Estimation Method, Medium, Device and System for Decryption Error Rate of Lattice-Based Encryption Algorithm

By combining the parameters of the grid cryptographic algorithm to determine the floating-point data type and heuristic rough estimation, the problem of unclear data type selection and cut-off threshold value in the decryption error rate estimation of the grid-based encryption algorithm is solved, and accurate and fast decryption error rate evaluation within the specified accuracy range is achieved.

CN116132046BActive Publication Date: 2025-08-01NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211579091.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-07
Publication Date
2025-08-01
Estimated Expiration
2042-12-07

AI Technical Summary

Technical Problem

The existing lattice encryption algorithm's decryption error rate estimation method fails to clarify the selection of the calculation data type and its basis, and fails to clarify the selection of the critical value of the intercepted data during the accelerated calculation process, and the different calculation methods are independent and unrelated, which affects the accuracy and efficiency of the decryption error rate evaluation.

Method used

By using the grid cryptography algorithm's own parameters to determine the floating-point data type required to estimate the decryption error rate, a combination of heuristic rough estimation and fine calculation is adopted. First, the heuristic rough estimation is run and then the small probability critical value that can be intercepted in the fine calculation is given, and finally, the fine estimation is run to quickly obtain the decryption error rate target value.

Benefits of technology

Ensure that the calculation results are accurate within the specified accuracy range, reduce the impact of machine errors, and improve the estimation speed. For example, more distribution table data can be cut off in the Frodo-640 algorithm, significantly speeding up the calculation speed of decryption error rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116132046B_ABST
    Figure CN116132046B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, medium, device and system for estimating the decryption error rate of a lattice-based encryption algorithm, belonging to the technical field of cryptographic security, including the steps of: determining the floating-point data type required for estimating the decryption error rate by using the parameters of the lattice cryptography algorithm itself; running the heuristic rough estimation cryptographic detection program code or computing device to give the small probability critical value that can be truncated in the fine calculation, and finally running the fine estimation cryptographic detection program code or computing device to quickly obtain the target value of the decryption error rate. The present invention can clarify the calculation data type adopted, ensure that the machine error does not affect the estimation result of the decryption error probability within the specified precision range of the input; can ensure that the truncated part of the distribution table does not affect the estimation result of the decryption error probability within the specified precision range of the input; and can accelerate the estimation process of the decryption error probability of the algorithm.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cryptographic security, and more specifically, to a method, medium, device and system for estimating the decryption error rate of a lattice-based encryption algorithm. Background Art

[0002] Quantum computing seriously threatens the security of existing public-key cryptography [1]. Therefore, the cryptographic community is researching post-quantum cryptography and carrying out standardization work [2] in order to still protect the security of information when quantum computers become practical. Among post-quantum cryptographies, lattice-based encryption is a very important technology. The only post-quantum encryption algorithm CRYSTALS-Kyber [4] announced by the National Institute of Standards and Technology (NIST) of the United States in July 2022 is a lattice-based encryption algorithm [3]. Encryptions such as SABER [6] and FrodoKEM [7] that entered the third round of evaluation of NIST post-quantum cryptography standardization are also lattice-based encryption algorithms.

[0003] Under the framework of the existing Lindner-Peikert lattice-based encryption algorithm [8], including algorithms such as Kyber [4], Saber [6], and FrodoKEM [7], there is a probability of decryption error in the algorithm, and the decryption error probability affects the security of the cryptographic algorithm to a certain extent [8]. Therefore, it is necessary to accurately and quickly estimate the decryption error rate of such lattice-based encryption algorithms.

[0004] In the field of lattice cryptography, the decryption error rate is usually calculated as the probability of the expression holding, where s1, e1, s2, e2, and e are secret vectors or perturbation vectors randomly generated by the cryptographic algorithm according to a specified distribution; in order to quantitatively compare the decryption error probability, usually the base-2 logarithm of the decryption error rate is used as the target value for comparison. For example, if the decryption error probability is 2 -136.87 , the target value of the decryption error probability is -136.87. Currently, there are mainly three estimation methods. The first is a rough estimate using the Chernoff inequality. The second is an approximate estimate using the Gaussian distribution based on the central limit theorem (including the Lyapunov theorem) [6]. The third is to calculate the sum of random distributions using convolution according to the discrete distribution adopted in the cryptographic algorithm [4][6][7]. In order to improve the estimation speed, the third method usually adopts a truncation method to remove some smaller probability distribution data during the calculation process [4][6][7].

[0005] References

[0006] [1] Peter Shor, Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer, 1994 Symposium of Foundations on Computer Science, SIAM Journal of Computing 26, pp. 1484-1509 (1997).

