Lattice public key data encryption and decryption method and key encapsulation method based on vector decoding

By employing a vector-based public-key data encryption and decryption method, which utilizes lattice cryptography encoding and NTT number theory transformations, the security issues of public-key encryption methods under the threat of quantum computing are resolved, achieving a more efficient data encryption and decryption process.

CN116366251BActive Publication Date: 2026-03-31BEIJING ACAD OF INFORMATION SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-21
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Existing public-key encryption methods based on RSA or elliptic curves are not secure enough in the face of quantum computing threats. They have large public key and ciphertext sizes, which leads to increased storage and communication overhead, low computational efficiency of encryption and decryption operations, and high decryption failure rates.

Method used

A vector-based public-key data encryption and decryption method based on vector decoding is adopted. The target ciphertext data is generated by encoding plaintext data into a polynomial and using the encoding method of lattice cryptography. The computational efficiency is optimized by using NTT number theory transformation operations, and smaller ring parameters are supported to reduce the size of public key and ciphertext.

Benefits of technology

It effectively reduces the decryption failure rate, reduces the size of public keys and ciphertext, reduces storage and communication overhead, and improves encryption and decryption speed and computational efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116366251B_ABST
    Figure CN116366251B_ABST
Patent Text Reader

Abstract

The application discloses a lattice public key data encryption and decryption method and a key encapsulation method based on vector decoding. The method comprises the following steps: obtaining first target ciphertext data according to predetermined plaintext data, a first predetermined encryption method, a first target public key and a predetermined interference term, so that lattice public key data encryption can be realized; obtaining target plaintext data according to the first target ciphertext data, a first target private key and a predetermined decryption method, so that lattice public key data decryption can be realized. Meanwhile, the application also proposes a variant problem of a ring learning with errors problem (RLWE), namely, a subset-sum parity RLWE (sspRLWE) problem, and further optimizes the lattice public key data encryption method based on vector decoding in the application based on the variant problem. The public key encryption method and the key encapsulation method designed in the application have the characteristics and advantages of provable security, resistance to quantum computer attacks, short public key and ciphertext length, high calculation efficiency, low decryption failure rate, flexible parameter selection and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of public-key cryptography and involves data encryption and decryption and related technologies in lattice cryptography. Specifically, it is manifested as a lattice public-key data encryption and decryption method and a key encapsulation method based on vector decoding. Background Technology

[0002] Public-key encryption has been widely deployed in many practical applications such as e-government and online banking. However, the improvement of large-scale computing power and the progress of cryptanalysis, especially the rapid development of quantum computing theory and quantum computers, have brought huge threats and challenges to the security of many public-key encryption methods based on RSA or elliptic curves. Therefore, there is an urgent need to design public-key encryption methods that are resistant to quantum computing attacks.

[0003] Currently, considering both efficiency and security, lattice-based public-key encryption methods have gained widespread recognition from scholars both domestically and internationally, and are among the most promising candidate methods. However, related technologies or methods still suffer from problems such as large public key and ciphertext sizes, leading to increased storage and communication overhead, low computational efficiency in encryption and decryption operations, and high decryption failure rates, which cannot adequately meet the needs of practical applications. Summary of the Invention

[0004] This invention provides a vector-based public key data encryption / decryption method and key encapsulation method to solve problems such as large public key and ciphertext sizes, low computational efficiency of encryption / decryption operations, and high decryption failure rate in related technologies or methods.

[0005] According to one aspect of the present invention, a lattice public-key data encryption method based on vector decoding is provided, comprising: determining predetermined plaintext data M a The predetermined plaintext data The The message space refers to the pre-defined plaintext data. The predetermined plaintext data is plaintext data of length 1 bit; using a first predetermined encryption method PKE.Enc(h, M), based on the predetermined plaintext data, a first target public key h1, and a predetermined interference term, a first target ciphertext data c1 is obtained; the first target ciphertext data c1 is sent to a first terminal, wherein, the step of using the first predetermined encryption method PKE.Enc(h, M), based on the predetermined plaintext data, the first target public key h1, and the predetermined interference term, to obtain the first target ciphertext data c1 includes: encoding the predetermined plaintext data M according to a predetermined encoding method. a The target encoding polynomial m is obtained, wherein the number of terms in the target encoding polynomial m is based on the predetermined plaintext data M. aThe predetermined bit length is determined, and the coefficients of each term of the target coding polynomial m are determined based on the plaintext data of the corresponding bit data in the predetermined plaintext data; based on the first target public key h1, the predetermined interference term and the target coding polynomial m, the first target ciphertext data c1 is obtained.

[0006] Optionally, obtaining the first target ciphertext data c1 based on the first target public key h1, the predetermined interference term, and the target coding polynomial m includes: when the predetermined coding method is Msg2poly(M), the target coding polynomial m = M0 + M1x + ... + M i x i +…+M l-1 x l-1 The predetermined interference term includes a random number r, a predetermined noise value e, and the inverse ring element v of the ring element v. -1 Based on the first target public key h1, the random number r, the predetermined noise value e, and the inverse loop element v -1 The first target ciphertext data c1 is obtained by combining the target encoding polynomial m, where M... i M represents a The data at the i-th bit length, M i ={0, 1}, the ring element v = (1-x n / k ), v∈R q Inverse cycle element m∈R q The It is R q The set of all invertible elements. For a predetermined ring structure, represent a polynomial ring of degree n-1. Where n is a power of 2, q is a prime number, and k is the largest integer satisfying k|n and n / k≥1, the... The set representing integers, the The set of positive integers.

[0007] Optionally, based on the first target public key h1, a predetermined interference term, and the target coding polynomial m, the first target ciphertext data c1 is obtained, including: when the predetermined coding method is Msg2noise(M, η), the target coding polynomial m = m0 + m1x + ... + m n-1 x n-1The predetermined interference term includes a random number r; based on the first target public key h1, the random number r and the target coding polynomial m are used to obtain the first target ciphertext data c1, where η represents the parameter value of the central binomial distribution, and the target coding polynomial m is a polynomial whose coefficients conform to the central binomial distribution with parameter value η, and the target coding polynomial m is determined to be m = m0 + m1x + ... + m n-1 x n-1 Includes: Determining Such that for all i∈[2kη-1], s i ∈{0,1} n / k and determine Based on the s and the s 2kη-1 For all i∈[k] and j∈[n / k], determine According to the m in / k+j Determine the target encoding polynomial m = m0 + m1x + ... + m n1 x n-1 .

[0008] Optionally, before obtaining the first target ciphertext data c1 based on the predetermined plaintext data, the first target public key h1, and the predetermined interference term using the first predetermined encryption method PKE.Enc(h, M), the method further includes: when the predetermined encoding method is Msg2poly(M), obtaining the initial private key f′, the predetermined private key g, and the ring element v, wherein the ring element v = (1-x n / k Based on the initial private key f′ and the ring element v, determine the first target private key f1; based on the first target private key f1 and the predetermined private key g, obtain the first target public key h1.

[0009] Optionally, before obtaining the first target ciphertext data c1 based on the predetermined plaintext data, the first target public key h1, and the predetermined interference term using the first predetermined encryption method PKE.Enc(h, M), the method further includes: when the predetermined encoding method is Msg2noise(M, η), obtaining the initial private key f′, the predetermined private key g, and the inverse loop element v. -1 , wherein the inverse ring element Based on the initial private key f′ and the inverse loop element v -1 Determine the first target private key f1; based on the first target private key f1 and the predetermined private key g, obtain the first target public key h1.

[0010] According to one aspect of the present invention, a method for decrypting lattice public key data based on vector decoding is provided, comprising: receiving first target ciphertext data c1 sent by a second terminal, wherein the first target ciphertext data c1 is obtained by using a first predetermined encryption method PKE.Enc(h, M) based on a first target public key h1, a predetermined interference term, and a target coding polynomial m, and the target coding polynomial m encodes the predetermined plaintext data M according to the predetermined encoding method. a The number of terms in the target encoding polynomial m is obtained based on the predetermined plaintext data M. a The predetermined bit length is determined, and the coefficients of each term in the target coding polynomial m are based on the predetermined plaintext data M. a In the process, the plaintext data corresponding to the data bits is determined, and the predetermined plaintext data is... The The message space refers to the pre-defined plaintext data. The target plaintext data is plaintext data of length l bits; using a predetermined decryption method PKE.Dec(f, c), based on the first target ciphertext data c1 and the first target private key f1, the target plaintext data M is obtained. b The first target private key f1 is determined according to the predetermined encoding method, and the predetermined decryption method PKE.Dec(f, c) is used to obtain the target plaintext data M based on the first target ciphertext data c1 and the first target private key f1. b This includes: determining the target decoding polynomial w based on the first target ciphertext data c1 and the first target private key f1; and decoding the target decoding polynomial w according to a predetermined decoding method to obtain the target plaintext data M. b The predetermined decoding method corresponds to the predetermined encoding method.

[0011] Optionally, a predetermined decryption method PKE.Dec(f, c) is used to obtain the target plaintext data M based on the first target ciphertext data c1 and the first target private key f1. b Previously, it also included: when the predetermined encoding method was Msg2poly(M), determining the first target private key f1 based on the initial private key f′ and the ring element v; and / or, when the predetermined encoding method was Msg2noise(M, η), determining the first target private key f1 based on the initial private key f′ and the inverse ring element v. -1 Determine the first target private key f1, wherein the ring element v = (1-x n / k ), v∈R q The inverse ring element The It is R q The set of all invertible elements. The predetermined ring structure represents a polynomial ring of degree n-1. Where n is a power of 2, q is a prime number, and k is the largest integer satisfying k|n and n / k≥1, the... The set representing integers, the Let η represent the set of positive integers, where η represents the parameter value of the central binomial distribution.

