition method,

[0100] (x 18 +ζ 18 )≡(x 18 -ζ 108 ·ζ 18 )≡(x 9 -ζ 63 )(x 9 +ζ 63 ) mod 433

[0101] Select the negative value of the constant term in the first binomial (x 9 -ζ 63 ), that is, ζ 63 ;

[0102] (3) For the third binomial (x 18 -ζ 90 ), decompose it according to Figure 4 the difference - of - squares decomposition method,

[0103] (x 18 -ζ 90 )≡(x 9 -ζ 45 )(x 9 +ζ 45 ) mod 433

[0104] Select the negative value of the constant term in the first binomial (x 9 -ζ 45 ), that is, ζ 45 ;

[0105] (4) For the 4th binomial \((x 18 +\zeta 90 )\), decompose it according to the Figure 5 sum of squares decomposition method,

[0106] (x 18 +\zeta 90 )\equiv(x 18 -\zeta 108 \cdot\zeta 90 )\equiv(x 9 -\zeta 99 )(x 9 +\zeta 99 )\bmod 433

[0107] Select the negative value of the constant term in the first binomial \((x 9 -\zeta 99 ), that is, \zeta 99 ;

[0108] After the third - layer decomposition, the following 8 ninth - degree binomials are obtained and cannot be further decomposed in step 2 - 2:

[0109] (x 72 -x 36 + 1)

[0110] \equiv(x 9 -\zeta 9 )(x 9 +\zeta 9 )(x 9 -\zeta 63 )(x 9 +\zeta 63 )(x 9 -\zeta 45 )(x 9 +\zeta 45 )(x 9 -\zeta 99 )(x 9 +\zeta 99 )\bmod 433

[0111] At this time Step 2 - 3, the first round: Fourth - layer decomposition and selection. The degrees of the 8 binomials obtained from the third - layer decomposition are multiples of 3 (9). Perform in the order from left to right:

[0112] (1) For the 1st binomial \((x 9 -\zeta 9 ), decompose it according to the Figure 6 cubic difference decomposition method,

[0113] (x 9 -\zeta 9 )\equiv(x 3 -\zeta3 )(x 3 -μζ 3 )(x 3 -μ 2 ζ 3 ) mod 433

[0114] ≡ (x 3 -ζ 3 )(x 3 -ζ 72 ·ζ 3 )(x 3 -ζ 144 ·ζ 3 ) mod 433

[0115] ≡ (x 3 -ζ 3 )(x 3 -ζ 75 )(x 3 -ζ 147 ) mod 433

[0116] Select the negative value of the constant term in the first binomial, that is, ζ 3 ;

[0117] (2) For the second binomial (x 9 +ζ 9 ), decompose it according to Figure 7 the sum - of - cubes decomposition method,

[0118] (x 9 +ζ 9 ) ≡ (x 9 -ζ 108 ·ζ 9 ) mod 433

[0119] ≡ (x 3 -ζ 39 )(x 3 -μζ 39 )(x 3 -μ 2 ζ 39 ) mod 433

[0120] ≡ (x 3 -ζ 39 )(x 3 -ζ 72 ·ζ 39 )(x 3 -ζ 144 ·ζ 39 ) mod 433

[0121] ≡ (x 3 -ζ 39)(x 3 -ζ 111 )(x 3 -ζ 183 ) mod 433

[0122] Select the negative value of the constant term in the first binomial, that is, ζ 39 ;

[0123] (3) For the 3rd binomial (x 9 -ζ 63 ), decompose it according to Figure 6 the difference - of - cubes decomposition method,

[0124] (x 9 -ζ 63 ) ≡ (x 3 -ζ 21 )(x 3 -μζ 21 )(x 3 -μ 2 ζ 21 ) mod 433

[0125] ≡ (x 3 -ζ 21 )(x 3 -ζ 72 ·ζ 21 )(x 3 -ζ 144 ·ζ 21 ) mod 433

[0126] ≡ (x 3 -ζ 21 )(x 3 -ζ 93 )(x 3 -ζ 165 ) mod 433

[0127] Select the negative value of the constant term in the first binomial, that is, ζ 21 ;

[0128] (4) For the 4th binomial (x 9 +ζ 63 ), decompose it according to Figure 7 the sum - of - cubes decomposition method,

[0129] (x 9 +ζ 63 ) ≡ (x 3 (x -ζ 111 )(x 3 -ζ 183 ) mod 433

[0122] Select the negative value of the constant term in the first binomial, that is, ζ 39 ;