[0007] [2] National Institute of Standards and Technology - NIST, Post-Quantum Cryptography PQC, https: / / csrc.nist.gov / projects / post-quantum-cryptography

[0008] [3] NIST, Post-Quantum Cryptography PQC Round 3 Submissions, https: / / csrc.nist.gov / Projects / post-quantum-cryptography / post-quantum-cryptography-standardization / round-3-submissions

[0009] [4] Peter Schwabe et al., CRYSTALS cryptographic suite for algebraic lattices,

[0010] https: / / pq-crystals.org / kyber / index.shtml

[0011] [5] GitHub - pq-crystals / kyber,https: / / github.com / pq-crystals / kyber

[0012] [6]D’Anvers, JP., Karmakar, A., Sinha Roy, S., Vercauteren, F. (2018). Saber: Module-LWR Based Key Exchange, CPA-Secure Encryption and CCA-Secure KEM. In: Joux, A., Nitaj, A., Rachidi, T. (eds) Progress in Cryptology–AFRICACRYPT 2018. AFRICACRYPT2018. Lecture Notes in Computer Science(), vol 10831. Springer, Cham.

[0013] https: / / doi.org / 10.1007 / 978-3-319-89339-6_16

[0014] [7]Erdem Alkim et al., FrodoKEM, practical quantum-secure key encapsulation from generic lattices, https: / / frodokem.org /

[0015] [8]R. Lindner and C. Peikert. Better key sizes(and attacks) for LWE-based encryption. In CT-RSA, pages 319–339. 2011.

[0016] [9]D’Anvers, JP., Guo, Q., Johansson, T., Nilsson, A., Vercauteren, F., Verbauwhede, I.

[0017] (2019). Decryption Failure Attacks on IND-CCA Secure Lattice-Based Schemes. In: Lin, D., Sako, K. (eds) Public-Key Cryptography–PKC 2019. PKC2019. Lecture Notes in Computer Science(), vol 11443. Springer, Cham.

[0018] https: / / doi.org / 10.1007 / 978-3-030-17259-6_19 Summary of the Invention

[0019] The object of the present invention is to overcome the deficiencies of the prior art and provide a method, medium, device and system for estimating the decryption error rate of a lattice-based encryption algorithm, which can clarify the type of calculation data used, ensure that machine errors do not affect the estimation result of the decryption error probability within the specified input precision range; ensure that the truncated part of the distribution table does not affect the estimation result of the decryption error probability within the specified input precision range; and can accelerate the estimation process of the algorithm decryption error probability, etc.

[0020] The object of the present invention is achieved by the following solutions:

[0021] A method for estimating the decryption error rate of a lattice-based encryption algorithm includes the following steps:

[0022] Determine the floating-point data type required for estimating the decryption error rate using the parameters of the lattice cryptography algorithm itself;

[0023] Run the heuristic rough estimate password detection program code or computing device to give the small probability critical value that can be truncated in the fine calculation, and finally run the fine estimate password detection program code or computing device to quickly obtain the target value of the decryption error rate.

[0024] Further, the step of determining the floating-point data type required for estimating the decryption error rate using the parameters of the lattice cryptography algorithm itself; determining the floating-point data type required for estimating the decryption error rate using the parameters of the lattice cryptography algorithm itself; running the heuristic rough estimate password detection program code or computing device to give the small probability critical value that can be truncated in the fine calculation, and finally running the fine estimate password detection program code or computing device to quickly obtain the target value of the decryption error rate includes the following sub-steps:

[0025] Step S0: Start: Input the modulus q of the lattice cryptography algorithm, the distribution table corresponding to the private key or random perturbation, the accumulation times r of the random variable s1e2 - e1s2 determined by the password operation, the boundary value b for judging whether decryption is incorrect, the number n of the final plaintext output units for each encryption operation, and the relative error upper bound ε of the target value of the decryption error rate r or the absolute error upper bound ε a ;

[0026] Step S1: Determine the estimation boundary index m0 according to the calculation method of the distribution table and determine the estimation boundary index m1 according to the calculation method of the distribution table D e ; calculate the index m for measuring the perturbation error expansion speed, m = (m0 + q)r - q + m1;

[0027] Step S2: Select the floating-point operation data type of the password detection program code or computing device, so that the relative error precision of the floating-point operation is always M No more than or no more than

[0028] Step S3: Calculate the distribution table

[0029] Step S4: roughly estimate the probability p of a single output unit of the tested cryptographic algorithm decrypting error clt ;

[0030] Step S5: Start to calculate the probability of decryption error of a single output unit of the tested cryptographic algorithm; set the upper bound of the interception to or

[0031] Step S6: Select the floating point operation data type of the password detection program code or computing device so that the minimum positive floating point number that the machine can represent does not exceed or

[0032] Step S7: Take the upper bound of the intercept as B abscnt or B relcnt , use simulation to calculate the probability p of a single output unit decryption error abscnt or p relcnt ;

[0033] Step S8: Start calculating the probability of decryption error of a single output unit of the tested cryptographic algorithm, and set the upper bound of the interception to: or,

[0034]

[0035] Step S9: If B abscnf ≥B abscnt or B relcnf ≥B relcnt , then set p abscnf =p abscnt or p relcnf =p relcnt , proceed to step S12;

[0036] Step S10: Select the floating point operation data type of the password detection program code or computing device so that the smallest normal positive floating point number that the machine can represent does not exceed or

[0037] Step S11: Take the upper bound of the intercept as Babscnf or B relcnf , use simulation to calculate the probability p of decryption error for a single output unit of the password algorithm to be detected abscnf or p relcnf ;

[0038] Step S12: According to the independence assumption of the output bits, output the target value log2(np of the decryption error probability of the password algorithm to be detected abscnf ) or log2(np relcnf ), and end.

