Non-transitory computer readable medium, decryption device and communication system
By selectively modifying the coefficients of the transmitted messages in the decryption device and decrypting, the problem that the security of the public key encryption algorithm in the quantum computing environment is solved, and flexible control of the error size in the encryption device is realized, ensuring the security of the encryption algorithm.
Patent Information
- Application Number
- CN202011087792.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-12-23
- Filing Date
- 2020-10-12
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2040-10-12
AI Technical Summary
In a quantum computing environment, the security of public key encryption algorithms is threatened by the computing power of quantum computers, and post-quantum cryptography may have weaknesses, resulting in decryption errors that limit the error size used in encryption devices.
By selectively modifying the coefficients of the transmission message in the decryption device, the modified transmission message is generated and decrypted, the limitation of the error size of the decryption error is avoided.
It effectively solves the problem that the error size used in encryption devices is limited by the decryption error, and ensures that the security of the encryption algorithm is not limited by the error size.
Smart Images

Figure CN113098680B_ABST
Abstract
Description
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This patent application claims the benefit of Korean Patent Application No. 10-2019-0172720, filed on December 23, 2019, which is hereby incorporated by reference in its entirety. Technical Field
[0003] Example embodiments of the inventive concepts relate to a non-transitory computer-readable medium storing a program code, a decryption device, and / or a communication system including the encryption device and the decryption device. Background Art
[0004] Public key encryption algorithms such as RSA (Rivest, Shamir, Adleman) algorithm are based on the difficulty of factorization or discrete logarithm problems. However, due to the Shor algorithm using quantum computers that perform quantum computing, the security of public key encryption algorithms may be greatly compromised due to the computing power of quantum computers. The National Institute of Standards and Technology (NIST) has standardized public key encryption algorithms that are secure in quantum computing environments, however, this post-quantum cryptography may have weaknesses. Summary of the invention
[0005] Example embodiments of the inventive concepts provide a non-transitory computer-readable medium storing a program code, a decryption device, and / or a communication system including the encryption device and the decryption device.
[0006] According to some example embodiments, a non-transitory computer-readable medium stores program code that, when executed by a processor, causes the processor to: calculate a message based on a first ciphertext, a second ciphertext, and a private key; compare coefficients of the message with reference values to generate a comparison result, the reference value being based on a prime number; based on the message, generate a modified message by selectively modifying coefficients of the message based on the comparison result; and decrypt the modified message.
[0007] According to some example embodiments, a decryption device includes a processing circuit configured to: calculate a message based on a first ciphertext, a second ciphertext, and a private key; compare coefficients of the message with reference values to generate a comparison result, the reference value being based on a prime number; based on the message, generate a modified message by selectively modifying the coefficients based on the comparison result; and decrypt the modified message.
[0008] According to some example embodiments, a communication system includes an encryption device and a decryption device. The encryption device may be configured to: calculate a first ciphertext based on a first public key; and calculate a second ciphertext based on a second public key and a plaintext message. The decryption device may be configured to: sample a private key based on a first normal distribution; sample the first public key according to a polynomial ring; calculate the second public key based on the private key and the first public key; receive the first ciphertext and the second ciphertext from the encryption device in response to sending the first public key and the second public key to the encryption device; generate a transmission message based on the first ciphertext, the second ciphertext and the private key; compare the coefficients of the transmission message with a reference value to generate a comparison result, the reference value being based on a prime number; based on the transmission message, generate a modified transmission message by selectively modifying the coefficients of the transmission message based on the comparison result; and decrypt the modified transmission message. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] The above and other objects and features of the present inventive concept will become more apparent by describing in detail some exemplary embodiments of the present inventive concept with reference to the attached drawings.
[0010] Figure 1 is a block diagram illustrating a communication system according to some example embodiments of the inventive concept.
[0011] Figure 2 It shows Figure 1 Flow chart of a method of operating a communication system.
[0012] Figure 3 is shown in more detail Figure 2 FIG. 1 is a flowchart of detailed operations of operation S180 .
[0013] Figure 4 is a diagram showing in more detail some example embodiments of the present invention. Figure 1 Block diagram of the communication system.
[0014] Figure 5 is a diagram showing in more detail some example embodiments of the present invention. Figure 1 Block diagram of the communication system.
[0015] Figure 6 It shows Figure 5 Block diagram of the key generation circuit.
[0016] Figure 7 It shows Figure 5 Block diagram of the decryption circuit.
[0017] Figure 8 It shows Figure 5 Block diagram of the encryption circuit.
[0018] Fig. 9is a block diagram illustrating an encryption / decryption device according to some example embodiments of the inventive concept.
[0019] Fig.10 is a block diagram illustrating an encryption / decryption device according to some example embodiments of the inventive concept.
[0020] Fig.11 is a block diagram illustrating an electronic device according to some example embodiments of the inventive concept.
[0021] Fig.12 is a block diagram illustrating a communication system according to some example embodiments of the inventive concept. DETAILED DESCRIPTION
[0022] Hereinafter, some exemplary embodiments of the inventive concept will be described clearly and in detail so that those skilled in the art can easily realize the inventive concept.
[0023] Fig.12 is a block diagram illustrating a communication system according to some example embodiments of the inventive concept.
[0024] refer to Figure 1 , the communication system 1000 may include a decryption device 1100 and an encryption device 1200. According to some example embodiments of the inventive concepts, the decryption device 1100 and the encryption device 1200 may communicate with each other based on an encryption algorithm.
[0025] The encryption algorithm used in the communication system 1000 may be based on a public key encryption algorithm. The public key encryption algorithm may be an asymmetric encryption algorithm that uses a public key for encryption and a private (eg, secret) key for decryption without using the same key for encryption and decryption.
[0026] The communication system 1000 according to some example embodiments of the inventive concept may use a ring learning with error (RLWE) encryption algorithm, which is a grid-based learning with error (LWE) encryption algorithm, as post-quantum cryptography that ensures security even in a quantum computer environment. The RLWE encryption algorithm can not only provide improved security, but also support homomorphic encryption that can search or analyze data. Homomorphic encryption is an encryption technology that can perform operations on encrypted data without decryption. An operation result can be generated when an operation is performed on data, and a first result can be generated when a subsequent operation result is encrypted. A second result can be generated when the same operation is performed on the encrypted data. Based on homomorphic encryption, the first result can be the same as the second result. Similarly, a third result can be generated when an operation is performed on data. An operation result can be generated when the same operation is performed on the encrypted data, and a fourth result can be generated when the subsequent operation result is decrypted. Based on homomorphic encryption, the third result can be the same as the fourth result.
[0027] The RLWE encryption algorithm of the communication system 1000 may include key generation, encryption operation, and decryption operation. The key generation and decryption operations may be performed (implemented) by the decryption device 1100, and the encryption operation may be performed by the encryption device 1200.