[0123] (3) For the 3rd binomial (x 9 -ζ 63 ), decompose it according to Figure 6 the difference - of - cubes decomposition method,

[0124] (x 9 -ζ 63 ) ≡ (x 3 -ζ 21 )(x 3 -μζ 21 )(x 3 -μ 2 ζ 21 ) mod 433

[0125] ≡ (x 3 -ζ 21 )(x 3 -ζ 72 ·ζ 21 )(x 3 -ζ 144 ·ζ 21 ) mod 433

[0126] ≡ (x 3 -ζ 21 )(x 3 -ζ 93 )(x 3 -ζ 165 ) mod 433

[0127] Select the negative value of the constant term in the first binomial, that is, ζ 21 ;

[0128] (4) For the 4th binomial (x 9 +ζ 63 ), decompose it according to Figure 7 the sum - of - cubes decomposition method,

[0129] (x 9 +ζ 63 ) ≡ (x 3 -ζ 108 ·ζ 63 ) mod 433

[0130] ≡ (x 3 -ζ 57)(x 3 -μζ 57 )(x 3 -μ 2 ζ 57 ) mod 433

[0131] ≡ (x 3 -ζ 57 )(x 3 -ζ 72 ·ζ 57 )(x 3 -ζ 144 ·ζ 57 ) mod 433

[0132] ≡ (x 3 -ζ 57 )(x 3 -ζ 129 (x 3 -ζ 201 ) mod 433

[0133] Select the negative value of the constant term in the first binomial, i.e., ζ 57 ;

[0134] (5) For the 5th binomial (x 9 -ζ 45 ), decompose it according to Figure 6 the cubic difference decomposition method,

[0135] (x 9 -ζ 45 ) ≡ (x 3 -ζ 15 (x 3 -μζ 15 (x 3 -μ 2 ζ 15 ) mod 433

[0136] ≡ (x 3 -ζ 15 (x 3 -ζ 72 ·ζ 15 (x 3 -ζ 144 ·ζ 15 ) mod 433

[0137] ≡ (x 3 -ζ 15 (x 3 -ζ 87 (x 3 -ζ 159 ) mod 433

[0138] Select the negative value of the constant term in the first binomial, i.e., ζ 15 ;

[0139] (6) For the 6th binomial (x 9 + ζ 45 ), decompose it according to Figure 7 the sum - of - cubes decomposition method,

[0140] (x 9 + ζ 45 ) ≡ (x 3 - ζ 108 ·ζ 45 ) mod 433

[0141] ≡ (x 3 - ζ 51 )(x 3 - μζ 51 )(x 3 - μ 2 ζ 51 ) mod 433

[0142] ≡ (x 3 - ζ 51 )(x 3 - ζ 72 ·ζ 51 )(x 3 - ζ 144 ·ζ 51 ) mod 433

[0143] ≡ (x 3 - ζ 51 )(x 3 - ζ 123 )(x 3 - ζ 195 ) mod 433

[0144] Select the negative value of the constant term in the first binomial, i.e., ζ 51 ;

[0145] (7) For the 7th binomial (x 9 - ζ 99 ), decompose it according to Figure 6 the difference - of - cubes decomposition method,

[0146] (x 9 - ζ 99 ) ≡ (x 3 - ζ 33 )(x 3 - μζ 33 )(x 3 - μ 2 ζ 33 ) mod 433

[0147] ≡(x 3 -ζ 33 )(x 3 -ζ 72 ·ζ 33 )(x 3 -ζ 144 ·ζ 33 ) mod 433

[0148] ≡(x 3 -ζ 33 )(x 3 -ζ 105 )(x 3 -ζ 177 ) mod 433

[0149] Select the negative value of the constant term in the first binomial, that is, ζ 33 ;

[0150] (8) For the 8th binomial (x 9 +ζ 99 ), decompose it according to Figure 7 the sum - of - cubes decomposition method,

[0151] (x 9 +ζ 99 ) ≡ (x 3 -ζ 108 ·ζ 99 ) mod 433

[0152] ≡ (x 3 -ζ 69 )(x 3 -μζ 69 )(x 3 -μ 2 ζ 69 ) mod 433

[0153] ≡ (x 3 -ζ 69 )(x 3 -ζ 72 ·ζ 69 )(x 3 -ζ 144 ·ζ 69 ) mod 433

[0154] ≡ (x 3 -ζ 69 )(x 3 -ζ 141 )(x 3 -ζ 213 ) mod 433

[0155] Select the negative value of the constant term in the first binomial, i.e., ζ 69 ;