[0012] Optionally, when the predetermined encoding method includes at least one of the following: Msg2poly(M) and Msg2noise(M, η), the predetermined decoding method is Poly2msg(w), and the target decoding polynomial w is decoded according to the predetermined decoding method to obtain the target plaintext data M. b This includes: inputting the target decoding polynomial w into the Poly2msg(w), where w = w0 + w1x + ... + w n-1 x n-1 The w∈R q Based on all i∈[n], determine Based on all j∈[l], determine in accordance with Obtain the target plaintext data M b .

[0013] According to one aspect of the present invention, a lattice key encapsulation method based on vector decoding is provided, comprising: determining target random data M c , wherein The Represents the message space, the The target random data is defined as data of length l bits; based on the second target public key h2 and the first cryptographic hash function H1, the item value H1(h) for the second cryptographic hash function H2 is determined, wherein the first cryptographic hash function H1: {0, 1} * →{0,1} κ The second cryptographic hash function H2 is used to convert data of arbitrary bit length into data of κ bit length. l+κ →{0,1} κ ×{0, 1} κ This is used to convert data of a specific bit length into data of two κ bits, wherein the specific bit length is determined based on data of 1 bit length and data of κ bits length; based on the item value H1(h) and the target random data M c The first unknown is determined using the second cryptographic hash function H2. and the first offset ρ; based on the second target public key h2, the target random data M cUsing the first offset ρ, the second predetermined encryption method PKE.Enc(h, M; ρ) is applied to obtain the second target ciphertext data c2; based on the first unknown... The second target ciphertext data c2 is used to determine the encapsulation key K through the third cryptographic hash function H3, wherein the third cryptographic hash function H3 is {0, 1}. * →{0,1} κ This is used to convert data of arbitrary bit length into data of κ bit length.

[0014] Optionally, based on the first unknown After determining the encapsulation key K using the third cryptographic hash function H3, the process further includes: obtaining the target decrypted data M by using a predetermined decryption method PKE.Dec(f, c) based on the second target ciphertext data c2 and the second target private key f2. d Based on the value H1(h) and the target decryption data M d The second unknown is determined using the second cryptographic hash function H2. And the second offset ρ′; based on the second target public key h2, the target decrypted data M d Using the second offset ρ′, the second predetermined encryption method PKE.Enc(h, M; ρ) is applied to obtain the third target ciphertext data c3; if the second target ciphertext data c2 is the same as the third target ciphertext data c3, the encapsulation key K is output to the third terminal.

[0015] According to one aspect of the present invention, a lattice public-key data encryption device based on vector decoding is provided, comprising: a first determining module, configured to determine predetermined plaintext data M a The predetermined plaintext data The The message space refers to the pre-defined plaintext data. The predetermined plaintext data is plaintext data of length 1 bit; a first encryption module is used to obtain first target ciphertext data c1 by using a first predetermined encryption method PKE.Enc(h, M) based on the predetermined plaintext data, a first target public key h1, and a predetermined interference term; a sending module is used to send the first target ciphertext data c1 to a first terminal, wherein the first encryption module includes: an encoding module used to encode the predetermined plaintext data M according to a predetermined encoding method. a The target encoding polynomial m is obtained, wherein the number of terms in the target encoding polynomial m is based on the predetermined plaintext data M. aThe predetermined bit length is determined, and the coefficients of each term of the target coding polynomial m are determined based on the plaintext data in the corresponding bit data position in the predetermined plaintext data; the encryption submodule is used to obtain the first target ciphertext data c1 based on the first target public key h1, the predetermined interference term and the target coding polynomial m.

[0016] According to one aspect of the present invention, a vector-based public-key data decryption device is provided, comprising: a receiving module, configured to obtain a first target ciphertext data c1 using a first predetermined encryption method PKE.Enc(h, M) based on a first target public key h1, a predetermined interference term, and a target coding polynomial m, wherein the target coding polynomial m encodes the predetermined plaintext data M according to the predetermined encoding method. a The number of terms in the target encoding polynomial m is obtained based on the predetermined plaintext data M. a The predetermined bit length is determined, and the coefficients of each term in the target coding polynomial m are based on the predetermined plaintext data M. a In the process, the plaintext data corresponding to the data bits is determined, and the predetermined plaintext data is... The The message space refers to the pre-defined plaintext data. The target plaintext data is plaintext data of length l bits; the decryption module is used to obtain the target plaintext data M by using a predetermined decryption method PKE.Dec(f, c) based on the first target ciphertext data c1 and the first target private key f1. b The first target private key f1 is determined according to the predetermined encoding method. The decryption module includes: a second determining module, used to determine a target decoding polynomial w based on the first target ciphertext data c1 and the first target private key f1; and a decoding module, used to decode the target decoding polynomial w according to a predetermined decoding method to obtain the target plaintext data M. b The predetermined decoding method corresponds to the predetermined encoding method.

[0017] According to one aspect of the present invention, a lattice key encapsulation device based on vector decoding is provided, comprising: a third determining module, configured to determine target random data M c , wherein The Represents the message space, the The target random data is defined as data of length l bits; the fourth determining module is used to determine the item value H1(h) for the second cryptographic hash function H2 based on the second target public key h2 and the first cryptographic hash function H1, wherein the first cryptographic hash function H1: {0, 1} * →{0,1} κThe second cryptographic hash function H2 is used to convert data of arbitrary bit length into data of κ bit length. l+κ →{0,1} κ ×{0, 1} κ The first module is used to convert data of a specific bit length into data of two κ bits, wherein the specific bit length is determined based on data of 1 bit length and data of κ bits length; the second module is used to determine the target random data M based on the item value H1(h). c The first unknown is determined using the second cryptographic hash function H2. and a first offset ρ; a second encryption module, used to, based on the second target public key h2, the target random data M c Using the first offset ρ, the second predetermined encryption method PKE.Enc(h, M; ρ) is applied to obtain the second target ciphertext data c2; the sixth determining module is used to determine the second target ciphertext data c2 based on the first unknown. The second target ciphertext data c2 is used to determine the encapsulation key K through the third cryptographic hash function H3, wherein the third cryptographic hash function H3 is {0, 1}. * →{0,1} κ This is used to convert data of arbitrary bit length into data of κ bit length.

[0018] According to one aspect of the present invention, an electronic device is provided, comprising: a processor; a memory for storing processor-executable instructions; wherein the processor is configured to execute the instructions to implement the vector decoding-based lattice public key data encryption method, the vector decoding-based lattice public key data decryption method, and the vector decoding-based lattice key encapsulation method as described in any of the preceding claims.

[0019] According to one aspect of the present invention, a computer-readable storage medium is provided, wherein when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to perform the vector decoding-based lattice public key data encryption method, the vector decoding-based lattice public key data decryption method, or the vector decoding-based lattice key encapsulation method as described in any of the preceding claims.

[0020] In an embodiment of the present invention, a predetermined plaintext data M of length l bits is determined. a The first predetermined encryption method PKE.Enc(h, M) is used. Based on the predetermined plaintext data, the first target public key h1, and a predetermined interference term, the first target ciphertext data c1 is obtained, thereby achieving the purpose of encrypting the predetermined plaintext data. The first predetermined encryption method is as follows: the predetermined plaintext data M is encoded according to a predetermined encoding method. aThe target encoding polynomial m is obtained, which encodes the predetermined plaintext data. Then, based on the first target public key h1, the predetermined interference term, and the target encoding polynomial m, the first target ciphertext data c1 is obtained, thus encrypting the encoded predetermined plaintext data, strengthening its protection and enhancing security. Finally, the first target ciphertext data c1 can be sent to the first terminal. Since the first target ciphertext data is encrypted after encoding the predetermined plaintext data, its transmission to the first terminal also protects against data leakage. Moreover, unlike other schemes that only encode plaintext data to the least significant bit, the predetermined encoding method of this invention can encode each piece of plaintext data to the most significant bit and encode the plaintext data multiple times, thereby greatly reducing the decryption failure rate. At the same time, the encoding and decoding method proposed in this invention supports a smaller ring parameter q, thereby significantly reducing the size of the public key and ciphertext, and reducing storage and communication overhead. In addition, the ring structure used in this invention has the property of supporting NTT number theory transformation operations, thereby greatly reducing the number of operations such as polynomial multiplication and finding the inverse. Therefore, the encryption and decryption speed of this invention is also greatly improved, thus solving the problems of large public key and ciphertext size, low computational efficiency of encryption and decryption operations, and high decryption failure rate existing in related technologies and methods. Attached Figure Description

[0021] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:

[0022] Figure 1 This is a flowchart of a vector-based public-key data encryption method according to an embodiment of the present invention;

[0023] Figure 2 This is a flowchart of a vector-based public key data decryption method according to an embodiment of the present invention;

[0024] Figure 3 This is a flowchart of a lattice key encapsulation method based on vector decoding according to an embodiment of the present invention;

[0025] Figure 4 This is a structural block diagram of a lattice public key data encryption device based on vector decoding according to an embodiment of the present invention;

[0026] Figure 5 This is a structural block diagram of a vector-based public key data decryption device according to an embodiment of the present invention;

[0027] Figure 6 This is a structural block diagram of a lattice key encapsulation device based on vector decoding according to an embodiment of the present invention. Detailed Implementation

[0028] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0029] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0030] First, some nouns or terms that appear in the description of the embodiments of this application shall be interpreted as follows:

[0031] 1) Represents a set consisting of integers, i.e. Denotes the set of residual classes modulo q, i.e. Where q is a positive integer; for any positive integer n, Represents n items The direct product, i.e.

[0032] 2) Represents a set consisting of positive integers, i.e.

[0033] 3) Order They are positive integers, R, R², and R. q They are defined in and A polynomial ring of degree n-1; when n=1, it is defined as as well as For any positive integer Represents k R q The direct product, i.e. For any positive integer Indicates that by R qThe set consisting of a k×k matrix composed of elements in the set;

[0034] 4) For distribution D, This indicates that element x is randomly selected according to distribution D; for a finite set S, This means uniformly and randomly selecting element x from set S;

[0035] 5) The symbol := represents assignment, that is, for any two values ​​a and b, a:=b means that b is assigned as a;

[0036] 6) For any positive integer B η χ denotes the binomial distribution with parameter η; χ denotes the probability distribution on the multinomial ring R.