[0028] The decryption device 1100 may sample the private key "s" according to the normal distribution x. For example, the normal distribution x may be a discrete Gaussian error distribution. For example, the standard deviation σ of the normal distribution x may be less than "2", but the scope of the inventive concept is not limited thereto. The decryption device 1100 may sample the error "e" according to the normal distribution x. The error "e" may be used to generate the public key a 0 . This error can also be called noise.
[0029] Assume f(x) = x n + 1, n = 2 k , “n” is a security parameter, “k” is a natural number, R = Z[x] / f(x), and R q = Z q [x] / f(x). f(x) may also be called a reference polynomial. "R" may be a ring of integer polynomials modulo f(x). For example, the elements of the ring R may be represented by integer polynomials of degree less than n. R q can be a ring of integer polynomials modulo f(x) and q. Where "q" can be a prime number satisfying q ≡ 1 mod 2n, and "≡" can represent congruence. For example, the ring R q The elements of can be represented by integer polynomials of degree less than n and coefficients less than q.
[0030] The decryption device 1100 can be configured according to the ring R q Sampling and generating public key a 1 The decryption device 1100 can be based on the public key a 1 and error e to calculate and generate the public key a 0 For example, the decryption device 1100 may be configured to decrypt the public key a 1 Multiply the private key s, multiply the parameter "t" by the error e, and add the two multiplication results to calculate the public key a 0 For example, a 0 Can be a 0 = -(a 1 *s + t*e). The decryption device 1100 may invert the sign of the addition result, or may also perform a multiplication operation or a subtraction operation on the addition result. The parameter t may be a predetermined integer and may be used to define a space of the message m described below.
[0031] The encryption device 1200 can sample the errors u, g, and h according to the normal distribution χ. The encryption device 1200 can sample the errors u, g, and h according to the normal distribution χ. 0 , errors u and g, parameter t and message m to calculate and generate ciphertext c 0 The message may also be called data, plaintext, plaintext message, etc. The space of message m may be a ring R q Or Ring R t In the following, although it is assumed that the space ring R of message m t , but the scope of the present invention is not limited thereto. t It can be R t = Z t [x] / f(x). t and q may be relatively prime numbers, and for example, parameter t may be 2, but the scope of the inventive concept is not limited thereto. t R may be a ring of integer polynomials modulo both f(x) and t. For example, the message m may be represented by an integer polynomial of degree less than n and coefficients less than t. The encryption device 1200 may generate the message m by encoding data to be sent to the decryption device 1100. In some example embodiments, the data may be generated internally by the encryption device 1200 or may be received from an external device. The decryption device 1100 may encode the data into an n-bit message m, and the n-bit message m may represent the ring R t When n is n = 8 and the 8-bit message m is 01011001, m can be m = x 6 + x 4 + x 3 + 1.
[0032] For example, the encryption device 1200 may be configured to0 Multiply the error u, multiply the parameter t and the error g, and add the two multiplication results to the message m to calculate the ciphertext c 0 For example, c 0 Can be c 0 = a 0 *u + t*g + m. The encryption device 1200 can be based on the public key a 1 , errors u and h, and parameter t to calculate and generate the ciphertext c 1 For example, encryption device 1200 may be configured to 1 Multiply the error u, multiply the parameter t and the error h, and add the two multiplication results to calculate the ciphertext c 1 For example, c 1 Can be c 1 = a 1 *u + t*h.
[0033] The decryption device 1100 can be based on the ciphertext c 0 and c 1 And the private key s is used to calculate and generate the message ψ. In order to distinguish it from the message m of the encryption device 1200, since the message ψ is based on the ciphertext c sent from the encryption device 1200 0 and c 1 Therefore, the message ψ can be called the transmission message ψ. For example, the decryption device 1100 can calculate the ciphertext c 1 Multiply it with the private key s and add the multiplication result to the ciphertext c 0 The transmission message ψ is calculated by adding . Here, the private key s is the same as the private key s used to generate the key.
[0034] In order to obtain the plaintext message m of the encryption device 1200, the transmission message ψ is decrypted. Conventional decryption devices other than the decryption device 1100 can also decrypt the transmission message ψ. However, depending on the size of the errors u, g, and h used by the encryption device 1200, a decryption operation error may occur in the conventional decryption device, and a message different from the plaintext message m may be calculated in the conventional decryption device. In particular, when the size of the errors u, g, and h exceeds a certain level (a certain value), a message different from the plaintext message m may be calculated or restored in the conventional decryption device. The errors u, g, and h in the encryption device 1200 are used to reduce or prevent an attacker from easily obtaining the plaintext message m. That is, the RLWE encryption algorithm uses a method of deliberately adding errors u, g, and h so that an attacker may not easily obtain the plaintext message m. Therefore, when the size of the errors u, g, and h that the encryption device 1200 can use is limited due to the error of the decryption operation (which may occur in the conventional decryption device), due to the size of the errors u, g, and h, a problem of weak security of the encryption algorithm occurs.
[0035] In order to solve the above-mentioned problem, the decryption device 1100 according to some exemplary embodiments of the present invention does not decrypt the transmission message ψ as it is. Instead, the decryption device 1100 can calculate and generate a modified transmission message ψ′ by modifying, changing or tuning the transmission message ψ. For example, the decryption device 1100 can determine the coefficients of the modified transmission message ψ′ based on the magnitude of the coefficients of the transmission message ψ. Since the transmission message ψ may include multiple coefficients depending on the dimension of the polynomial, the decryption device 1100 can determine each coefficient of the modified transmission message ψ′. The decryption device 1100 can determine the coefficients of the modified transmission message ψ′ by using a determination function ζ. Reference Figure 1 , the coefficient of the transmission message ψ can be expressed as coef(ψ), and the coefficient of the modified transmission message ψ′, that is, the coefficient determined by the determination function ζ, can be expressed as coef(ψ′). The modified transmission message ψ′ can also be called the modified message ψ′.
[0036] For example, when coef(ψ) is greater than (>; or equal to or greater than (≥)) the reference value q / 2 and coef(ψ) is an even number, the decryption device 1100 may decide coef(ψ′) to be 1 (coef(ψ′) = 1) by modifying coef(ψ) to 1. When coef(ψ) is greater than (>; or equal to or greater than (≥)) the reference value q / 2 and coef(ψ) is an odd number, the decryption device 1100 may decide coef(ψ′) to be 0 (coef(ψ′) = 0) by modifying coef(ψ) to 0. When coef(ψ) is less than (<; or equal to or less than (≤)) the reference value q / 2, the decryption device 1100 may maintain coef(ψ) and may decide coef(ψ´) to be coef(ψ). For example, the decryption device 1100 may calculate the reference value q / 2 by performing a division operation with a divisor of 2 on the prime number q, and performing one of a rounding operation, a floor operation, and a ceiling operation on the result of the division operation. Of course, the reference value is not limited to q / 2. The decryption device 1100 may calculate the reference value by performing a division operation with a divisor of any natural number other than 2 on the prime number, and performing one of a rounding operation, a floor operation, and a ceiling operation on the result of the division operation.