[0156] After the fourth layer of decomposition, 24 cubic binomials are obtained, and the decomposition in step 2-3 can be continued:

[0157] (x 72 -x 36 +1)

[0158] ≡(x 3 -ζ 3 )(x 3 -ζ 75 )(x 3 -ζ 147 )(x 3 -ζ 39 )(x 3 -ζ 111 )(x 3 -ζ 183 )(x 3

[0159] -ζ 21 )(x 3 -ζ 93 )(x 3 -ζ 165 )(x 3 -ζ 57 )(x 3 -ζ 129 )(x 3 -ζ 201 )(x 3

[0160] -ζ 15 )(x 3 -ζ 87 )(x 3 -ζ 159 )(x 3 -ζ 51 )(x 3 -ζ 123 )(x 3 -ζ 195 )(x 3

[0161] -ζ 33 )(x 3 -ζ 105 )(x 3 -ζ 177 )(x 3 -ζ 69 )(x 3 -ζ 141 )(x 3

[0162] -ζ 213 ) mod 433

[0163] At this time Step 2-3 Second round: Decomposition and selection of the fifth layer. The 24 binomials obtained from the decomposition of the fourth layer have a degree of 3 and are carried out in the order from left to right:

[0164] (1) For the 1st binomial (x 3 -ζ 3 ), decompose it according to Figure 6 the cubic difference decomposition method,

[0165] (x 3 -ζ 3 ) ≡ (x - ζ)(x - μζ)(x - μ 2 ζ) mod 433

[0166] ≡ (x - ζ)(x - ζ 72 ·ζ)(x - ζ 144 ·ζ) mod 433

[0167] ≡ (x - ζ)(x - ζ 73 )(x - ζ 145 ) mod 433

[0168] Select the negative value of the constant term in the first binomial, that is, ζ;

[0169] (2) For the 2nd binomial (x 3 -ζ 75 ), decompose it according to Figure 6 the cubic difference decomposition method,

[0170] (x 3 -ζ 75 ) ≡ (x - ζ 25 )(x - μζ 25 )(x - μ 2 ζ 25 ) mod 433

[0171] ≡ (x - ζ 25 )(x - ζ 72 ·ζ 25 )(x - ζ 144 ·ζ 25 ) mod 433

[0172] ≡ (x - ζ 25 )(x - ζ 97 )(x - ζ 169 ) mod 433

[0173] Select the negative value of the constant term in the first binomial, that is, ζ25 ;

[0174] (3) For the 3rd binomial (x 3 -ζ 147 ), decompose it according to Figure 6 the difference - of - cubes decomposition method,

[0175] (x 3 -ζ 147 ) ≡ (x - ζ 49 )(x - μζ 49 )(x - μ 2 ζ 49 ) mod 433

[0176] ≡ (x - ζ 49 )(x - ζ 121 )(x - ζ 193 ) mod 433

[0177] Select the negative value of the constant term in the first binomial, i.e., ζ 49 ;

[0178] ……

[0179] (22) For the 22nd binomial (x 3 -ζ 69 ), decompose it according to Figure 6 the difference - of - cubes decomposition method,

[0180] (x 3 -ζ 69 ) ≡ (x - ζ 23 )(x - μζ 23 )(x - μ 2 ζ 23 ) mod 433

[0181] ≡ (x - ζ 23 )(x - ζ 95 )(x - ζ 167 ) mod 433

[0182] Select the negative value of the constant term in the first binomial, i.e., ζ 23 ;

[0183] (23) For the 23rd binomial (x 3 -ζ 141 ), decompose it according to Figure 6 the difference - of - cubes decomposition method,

[0184] (x 3 -ζ 141 ) ≡ (x - ζ 47 )(x - μζ 47 )(x - μ 2ζ 47 ) mod 433

[0185] ≡ (x - ζ 47 )(x - ζ 119 )(x - ζ 191 ) mod 433

[0186] Select the negative value of the constant term in the first binomial, i.e., ζ 47 ;

[0187] (24) For the 24th binomial (x 3 - ζ 213 ), decompose it according to Figure 6 the cube difference decomposition method,

[0188] (x 3 - ζ 213 ) ≡ (x - ζ 71 )(x - μζ 71 )(x - μ 2 ζ 71 ) mod 433

[0189] ≡ (x - ζ 71 )(x - ζ 143 )(x - ζ 215 ) mod 433

[0190] Select the negative value of the constant term in the first binomial, i.e., ζ 71 ;