[0037] 7) For a positive even number α and any integer r, define the operation r′ = r modulo α. ± α output The operation r′ = r mod α holds true; for a positive odd number α and any integer r, define the operation r′ = r mod α. ± α output The condition r′=r mod α holds true. For any positive integer α and integer r, define the operation r′=r mod α. + The output r′∈[0, α) satisfies r′=r mod α. When the exact modulo operation representation is not important, it is abbreviated as rmod α;

[0038] 8) Central binomial distribution B with a positive integer η as parameter η The definition is as follows:

[0039]

[0040] Where (a1, ..., a) η b1, ..., b η )←{0,1} 2η This indicates that from the set {0, 1} 2η Bits a1, ..., a2 are randomly selected uniformly from the data. η b1, ..., b η From B η Sampling a polynomial f∈R q or polynomial vector means from B η The coefficients of each polynomial are sampled in the middle. It is easy to prove that the binomial distribution with parameter η is based on the coefficients of each polynomial. A sub-Gaussian distribution with standard deviation;

[0041] 9) Triadic distribution with positive real number σ∈(0, 1 / 2) as parameter This refers to sampling element x from the ternary set {-1, 0, 1} with the following probabilities:

[0042] Pr[x=1]=Pr[x=-1]=σ and Pr[x=0]=1-2σ,

[0043] Easy to prove, It is a uniform distribution on the set {-1, 0, 1}. It is a central binomial distribution with parameter η = 1;

[0044] 10) RSA algorithm: A public-key encryption algorithm proposed by Rivest, Shamir and Adleman. Public-key encryption algorithms use different encryption keys and decryption keys to perform data encryption and decryption operations.

[0045] 11) NTRU lattice public-key encryption method: It is an important branch of lattice cryptography, and its security is based on the difficulty of the NTRU problem proposed by Hoffstein, Pipher and Silverman in 1996;

[0046] 12) RLWE: Ring Learning with Errors Problem;

[0047] 13) sspRLWE: Subset-Sum Parity RLWE (sspRLWE), a variant of the RLWE problem;

[0048] 14) NTT: Number Theoretic Transform, is a practical technique that can be used to accelerate arithmetic operations.

[0049] Example 1

[0050] According to an embodiment of the present invention, an embodiment of a lattice public key data encryption method based on vector decoding is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0051] Figure 1 This is a flowchart of a lattice public-key data encryption method based on vector decoding according to an embodiment of the present invention, such as... Figure 1 As shown, the method includes the following steps:

[0052] Step S102, determine the predetermined plaintext data M a Among them, the pre-reserved plaintext data Represents the message space, reserved for plaintext data. This indicates that the plaintext data is intended to be 1 bit in length.

[0053] After step S102, the first predetermined encryption method PKE.Enc(h, M) is used. Based on the predetermined plaintext data, the first target public key h1, and the predetermined interference terms, the first target ciphertext data c1 is obtained, including:

[0054] Step S104: Encode the predetermined plaintext data M according to the predetermined encoding method. a The target encoding polynomial m is obtained, wherein the number of terms in the target encoding polynomial m is based on the predetermined plaintext data M. a The predetermined bit length is determined, and the coefficients of each term in the target coding polynomial m are determined based on the plaintext data in the corresponding bit data position in the predetermined plaintext data.

[0055] Step S106: Based on the first target public key h1, the first target ciphertext data c1 is obtained by pre-determining the interference term and the target encoding polynomial m.

[0056] Step S108: Send the first target encrypted data c1 to the first terminal.

[0057] Through the above steps, a predetermined plaintext data M of length l bits is determined. a The first predetermined encryption method PKE.Enc(h, M) is used. Based on the predetermined plaintext data, the first target public key h1, and predetermined interference terms, the first target ciphertext data c1 is obtained, thus achieving the purpose of encrypting the predetermined plaintext data. The first predetermined encryption method is as follows: the predetermined plaintext data M is encoded according to a predetermined encoding method. aThe target encoding polynomial m is obtained, which encodes the predetermined plaintext data. Then, based on the first target public key h1, the predetermined interference term, and the target encoding polynomial m, the first target ciphertext data c1 is obtained, thus achieving the encryption operation of the encoded predetermined plaintext data, strengthening the protection of the predetermined plaintext data, and enhancing the security of the process. Finally, the first target ciphertext data c1 can be sent to the first terminal. Since the first target ciphertext data is encrypted after encoding the predetermined plaintext data, the transmission of the first target ciphertext data to the first terminal can also protect the data from leakage. Moreover, unlike other schemes that only encode the plaintext data to the least significant bit, the predetermined encoding method of this invention can encode each piece of plaintext data to the most significant bit and encode the plaintext data multiple times, thereby greatly reducing the decryption failure rate. Simultaneously, the encoding and decoding method proposed in this invention supports smaller ring parameters q, thereby significantly reducing the size of the public key and ciphertext, and reducing storage and communication overhead. In addition, the ring structure used in this invention has the property of supporting NTT number theory transformation operations, thereby greatly reducing the number of operations such as polynomial multiplication and finding inverses, thus greatly improving the encryption and decryption speed of this invention. This solves the problems of large public key and ciphertext sizes, low computational efficiency of encryption and decryption operations, and high decryption failure rate in related technologies or methods.

[0058] As an optional embodiment, based on the first target public key h1, a predetermined interference term, and the target coding polynomial m, the first target ciphertext data c1 is obtained, including: when the predetermined coding method is Msg2poly(M), the target coding polynomial m = M0 + M1x + ... + M i x i +…+M l-1 x l-1 The predetermined interference terms include a random number r, a predetermined noise value e, and the inverse ring element v of the ring element v. -1 Based on the first target public key h1, random number r, predetermined noise value e, and inverse loop element v -1 Combined with the target encoding polynomial m, the first target ciphertext data c1 is obtained, where M i M represents a The data at the i-th bit length, M i ={0, 1}, ring element v = (1-x n / k ), v∈R q Inverse cycle element m∈R q , It is R q The set of all invertible elements. For a predetermined ring structure, represent a polynomial ring of degree n-1. n is a power of 2, q is a prime number, and k is the largest integer satisfying k|n and n / k≥l. A set representing integers. The set of positive integers.

[0059] In this embodiment, an encryption method is described when the predetermined encoding method is Msg2poly(M), in which M in the target polynomial i M represents a Plaintext data M at length i-th bit a It has a length of l bits. Unlike other schemes that only encode plaintext data to the least significant bit, the coding polynomial of this invention is v. -1 Each plaintext data point is encoded to its most significant bit, and the plaintext data is encoded multiple times, thus significantly reducing the decryption failure rate. Simultaneously, the encoding and decoding method proposed in this invention supports a smaller ring parameter q, thereby greatly reducing the size of the public key and ciphertext, and lowering storage and communication overhead. Furthermore, the ring used in this invention... This invention supports NTT number theory transformations, significantly reducing the number of computational operations and thus greatly improving encryption and decryption speed. This solves the problems of large public key and ciphertext sizes, low computational efficiency in encryption and decryption operations, and high decryption failure rates in related technologies or methods.

[0060] It should be noted that the polynomial ring R, R0 mentioned in this invention... q and cyclic elements The parameters can be selected in multiple ways and are not limited to the specific examples given in this invention. For example, rings that also support NTT operation... Where d is an even number, etc. For those skilled in the art, several improvements or modifications can be made without departing from the principles and methods of this invention, and these improvements and modifications are also considered to be within the scope of protection of this invention.

[0061] As an optional embodiment, based on the first target public key h1, a predetermined interference term, and a target coding polynomial m, the first target ciphertext data c1 is obtained, including: when the predetermined encoding method is Msg2noise(M, η), the target coding polynomial m = m0 + m1x + ... + m n-1 x n-1 The predetermined interference term includes a random number r; based on the first target public key h1, the random number r and the target coding polynomial m, the first target ciphertext data c1 is obtained, where η represents the parameter value of the central binomial distribution, and the target coding polynomial m is a polynomial whose coefficients conform to the central binomial distribution with parameter value η. The target coding polynomial m is determined to be m = m0 + m1x + ... + m n-1 x n-1 Includes: Determining Such that for all i∈[2kη-1], s i∈{0,1} n / k and determine Based on s and s 2kη-1 For all i∈[k] and j∈[n / k], determine According to m in / k+j Determine the target encoding polynomial m = m0 + m1x + ... + m n- 1x n-1 .

[0062] This embodiment describes the encryption method under the predetermined encoding method Msg2noise(M, η). In this case, while keeping the storage overhead of ciphertext and public key unchanged, by encoding plaintext data into noise, the overall noise term carried by the ciphertext is reduced, thereby further reducing the impact of noise on the decryption failure rate and achieving a lower decryption failure rate.

[0063] As an optional embodiment, before obtaining the first target ciphertext data c1 based on the first predetermined encryption method PKE.Enc(h, M), according to the predetermined plaintext data, the first target public key h1, and the predetermined interference term, the method further includes: obtaining the initial private key f′, the predetermined private key g, and the ring element v, where the predetermined encoding method is Msg2poly(M). Based on the initial private key f′ and the ring element v, the first target private key f1 is determined; based on the first target private key f1 and the predetermined private key g, the first target public key h1 is obtained.

[0064] This embodiment describes the key generation process when the predetermined encoding method is Msg2poly(M). In this case, it is necessary to generate the first target private key and the first target public key based on the ring elements.

[0065] As an optional embodiment, before obtaining the first target ciphertext data c1 based on the first predetermined encryption method PKE.Enc(h, M), according to the predetermined plaintext data, the first target public key h1, and the predetermined interference term, the method further includes: obtaining the initial private key f′, the predetermined private key g, and the inverse loop element v, when the predetermined encoding method is Msg2noise(M, 77). -1 Among them, the inverse ring element Based on the initial private key f′ and the inverse loop element v -1 Determine the first target private key f1; based on the first target private key f1 and the predetermined private key g, obtain the first target public key h1.