[0037] For example, the transmission message ψ may have coefficients greater than (or equal to) the reference value q / 2, but the modified transmission message ψ′ does not have coefficients greater than (or equal to) the reference value q / 2. In some example embodiments, when all coefficients of the transmission message ψ are less than the reference value q / 2, the modified transmission message ψ′ may be the same as the transmission message ψ.
[0038] The decryption device 1100 can decrypt a modified transmission message ψ′ having coefficients determined by the determination function ζ instead of the transmission message ψ. For example, the decryption device 1100 can calculate the decrypted message m′′ by performing a modulo operation (e.g., ψ′ mod t) on the modified transmission message ψ′, and can restore the plaintext message m. For example, the divisor of the modulo operation of the decryption can be a parameter t. For example, the parameter t can be 2, but the inventive concept is not limited thereto. Here, the parameter t is the same as the parameter t for key generation. Since the decryption device 1100 determines the coefficients of the transmission message ψ and decrypts the modified transmission message ψ′ having the determined coefficients instead of the transmission message ψ, the decryption device 1100 can solve the following problem: due to the decryption error of the transmission message ψ, the size of the errors u, g, and h used in the encryption device 1200 is limited.
[0039] Hereinafter, an operation example of a conventional decryption device for decrypting a transmission message ψ and a decryption device 1100 for decrypting a modified transmission message ψ′ will be described. However, the scope of the inventive concept is not limited to the numerical values described below. Assume that n is 8, q is 257, and t is 2. Assume that a plaintext message m is {(7) times} [1. 0. 0. 0. 0. 1. 1. 1.] (e.g., m = x 7 + x 2 + x 1 + 1). Assume that the decryption device 1100 generates a public key a {(7) times} [161. -207. -91. -170.100. -76. -49. -185.] 0 (For example, a 0 = 161x 7 - 207x 6 - 91x 5 - 170x 4 +100x 3 -76x 2 - 49x 1 - 185) and {(7) times}[77. -118. -150. 173. 167. 133. 5. -183.] 1 (For example, a 1 = 77x 7 - 118x 6 - 150x 5 +173x 4 +167x 3 +133x 2 +5x 1 - 183). Assume that the encryption device 1200 uses the public key a 0and a 1 To generate the ciphertext c of {(7) times}[-25. 125. 234. 89. -48. -44. -3. -67.] 0 (For example, c 0 = -25x 7 +125x 6 +234x 5 +89x 4 - 48x 3 - 44x 2 - 3x 1 - 67) and the ciphertext c of {(7) times}[216. -136. 5. -39. -13. 21. -176.] 1 (For example, c 1 = 216x 7 - 136x 6 +178x 5 +5x 4 - 39x 3 - 13x 2 +21x 1 - 176). Assume that the decryption device 1100 uses the above ciphertext c 0 and c 1 to calculate the transmission message ψ {(7) times} [-11. 253. 2. -2. 0. -5. -3. -254.] (e.g., ψ = -11x 7 +253x 6 +2x 5 -2x 4 - 5x 2 - 3x 1 - 254).
[0040] A conventional decryption device will decrypt the transmission message ψ and can perform a modulo operation on the transmission message ψ with a divisor having the parameter t. The conventional decryption device can calculate the decrypted message m′ (e.g., m′ = x) {(7) times} [1. 1. 0. 0. 0. 1. 1. 0.] 7 + x 6 + x 2 + x 1 ) as a result of decryption. The decrypted message m′ of the conventional decryption device is different from the plaintext message m.
[0041] Instead, the decryption device 1100 may calculate the modified transmission message ψ′ by modifying the transmission message ψ. The decryption device 1100 may determine each coefficient of the modified transmission message ψ′ and may calculate the modified transmission message ψ′ {(7) times} [-11. 0. 2. -2. 0. -5. -3. 1.] (e.g., ψ´ = -11x 7 +2x 5 - 2x 4 - 5x 2 - 3x 1 + 1). Referring to the transmission message ψ and the modified transmission message ψ′ together, the decryption device 1100 can maintain x based on the determination function ζ 7 、x 5 、x 4 、x 3 、x 2 、x 1 The coefficients (-11, 2, -2, 0, -5, -3) (less than the reference value 257 / 2) can be converted to x which is greater than the reference value 257 / 2 and is an odd number. 6 The coefficient 253 of is modified to 0, and the x that is greater than the reference value 257 / 2 and is an even number can be 0 The coefficient -254 of ψ′ is modified to 1. The decryption device 1100 may perform a modulo operation with a divisor of parameter t on the modified transmission message ψ′. The decryption device 1100 may calculate a decrypted message m′′ (e.g., m′′ = x′) {(7) times} [1. 0. 0. 0. 0. 1. 1. 1.] 7 + x 2 + x 1 + 1) as a result of decryption. The decrypted message m′′ of the decryption device 1100 is identical to the plaintext message m. That is, the conventional decryption device calculates a decrypted message m′ that is different from the plaintext message m, but the decryption device 1100 can calculate a decrypted message m′′ that is identical to the plaintext message m regardless of the magnitude of the errors u, g, and h.
[0042] Figure 2 It shows Figure 1 Operations S110 and S120 performed by the decryption device 1100 may correspond to key generation of the RLWE encryption algorithm, operations S140 and S150 performed by the encryption device 1200 may correspond to encryption of the RLWE encryption algorithm, and operations S170 to S190 performed by the decryption device 1100 may correspond to decryption of the RLWE encryption algorithm.
[0043] In operation S110, the decryption device 1100 can q For public key a1 For sampling, the private key s can be sampled according to the normal distribution χ, and the error e can be sampled according to the normal distribution χ. As mentioned above, f(x) is an n-order integer polynomial. For example, the public key a 1 Each of , the private key s, and the error e is an n-1 order integer polynomial and may have coefficients that may be less than the prime number q.
[0044] In operation S120, the decryption device 1100 may 1 To calculate the public key a 0 The decryption device 1100 can be realized by comparing the error e with the private key s and the public key a 1 The multiplication result is added to calculate the public key a 0 For example, public key a 0 is an integer polynomial of order n-1 and can have coefficients less than a prime number q.
[0045] In operation S130, the decryption device 1100 may send (provide or output) a public key (pk = (a 0 , a 1 )). The encryption device 1200 may receive a public key (pk = (a 0 , a 1 )).
[0046] In operation S140, the encryption device 1200 may sample the errors u, g, and h according to the normal distribution x. The normal distribution x used by the decryption device 1100 may be different from the normal distribution x used by the encryption device 1200. For example, each of the errors u, g, and h is an n-1 order integer polynomial and may have a coefficient less than the prime number q.