[0191] After the fifth - layer decomposition, 72 first - degree binomials are obtained and the decomposition in step 2 - 3 cannot be continued:

[0192] (x 72 - x 36 + 1)

[0193] ≡ (x - ζ)(x - ζ 73 )(x - ζ 145 )(x - ζ 25 )(x - ζ 97 )(x - ζ 169 ) …… (x

[0194] - ζ 47 )(x - ζ 119 )(x - ζ 191 )(x - ζ 71 )(x - ζ 143 )(x - ζ 215 ) mod 433 At this time

[0195]

[0196] After completing the entire Step 2, a rotation factor table for positive number-theoretic transform composed of the selected values can be obtained:

[0197] Step 3: Inverse number-theoretic transform data calculation: For each element in the table obtained in Step 2, find the inverse element in , and arrange them in reverse order between levels and in forward order within levels, that is, in the order of the 16th to 39th (the 1st to 24th selections in the 5th layer), the 8th to 15th (the 1st to 8th selections in the 4th layer), 4th to 7th (the 1st to 4th selections in the 3rd layer), 2nd to 3rd (the 1st to 2nd selections in the 2nd layer), 1st (the 1st selection in the 1st layer) to obtain the rotation factor table used in the inverse number-theoretic transform:

[0198]

[0199] ζ 201 , ζ 165 , ζ 183 , ζ 147 , ζ 207 , ζ 153 , ζ 171 , ζ 117 , ζ 198 , ζ 126 , ζ 180}

[0200] ={52, 162, 105, 111, 96, 399, 409, 225, 218, 82, 422, 49, 155, 333, 288, 156, 53, 315, 95, 246, 400, 361, 242, 221, 316, 217, 32, 159, 75, 305, 35, 431, 54, 293, 133, 8, 318, 369, 235}

[0201] Step 4: Montgomery domain conversion: Multiply each element in the rotation factor table and by the Montgomery transformation constant R = 2 in 16 to obtain the finally used rotation factor tables tab and tab ;1 :

[0202]

[0203] The present invention also provides a rotation factor table generation system for number-theoretic transform, which is used to generate rotation factor tables for positive number-theoretic transform and inverse number-theoretic transform on the polynomial ring , where the modulus q is a prime number and satisfies the condition q ≡ 1 mod m, m = 2 u 3 v:1, where \(u\geq1\), \(v\geq1\), and both are integers. is the Euler's totient function, \(Z\) represents the ring of integers, \(Z\) q represents the \(q\)-ary finite field, \(x\) is the independent variable in the polynomial, is the multiplicative group of units of \(Z\) q ; It includes the following modules:

[0204] The key data generation module is used to generate the following data, an \(m\)-th primitive root of unity \(\zeta\) in, the expression of \(-1\) with respect to \(\zeta\), a 6-th primitive root of unity \(\eta\) and \(\eta\) 5 the expression of \(\eta\) with respect to \(\zeta\), a 3rd primitive root of unity \(\mu\) and \(\mu\) 2 the expression of \(\mu\) with respect to \(\zeta\), the Montgomery transformation constant \(R\), for direct use in subsequent steps;

[0205] The polynomial decomposition and data selection module is used to decompose the original trinomial layer by layer During the decomposition process, according to the decomposition result of the previous layer, use the difference of squares, sum of squares, difference of cubes or sum of cubes decomposition method for this layer of decomposition, and select the negative value of the constant term in the first binomial after each decomposition to form the positive number theory transform rotation factor table;

[0206] The inverse number theory transform data calculation module, according to the positive number theory transform rotation factor table, first takes the inverse of the elements in the table and then obtains the inverse number theory transform rotation factor table in the order of inverse order between layers and positive order within layers;

[0207] The Montgomery domain conversion module converts the elements in the positive number theory transform rotation factor table and the inverse number theory transform rotation factor table to the Montgomery domain to obtain the final rotation factor table.

[0208] The specific module functions are implemented according to the foregoing method.

[0209] The present invention also provides a method for quickly implementing lattice-based cryptography. The cryptography implementation process includes three steps: key generation (generating a public and private key pair), plaintext encryption, and ciphertext decryption (or three steps: key generation, signature, and signature verification). When performing multiplication operations on the polynomial ring in the three steps, use the rotation factor table generation method for number theory transform as described above to perform number theory transform.

[0210] The present invention also provides a communication system, including four modules: a source and a destination, a transmitting device, a channel, and a receiving device. In the encoding, encryption operations of the transmitting device and the decoding, decryption operations of the receiving device, use the rotation factor table generation method for number theory transform as described above to perform number theory transform.