[0039] Furthermore, in step S3, the calculation distribution table includes the following sub-steps:

[0040] represents the residue class ring of the modulus q, and take the representative elements {0, 1,..., q - 1} or {-[q / 2],..., [(q - 1) / 2]};

[0041] Step S31: Calculate the distribution table For any

[0042]

[0043] Calculate For any

[0044]

[0045] Step S32: Calculate the distribution table For any

[0046]

[0047] Step S33: Calculate the mean μ0 and variance σ0 of the distribution table ,

[0048]

[0049]

[0050] Furthermore, in step 4, the rough estimation of the probability p of decryption error for a single output unit of the password algorithm to be detected clt , includes the following sub-steps:

[0051] Step S41: Select the lower bound of the decryption error probability of a single output unit, or select to use the central limit theorem to estimate the approximation of the decryption error probability of a single output unit of the cryptographic algorithm to be detected; if the former is selected, then proceed to step S42; if the central limit theorem is selected, then proceed to step S43;

[0052] Step S42: Estimate the lower bound of the decryption error probability of a single output unit or select an inequality according to specific conditions, and then set it as the estimated value p of the decryption error probability of a single output unit clt ;

[0053] Step S43: Use the central limit theorem or select the usage mode of the central limit theorem according to specific conditions to estimate the approximation value p of the decryption error probability of a single output unit clt 。

[0054] Furthermore, step S7 includes the following steps:

[0055] Step S71: Input the upper bound B of the interception, the distribution table and D e ;

[0056] Step S72: Calculate the binary representation sequence r k-1 …r1r0 of r without the highest bit, that is, satisfy r = r0 + 2r1 + … 2 k-1 r k-1 + 2 k , where r0, r1,..., r k-1 ∈{0, 1};

[0057] Step S73: Set l = k, the distribution table

[0058] Step S75: Calculate the convolution distribution table D l of the distribution table D l and the distribution table D bl , that is, satisfy

[0059]

[0060] Step S76: Truncate the values in the distribution table D bl below the boundary B to obtain the distribution table D' bl ; that is,

[0061]

[0062] Step S77: If r l = 1, then proceed to step S78, otherwise set the distribution table D l-1 = D' bl , and proceed to step S711;

[0063] Step S78: Calculate the distribution table D′ bl and the convolution distribution table D of the distribution table al , that is, satisfy

[0064]

[0065] Step S79: Truncate the values in the distribution table D al that are lower than the boundary B; that is,[[]]

[0066]

[0067] Step S710: Set the discrete probability distribution D l-1 = D′ al ;

[0068] Step S711: If l > 1, then set l = l - 1 and then go to Step S7.5;

[0069] Step S712: Calculate the convolution distribution table D1 of the distribution table D0 and the distribution table D e , that is, satisfy

[0070]

[0071] Step S714: Calculate

[0072]

[0073] Step S715: Return the value p;

[0074] Step S11 includes the following steps:

[0075] Step S111: Input the upper bound B of the truncation, the distribution table and D e ;

[0076] Step S112: Calculate the binary representation sequence r k-1 …r1r0 of r without the highest - order bit, that is, satisfy r = r0 + 2r1+…2 k-1 r k-1 +2 k , where r0, r1,..., r k-1 ∈{0, 1};

[0077] Step S113: Set l = k, the distribution table

[0078] Step S115: Calculate the convolution distribution table D l of the distribution table D l and the distribution table D bl, that is, satisfying

[0079]

[0080] Step S116: Truncate the values in the distribution table D bl that are lower than the boundary B to obtain a distribution table D' bl ; that is,

[0081]

[0082] Step S117: If r l = 1, then enter step S78; otherwise, set the distribution table D l-1 = D' bl , and enter step S1111;

[0083] Step S118: Calculate the convolution distribution table D bl of the distribution table D' and the distribution table al , that is, satisfying:

[0084]

[0085] Step S119: Truncate the values in the distribution table D al that are lower than the boundary B; that is:

[0086]

[0087] Step S1110: Set the discrete probability distribution D l-1 = D' al ;

[0088] Step S1111: If l > 1, then set l = l - 1 and then enter step S115;

[0089] Step S1112: Calculate the convolution distribution table D1 of the distribution table D0 and the distribution table D e , that is, satisfying

[0090]

[0091] Step S1114: Calculate

[0092]

[0093] Step S1115: Return the value p.

[0094] Furthermore, in step S43, when estimating the approximation value p clt of the probability that a single output unit of the detected cryptographic algorithm decrypts incorrectly by using the central limit theorem, it includes sub-steps:

[0095] First, calculate the mean μ of the discrete probability distribution D e and the variance σ e . Calculate the mean μ = rμ0 + μ of the sum of random variables e and the variance σ = rσ0 + σ e ; e

[0096] Next, calculate the estimated value of the probability that a single output unit of the password algorithm under test decrypts incorrectly:

[0097]

[0098] It is usually calculated more simply under specific parameters:

[0099]

[0100] In practice, this step is calculated through the error function, complementary error function, or integral.