[0047] In operation S150, the encryption device 1200 may calculate the ciphertext c 0 and c 1 The encryption device 1200 can be based on the public key a 0 and plaintext message m to calculate ciphertext c 0 For example, the plaintext message m is an n-1 order integer polynomial and may have coefficients less than the parameter t. For another example, the plaintext message m is an n-1 order integer polynomial and may have coefficients less than the prime number q. The encryption device 1200 may be configured to receive the public key a by passing the public key a to the encryption device 1200. 0 The ciphertext c is calculated by adding the multiplication result of the error u, the multiplication result of the parameter t and the error g, and the plaintext message m. 0 The encryption device 1200 can be based on the public key a 1 To calculate the ciphertext c 1 The encryption device 1200 can be used to 1The ciphertext c is calculated by adding the multiplication result of the error u and the multiplication result of the parameter t and the error h. 1 For example, the ciphertext c 0 and c 1 Each of is an integer polynomial of order n-1 and can have coefficients less than a prime number q.
[0048] In operation S160, the encryption device 1200 may send the ciphertext (ct = (c 0 , c 1 )). The decryption device 1100 can receive the ciphertext (ct = (c 0 , c 1 )).
[0049] In operation S170, the decryption device 1100 may 0 and c 1 The decryption device 1100 can calculate the transmission message ψ by converting the ciphertext c 1 The multiplication result of the private key s and the ciphertext c 0 The transmission message ψ is calculated by adding. For example, the transmission message ψ is an integer polynomial of order n-1 and may have coefficients less than a prime number q.
[0050] In operation S180, the decryption device 1100 may calculate a modified transmission message ψ′ by modifying the transmission message ψ. For example, the modified transmission message ψ′ is an n-1 order integer polynomial and may have a coefficient less than the prime number q. The decryption device 1100 may determine the coefficient of the modified transmission message ψ′ according to a comparison result of the coefficient of the transmission message ψ with a reference value q / 2 based on the prime number q.
[0051] In operation S190, the decryption device 1100 may decrypt the modified transmission message ψ' and calculate the decrypted message m''. For example, the decryption device 1100 may perform a modulo operation with a divisor having a parameter t on the modified transmission message ψ'.
[0052] Figure 3 is shown in more detail Figure 2 FIG. 1 is a flowchart of detailed operations of operation S180 .
[0053] refer to Figure 2 and Figure 3, in operation S181, the decryption device 1100 may determine whether the coefficient coef(ψ) of the transmission message ψ is greater than (>; or equal to or greater than (≥)) the reference value q / 2. As described above, the decryption device 1100 may perform a division operation with a divisor of 2 on the prime number q, and perform one of a rounding operation, a floor operation, and a ceiling operation on the result of the division operation, and may calculate the execution result of the division operation and one of the rounding operation, the floor operation, and the ceiling operation as a reference value. For example, the decryption device 1100 may compare coef(ψ) with the reference value q / 2.
[0054] When coef(ψ) > q / 2 or coef(ψ) ≥ q / 2, in operation S182, the decryption device 1100 may check whether coef(ψ) is an even number or an odd number. For example, the decryption device 1100 may perform a division operation of a divisor 2 on coef(ψ) and may check a remainder. The decryption device 1100 may divide coef(ψ) by 2 and may check a remainder. Here, 2 is due to the above-mentioned parameter t.
[0055] When coef(ψ) is an odd number, in operation S183, the decryption device 1100 may decide the coefficient coef(ψ′) of the modified transmission message ψ′ to be 0, and may modify coef(ψ) to 0. When coef(ψ) is an even number, in operation S184, the decryption device 1100 may decide coef(ψ′) to be 1, and may modify coef(ψ) to be 1. When coef(ψ) < q / 2 or coef(ψ) ≤ q / 2, in operation S185, the decryption device 1100 may decide coef(ψ′) to be coef(ψ) and may maintain coef(ψ).
[0056] References Figure 3 Operations S181 to S185 described above relate to some example embodiments in which the parameter t is 2. For example, the parameter t may be 2 or greater. Figure 3 Unlike the illustration of FIG. 1 , in operation S182, the decryption device 1100 may divide coef(ψ) by the parameter t, and may check the remainder. Figure 3 Unlike the illustration, in operation S183 and operation S184, the decryption device 1100 may decide coef(ψ′) to be one of a plurality of values, and may modify coef(ψ) to a corresponding value based on the remainder. The plurality of values may be values that the remainder may have. In summary, when coef(ψ) is less than or equal to the reference value q / 2, coef(ψ′) may be coef(ψ). When coef(ψ) is greater than or equal to the reference value q / 2, coef(ψ′) may be modified to be one of the values that the remainder may have when coef(ψ) is divided by the parameter t.
[0057] Figure 4 is a diagram showing in more detail some example embodiments of the present invention. Figure 1 Block diagram of the communication system.
[0058] refer to Figure 1 and Figure 4 , the communication system 1000a may be Figure 1 An example of a communication system 1000 such that the decryption device 1100a may be Figure 1 An example of a decryption device 1100, and an encryption device 1200a may be Figure 1 An example of an encryption device 1200 is shown.
[0059] The decryption device 1100a may include a processor 1110, a memory 1120, and an interface (I / F) circuit 1130, which communicate with each other through an internal bus. The processor 1110, as a hardware device, can execute the decryption program code stored in the memory 1120. For example, the processor 1110 may include multiple cores of homogeneous or heterogeneous structure and a cache memory shared by multiple cores, etc. The multiple cores of homogeneous or heterogeneous structure may include a central processing unit (CPU), an image signal processing unit (ISP), a digital signal processing unit (DSP), a graphics processing unit (GPU), a visual processing unit (VPU), and a neural processing unit (NPU). The processor 1110 may perform processing operations for instructions of decryption program code and arithmetic operations, such as obtaining, executing, requesting data, and storing data. For example, the processor 1110 may control the memory 1120 and the interface circuit 1130. The number of processors 1110 may be one or more.
[0060] The memory 1120 may be a non-transitory computer-readable medium storing a decryption program code executable by the processor 1110 (ie, a hardware device). For example, the memory 1120 may be implemented using various memory devices (e.g., dynamic random access memory (DRAM) devices, static random access memory (SRAM) devices, thyristor random access memory (TRAM) devices, NAND flash memory devices, NOR flash memory devices, resistive random access memory (RRAM) devices, ferroelectric random access memory (FRAM) devices, phase change random access memory (PRAM) devices, magnetic random access memory (MRAM) devices, etc.). The number of memories 1120 may be one or more. In addition, the memory 1120 may be implemented using an external device capable of communicating with the decryption device 1100.