[0066] In this embodiment, the key generation process is described under the condition that the predetermined encoding method is Msg2noise(M, η). In this case, it is necessary to generate the first target private key and the first target public key based on the inverse loop element.

[0067] Figure 2 This is a flowchart of a vector-based public-key data decryption method according to Embodiment 1 of the present invention, as shown below. Figure 2 As shown, the method includes the following steps:

[0068] Step S202: Receive the first target ciphertext data c1 sent by the second terminal. The first target ciphertext data c1 is obtained using the first target public key h1, a predetermined interference term, and a target encoding polynomial m, employing the first predetermined encryption method PKE.Enc(h, M). The target encoding polynomial m encodes the predetermined plaintext data M according to a predetermined encoding method. a The number of terms in the target encoding polynomial m is obtained based on the predetermined plaintext data M. a The predetermined bit length is determined, and the coefficients of each term in the target coding polynomial m are based on the predetermined plaintext data M. a In the middle, the plaintext data corresponding to the data bits is determined, and the plaintext data is predetermined. Represents the message space, reserved for plaintext data. The target plaintext data is m∈R q Plaintext data of bit length;

[0069] After step S202, the predetermined decryption method PKE.Dec(f, c) is used to obtain the target plaintext data M based on the first target ciphertext data c1 and the first target private key f1. b ,include:

[0070] Step S204: Determine the target decoding polynomial w based on the first target ciphertext data c1 and the first target private key f1, wherein the first target private key f1 is determined according to a predetermined encoding method;

[0071] Step S206: Decode the target decoding polynomial w according to the predetermined decoding method to obtain the target plaintext data M. b The predetermined decoding method corresponds to the predetermined encoding method.

[0072] Through the above steps, the system receives the first target ciphertext data sent by the second terminal, determines the target decoding polynomial based on the first target ciphertext data and the first target private key, and finally decodes the target polynomial according to a predetermined decoding method to obtain the target plaintext data. Since the first target ciphertext data is encrypted using the first target public key h1, a predetermined interference term, and the target encoding polynomial m, it performs an encryption operation on the encoded predetermined plaintext data, strengthening the protection of the predetermined plaintext data and enhancing security during the process. Because the first target ciphertext data is encrypted after encoding the predetermined plaintext data, the process of transmitting the first target ciphertext data also protects against data leakage. Moreover, unlike other schemes that only encode plaintext data to the least significant bit, the predetermined encoding method of this invention can encode each piece of plaintext data to the most significant bit and encode the plaintext data multiple times, thereby greatly reducing the decryption failure rate. Simultaneously, the encoding and decoding method proposed in this invention supports a smaller ring parameter q, thus significantly reducing the size of the public key and ciphertext, and lowering storage and communication overhead. Furthermore, the ring structure used in this invention supports NTT number theory transformation operations, thereby greatly reducing the number of operations such as polynomial multiplication and inverse calculations, thus greatly improving the encryption and decryption speed of this invention. This solves the problems of large public key and ciphertext sizes, low computational efficiency in encryption and decryption operations, and high decryption failure rates in related technologies or methods.

[0073] As an optional embodiment, a predetermined decryption method PKE.Dec(f, c) is used to obtain the target plaintext data M based on the first target ciphertext data c1 and the first target private key f1. b Previously, it also included: when the predetermined encoding method was Msg2poly(M), determining the first target private key f1 based on the initial private key f′ and the ring element v; and / or, when the predetermined encoding method was Msg2noise(M, 77), determining the first target private key f1 based on the initial private key f′ and the inverse ring element v. -1 Determine the first target private key f1, where the ring element v = (1-x) n / k ), v∈R q Inverse cycle element It is R q The set of all invertible elements. For a predetermined ring structure, represent a polynomial ring of degree n-1. n is a power of 2, q is a prime number, and k is the largest integer satisfying k|n and n / k≥l. A set representing integers. Let η represent the set of positive integers, and let η represent the parameter value of the central binomial distribution.

[0074] In this embodiment, the operation of obtaining the first target private key before determining the target decoding polynomial w based on the first target ciphertext data and the first target private key is described. The process of determining the first target private key is also different when the predetermined encoding used in the encoding process is different, and can be customized according to the actual application and scenario.

[0075] As an optional embodiment, when the predetermined encoding method includes at least one of the following: Msg2poly(M) and Msg2noise(M, η), the predetermined decoding method is Poly2msg(w). The target decoding polynomial w is decoded according to the predetermined decoding method to obtain the target plaintext data M. b This includes: inputting the target decoding polynomial w into Poly2msg(w), where w = w0 + w1x + ... + w n-1 x n-1 w∈R q Based on all i∈[n], determine Based on all j∈[l], determine in accordance with Obtain the target plaintext data M b .

[0076] In this embodiment, a predetermined decoding method is described when the predetermined encoding method is Msg2poly(M) or Msg2noise(M, η), and the process of decoding to obtain the target plaintext data according to the predetermined decoding method is explained. In this process, due to the precise reduction operation, noise and other data are appropriately processed so that the obtained target plaintext data can be the same as the original predetermined plaintext data with a high probability, thereby achieving the purpose of data restoration and realizing the entire data decryption process.

[0077] Figure 3 This is a flowchart of a lattice key encapsulation method based on vector decoding according to Embodiment 1 of the present invention, as follows: Figure 3 As shown, the method includes the following steps:

[0078] S302, Determine the target random data M c ,in, Represents the message space, This indicates that the target random data is data of length l bits;

[0079] Step S304: Based on the second target public key h2 and the first cryptographic hash function H1, determine the item value H1(h) for the second cryptographic hash function H2, wherein the first cryptographic hash function H1: {0, 1} * →{0,1} κThe second cryptographic hash function H2 is used to convert data of arbitrary bit length into data of κ bit length. H2: {0, 1} l+κ →{0,1} κ ×{0, 1} κ This is used to convert data of a specific bit length into data of two κ bit lengths, where the specific bit length is determined based on the data of 1 bit length and the data of κ bit length.

[0080] Step S306, based on the item value H1(h) and the target random data M c The first unknown is determined using the second cryptographic hash function H2. And the first offset ρ;

[0081] Step S308, based on the second target public key h2, target random data M c Using the first offset ρ, the second predetermined encryption method PKE.Enc(h, M; ρ) is applied to obtain the second target ciphertext data c2;

[0082] It should be noted that the second predetermined encryption method is similar to the first predetermined encryption method. The difference is that the first offset in the second encryption method is equivalent to the predetermined interference term in the first predetermined encryption method, that is, the predetermined interference term in the second encryption method is calculated.

[0083] This is equivalent to using the first predetermined encryption method PKE.Enc(h, M) as described above, based on the predetermined plaintext data M. a In the process of obtaining the first target ciphertext data c1 from the first target public key h1 and the predetermined interference term, the predetermined interference term is obtained based on the first offset, and the calculation process is the same as that described above for encoding the predetermined plaintext data M according to the predetermined encoding method. a The target coding polynomial m is obtained, and based on the first target public key h1, the predetermined interference term is similar to the target coding polynomial m, resulting in the first target ciphertext data c1.

[0084] Step S310, based on the first unknown The second target ciphertext data c2, through the third cryptographic hash function H3, determines the encapsulation key K, where the third cryptographic hash function H3 is {0, 1}. * →{0,1} κ This is used to convert data of arbitrary bit length into data of κ bit length.

[0085] It should be noted that the encapsulation key K can be applied to symmetric encryption algorithms.

[0086] Through the above steps, by determining the target random data, and based on the second target public key, the first cryptographic hash function, and the second cryptographic hash function, the item value used in the second cryptographic hash function is determined. Based on the item value and the target random data, the first unknown and the first offset are determined using the second cryptographic hash function. Then, based on the second target public key, the target random data, and the first offset, the second predetermined encryption method is used to obtain the second ciphertext data. Based on the first unknown and the second ciphertext data, the final encapsulation key is determined using the third cryptographic hash function to verify the security of the data transmission process. Because the second predetermined encryption method is used in determining the second target ciphertext data, the encrypted target random data is encrypted, strengthening the protection of the target random data and enhancing the security of the data transmission process. Furthermore, because this invention uses a second predetermined encryption method and a predetermined encoding scheme, unlike other schemes that only encode plaintext data to the least significant bit, this invention can encode each piece of plaintext data to the most significant bit and encode the plaintext data multiple times, thereby greatly reducing the decryption failure rate. Simultaneously, the encoding and decoding method proposed in this invention supports a smaller ring parameter q, thus significantly reducing the size of the public key and ciphertext, and lowering storage and communication overhead. In addition, the ring structure used in this invention has the property of supporting NTT number theory transformation operations, thereby greatly reducing the number of operations such as polynomial multiplication and finding inverses, thus greatly improving the encryption and decryption speed of this invention. Therefore, it solves the problems of large public key and ciphertext sizes, low computational efficiency in encryption and decryption operations, and high decryption failure rates in related technologies or methods.

[0087] As an optional embodiment, based on the first unknown... After determining the encapsulation key K using the third cryptographic hash function H3, the process also includes: obtaining the target decrypted data M by using the predetermined decryption method PKE.Dec(f, c) based on the second target ciphertext data c2 and the second target private key f2. d Based on the value H1(h) and the target decryption data M d The second unknown is determined using the second cryptographic hash function H2. And the second offset ρ′; based on the second target public key h2, the target decrypted data M d Using the second offset ρ′, the second predetermined encryption method PKE.Enc(h, M; ρ) is used to obtain the third target ciphertext data c3; if the second target ciphertext data c2 and the third target ciphertext data c3 are the same, the encapsulation key K is output to the third terminal.

[0088] This embodiment illustrates the process of verifying the encapsulation key. Specifically, if the encrypted second target ciphertext data matches the third target ciphertext data, the encapsulation key can be obtained to perform data encryption and decryption. This process utilizes a second predetermined encryption method with a predetermined ring structure, ring elements, and inverse ring elements, thus achieving the aforementioned beneficial effects.