[0101] Furthermore,

[0102] Between step S73 and step S75, it includes the steps:

[0103] Step S74: Truncate the values in the distribution table D l that are lower than the boundary B; that is, set

[0104]

[0105] Between step S712 and step S714, it includes the steps:

[0106] Step S713: Truncate the values in the distribution table D1 that are lower than the boundary B; that is,

[0107]

[0108] Between step S113 and step S115, it includes the steps:

[0109] Step S114: Truncate the values in the distribution table D l that are lower than the boundary B; that is, set

[0110]

[0111] Between step S1112 and step S1114, it includes the steps:

[0112] Step S1113: Truncate the values in the distribution table D1 that are lower than the boundary B; that is,

[0113]

[0114] A readable storage medium stores a computer program, and the computer program is loaded and executed by a processor to perform the method described in any one of the above.

[0115] A computer device includes a processor and a memory. A computer program is stored in the memory, and when the computer program is loaded and executed by the processor, the method described in any one of the above is performed.

[0116] An estimation system for the decryption error rate of a lattice-based encryption algorithm includes the computer device described above, or includes a detection device, and the detection device is used to perform the method described in any one of claims 1 to 7.

[0117] The beneficial effects of the present invention include:

[0118] Aiming at the defects of the existing decryption error rate evaluation technology for lattice-based encryption algorithms, the technical solution of the present invention has the following beneficial effects and advantages:

[0119] (1) It can clarify the type of calculation data used, ensuring that machine errors do not affect the estimation result of the decryption error probability within the specified precision range of the input.

[0120] (2) It gives the boundary values of the small-probability data truncated during the acceleration of the calculation process, ensuring that the truncated data in the distribution table does not affect the estimation result of the decryption error probability within the specified precision range of the input.

[0121] (3) Using the strategy of "coarse estimation first and then refined calculation, with coarse estimation assisting refined calculation" can accelerate the estimation process of the decryption error probability of the algorithm. For example, in the calculation of the decryption error rate of the Frodo-640 algorithm, according to this method, 2 -181.04 can be truncated, instead of being less than 10 -200 . Therefore, more distribution table data can be truncated during the calculation process compared with the previous existing counting, thus obtaining a faster calculation speed of the decryption error probability. BRIEF DESCRIPTION OF THE DRAWINGS

[0122] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0123] Figure 1 It is the overall step flowchart of the method in the embodiment of the present invention;

[0124] Figure 2 It is the information flowchart for calculating the basic distribution table of the method in the embodiment of the present invention;

[0125] Figure 3 It is a flowchart for estimating the probability of decryption error of a single output unit in the method of the embodiment of the present invention;

[0126] Figure 4 It is a flowchart for simulating and calculating the target value of decryption error rate in the method of the embodiment of the present invention. Specific embodiments

[0127] All features disclosed in all embodiments in this specification, or steps in all methods or processes implicitly disclosed, except for mutually exclusive features and / or steps, can be combined and / or extended and replaced in any way.

[0128] Term explanation

[0129] Distribution table: A data structure used to specify non - negative values on some integers, and is used to record the whole or part of a discrete probability distribution.

[0130] The residue class ring of modulus q, often taking representative elements {0, 1,..., q - 1} or {-[q / 2],..., [(q - 1) / 2]}.

[0131] In view of the problems in the background, after creative analysis and thinking by the inventors of the present invention, it is further found that: According to the published literature and open - source code, the existing calculation methods for the decryption error rate of lattice - based encryption algorithms still have the following deficiencies:

[0132] (1) The choice of calculation data type and its basis are not clearly defined.

[0133] In order to make the estimation process feasible in terms of time and space resources, floating - point operations are generally used. However, floating - point data types have different precisions, and the storage space and calculation time consumed are different. The existing methods do not clearly state how to choose the floating - point operation data type to be used and the basis for the choice.

[0134] (2) The choice of the critical value for truncating data during the acceleration of the calculation process and its basis are not clearly defined.

[0135] In order to reduce the estimation time, when successively calculating the convolution of discrete distributions, it is not yet clear how small the distribution value can be truncated, and the basis for choosing the truncation critical value. For example, in the decryption error rate test codes of the CRYSTALS - Kyber and Saber algorithms, discrete probability values less than or equal to 2 - 300 are truncated [3][6][4][5]; in the decryption error rate test code of the FrodoKEM algorithm, discrete probability values less than 10 -200 (annotation code 2 -650 ) are truncated [7][3].

[0136] (3) Fail to correlate different calculation methods and results of decryption error rate.

[0137] In the calculation of the decryption error rate of the existing lattice cryptography, the above three different calculation methods are carried out independently of each other, failing to characterize or utilize the internal relationship of the obtained data results, and no overall unified evaluation of the decryption error rate has been formed.