[0061] The decryption program code stored in the memory 1120 and executed by the processor 1110 may include the decryption program code for the above reference Figures 1 to 3For example, the processor 1110 may execute the decryption program code stored in the memory 1120 to perform the above reference. Figures 1 to 3 The processor 1110 may generate a normal distribution x, a number k and a number q, a security parameter n, a parameter t, a public key a, and a key generation and decryption of the RLWE encryption algorithm described above, and may perform operations S110, S120, S170, S180 including S181 to S185, and S190. In addition, when performing the above operations, the processor 1110 may generate a normal distribution x, a number k and a number q, a security parameter n, a parameter t, a public key a, and a key generation and decryption of the RLWE encryption algorithm described above, and may perform operations S110, S120, S170, S180 including S181 to S185, and S190. 0 and a 1 , private key s, error e, ciphertext c 0 and c 1 , a transmission message ψ, a modified transmission message ψ′, and an intermediate operation result (or multiple results) of the above operations, and the generated information can be stored in the memory 1120.
[0062] The interface circuit 1130 as a hardware device can communicate with the interface (I / F) circuit 1230 of the encryption device 1200a based on various wired or wireless protocols. The interface circuit 1130 can send the public key a generated by the processor 1110 and stored in the memory 1120 to the interface circuit 1230 of the encryption device 1200a in response to the request of the processor 1110. 0 and a 1 The interface circuit 1130 may receive the ciphertext c sent from the interface circuit 1230 of the encryption device 1200a. 0 and c 1 , and can provide the ciphertext c to the memory 1120 or the processor 1110 0 and c 1 .
[0063] The encryption device 1200a may include a processor 1210, a memory 1220, and an interface circuit 1230, which communicate with each other via an internal bus. The processor 1210, as a hardware device, may execute the encryption program code stored in the memory 1220. For example, the processor 1210 may be implemented similarly to the processor 1110. The processor 1210 may perform processing operations for instructions of the encryption program code and arithmetic operations, such as obtaining, executing, requesting data, and storing data. For example, the processor 1210 may control the memory 1220 and the interface circuit 1230. The number of the processors 1210 may be one or more.
[0064] The memory 1220 may be a non-transitory computer-readable medium storing an encryption program code executable by the processor 1210 (ie, a hardware device). For example, the memory 1220 may be implemented similarly to the memory 1120. The number of memories 1220 may be one or more. In addition, the memory 1220 may be implemented with an external device capable of communicating with the encryption device 1200a.
[0065] The encrypted program code stored in the memory 1220 and executed by the processor 1210 may include the above reference Figures 1 to 3 For example, the processor 1210 may execute the encryption program code stored in the memory 1220 to perform the above-mentioned Figures 1 to 3 The encryption of the RLWE encryption algorithm described in the above, and operations S140 and S150 can be performed. In addition, when the processor 1210 performs the above operations, it can generate a normal distribution x, numbers k and q, a security parameter n, a parameter t, a public key a 0 and a 1 , errors u, g and h, ciphertext c 0 and c 1 As well as intermediate operation results (or multiple results) of the above operations, and the generated information can be stored in the memory 1220.
[0066] The interface circuit 1230 as a hardware device can communicate with the interface circuit 1130 of the decryption device 1100a based on various wired or wireless protocols. The interface circuit 1230 can send the ciphertext c generated by the processor 1210 and stored in the memory 1220 to the interface circuit 1130 of the decryption device 1100a in response to the request of the processor 1210. 0 and c 1 The interface circuit 1230 may receive the public key a sent from the interface circuit 1130 of the decryption device 1100a. 0 and a 1 , and may provide a public key a to the memory 1220 or the processor 1210 0 and a 1 .
[0067] Figure 5 is a diagram showing in more detail some example embodiments of the present invention. Figure 1 Block diagram of the communication system.
[0068] refer to Figure 1 , Figure 4 and Figure 5 , the communication system 1000b may be Figure 1 An example of a communication system 1000 such that the decryption device 1100b may be Figure 1An example of a decryption device 1100 and an encryption device 1200b may be Figure 1 The differences between the communication system 1000b and the communication system 1000a will be mainly described. The communication system 1000a may be an example of the communication system 1000 implemented in hardware and software. Conversely, the communication system 1000b may be an example of the communication system 1000 implemented in hardware.
[0069] The decryption device 1100b may include a key generation circuit 1140, a decryption circuit 1150, and an interface circuit 1130, which communicate with each other via an internal bus. The key generation circuit 1140 may perform the above-mentioned Figures 1 to 3 The key generation circuit 1140 can generate and store the normal distribution χ, the numbers k and q, the security parameter n, the parameter t, the public key a, and the ... 0 and a 1 , private key s, error e and the intermediate operation result (or multiple results) of the above operation. For example, the storage location may be the internal memory of the key generation circuit 1140 or the memory of the decryption device 1100b. The decryption circuit 1150 may perform the above reference Figures 1 to 3 The decryption circuit 1150 can generate and store the ciphertext c when performing the above operations. 0 and c 1 , a transmission message ψ, a modified transmission message ψ' and an intermediate operation result (or multiple intermediate operation results) of the above operation. For example, the storage location may be an internal memory of the decryption circuit 1150 or a memory of the decryption device 1100b. For example, the decryption device 1100b may also include Figure 4 The interface circuit 1130 of the decryption device 1100b may be similar to Figure 4 Each of the key generation circuit 1140, the decryption circuit 1150 and the interface circuit 1130 may include one or more analog circuits, digital circuits, logic circuits, etc. to perform the above operations.
[0070] The encryption device 1200b may include an encryption circuit 1240 and an interface circuit 1230, which communicate with each other via an internal bus. The encryption circuit 1240 may perform the above-mentioned Figures 1 to 3The encryption of the RLWE encryption algorithm described above can be performed, and operations S140 and S150 can be performed. When performing the above operations, the encryption circuit 1240 can generate and store the normal distribution χ, the numbers k and q, the security parameter n, the parameter t, the public key a 0 and a 1 , errors u, g and h, ciphertext c 0 and c 1 and the intermediate operation results (or multiple intermediate operation results) of the above operations. For example, the storage location may be the internal memory of the encryption circuit 1240 or the memory of the encryption device 1200b. For example, the encryption device 1200b may also include Figure 4 The interface circuit 1230 of the encryption device 1200b may be similar to Figure 4 The encryption circuit 1240 and the interface circuit 1230 may each include one or more analog circuits, digital circuits, logic circuits, etc. to perform the above operations.
[0071] Figure 6 It shows Figure 5 Block diagram of the key generation circuit.
[0072] refer to Figure 5 and Figure 6 The key generation circuit 1140 may include a processing circuit configured to perform the functions of a sampler 1141 , a multiplier 1142 , a multiplier 1143 , and an adder 1144 .