[0089] It should be noted that the above-mentioned pre-decryption method is the same as the method in steps S204-S206, and will not be described again here.

[0090] It should also be noted that the common parameters in the above-mentioned vector-decoding-based lattice public key data encryption method, vector-decoding-based lattice public key data decryption method, and vector-decoding-based lattice public key data encryption device have the same meaning, such as the ring element v = (1-x n / k ), v∈R q Inverse cycle element It is R q The set of all invertible elements. For a predetermined ring structure, represent a polynomial ring of degree n-1. n is a power of 2, q is a prime number, and k is the largest integer satisfying k|n and n / k≥l. A set representing integers. Let η represent the set of positive integers, and let η represent the parameter value of the central binomial distribution, which will not be elaborated upon above.

[0091] Based on the above embodiments and optional embodiments, an optional implementation method is provided, which is described in detail below.

[0092] In related technologies, existing public-key encryption, decryption, and key encapsulation methods based on NTRU suffer from problems such as large public key and ciphertext sizes, low computational efficiency in encryption and decryption operations, and high decryption failure rates.

[0093] In view of this, the optional embodiments of the present invention provide a lattice public key data encryption and decryption method based on vector decoding, and a lattice key encapsulation and decapsulation method based on vector decoding. The public key and ciphertext sizes are small, resulting in low storage and communication overhead. Simultaneously, the use of NTT number theory transformation operations reduces the number of operations in polynomial multiplication and inverse calculation, thereby improving the computational efficiency of encryption and decryption operations. This solves the problems of large public key and ciphertext sizes, low computational efficiency of encryption and decryption operations, and high decryption failure rates in related NTRU-based lattice public key encryption, decryption, and key encapsulation methods. The optional embodiments of the present invention are described in detail below:

[0094] The optional embodiments of the present invention include the following aspects:

[0095] (I) Design a public key encryption method based on NTRU based on vector encoding and decoding.

[0096] (ii) Define a subset of variant problems of the learning mathematical difficulty problem with errors on a ring (RLWE) and the parity RLWE problem (subset-sum parity RLWE, sspRLWE), and design an improved vector decoding-based lattice public key encryption method based on the sspRLWE problem.

[0097] (iii) Design an efficient key encapsulation mechanism using the public key encryption method.

[0098] The following is a separate introduction to the three aspects mentioned above:

[0099] (I) A lattice public-key encryption method based on vector decoding:

[0100] (1) Define mathematically difficult problems:

[0101] make Let n be a positive integer, where n is a power of 2 and q is a prime number. It is a polynomial ring. It is R q Let χ be the set of all invertible elements. f , χ g For ring The probability distribution on the surface. Computational NTRU problem. The goal is for Given a sample h = g / f ∈ R q Solve for the secret vector f′. This is the decision-based NTRU problem. The goal is to differentiate and R q Uniform random tuples on

[0102] (2) Define message vector encoding and decoding methods:

[0103] For positive integers Where n is a power of 2, q is a prime number, let and It is a polynomial ring. It is R q The set of all invertible elements;

[0104] make For message space, Let k|n be the largest integer satisfying n / k≥l, and let the ring element be... Then its inverse (similar to the inverse ring element mentioned above) is in and R represents the sets of integers and positive integers, respectively. q It is defined in For a polynomial ring of degree n-1, when n=1, we have

[0105] 1) Define the predefined encoding method:

[0106] Msg2poly(M): Given a message, pre-determine plaintext data M a As input, return the target encoding polynomial m = M0 + M1x + ... + M i x i +…+M l-1 x l-1 ∈R q Among them, the pre-reserved plaintext data m∈R q M here i Let ∈{0,1} be the i-th bit of M, and denote m = Msg2poly(M);

[0107] 2) Define the predefined decoding method:

[0108] Poly2msg(w): Given the target decoding polynomial w = w0 + w1x + ... + w n-1 x n-1 ∈R q As input, first compute for all i∈[n] Then calculate for all j∈[l]. Final settings Ultimately, it can output the target plaintext data M. b .

[0109] (3) Implement encryption and decryption:

[0110] Based on the aforementioned pre-defined encoding and decoding methods, a lattice-based public-key encryption method based on vector decoding is proposed. The plaintext is encrypted using the public key to obtain the ciphertext, and the ciphertext is decrypted using the private key to obtain the plaintext.

[0111] For example, the lattice public-key encryption method based on vector decoding consists of 4 positive integer parameters. 1 ring element and 4 Rs q The probability distribution χ on f , χ g , χ r , χ e To instantiate, including: key generation method PKE.KeyGen(1 κThe public key pk (which can also be expressed as h) and the private key sk are generated based on the security parameter κ. The encryption method PKE.Enc(h, M) encrypts the plaintext M with the public key h and outputs the ciphertext c. The decryption method PKE.Dec(sk, c) decrypts the ciphertext c with the private key sk and outputs the plaintext M.

[0112] 1) Key generation method PKE.KeyGen(1 κ ):

[0113] S1, randomly selected satisfy in (As above, in the case of Msg2poly(M) encoding method, the first target private key f1 is determined based on the initial private key f′ and the ring element v);

[0114] S2, randomly selected Calculate h1 = g / f1 (similar to the above method of obtaining the first target public key h1 based on the first target private key f1 and the predetermined private key g);

[0115] S3, output the public / private key pair (pk, sk) = (h, f) ∈ R q ×R q .

[0116] 2) Encryption method PKE.Enc(pk, M):

[0117] S1, Obtain the pre-defined plaintext data M a Among them, the pre-reserved plaintext data

[0118] S2, when the predetermined encoding method is Msg2poly(M), m = Msg2poly(M) a ), thus obtaining the target encoding polynomial m = M0 + M1x + ... + M i x i +…+M l-1 x l-1 ;

[0119] S3, determine c1 = h1r + e + v -1 m, where the number of random selections is... and (same as above, based on the first target public key h1, random number r, predetermined noise value e, and inverse loop element v) -1 Combined with the target encoding polynomial m, the first target ciphertext data c1 is obtained.

[0120] S4 outputs the target decrypted data c1.

[0121] 3) Decryption method PKE.Dec(sk, c):

[0122] S1, Obtain the target decryption data c1∈R q .

[0123] S2, calculate w = f1c1 (same as above, determine the target decoding polynomial w based on the first target ciphertext data c1 and the first target private key f1);

[0124] S3, calculate M b =Poly2msg(w) (same as above, decodes the target decoding polynomial w according to the predetermined decoding method to obtain the target plaintext data M) b );

[0125] S4, Output target plaintext data M b .

[0126] (ii) Define a subset of variant problems of the learning mathematical difficulty problem with errors on a ring (RLWE) and the parity RLWE problem (subset-sum parity RLWE, sspRLWE), and design an improved vector decoding-based lattice public key encryption method based on the sspRLWE problem.

[0127] (1) Define the sspRLWE mathematically difficult problem:

[0128] Define the sspRLWE mathematical problem: for positive integers (where n is a power of 2 and q is a prime number), defined in and polynomial ring of degree n-1 and (When n=1, we have) ), computation The mathematically difficult problem is given a sample (a, b = ar + e) ​​∈ R q Solve for ve mod 2∈R2, where and All values ​​are randomly selected, v∈R q It is a fixed ring element. and Let χ represent the sets of integers and positive integers, respectively. r , χ e For R q The probability distribution on.

[0129] (2) Define message encoding and decoding methods:

[0130] For positive integers (where n is a power of 2 and q is a prime number), let and Defined in and A polynomial ring of degree n-1 (when n=1, we have) and ), It is R q The set of all invertible elements;

[0131] make For message space, And satisfying k|n, let the ring element So its inverse is make B is a positive integer. η It is a central binomial distribution with a positive integer η as the parameter.

[0132] 1) Define the predefined encoding method:

[0133] Msg2noise(M, η; ρ): Given a message And an integer η as input, randomly selected Let s = (s0, ..., s) 2kη-2 The parsing is divided into (2kη-1) blocks of length n / k bits (i.e., for all i∈[2kη-1], there are s). i ∈{0,1} n / k Then let Calculate and return m = m0 + m1x + ... + m n- 1x n-1 ∈R q For all i∈[k] and j∈[n / k], we have

[0134]

[0135] 2) Define the predefined decoding method:

[0136] Noise2msg(w): Given a ring element w = w0 + w1x + ... + w n-1 x n-1 ∈R q As input, calculate and return the message M = Poly2msg(w).

[0137] (3) Implement encryption and decryption:

[0138] Based on the above-mentioned predetermined encoding and decoding methods, an improved vector-based public-key encryption method is proposed. The plaintext is encrypted with the public key to obtain the ciphertext, and the ciphertext is decrypted with the private key to obtain the plaintext.

[0139] For example, the improved vector-based lattice public-key encryption method consists of four positive integer parameters. 3 Rs q The probability distribution χ on f , χg , χ r and 1 ring element To instantiate, including: key generation method PKE.KeyGen(1 κ The function generates a public key pk and a private key sk based on the security parameter κ; the encryption method PKE.Enc(pk, M) encrypts the plaintext M with the public key pk and outputs the ciphertext c; the decryption method PKE.Dec(sk, c) decrypts the ciphertext c with the private key sk and outputs the plaintext M.

[0140] 1) Key generation method PKE.KeyGen(1 κ ):

[0141] S1, randomly selected satisfy in (Similar to the above case where the predetermined encoding method is Msg2noise(M, η), based on the initial private key f′ and the inverse loop element v) -1 Determine the first target private key f1);

[0142] S2, randomly selected Calculate h1 = g / f1 (similar to the above method of obtaining the first target public key h1 based on the first target private key f1 and the predetermined private key g);

[0143] S3, output the public-private key pair (pk, sk) = (h1, f1), where (h1, f1) ∈ R q ×R q .