[0211] The present invention also provides an image processing system, which includes five modules: image preprocessing, frequency domain transformation, compression encoding, feature extraction and recognition, and security encryption. In the security encryption module, when performing image encryption or digital watermark embedding, the method for generating the rotation factor table for number theory transformation as described above is used to perform number theory transformation.

[0212] It can be understood that the present invention is described through embodiments. Those skilled in the art know that, without departing from the spirit and scope of the present invention, various changes or equivalent replacements can be made to these features and embodiments. Additionally, under the teaching of the present invention, these features and embodiments can be modified to adapt to specific situations without departing from the spirit and scope of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed herein, and the embodiments that can fall within the scope of the claims of this application all belong to the scope protected by the present invention.

[0213] The content not detailedly described in the specification of the present invention belongs to the well-known technology of those skilled in the art.

Claims

1. A method for generating a rotation factor table for number-theoretic transform, characterized in that: For generating a polynomial ring The rotation factor table for the positive number theoretic transform and the inverse number theoretic transform on it, where the modulus q is a prime number and satisfies the condition q ≡ 1 mod m, m = 2 u 3 v:1 , u ≥ 1, v ≥ 1, and both are integers, is the Euler's totient function, Z represents the ring of integers, Z q represents the finite field with q elements, x is the independent variable in the polynomial, is the multiplicative group of units of Z q ; The method includes the following steps: Key data generation: including generating the following data, An m-th primitive root of unity ζ in one of them, the expression of -1 in terms of ζ, the 6-th primitive root of unity η and η 5 The expression of ζ in terms of μ, the 3rd primitive root of unity μ and μ 2 The expression of ζ in terms of μ, the Montgomery transformation constant R, for direct use in subsequent steps; Polynomial Decomposition and Data Selection: Decompose the original trinomial layer by layer During the decomposition process, according to the decomposition results of the previous layer, use the difference of squares, sum of squares, difference of cubes or sum of cubes decomposition methods for this layer of decomposition, select the negative value of the constant term in the first binomial after each decomposition, and form a positive number theory transformation rotation factor table; Inverse number-theoretic transform data calculation: According to the positive number-theoretic transform rotation factor table, first take the inverse of the elements in the table, and then obtain the inverse number-theoretic transform rotation factor table in the order of inverse order between layers and positive order within layers. Montgomery domain conversion: Convert the elements in the positive number-theoretic transform rotation factor table and the inverse number-theoretic transform rotation factor table to the Montgomery domain to obtain the final rotation factor table.

2. The method for generating a rotation factor table for number theory transform according to claim 1, characterized in that: The generation of the key data includes: Calculation for the generator g; Calculation m-th primitive root of unity Expression of -1 in terms of ζ: Calculation 6th primitive root of unity Calculation The 3rd primitive root of unity μ 2 ≡ζ 2n mod q; Select the Montgomery transformation constant R according to the bit width of q, requiring R > q and gcd(R, q) = 1; gcd() represents the greatest common divisor.

3. The method for generating a rotation factor table for number-theoretic transform according to claim 2, characterized in that: Obtain by using the calculation method of the order of an integer modulo a prime number an element of order q - 1, and this element is the generator g of 4. The method for generating a rotation factor table for number-theoretic transform according to claim 1, wherein: The polynomial decomposition and data selection are specifically as follows: Step 2-1: First-layer decomposition and selection, decompose the original trinomial into two binomials: Select the negative value of the constant term in the first binomial, i.e., Step 2-2: Second-layer to u-layer decomposition and selection, if the degree of the binomial obtained from the previous layer decomposition is odd, go to Step 2-3; if it is even, perform the following operations on each newly obtained binomial in sequence from left to right: If the binomial is in the form of (x 2d -ζ 2f ), that is, the sign of the constant term is negative, decompose it according to the difference of squares decomposition method: (x 2d -ζ 2f )≡(x d -ζ f )(x d +ζ f ) mod q Select the negative value of the constant term in the first binomial, i.e., ζ f ; If the binomial is in the form of (x 2d +ζ 2f ), that is, the sign of the constant term is positive, decompose it according to the sum of squares decomposition method: Select the negative value of the constant term in the first binomial, i.e., After the polynomial decomposition and selection at this level are completed, return to Step 2-2 to enter the next layer; Step 2-3: (u + 1)-layer to (u + v)-layer decomposition and selection, if the degree of the binomial obtained from the previous layer is a multiple of 3, perform the following operations on each newly obtained binomial in sequence from left to right: If the binomial is in the form of (x 3d -ζ 3f ), that is, the sign of the constant term is negative, decompose it according to the cube difference decomposition method: (x 3d - ζ 3f ) ≡ (x d - ζ f )(x d - μζ f )(x d - μ 2 ζ f ) mod q ≡(x d -ζ f )(x d -ζ n ·ζ f )(x d -ζ 2n ·ζ f ) mod q ≡(x d -ζ f )(x d -ζ f:n )(x d -ζ f:2n ) mod q Select the negative value of the constant term in the first binomial, i.e., ζ f ; If the binomial is in the form of (x 3d + ζ 3f ), that is, the sign of the constant term is positive, it is decomposed according to the sum - of - cubes decomposition method: Select the negative value of the constant term in the first binomial, i.e., After the polynomial decomposition and selection at this level are completed, return to Step 2-3 to enter the next layer; Until the degree of the obtained binomial is not a multiple of 3, complete the polynomial decomposition and data selection, and form the rotation factor table for the positive number-theoretic transform from the selected values in the selection order: where ζ i,j represents the j-th value selected in the i-th layer, and the number of values selected in the i-th layer is:

5. The method for generating a rotation factor table for number-theoretic transform according to claim 4, wherein: The inverse number-theoretic transform data calculation is specifically as follows: The obtained in each element of the table finds the inverse element and arranges them in the order of reverse between levels and forward within levels to obtain the rotation factor table used in the inverse number theory transform:

6. The method for generating a rotation factor table for number-theoretic transform according to claim 5, characterized in that: The Montgomery domain conversion is specifically as follows: Multiply each element in the rotation factor tables of the positive number theory transformation and the inverse number theory transformation by the Montgomery transformation constant R in to obtain the finally used rotation factor table:

7. A fast implementation method of lattice-based cryptography. The process of cryptography implementation includes three steps: key generation, plaintext encryption, and ciphertext decryption, and is characterized in that: When performing multiplication operations on the polynomial ring in the above three steps, use the rotation factor table generation method for number-theoretic transform as described in any one of claims 1 to 6 to perform number-theoretic transform.

8. A communication system includes four modules: a source, a destination, a transmitting device, a channel, and a receiving device, characterized in that: In the encoding, encryption operations of the sending device and the decoding, decryption operations of the receiving device, use the rotation factor table generation method for number-theoretic transform as described in any one of claims 1 to 6 to perform number-theoretic transform.

9. An image processing system includes five modules: image preprocessing, frequency domain transformation, compression coding, feature extraction and recognition, and security encryption, and is characterized in that: In the security encryption module, when performing image encryption or digital watermark embedding, use the rotation factor table generation method for number-theoretic transform as described in any one of claims 1 to 6 to perform number-theoretic transform.

10. A rotation factor table generation system for number-theoretic transform, characterized in that: For generating a polynomial ring The rotation factor table for the number-theoretic transform and inverse number-theoretic transform over , where the modulus q is a prime number and satisfies the condition q ≡ 1 mod m, m = 2 u 3 v:1 , u ≥ 1, v ≥ 1, and both are integers is the Euler's totient function, Z represents the ring of integers, Z q represents the finite field with q elements, x is the independent variable in the polynomial is the multiplicative group of units of Z q ; including the following modules: A key data generation module for generating the following data, an m-th primitive root of unity ζ in one of them, the expression of -1 with respect to ζ, the 6-th primitive roots of unity η and η 5 the expression of μ with respect to ζ, the 3-th primitive roots of unity μ and μ 2 the expression of μ with respect to ζ, the Montgomery transformation constant R, for direct use in subsequent steps; Polynomial decomposition and data selection module, which is used to decompose the original trinomial layer by layer During the decomposition process, according to the decomposition results of the previous layer, the square difference, sum of squares, cube difference or sum of cubes decomposition method is used for the decomposition of this layer, and the negative value of the constant term in the first binomial after each decomposition is selected to form a positive number theory transformation rotation factor table; Inverse number-theoretic transform data calculation module, according to the positive number-theoretic transform rotation factor table, first take the inverse of the elements in the table, and then obtain the inverse number-theoretic transform rotation factor table in the order of inverse order between layers and positive order within layers. Montgomery domain conversion module, convert the elements in the positive number-theoretic transform rotation factor table and the inverse number-theoretic transform rotation factor table to the Montgomery domain to obtain the final rotation factor table.