[0073] The sampler 1141 may generate a normal distribution χ, and may sample the private key s and the error e according to the normal distribution χ. q For public key a 1 The multiplier 1142 may multiply the parameter t and the error e, and may provide the multiplication result te to the adder 1144. The multiplier 1143 may 1 Multiply the private key s, and provide the multiplication result a to the adder 1144 1 *s. Adder 1144 can add the two multiplication results te and a 1 *s are added, and the public key a can be calculated 0 Although not shown, the adder 1144 may further include an internal circuit that inverts the sign of the addition result, or performs a multiplication operation or a subtraction operation on the addition result. The key generation circuit 1140 may provide the public key a to the interface circuit 1130 or the memory of the decryption device 1100b. 0 and a 1The key generation circuit 1140 may provide the private key s to the decryption circuit 1150. Regardless of the implementation method, the private key s is not provided outside the decryption device 1100b.
[0074] Figure 7 It shows Figure 5 Block diagram of the decryption circuit.
[0075] refer to Figure 5 and Figure 7 The decryption circuit 1150 may include a processing circuit configured to perform the functions of a calculator 1151 including a multiplier 1152 and an adder 1153 , a comparator 1154 , a decider 1155 , and an operator 1156 .
[0076] Multiplier 1152 can convert the ciphertext c 1 Multiply the private key s, and provide the multiplication result c to the adder 1153 1 s. Adder 1153 can convert the multiplication result c 1 s and ciphertext c 0 The transmission message ψ is added, and the transmission message ψ can be calculated. The comparator 1154 can compare the transmission message ψ with the reference value q / 2, and can provide the comparison result CR to the decider 1155. The decider 1155 can decide the coefficient of the modified transmission message ψ' based on the comparison result CR, and can provide the modified transmission message ψ' to the operator 1156. The operator 1156 can perform a decryption operation (e.g., a modulus operation with a divisor of the parameter t) on the modified transmission message ψ', and can generate a decrypted message m''.
[0077] The decider 1155 may include a processing circuit configured to perform the functions of the checker 1155_1 , the multiplexer 1155_2 , and the multiplexer 1155_3 .
[0078] The checker 1155_1 may check whether coef (ψ) is an even number or an odd number. For example, the checker 1155_1 may perform a division operation on coef (ψ), wherein the divisor is a parameter t, and the remainder may be checked. The checker 1155_1 may provide the check result (or remainder) to the multiplexer 1155_2. The multiplexer 1155_2 may select one of a plurality of values (0, 1) based on the check result, and may provide the selected value to the multiplexer 1155_3. The multiplexer 1155_2 may select 1 based on the check result indicating that coef (ψ) is an even number. The multiplexer 1155_2 may select 0 based on the check result indicating that coef (ψ) is an odd number. Figure 7Some example embodiments relate to a parameter t of 2, and the number of values that the multiplexer 1155_2 can select can be 2 or more, depending on whether the value of the parameter t is 2 or greater. The multiplexer 1155_3 can select one of coef(ψ) and the value (0 or 1) selected by the multiplexer 1155_2 based on the comparison result CR, and can output the selected value as coef(ψ´). The multiplexer 1155_3 can select coef(ψ) based on a comparison result CR indicating that coef(ψ) < q / 2 or coef(ψ) ≤ q / 2. The multiplexer 1155_3 can select the value (0 or 1) selected by the multiplexer 1155_2 based on a comparison result CR indicating that coef(ψ) > q / 2 or coef(ψ) ≥ q / 2.
[0079] Figure 8 is a block diagram showing Figure 5 the encryption circuit.
[0080] Referring to Figure 5 and Figure 8 , the encryption circuit 1240 may include processing circuitry configured to perform the functions of sampler 1241, multiplier 1242, multiplier 1243, encoder 1244, adder 1245, multiplier 1246, multiplier 1247, and adder 1248.
[0081] The sampler 1241 may generate a normal distribution χ, and may sample the errors u, g, and h according to the normal distribution χ. The sampler 1241 may provide the error u to multipliers 1242 and 1246, may provide the error g to multiplier 1243, and may provide the error h to multiplier 1247. The multiplier 1242 may multiply the public key a 0 and the error u, and may provide the multiplication result a 0 u to the adder 1245. The multiplier 1243 may multiply the parameter t and the error g, and may provide the multiplication result tg to the adder 1245. The encoder 1244 may encode the data of the encryption device 1200b and may generate a message m. For example, the encoder 1244 may encode the data to generate an n-bit message m belonging to the ring (R t = Z t [x] / f(x)). The adder 1245 may add the two multiplication results a 0 u and tg to the message m to generate a ciphertext c 0 . The multiplier 1246 may multiply the public key a 1 and the error u, and may provide the multiplication result a 1u. The multiplier 1246 may multiply the parameter t and the error h, and may provide the multiplication result th to the adder 1248. The adder 1248 may add the two multiplication results a 1 u and th are added to generate the ciphertext c 1 .
[0082] Fig. 9 is a block diagram illustrating an encryption / decryption device according to some example embodiments of the inventive concept.
[0083] refer to Fig. 9 , the encryption / decryption device 2000a can communicate with other electronic devices (not shown) and can perform reference Figures 1 to 8 Describes key generation, encryption, and decryption for RLWE.
[0084] The encryption / decryption device 2000a may include a processor 2110, a memory 2120, and an interface (I / F) circuit 2130, which communicate with each other through an internal bus. For example, the processor 2110 may be implemented similarly to the processors 1110 and 1210, and may execute encryption program codes and decryption program codes stored in the memory 2120. The memory 2120 may be implemented similarly to the memories 1120 and 1220, and may store encryption program codes and decryption program codes executable by the processor 2110. The interface circuit 2130 may be implemented similarly to the interface circuits 1130 and 1230, and may send a public key a to other electronic devices. 0 and a 1 , can receive the public key a from other electronic devices 0 and a 1 , can send ciphertext c to other electronic devices 0 and c 1 , or can receive ciphertext c from other electronic devices 0 and c 1 .
[0085] Fig.10 is a block diagram illustrating an encryption / decryption device according to some example embodiments of the inventive concept.
[0086] refer to Fig.10 , the encryption / decryption device 2000b may include an interface circuit 2130, a key generation circuit 2140, a decryption circuit 2150, and an encryption circuit 2160, which communicate with each other via an internal bus. The interface circuit 2130 may communicate with Fig. 9 The key generation circuit 2140 may be the same as or substantially the same as the interface circuit 2130 of Figure 5 The decryption circuit 2150 may be the same as or substantially the same as the key generation circuit 1140 of Figure 5The encryption circuit 2160 may be the same as or substantially the same as the decryption circuit 1150 of Figure 5 The encryption circuit 1240 is the same or substantially the same.
[0087] Fig.11 is a block diagram illustrating an electronic device according to some example embodiments of the inventive concept.
[0088] refer to Fig.11 , the electronic device 3000 may be the above reference Figures 1 to 10 Example implementations of each of the decryption devices 1100, 1100a, and 1100b, the encryption devices 1200, 1200a, and 1200b, or the encryption / decryption devices 2000a and 2000b are described.