[0144] 2) Encryption method PKE.Enc(pk, M):

[0145] S1, Obtain the pre-defined plaintext data M b Among them, the pre-reserved plaintext data

[0146] S2, when the predetermined encoding method is Msg2noise(M, η), m = Msg2noise(M b ,η), to obtain the target encoding polynomial m=m0+m1x+…+m n-1 x n-1 ∈R q ;

[0147] S3, determine c1 = h1r + m, and randomly select a number. (As mentioned above, based on the first target public key h1, the random number r and the target encoding polynomial m, the first target ciphertext data c1 is obtained);

[0148] S4 outputs the target decrypted data c1.

[0149] 3) Decryption method PKE.Dec(sk, c):

[0150] S1, Obtain the target decryption data c1∈R q .

[0151] S2, calculate u = f1c1 (same as above, based on the first target ciphertext data c1 and the first target private key f1, determine the target decoding polynomial w);

[0152] S3, calculate M b =Noise2msg(u) (Same as above, decode the target decoding polynomial w according to the predetermined decoding method, and use the predetermined decryption method PKE.Dec(sk, c) to obtain the target plaintext data M) b );

[0153] S4, Output target plaintext data M b .

[0154] (iii) Design an efficient key encapsulation mechanism using the public key encryption method.

[0155] The above public-key encryption method can be extended to a key encapsulation mechanism based on vector decoding, where the first cryptographic hash function H1 is {0, 1}. * →{0,1} κ The second cryptographic hash function H2: {0, 1} l+κ →{0,1} κ ×{0, 1} κ And the third cryptographic hash function H3: {0, 1} * →{0,1} κ The key encapsulation mechanism includes the following sub-methods:

[0156] 1) Key generation method KEM.KeyGen(1 κ ): Input security parameter κ, output public key pk and private key sk;

[0157] 2) The encapsulation method KEM.Encaps(pk) encapsulates a key K with the public key pk and outputs a ciphertext c;

[0158] 3) The decapsulation method KEM.Decaps(sk, c) decapsulates the ciphertext c and obtains the key K based on the private key sk=(sk′,pk,H1(pk),s).

[0159] The three sub-methods are described below:

[0160] 1) Key generation method KEM.KeyGen(1 κ ):

[0161] S1, randomly selected

[0162] S2, execute (h, f): = PKE.KeyGen(1 κ );

[0163] S3, output the public key h = h2 and the private key f = (f, h2H1(h2), s);

[0164] 2) Encapsulation method KEM.Encaps(pk):

[0165] S1, Determine the target random data M c ,in, M∈{0,1} l Represents the message space, This indicates that the target random data is data of length l bits;

[0166] S2, determine H1(h2), (same as above, based on the second target public key h2 and the first cryptographic hash function H1, determine the item value H1(h) used for the second cryptographic hash function H2);

[0167] S3, Calculation (Similar to the above, based on the numerical value H1(h) and the target random data M) c The first unknown is determined using the second cryptographic hash function H2. And the first offset ρ);

[0168] S4, calculate c2:=PKE.Enc(h2,M c ;ρ), (same as above based on the second target public key h2, target random data M) c The second predetermined encryption method PKE.Enc(h2, M) is used with the first offset ρ. c ;ρ), to obtain the second target ciphertext data c2);

[0169] S5, Calculation (same as above, based on the first unknown) And the second target ciphertext data c2, through the third cryptographic hash function H3, determines the encapsulation key K);

[0170] S6 outputs the second target ciphertext data c2 and the encapsulated key K.

[0171] 3) Decapsulation method KEM.Decaps(sk, c):

[0172] S1, calculate M d =PKE.Dec(f2, c2), (same as above, based on the second target ciphertext data c2 and the second target private key f2, using the predetermined decryption method PKE.Dec(f, c) to obtain the target decrypted data M) d );

[0173] S2, Calculation (Similar to the above, based on the value H1(h) and the target decryption data M) d The second unknown is determined using the second cryptographic hash function H2. And the second offset ρ′);

[0174] S3, calculate c3:=PKE.Enc(h2,M d ;ρ′), (same as above, based on the second target public key h2, target decryption data M) d Using the second offset ρ′, and employing the second predetermined encryption method PKE.Enc(h, M; ρ), the third target ciphertext c3) is obtained;

[0175] S4, if c3 = c2, then output Otherwise, output K:=H3(s,c), (same as above, when the second target ciphertext data c2 and the third target ciphertext c3 are the same, output the encapsulation key K).

[0176] Therefore, it can be seen that key encapsulation and decapsulation can be achieved through (iii). The public-key encryption method with plaintext security and the key encapsulation mechanism with ciphertext security proposed in this invention can both be converted into a public-key encryption method with ciphertext security. Furthermore, using known general conversion methods, the public-key encryption method and key encapsulation mechanism proposed in this invention can both be converted into a key exchange protocol or an authenticated key exchange protocol.

[0177] It should be noted that,

[0178] For the above (i), this optional implementation can be selected as a positive integer n that is a power of 2, a prime number q that satisfies q = 1 mod 2n, and a polynomial ring. To support NTT operations. Alternatively, a ring can be selected that also supports NTT operations when the positive integer d is even. Note that the polynomial rings R, R supported by the above optional implementations q and cyclic elements The parameters have multiple options and are not limited to the cases given in this specific example.

[0179] In the above vector-decoding-based lattice public-key encryption method, this invention provides a Gaussian distribution as the noise distribution χ. f , χ g , χ r , χ e Candidates. For ease of system implementation, this invention will use a binomial distribution or a ternary distribution as the noise distribution in the NTRU problem. Note that the noise distribution χ... f , χ g , χ r , χe The choice of parameters is not limited to discrete Gaussian distribution, binomial distribution, or ternary distribution. Table 1 provides two sets of parameter lists for this invention. Optional embodiments of this invention provide the two sets of parameter choices shown in Table 1 below for reference, but are not limited to these two sets of parameter choices.

[0180] Table 1

[0181] Parameter set name (n, q) <![CDATA[(χ f , χ g Distribution <![CDATA[(χ r , χ e Distribution Decryption error rate PARAMS I (512,769) <![CDATA[(B1,B1)]]> <![CDATA[(B1,T 1 / 6 )]]> <![CDATA[2 -138 ]]> PARAMS II (1024,769) <![CDATA[(B1,B1)]]> <![CDATA[(B1,T 1 / 6 )]]> <![CDATA[2 -152 ]]>

[0182] For the above (ii), this alternative implementation can also choose a positive integer n that is a power of 2, a prime number q that satisfies q = 1 mod 2n, and a polynomial ring. To support NTT operations. Alternatively, a ring can be selected that also supports NTT operations when the positive integer d is even. Note that the polynomial rings R, R supported by the above optional implementations q and cyclic elements The parameters have multiple options and are not limited to the cases given in this specific example. Table 2 is a list of two sets of parameters provided by the present invention. The optional embodiments of the present invention provide the two sets of parameter selections shown in Table 2 below for reference, but are not limited to these two sets of parameter selections.

[0183] Table 2

[0184]

[0185]

[0186] Table 3 shows the experimental data of the present invention when using the two sets of parameters in Table 2. As shown in Table 3, Table 3 provides some experimental data for optional embodiments of the present invention. The experimental platform was a 64-bit CentOS Linux 7.6 system equipped with an Intel Core-i7 4790 chip, featuring a 3.6GHz CPU and 4GB of memory, and the programming language was C.

[0187] Table 3

[0188]

[0189] Regarding (iii) above, Table 4 shows the experimental data of the optional embodiments of the present invention when using the two sets of parameters in Table 1. The experimental platform was a 64-bit CentOS Linux 7.6 system, equipped with an Intel Core-i7 4790 chip, with a 3.6GHz CPU and 4GB of memory, and the programming language was C.

[0190] Table 4

[0191]

[0192] Therefore, it can be seen that the above-mentioned optional implementation methods can achieve at least the following beneficial effects:

[0193] 1) High security: This invention is proven to be secure against chosen-ciphertext attacks and can resist attacks from future quantum computers;

[0194] 2) Short public key and ciphertext length: Compared with similar schemes on the lattice, it has shorter public key and ciphertext lengths;

[0195] 3) High computational efficiency: Provides sub-methods for key generation, encryption and decryption, encapsulation and decapsulation with very fast computation speed;

[0196] 4) Low decryption failure rate: The proposed encoding and decoding methods result in a lower decryption failure rate for this invention;

[0197] 5) Flexible parameter selection: Supports more flexible and fine-grained parameter selection, making it easier to achieve a balance between security and performance;

[0198] 6) Resistance to multi-target attacks: Prevents attackers from recovering the private keys of multiple users at the cost of recovering the private key of one user;

[0199] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the present invention is not limited to the described order of actions, because according to the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.

[0200] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.

[0201] Example 2

[0202] According to embodiments of the present invention, an apparatus for implementing the above-described vector-based public-key data encryption method is also provided. Figure 4 This is a structural block diagram of a lattice public-key data encryption device based on vector decoding according to an embodiment of the present invention, as shown below. Figure 4 As shown, the device includes: a first determining module 402, a first encryption module 404, and a sending module 406. The device will be described in detail below.

[0203] The first determining module 402 is used to determine the predetermined plaintext data M. a Among them, the pre-reserved plaintext data Represents the message space, reserved for plaintext data. The first encryption module 404, connected to the first determining module 402, is used to obtain the first target ciphertext data c1 by using the first predetermined encryption method PKE.Enc(h, M) based on the predetermined plaintext data, the first target public key h1, and a predetermined interference term; the second encryption module 406, connected to the first encryption module 404, is used to send the first target ciphertext data c1 to the first terminal.

[0204] The first encryption module 404 includes:

[0205] The encoding module is used to encode predetermined plaintext data M according to a predetermined encoding method. a The target encoding polynomial m is obtained, wherein the number of terms in the target encoding polynomial m is based on the predetermined plaintext data M. a The predetermined bit length is determined, and the coefficients of each term in the target coding polynomial m are determined based on the plaintext data in the corresponding bit data bits of the predetermined plaintext data; the encryption submodule, connected to the encoding module, is used to obtain the first target ciphertext data c1 based on the first target public key h1, the predetermined interference term and the target coding polynomial m.