[0138] Regarding the problem of estimating the decryption error rate of a class of lattice-based encryption algorithms, the technical solution of the present invention proposes a technical solution for estimating the decryption error rate of a lattice-based encryption algorithm, including corresponding methods, media, devices and systems. The method can use the parameters of the lattice cryptography algorithm itself to determine the floating-point data type required for estimating the decryption error rate, cooperate with the existing calculation methods of the decryption error rate, first run a heuristic rough estimate and then give the small-probability critical value that can be truncated in the subsequent fine calculation, and finally run the fine estimate to quickly obtain the target value of the decryption error rate. This method improves the known calculation method of the decryption error rate and is also applicable to lattice-based key exchange protocols, key encapsulation, etc.

[0139] The technical innovation points of the technical solution of the embodiment of the present invention are: (1) First estimate the probability of decryption error, and then use the estimated value to help accurately evaluate the probability of decryption error; (2) Use a quantization method to determine the data type required for accurately calculating the decryption error rate, and predict the decision boundary value for truncating part of the probability to accelerate the accurate calculation of the decryption error rate; (3) The absolute error and relative error of the given decryption error rate are within the specified accuracy range.

[0140] Embodiment 1

[0141] Further, the technical solution of the embodiment of the present invention is described in detail as follows. Some basic concepts involved are as follows.

[0142] Distribution table: A data structure used to specify non-negative values on some integers, used to record the whole or part of a discrete probability distribution.

[0143] The residue class ring of modulus q, often taking representative elements {0, 1,..., q - 1} or {-[q / 2],..., [(q - 1) / 2]}.

[0144] A method for estimating the decryption error rate of a lattice-based encryption algorithm provided by the technical solution of the present invention includes the following steps:

[0145] Start: Input the modulus q of the lattice cryptography algorithm into the password detection program code or computing device, and characterize the distribution table corresponding to the private key or random perturbation The accumulation count r of the random variable s1e2 - e1s2 determined by the cryptographic operation, the boundary value b for determining whether decryption is in error, the number of plaintext output units n in each encryption operation, the precision requirement for the target value of the decryption error rate (the relative error upper bound ε r or the absolute error upper bound ε a ).

[0146] Step 1: Determine the estimation boundary index m0 according to the calculation method of the distribution table , determine the estimation boundary index m1 according to the calculation method of the last-step distribution D e , and calculate m = (m0 + q)r - q + m1. For example, for CRYSTALS-Kyber, m0 = 5q + 2 and m = 6qr + 2r can be selected.

[0147] Step 2: Select the cryptographic detection program code or the floating-point operation data type of the computing device, always making the relative error precision ε of the floating-point operation M not exceed (or not exceed ).

[0148] Step 3: Calculate the distribution table

[0149] Step 4: Coarsely estimate the probability p of decryption error for a single output unit of the cryptographic algorithm to be detected clt .

[0150] Step 5: Start the trial calculation of the probability of decryption error for a single output unit of the cryptographic algorithm to be detected. Set the upper bound of the truncation to (or ... ).

[0151] Step 6: Select the cryptographic detection program code or the floating-point operation data type of the computing device, such that the smallest positive normal floating-point number that the machine can represent does not exceed (or ).

[0152] Step 7: Use B abscnt (or B relcnt ) as the upper bound of the truncation, and use simulation to calculate the probability p of decryption error for a single output unit abscnt (or p relcnt ).

[0153] Step 8: Start the verification of the probability of decryption error for a single output unit of the cryptographic algorithm to be detected. Set the upper bound of the truncation to:

[0154]

[0155] (or)

[0156]

[0157] Step 9: If B abscnf ≥ B abscnt (or B relcnf ≥ B relcnt ), then set p abscnf = p abscnt (or p relcnf = p relcnt ), and go to Step 12.

[0158] Step 10: Select the password detection program code or the floating-point operation data type of the computing device such that the smallest positive normal floating-point number that the computing device can represent does not exceed (or ).

[0159] Step 11: Using B abscnf (or B relcnf ) as the upper bound of the truncation, use simulation to calculate the probability p abscnf (or p relcnf ) of decryption error for a single output unit of the password algorithm to be detected.

[0160] Step 12: According to the independence assumption of the output bits, output the target value log2(np abscnf )(or log2(np relcnf )) of the decryption error probability of the password algorithm to be detected, and end.

[0161] Embodiment 2

[0162] Based on Embodiment 1, in the method for estimating the decryption error rate of the lattice-based encryption algorithm provided by the technical solution of the embodiment of the present invention, Step 3 includes the following sub-steps:

[0163] Step 3.1: Calculate the distribution table For any

[0164]

[0165] Step 3.2: Calculate For any

[0166]

[0167] Step 3.3: Calculate the distribution table For any

[0168]

[0169] Step 3.4: Calculate the distribution table with a mean μ0 and a variance σ0

[0170]

[0171]

[0172] Example 3

[0173] Based on Example 1, in the method for estimating the decryption error rate of the lattice-based encryption algorithm provided by the technical solution of the embodiment of the present invention, step 4 includes the following sub-steps:

[0174] Step 4.1: To estimate the probability of decryption error for a single output unit of the password algorithm to be detected, choose to use the lower bound of the probability of decryption error for a single output unit, or choose to use the central limit theorem (including the Lyapunov theorem) to estimate the approximation value of the probability of decryption error for a single output unit of the password algorithm to be detected. If the former is chosen, then proceed to step 4.2; if the central limit theorem (including the Lyapunov theorem) is chosen, then proceed to step 4.3.