[0089] The electronic device 3000 may also be referred to as a computing system, a storage system, an electronic system, a communication system, etc. For example, the electronic device 3000 may be a desktop computer, a laptop computer, a tablet computer, a mobile device, a smart phone, a personal digital assistant (PDA), a portable media player (PMP), a wearable device, a video game console, a workstation, a server, a data processing device that can use or support the interface protocol proposed by the MIPI Alliance (Mobile Industry Processor Interface Alliance), a home appliance, a black box, a drone, an Internet of Things (IoT) device, a smart card, a security device, etc. The electronic device 3000 may include a system on chip 3100. The system on chip 3100 may include a processor 3110, an encryptor / decryptor 3120, and a memory 3130. The processor 3110 may be an example of one of the aforementioned processors 1110, 1210, and 2110. The encryptor / decryptor 3120 may include at least some or all of the key generation circuits 1140 and 2140, the decryption circuits 1150 and 2150, and the encryption circuits 1240 and 2160. As described above, when the RLWE encryption algorithm is implemented in a combination of hardware and software, the system on chip 3100 may not include the encryptor / decryptor 3120. The memory 3130 may be an example of one of the aforementioned memories 1120, 1220, and 2120.
[0090] The electronic device 3000 may include a display 3220 and an image sensor 3230. The system on chip 3100 may further include a DigRF host device 3141, a display serial interface (DSI) host 3150, a camera serial interface (CSI) host 3160, and a physical layer (PHY) 3142. The DSI host 3150 may communicate with a DSI device 3225 of the display 3220 based on DSI. The serializer SER may be implemented in the DSI host 3150, and the deserializer DES may be implemented in the DSI device 3225. The CSI host 3160 may communicate with a SER device 3235 of the image sensor 3230 based on CSI. The deserializer (DES) may be implemented in the CSI host 3160, and the serializer SER may be implemented in the SER device 3235. The electronic device 3000 may further include a radio frequency (RF) chip 3240 that communicates with the system on chip 3100. The RF chip 3240 may include a physical layer 3242, a DigRF slave device 3244, and an antenna 3246. For example, the physical layer 3242 and the physical layer 3142 may exchange data with each other based on the DigRF interface proposed by the MIPI Alliance. The electronic device 3000 may also include a working memory 3250 and an embedded / card-type storage device 3255. The working memory 3250 and the embedded / card-type storage device 3255 may store or output data related to the system on chip 3100. The embedded storage device 3255 may be embedded in the electronic device 3000, and the card-type storage device 3255 may be installed on the electronic device 3000 as a removable device. The electronic device 3000 may communicate with an external device / system through a communication module such as Wimax (Worldwide Interoperability for Microwave Access, 3260), WLAN (Wireless Local Area Network, 3262), UWB (Ultra Wideband, 3264), etc. The electronic device 3000 may further include a speaker 3270 , a microphone 3275 , a global positioning system (GPS) device 3280 , and a bridge chip 3285 .
[0091] Fig.12 is a block diagram illustrating a communication system according to some example embodiments of the inventive concept.
[0092] refer to Figure 1 and Fig.12 , the above reference Figure 1 The described communication system 1000 may correspond to a portion of the communication system 4000. The communication system 4000 may correspond to an example of an IoT communication system or a machine-to-machine (M2M) communication system. The communication system 4000 may include an application layer 4100, a network layer 4200, and a perception layer 4300. The perception layer 4300 may include terminal devices 4310 to 4340.
[0093] For example, the terminal devices 4310 to 4340 may include sensors, actuators, etc. that interact with the surrounding environment of the communication system 4000. The network layer 4200 may include gateways 4210 and 4220, which can search, find and connect the terminal devices 4310 to 4340 of the perception layer 4300 through the network in cooperation with the application layer 4100. The gateways 4210 and 4220 can transmit data bidirectionally between the terminal devices 4310 to 4340 and the server 4110. The application layer 4100 may include a server 4110 (or a cloud device) equipped with services and functions for users. For example, the server 4110 can collect, manage or analyze data of the terminal devices 4310 to 4340 through the gateways 4210 and 4220, and can control the gateways 4210 and 4220 and the terminal devices 4310 to 4340. The components 4110, 4210 to 4220 and 4310 to 4340 are not limited to Fig.12 , and can communicate with each other through various wired or wireless network methods. For example, each of the components 4110, 4210 to 4220, and 4310 to 4340 can be the above Figures 1 to 11 One of the components 1100, 1100a, 1100b, 1200, 1200a, 1200b, 2000a, 2000b and 3000 described in.
[0094] According to some example embodiments of the present inventive concept, since the decryption device of the communication system determines to use the ciphertext c sent from the encryption device 0 and c 1 The coefficients of the transmission message ψ are calculated, and the modified transmission message ψ′ having the determined coefficients is decrypted instead of the transmission message ψ, thereby solving the problem of limiting the size of errors u, g and h used in the encryption device due to the decryption error of the transmission message ψ.
[0095] This can be done in areas such as Figure 5-8 and 10, analog circuits, digital circuits and / or logic circuits, such as hardware Figure 4 and Fig. 9 The components of the above communication system are implemented in a hardware / software combination of a processor executing software as shown, or a combination of the two, including for example Figure 4 and Figure 5 discrete decryption devices and encryption devices, or for example Fig. 9 and Fig.10 A combined encryption / decryption device.
[0096] For example, the processing circuit may include, but is not limited to, a central processing unit (CPU), an arithmetic logic unit (ALU), a digital signal processor, a microcomputer, a field programmable gate array (FPGA), a programmable logic unit, a microprocessor, an application specific integrated circuit (ASIC), etc.
[0097] The processing circuit may be a dedicated processing circuit that calculates a decrypted message m′′ that is the same as the plaintext message m by generating a modified transmission message ψ′ from the transmission message ψ so that the modified transmission message ψ′ is an n-1 order integer polynomial and has a coefficient less than a prime number q, regardless of the size of the errors u, g, and h. Therefore, the dedicated processing circuit can improve the function of the communication system itself by solving the problem that the size of the errors u, g, and h used in the encryption device is limited due to the decryption error of the transmission message ψ.
[0098] The above-described contents are some example embodiments for realizing the inventive concept. The inventive concept may include not only the above-mentioned example embodiments, but also example embodiments in which the design can be simply or easily changed. In addition, the inventive concept may also include techniques that are easily changed so as to be realized using the example embodiments in the future.
Claims
1. A non-transitory computer readable medium storing program code which, when executed by a processor, causes the processor to: Calculate a message based on the first ciphertext, the second ciphertext and the private key, wherein the message is represented by a polynomial; comparing a coefficient of the message with a reference value to generate a comparison result, the reference value being based on a prime number; generating a modified message based on the message by selectively modifying the corresponding one of the coefficients of the message to one of the values that a remainder when the corresponding coefficient is divided by a parameter can have in response to the comparison result indicating that the corresponding one of the coefficients of the message is greater than the reference value, the parameter being a predetermined integer and used to define a space of the message; as well as The modified message is decrypted.