[0206] It should be noted here that the first determining module 402, the first encryption module 404 and the sending module 406 mentioned above correspond to steps S102 to S108 in the implementation of the vector decoding-based public key data encryption method. The multiple modules and the corresponding steps are the same in terms of implementation instances and application scenarios, but are not limited to the content disclosed in the above embodiment 1.

[0207] Example 3

[0208] According to embodiments of the present invention, an apparatus for implementing the above-described vector-based public-key data decryption method is also provided. Figure 5 This is a structural block diagram of a lattice public-key data encryption device based on vector decoding according to an embodiment of the present invention, as shown below. Figure 5 As shown, the device includes a receiving module 502 and a decryption module 504. The device will be described in detail below.

[0209] The receiving module 502 is used to receive the first target ciphertext data c1 sent by the second terminal. The first target ciphertext data c1 is obtained using the first target public key h1, a predetermined interference term, and a target coding polynomial m, employing a first predetermined encryption method PKE.Enc(h, M). The first predetermined encryption method PKE.Enc(h, M) is determined based on a predetermined ring structure. The target coding polynomial m encodes the predetermined plaintext data M according to a predetermined encoding method. a The number of terms in the target encoding polynomial m is obtained based on the predetermined plaintext data M. a The predetermined bit length is determined, and the coefficients of each term in the target coding polynomial m are based on the predetermined plaintext data M. a In the middle, the plaintext data corresponding to the data bits is determined, and the plaintext data is predetermined. Represents the message space, reserved for plaintext data. The target plaintext data is m∈R q Plaintext data of bit length;

[0210] Decryption module 504, connected to the receiving module 502, is used to obtain target plaintext data M using a predetermined decryption method PKE.Dec(f, c) based on the first target ciphertext data c1 and the first target private key f1. b The first target private key f1 is determined according to a predetermined encoding method.

[0211] The decryption module 504 includes:

[0212] The second determining module is used to determine the target decoding polynomial w based on the first target ciphertext data c1 and the first target private key f1; the decoding module is connected to the second determining module and is used to decode the target decoding polynomial w according to a predetermined decoding method to obtain the target plaintext data M. b The predetermined decoding method corresponds to the predetermined encoding method.

[0213] It should be noted that the receiving module 502 and the decryption module 504 mentioned above correspond to steps S202 to S206 in the implementation of the vector decoding-based public key data encryption method. The multiple modules and the corresponding steps are the same in terms of implementation instances and application scenarios, but are not limited to the content disclosed in the above embodiment 1.

[0214] Example 4

[0215] According to embodiments of the present invention, an apparatus for implementing the above-described vector-based public-key encapsulation method is also provided. Figure 6 This is a structural block diagram of a lattice public-key data encryption device based on vector decoding according to an embodiment of the present invention, as shown below. Figure 6As shown, the device includes: a third determining module 602, a fourth determining module 604, a fifth determining module 606, a second encryption module 608, and a sixth determining module 610. The device will be described in detail below.

[0216] The third determining module 602 is used to determine the target random data M. c ,in, Represents the message space, The target random data represents data of length l bits; the fourth determining module 604, connected to the third determining module 602, is used to determine the item value H1(h) for the second cryptographic hash function H2 based on the second target public key h2 and the first cryptographic hash function H1, wherein the first cryptographic hash function H1: {0, 1} * →{0,1} κ The second cryptographic hash function H2 is used to convert data of arbitrary bit length into data of κ bit length. H2: {0, 1} l+κ →{0,1} κ ×{0, 1} κ The first module is used to convert data of a specific bit length into data of two κ bits, the specific bit length being determined based on data of 1 bit length and data of κ bits length; the fifth determining module 606, connected to the fourth determining module 604, is used to determine the value of item H1(h) and the target random data M. c The first unknown is determined using the second cryptographic hash function H2. And the first offset ρ; the second encryption module 608, connected to the fifth determining module 606, is used to determine the target random data M based on the second target public key h2. c Using the first offset ρ, the second predetermined encryption method PKE.Enc(h, M; ρ) is applied to obtain the second target ciphertext data c2; the sixth determining module 610, connected to the aforementioned second encryption module 608, is used to determine the second target ciphertext data c2 based on the first unknown. The second target ciphertext data c2, through the third cryptographic hash function H3, determines the encapsulation key K, where the third cryptographic hash function H3 is {0, 1}. * →{0,1} κ This is used to convert data of arbitrary bit length into data of κ bit length.

[0217] It should be noted that the third determining module 602, the fourth determining module 604, the fifth determining module 606, the second encryption module 608 and the sixth determining module 610 mentioned above correspond to steps S302 to S310 in the implementation of the vector decoding-based public key data encryption method. The instances and application scenarios implemented by multiple modules and their corresponding steps are the same, but are not limited to the content disclosed in the above embodiment 1.

[0218] Example 5

[0219] According to another aspect of the present invention, an electronic device is also provided, comprising: a processor; and a memory for storing processor-executable instructions, wherein the processor is configured to execute instructions to implement the vector decoding-based lattice public key data encryption method, the vector decoding-based lattice public key data decryption method, and the vector decoding-based lattice key encapsulation method of any of the above claims.

[0220] Example 6

[0221] According to another aspect of the present invention, a computer-readable storage medium is also provided, wherein when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to perform any of the above-described vector-decoding-based lattice public key data encryption methods, any of the above-described vector-decoding-based lattice public key data decryption methods, and any of the above-described vector-decoding-based lattice key encapsulation methods.

[0222] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0223] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0224] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0225] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0226] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0227] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0228] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A lattice public-key data encryption method based on vector decoding, characterized by, comprising: determining predetermined plaintext data wherein the predetermined plaintext data , the represents a message space, the predetermined plaintext data represents that the predetermined plaintext data is plaintext data of a bit length; Adopting a first predetermined encryption method , according to the predetermined plaintext data , a first target public key , and a predetermined interference term, obtaining a first target ciphertext data ; sending the first target ciphertext data to the first terminal, The first predetermined encryption method is adopted. Based on the predetermined plaintext data The first target public key And the predetermined interference terms, to obtain the first target ciphertext data. Includes: encoding the predetermined plaintext data according to a predetermined encoding method. The target encoding polynomial is obtained. The target encoding polynomial The number of items is based on the predetermined plaintext data. The predetermined bit length is determined, and the target encoding polynomial is... The coefficients for each term are determined based on the plaintext data at the corresponding bit positions in the predetermined plaintext data; based on the first target public key. The predetermined interference term and the target encoding polynomial The first target ciphertext data is obtained. ; Wherein, according to the first target public key , the predetermined interference term and the target encoding polynomial , the first target ciphertext data is obtained , comprising: in the case of the predetermined encoding mode , the target encoding polynomial , the predetermined interference term includes a random number , a predetermined noise value , a ring element The inverse ring element ; according to the first target public key , the random number , the predetermined noise value , the inverse ring element And the target encoding polynomial , the first target ciphertext data is obtained , wherein, Indicates the data of the th bit in , , the ring element , , the inverse ring element , , , the is the set of all invertible elements on , is a predetermined ring structure, indicating a polynomial ring with degree , , , , the is the power of 2, the is a prime number, the is the largest integer satisfying And , the indicates the set of integers, the indicates the set of positive integers.

2. The method of claim 1, wherein, using a first predetermined encryption method , in accordance with the predetermined plaintext data , a first target public key , and a predetermined interference term, to obtain first target ciphertext data Further comprising, before the obtaining: In the case where the predetermined encoding mode is , an initial private key is acquired , a predetermined private key is acquired ; According to the initial private key With the ring element , determine the first target private key ; According to the first target private key With the predetermined private key , the first target public key is obtained 3. A lattice public-key data encryption method based on vector decoding, characterized by, comprising: determining predetermined plaintext data wherein the predetermined plaintext data is determined based on represents a message space, the predetermined plaintext data represents that the predetermined plaintext data is plaintext data of a bit length; Adopting a first predetermined encryption method , according to the predetermined plaintext data , a first target public key , and a predetermined interference term, obtaining a first target ciphertext data ; sending the first target ciphertext data to the first terminal, The first predetermined encryption method is adopted. Based on the predetermined plaintext data The first target public key And the predetermined interference terms, to obtain the first target ciphertext data. Includes: encoding the predetermined plaintext data according to a predetermined encoding method. The target encoding polynomial is obtained. The target encoding polynomial The number of items is based on the predetermined plaintext data. The predetermined bit length is determined, and the target encoding polynomial is... The coefficients for each term are determined based on the plaintext data at the corresponding bit positions in the predetermined plaintext data; based on the first target public key. The predetermined interference term and the target encoding polynomial The first target ciphertext data is obtained. ; The first target ciphertext data is obtained according to the first target public key , the target encoding polynomial , and the predetermined interference term , and the first target ciphertext data is obtained according to the first target public key , the target encoding polynomial , and the predetermined interference term ; the predetermined interference term includes a random number ; the random number , and the target encoding polynomial , and the first target ciphertext data is obtained according to the first target public key , wherein the represents a parameter value of a central binomial distribution, the target encoding polynomial is a polynomial with coefficients conforming to a central binomial distribution with a parameter value being the , and the target encoding polynomial is determined by determining , such that for all , there is , and determining ; according to the and the , for all and , determining , and according to the , the target encoding polynomial is determined.