[0175] Step 4.2: Estimate the lower bound of the probability of decryption error for a single output unit, and set it as the estimated value p of the probability of decryption error for a single output unit of the password algorithm to be detected clt . For example, set the return value pclt.

[0176] Step 4.3: Use the central limit theorem (including the Lyapunov theorem) to estimate the approximation value p of the probability of decryption error for a single output unit of the password algorithm to be detected clt . For example, in the following manner (steps 4.4 to 4.5):

[0177] Step 4.4: Calculate the discrete probability distribution D e with a mean μ e and a variance σ e , calculate the mean μ = rμ0 + μ of the sum of random variables e and the variance σ = rσ0 + σ e .

[0178] Step 4.5: Calculate the estimated value of the probability of decryption error for a single output unit of the password algorithm to be detected:

[0179]

[0180] It is usually calculated more simply under specific parameters:

[0181]

[0182] In practice, this step can be calculated through the error function, complementary error function, or integral.

[0183] Example 4

[0184] On the basis of Example 1, in the method for estimating the decryption error rate of the lattice-based encryption algorithm provided by the technical solution of the embodiment of the present invention, step 7 or step 11 is completed through the following steps:

[0185] Step 7.1: Input the upper bound B intercepted in step 7 or step 11, the distribution table and D e .

[0186] Step 7.2: Calculate the binary representation sequence r of r without the highest bit, i.e., r k-1 …r1r0, which satisfies r = r0 + 2r1 + … 2 k-1 r k-1 + 2 k , where r0, r1, ..., r k-1 ∈ {0, 1}.

[0187] Step 7.3: Set l = k, the distribution table

[0188] Step 7.4: Cut off the values in the distribution table D l that are lower than the boundary B. That is, set

[0189]

[0190] Step 7.5: Calculate the convolution distribution table D l of the distribution table D l and the distribution table D bl , that is, satisfy

[0191]

[0192] Step 7.6: Cut off the values in the distribution table D bl that are lower than the boundary B to obtain the distribution table D′ bl . That is,[[]]

[0193]

[0194] Step 7.7: If r l = 1, then enter step 7.8, otherwise set the distribution table D l-1 = D′ bl , and enter step 7.11.[[]]

[0195] Step 7.8: Calculate the convolution distribution table D bl of the distribution table D′ and the distribution table al , that is, satisfy

[0196]

[0197] Step 7.9: Truncate the distribution table D al values lower than the boundary B in it. That is,

[0198]

[0199] Step 7.10: Set the discrete probability distribution D l -1 = D′ al .

[0200] Step 7.11: If l > 1, then set l = l - 1 and then go to Step 7.5.

[0201] Step 7.12: Calculate the convolution distribution table D1 of the distribution table D0 and the distribution table D e , that is, satisfying

[0202]

[0203] Step 7.13: Truncate the values lower than the boundary B in the distribution table D1. That is,

[0204]

[0205] Step 7.14: Calculate

[0206]

[0207] Step 7.15: Return the value p.

[0208] Furthermore, in other embodiments, in the method for estimating the decryption error rate of the lattice-based encryption algorithm provided by the technical solution of the embodiment of the present invention, the estimated object distribution is the normal situation, and corresponding adjustments will be made in specific solutions. However, if the key link of the decryption error rate estimation after adjustment is still the successive convolution of the same distribution, the technical solution of the present invention is still applicable.

[0209] Furthermore, in other embodiments, in the method for estimating the decryption error rate of the lattice-based encryption algorithm provided by the technical solution of the embodiment of the present invention, the number of output units is not necessarily the number of bits of the plaintext. In the case where coding and decoding technologies are not used in the cryptographic algorithm, note that the number of output units usually refers to the number of ciphertext vector coefficients used to load the plaintext for each encryption or key encapsulation. In the case where coding and decoding technologies are used in the cryptographic algorithm, it needs to be determined in combination with the coding and decoding technologies.

[0210] Further, in other embodiments, in the method for estimating the decryption error rate of the lattice-based encryption algorithm provided by the technical solution of the embodiments of the present invention, steps 3.1 and 3.2 can be calculated in parallel, the order can be exchanged, and in some specific parameter cases, they can be combined into one calculation.

[0211] Further, in other embodiments, in the method for estimating the decryption error rate of the lattice-based encryption algorithm provided by the technical solution of the embodiments of the present invention, the lower bound of step 4.2 is not the only approach, and inequalities can be selected according to specific conditions.

[0212] Further, in other embodiments, in the method for estimating the decryption error rate of the lattice-based encryption algorithm provided by the technical solution of the embodiments of the present invention, steps 4.4 and 4.5 are not the only ways to use the central limit theorem (including the Lyapunov theorem), and the usage mode of the central limit theorem (including the Lyapunov theorem) can be selected according to specific conditions.