2. The non-transitory computer-readable medium of claim 1, wherein: When the program code is executed, the processor generates the modified message by: In response to the corresponding one of the coefficients of the message being less than the reference value, the corresponding one of the coefficients of the message is maintained.
3. The non-transitory computer-readable medium of claim 1, wherein: The program code, when executed, causes the processor to selectively modify the coefficients of the message by: in response to the corresponding one of the coefficients of the message being greater than the reference value and the corresponding one of the coefficients of the message being an even number, setting the corresponding one of the coefficients in the modified message to a first value, and In response to the corresponding one of the coefficients of the message being greater than the reference value and the corresponding one of the coefficients of the message being an odd number, the corresponding one of the coefficients in the modified message is set to a second value.
4. The non-transitory computer-readable medium of claim 1, wherein: When the program code is executed, the processor calculates the reference value by performing a division operation on the prime number with a divisor of 2, and performing one of a rounding operation, a floor operation, and a ceiling operation on a result of the division operation.
5. The non-transitory computer readable medium of claim 1, wherein: When the program code is executed, the processor calculates the message by: performing a multiplication operation on the second ciphertext and the private key to generate a multiplication result; and An addition operation is performed on the multiplication result and the first ciphertext.
6. The non-transitory computer-readable medium of claim 1, wherein: The program code, when executed, causes the processor to decrypt the modified message by performing a modulo operation on the modified message.
7. The non-transitory computer readable medium of claim 6, wherein: The divisor of the modulo operation is "2".
8. A decryption device, comprising: The processing circuit is configured to: Calculate a message based on the first ciphertext, the second ciphertext and the private key, wherein the message is represented by a polynomial; comparing a coefficient of the message with a reference value to generate a comparison result, the reference value being based on a prime number, generating a modified message based on the message by selectively modifying the corresponding one of the coefficients of the message to one of the values that a remainder when the corresponding coefficient is divided by a parameter can have in response to the comparison result indicating that the corresponding one of the coefficients of the message is greater than the reference value, the parameter being a predetermined integer and used to define a space of the message, and The modified message is decrypted.
9. The decryption device according to claim 8, wherein: The processing circuit is configured to generate the modified message by: In response to the corresponding one of the coefficients of the message being less than the reference value, the corresponding one of the coefficients of the message is maintained.
10. The decryption device according to claim 8, wherein: The processing circuit is configured to selectively modify the coefficients of the message by: in response to the corresponding one of the coefficients of the message being greater than the reference value and the corresponding one of the coefficients of the message being an even number, setting the corresponding one of the coefficients in the modified message to a first value, and In response to the corresponding one of the coefficients of the message being greater than the reference value and the corresponding one of the coefficients of the message being an odd number, the corresponding one of the coefficients in the modified message is set to a second value.
11. The decryption device according to claim 8, wherein: The processing circuit is configured to calculate the reference value by performing a division operation on the prime number with a divisor of 2, and performing one of a rounding operation, a floor operation, and a ceiling operation on a result of the division operation.
12. The decryption device according to claim 8, wherein: The processing circuit is configured to calculate the message by: performing a multiplication operation on the second ciphertext and the private key to generate a multiplication result; and An addition operation is performed on the multiplication result and the first ciphertext.
13. The decryption device according to claim 8, wherein: The processing circuit is configured to decrypt the modified message by performing a modulo operation on the modified message.
14. The decryption device according to claim 13, wherein: The divisor of the modulo operation is "2".
15. A communication system comprising: Encryption devices are configured as: computing a first ciphertext based on the first public key, and Calculate a second ciphertext based on the second public key and the plaintext message; as well as Decryption device, configured as: Sampling private keys based on the first normal distribution, Sampling the first public key according to a polynomial ring, Calculate the second public key based on the private key and the first public key, In response to sending the first public key and the second public key to the encryption device, receiving the first ciphertext and the second ciphertext from the encryption device, Based on the first ciphertext, the second ciphertext and the private key, a transmission message is generated, where the transmission message is represented by a polynomial. comparing the coefficient of the transmission message with a reference value to generate a comparison result, the reference value being based on a prime number, generating a modified transmission message based on the transmission message by selectively modifying the corresponding one of the coefficients of the transmission message to one of the values that a remainder when the corresponding coefficient is divided by a parameter can have in response to the comparison result indicating that the corresponding one of the coefficients of the transmission message is greater than the reference value, wherein the parameter is a predetermined integer and is used to define a space of the message, and The modified transmission message is decrypted.
16. The communication system according to claim 15, wherein: The decryption device is configured to generate the modified transmission message by: in response to the corresponding one of the coefficients of the transmission message being greater than the reference value and the corresponding one of the coefficients of the transmission message being an even number, setting the corresponding one of the coefficients in the modified transmission message to a first value, in response to the corresponding one of the coefficients of the transmission message being greater than the reference value and the corresponding one of the coefficients of the transmission message being an odd number, setting the corresponding one of the coefficients in the modified transmission message to a second value, and In response to the corresponding one of the coefficients of the transmission message being smaller than the reference value, the corresponding one of the coefficients of the transmission message is maintained.
17. The communication system according to claim 15, wherein: The decryption device is further configured to calculate the second public key by: performing a first multiplication operation on the private key and the first public key; and performing a first addition operation on a result of the first multiplication operation and a first error sampled according to the first normal distribution.
18. The communication system according to claim 17, wherein: The encryption device is further configured to: Calculating the first ciphertext by performing a second multiplication operation on the first public key and a second error sampled according to a second normal distribution, performing a third multiplication operation on a third error sampled according to the second normal distribution and the parameter, and performing a second addition operation on a multiplication result of the second multiplication operation and the third multiplication operation; as well as The second ciphertext is calculated by performing a fourth multiplication operation on the second public key and the second error, performing a fifth multiplication operation on the fourth error sampled according to the second normal distribution and the parameter, and performing a third addition operation on the multiplication results of the fourth multiplication operation and the fifth multiplication operation and the plaintext message.
19. The communication system according to claim 18, wherein: The decryption device is further configured to calculate the transmission message by performing a sixth multiplication operation on the first ciphertext and the private key, and performing a fourth addition operation on a multiplication result of the sixth multiplication operation and the second ciphertext.
20. The communication system according to claim 15, wherein: The decryption device is configured to recover the plaintext message by performing a modulo operation on the modified transmission message.
Citation Information
Patent Citations
Encryption method for error learning problem in ring domain and circuit
CN106685663A
Sequencing method based on fully homomorphic encryption
CN110309674A
Fully Homomorphic Encryption
US20130170640A1
Fully homomorphic encrypted ciphertext query method and system
US20180367294A1