[0213] Further, in other embodiments, in the method for estimating the decryption error rate of the lattice-based encryption algorithm provided by the technical solution of the embodiments of the present invention, steps 7.4 and 7.13 are optional steps and can also be skipped without execution. Whether to select them will affect the selection of data types and the setting of the truncation value boundary B, but the impact is usually small.

[0214] A method for estimating the decryption error rate of a lattice-based encryption algorithm proposed by the technical solution of the present invention is also applicable to similar lattice-based key exchange protocols, key encapsulation mechanisms, etc. that require estimating the decryption error rate.

[0215] It should be noted that within the scope of protection defined in the claims of the present invention, the following embodiments can be combined and / or extended, replaced in any logical manner from the above specific embodiments, such as the disclosed technical principles, disclosed technical features, or implicitly disclosed technical features.

[0216] The units described in the embodiments of the present invention can be implemented in software or in hardware, and the described units can also be provided in a processor. Among them, the names of these units do not constitute a limitation to the unit itself in some cases.

[0217] According to one aspect of the embodiments of the present invention, there is provided a computer program product or a computer program or a password detection program code or a computing device, which includes computer instructions stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the methods provided in the above various alternative implementation manners.

[0218] As another aspect, an embodiment of the present invention further provides a computer-readable medium, which may be included in the electronic device described in the above embodiment; or may exist alone without being assembled into the electronic device. The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by an electronic device, the electronic device implements the method described in the above embodiment.

[0219] The parts not involved in the present invention are the same as or can be implemented by the prior art.

[0220] The above technical solution is only one implementation manner of the present invention. For those skilled in the art, based on the application methods and principles disclosed in the present invention, it is very easy to make various types of improvements or deformations, not limited to the methods described in the above specific implementation manners of the present invention. Therefore, the manner described above is only preferred and does not have a restrictive meaning.

[0221] Except for the above examples, those skilled in the art obtain inspiration based on the above disclosure or make other embodiments by using the knowledge or technology in related fields. The features of each embodiment can be interchanged or replaced. As long as the changes and modifications made by those skilled in the art do not depart from the spirit and scope of the present invention, they should all be within the protection scope of the appended claims of the present invention.

Claims

1. A method for estimating the decryption error rate of a lattice-based encryption algorithm, characterized in that, The steps are as follows: Determine the floating-point data type required for estimating the decryption error rate by using the parameters of the lattice cryptography algorithm itself; Run the heuristic rough estimation password detection program code or computing device to give the small-probability critical value that can be truncated in the fine calculation, and finally run the fine estimation password detection program code or computing device to quickly obtain the target value of the decryption error rate; The step of determining the floating-point data type required for estimating the decryption error rate by using the parameters of the lattice cryptography algorithm itself; determining the floating-point data type required for estimating the decryption error rate by using the parameters of the lattice cryptography algorithm itself; running the heuristic rough estimation password detection program code or computing device to give the small-probability critical value that can be truncated in the fine calculation, and finally running the fine estimation password detection program code or computing device to quickly obtain the target value of the decryption error rate, includes the following sub-steps: Step S0: Start: Input the modulus q of the lattice password algorithm into the password detection program code or computing device, representing the distribution table corresponding to the private key or random perturbation D e , the accumulation times r of the random variable s1e2 - e1s2 determined by the password operation, the boundary value b for judging whether decryption is in error, the number of plaintext output units n in the final encryption operation each time, and the relative error upper bound ε of the decryption error rate target value r or the absolute error upper bound ε a ; Step S1: Determine the estimated boundary index m0 according to the calculation method of the distribution table , and determine the estimated boundary index m1 according to the calculation method of the distribution table D e . Calculate the index m for measuring the disturbance error expansion rate: m = (m0 + q)r - q + m1; Step S2: Select the password detection program code or the floating-point operation data type of the computing device, always making the relative error precision ε of the floating-point operation M not exceed or not exceed Step S3: Calculate the distribution table Step S4: Coarsely estimate the probability p of decryption error for a single output unit of the password algorithm to be detected clt ; Step S5: Start calculating the decryption error probability of a single output unit of the password algorithm to be detected; set the upper bound of the intercepted data as or Step S6: Select the password detection program code or the floating-point operation data type of the computing device such that the smallest positive normal floating-point number representable by the machine does not exceed or Step S7: Use B as the upper bound of the intercepted data abscnt or B relcnt , and use simulation to calculate the probability p of decryption error of a single output unit of the password algorithm to be detected abscnt or p relcnt ; Step S8: Start calculating the decryption error probability of a single output unit of the detected cryptographic algorithm, and set the upper bound of the intercepted data as: Or, Step S9: If B abscnf ≥ B abscnt or B relcnf ≥ B relcnt , then set p abscnf = p abscnt or p relcnf = p rekcnt , and go to Step S12; Step S10: Select the password detection program code or the floating-point operation data type of the computing device such that the smallest positive normal floating-point number that the computing device can represent does not exceed or Step S11: With the upper bound of the interception being B abscnf or B relcnf , use simulation to calculate the probability p of decryption error of a single output unit of the password algorithm to be detected abscnf or p relcnf ; Step S12: According to the independence assumption of the output bits, output the target value log2(np abscnf ) or log2(np relcnf ) of the decryption error probability of the cryptographic algorithm to be detected, and end.

2. The method for estimating the decryption error rate of the lattice-based encryption algorithm according to claim 1, wherein In step S3, the calculation distribution table includes the following sub-steps: Denote the residue class ring of modulus \(q\), and take the representative elements \(\{0, 1, \ldots, q - 1\}\) or \(\{-\lfloor q / 2\rfloor, \ldots, \lfloor(q - 1) / 2\rfloor\}\); Step S31: Calculate the distribution table For any Calculation For any Step S32: Calculate the distribution table For any Step S33: Calculate the distribution table for the mean μ0 and variance σ0, 3. The method for estimating the decryption error rate of the lattice-based encryption algorithm according to claim 1, characterized in that, In step 4, roughly estimate the probability p that a single output unit of the password algorithm to be detected decrypts incorrectly clt , including the following sub-steps: Step S41: Select to adopt the lower bound of the decryption error probability of a single output unit, or select to use the central limit theorem to estimate the approximation value of the decryption error probability of a single output unit of the password algorithm to be detected; if the former is selected, then go to step S42; if the central limit theorem is selected, then go to step S43; Step S42: Estimate the lower bound of the probability of decryption error for a single output unit or select an inequality according to specific conditions, and then set it as the estimated value p of the probability of decryption error for a single output unit clt ; Step S43: Estimate the approximation value p of the probability that a single output unit decrypts incorrectly by using the central limit theorem or selecting the way to use the central limit theorem according to specific conditions clt .

4. The method for estimating the decryption error rate of the lattice-based encryption algorithm according to claim 1, characterized in that Step S7 includes the following steps: Step S71: Input the upper bound B of the intercept, the distribution table and D e ; Step S72: Calculate the binary representation sequence r of r without the highest - order bit k-1 …r1r0, that is, satisfying r = r0 + 2r1+…2 k-1 r k-1 +2 k , where r0, r1, …, r k-1 ∈{0,1}; Step S73: Set l = k, distribution table Step S75: Calculate the distribution table D l and the convolution distribution table D l of the distribution table D bl , that is, satisfying Step S76: Truncate the distribution table D bl for values lower than the boundary B therein to obtain a distribution table D' bl ; that is Step S77: If r l = 1, then proceed to step S78; otherwise, set the distribution table D l-1 = D' bl , and proceed to step S711; Step S78: Calculate the distribution table D' bl and the distribution table to obtain the convolution distribution table D al , that is, satisfy Step S79: Truncate the distribution table D al for values lower than the boundary B; that is, Step S710: Set the discrete probability distribution D l-1 = D' al ; Step S711: If l>1, then set l = l - 1 and then go to step S7.5; Step S712: Calculate the convolution distribution table D1 of the distribution table D0 and the distribution table D e , that is, satisfying Step S ​ ​ Step S111: Input the upper bound B of the interception and the distribution table and D e ; Step S112: Calculate the binary representation sequence r of r without the highest bit k-1 …r1r0, that is, satisfying r = r0 + 2r1 + … 2 k-1 r k-1 + 2 k , where r0, r1, …, r k-1 ∈ {0, 1}; Step S113: Set l = k, distribution table Step S115: Calculate the distribution table D l and the distribution table D l of the convolutional distribution table D bl , that is, satisfying Step S116: Truncate the distribution table D bl by values lower than the boundary B, obtaining a distribution table D' bl ; that is, Step S117: If r l = 1, then go to step S78, otherwise set the distribution table D l-1 = D' bl , and go to step S1111; Step S118: Calculate the distribution table D' bl and the distribution table to obtain the convolution distribution table D al , that is, it satisfies: Step S119: Truncate the distribution table D al for values lower than the boundary B; that is: Step S1110: Set the discrete probability distribution D l-1 = D' al ; ​ Step S1112: Calculate the convolution distribution table D1 of the distribution table D0 and the distribution table D e , that is, satisfy ​ ​ 5. The method for estimating the decryption error rate of the lattice-based encryption algorithm according to claim 1, wherein, In step S43, when estimating the approximation value p of the probability that a single output unit of the detected cryptographic algorithm decrypts incorrectly by using the central limit theorem, the method includes sub-steps: clt When First, calculate the distribution table D e of the mean μ e , variance σ e . Calculate the mean μ = rμ0 + μ of the sum of random variables e , variance σ = rσ0 + v e ; ​ ​ ​ ​ ​ Step S74: Truncate the distribution table D l of values below the boundary B; that is, set ​ ​ ​ Step S114: Truncate the distribution table D l for values below the boundary B; that is, set ​ ​ 7. A readable storage medium, characterized in that, ​ 8. A computer device, characterized in that, ​ 9. An estimation system for the decryption error rate of a lattice-based encryption algorithm, characterized in that, ​