4. The method of claim 3, wherein, using a first predetermined encryption method , in accordance with the predetermined plaintext data , a first target public key , and a predetermined interference term, to obtain first target ciphertext data Further comprising, prior to the obtaining, In the case where the predetermined encoding scheme is , an initial private key is acquired , a predetermined private key is acquired ; According to the initial private key With the inverse ring element , determine the first target private key ; According to the first target private key With the predetermined private key , the first target public key is obtained 5. A lattice public key data decryption method based on vector decoding, characterized by, comprising: receive the first target ciphertext data sent by the second terminal , wherein the first target ciphertext data is obtained according to the first target public key , the predetermined interference term and the target encoding polynomial are obtained by using the first predetermined encryption method , the target encoding polynomial is obtained by encoding the predetermined plaintext data according to a predetermined encoding mode , the number of terms of the target encoding polynomial is determined according to a predetermined bit length of the predetermined plaintext data , the coefficients on each term of the target encoding polynomial are determined according to the plaintext data on the corresponding bit data position in the predetermined plaintext data , the predetermined plaintext data , the represents a message space, the predetermined plaintext data represents that the target plaintext data is plaintext data with a bit length of . Adopting a predetermined decryption method , according to the first target ciphertext data and the first target private key , obtaining target plaintext data , wherein the first target private key is determined according to the predetermined encoding mode; The predetermined decryption method is used According to the first target ciphertext data And the first target private key , the target plaintext data is obtained It includes: according to the first target ciphertext data And the first target private key , the target decoding polynomial is determined ; According to the predetermined decoding mode, the target decoding polynomial is decoded , the target plaintext data is obtained , wherein the predetermined decoding mode corresponds to the predetermined encoding mode; Among them, the first target ciphertext data Based on the first target public key Predetermined interference term and target encoding polynomial The first predetermined encryption method is adopted. Obtaining, including: in the predetermined encoding method In the case of the target encoding polynomial The predetermined interference item includes random numbers. Predetermined noise value cyclic elements Inverse cycle element Based on the first target public key The random number The predetermined noise value The inverse ring element With the target encoding polynomial The first target ciphertext data is obtained. ,in, express The first in One bit of data, The ring element , Inverse cycle element , , The yes The set of all invertible elements. For a predetermined ring structure, the degree is represented as Polynomial ring of degree 1 , , The It is a power of 2, the stated It is a prime number, as stated It is to satisfy and The largest integer, the The set representing integers, the The set of positive integers; Among them, a predetermined decryption method is adopted. Based on the first target ciphertext data and the first target private key Obtain the target plaintext data Previously, it also included: in the predetermined encoding method, In the case of, based on the initial private key With ring elements Determine the first target private key .

6. A lattice public key data decryption method based on vector decoding, characterized by, comprising: receiving the first target ciphertext data sent by the second terminal , wherein the first target ciphertext data is obtained according to the first target public key , the predetermined interference term and the target encoding polynomial , the first predetermined encryption method is adopted , the target encoding polynomial is obtained according to the predetermined encoding manner , the target encoding polynomial , the number of terms of the target encoding polynomial is determined according to the predetermined bit length of the predetermined plaintext data , the coefficients on each term of the target encoding polynomial are determined according to the plaintext data on the corresponding bit data position in the predetermined plaintext data , the predetermined plaintext data represents a message space, and the predetermined plaintext data represents the target plaintext data as plaintext data with a bit length ; Adopting a predetermined decryption method , according to the first target ciphertext data and the first target private key , obtaining target plaintext data , wherein the first target private key is determined according to the predetermined encoding mode; The method of pre-defined decryption is mentioned above. Based on the first target ciphertext data and the first target private key Obtain the target plaintext data Includes: based on the first target encrypted data and the first target private key Determine the target decoding polynomial Decode the target decoding polynomial according to the predetermined decoding method. The target plaintext data is obtained. The predetermined decoding method corresponds to the predetermined encoding method; The first target ciphertext data is obtained according to the first target public key, the random number and the target encoding polynomial. The first target ciphertext data is obtained according to the first target public key The predetermined interference term and the target encoding polynomial The first predetermined encryption method is adopted The first target ciphertext data is obtained, comprising: in the case that the predetermined encoding mode is The target encoding polynomial The predetermined interference term comprises a random number The first target ciphertext data is obtained according to the first target public key The random number The target encoding polynomial The first target ciphertext data is obtained according to the first target public key , wherein the first target ciphertext data The target encoding polynomial is a polynomial with coefficients conforming to a central binomial distribution with a parameter value being the first target public key The target encoding polynomial comprises: determining , so that for all , and determining The target encoding polynomial is determined according to the first target public key and the random number , for all and , determining The target encoding polynomial is determined according to the first target public key ; Wherein, the predetermined decryption method is adopted , according to the first target ciphertext data and the first target private key , the target plaintext data is obtained , in the case where the predetermined encoding mode is , according to the initial private key and the inverse ring element , the first target private key is determined 7. The method according to claim 5 or 6, characterized in that, In a case where the predetermined decoding mode is , decoding the target decoding polynomial according to the predetermined decoding mode , to obtain the target plaintext data , comprising: decoding the target polynomial input to the wherein , the ; based on all , determine ; based on all , determine ; According to , the target plaintext data is obtained.

8. A lattice public-key data encryption device based on vector decoding, characterized by comprising: comprising: a first determining module, configured to determine predetermined plaintext data wherein the predetermined plaintext data the predetermined plaintext data represents a message space, the predetermined plaintext data represents that the predetermined plaintext data is plaintext data with a bit length of ​ The first encryption module is used to employ a first predetermined encryption method. Based on the predetermined plaintext data, the first target public key And, with predetermined interference items, the first target ciphertext data is obtained. ; The sending module is configured to send the first target ciphertext data to the first terminal. to a first terminal. The first encryption module comprises: an encoding module, configured to encode the predetermined plaintext data according to a predetermined encoding mode, to obtain a target encoding polynomial The number of terms of the target encoding polynomial is determined according to a predetermined bit length of the predetermined plaintext data , and the coefficients on each term of the target encoding polynomial are determined according to plaintext data on corresponding bit data positions in the predetermined plaintext data; and an encryption submodule, configured to encrypt the predetermined interference term and the target encoding polynomial according to the first target public key , to obtain the first target ciphertext data .​ The encryption submodule is further configured to, in the predetermined encoding method, In the case of the target encoding polynomial The predetermined interference item includes random numbers. Predetermined noise value cyclic elements Inverse cycle element Based on the first target public key The random number The predetermined noise value The inverse ring element With the target encoding polynomial The first target ciphertext data is obtained. ,in, express The first in One bit of data, The ring element , Inverse cycle element , , The yes The set of all invertible elements. For a predetermined ring structure, the degree is represented as Polynomial ring of degree 1 , , The It is a power of 2, the stated It is a prime number, as stated It is to satisfy and The largest integer, the The set representing integers, the The set of positive integers.

9. A lattice public-key data encryption device based on vector decoding, characterized by comprising: comprising: a first determining module, configured to determine predetermined plaintext data , wherein the predetermined plaintext data , the represents a message space, the predetermined plaintext data represents that the predetermined plaintext data is plaintext data with a bit length of ​ The first encryption module is used to employ a first predetermined encryption method. Based on the predetermined plaintext data, the first target public key And, with predetermined interference items, the first target ciphertext data is obtained. ; The sending module is configured to send the first target ciphertext data to the first terminal. to a first terminal. The first encryption module comprises: an encoding module, configured to encode the predetermined plaintext data according to a predetermined encoding mode to obtain a target encoding polynomial The number of terms of the target encoding polynomial is determined according to a predetermined bit length of the predetermined plaintext data , and the coefficients on each term of the target encoding polynomial are determined according to plaintext data on corresponding bit data positions in the predetermined plaintext data; and an encryption submodule, configured to obtain the first target ciphertext data by multiplying the first target public key with the predetermined interference term and the target encoding polynomial .​ The encryption sub-module is further configured to, when the predetermined encoding mode is , the target encoding polynomial , the predetermined interference term includes a random number ; according to the first target public key , the random number and the target encoding polynomial , the first target ciphertext data is obtained, wherein the represents a parameter value of a central binomial distribution, the target encoding polynomial is a polynomial with coefficients conforming to a central binomial distribution with the parameter value being the , and the target encoding polynomial is determined by: determining , such that for all , , and determining ; according to the and the , for all and , the is determined, and according to the , the target encoding polynomial is determined.

10. A lattice public key data decryption apparatus based on vector decoding, characterized by, comprising: The receiving module is configured to receive first target ciphertext data sent by a second terminal , wherein the first target ciphertext data is obtained according to a first target public key , a predetermined interference term and a target encoding polynomial , by using a first predetermined encryption method , the target encoding polynomial is obtained according to a predetermined encoding manner and a predetermined plaintext data , the number of terms of the target encoding polynomial is determined according to a predetermined bit length of the predetermined plaintext data , the coefficients on each term of the target encoding polynomial are determined according to the plaintext data on corresponding bit data positions in the predetermined plaintext data , and the predetermined plaintext data , wherein the represents a message space, the predetermined plaintext data represents target plaintext data being plaintext data with a bit length of . The decryption module is used to employ a predetermined decryption method. Based on the first target ciphertext data and the first target private key Obtain the target plaintext data The first target private key Determined according to the predetermined encoding method, The decryption module includes a second determining module, configured to determine the target ciphertext data based on the first target ciphertext data. and the first target private key Determine the target decoding polynomial The decoding module is used to decode the target decoding polynomial according to a predetermined decoding method. The target plaintext data is obtained. The predetermined decoding method corresponds to the predetermined encoding method; Among them, the first target ciphertext data Based on the first target public key Predetermined interference term and target encoding polynomial The first predetermined encryption method is adopted. Obtaining, including: in the predetermined encoding method In the case of the target encoding polynomial The predetermined interference item includes random numbers. Predetermined noise value cyclic elements Inverse cycle element Based on the first target public key The random number The predetermined noise value The inverse ring element With the target encoding polynomial The first target ciphertext data is obtained. ,in, express The first in One bit of data, The ring element , Inverse cycle element , , The yes The set of all invertible elements. For a predetermined ring structure, the degree is represented as Polynomial ring of degree 1 , , The It is a power of 2, the stated It is a prime number, as stated It is to satisfy and The largest integer, the The set representing integers, the The set of positive integers; The decryption module is further configured to determine the first target private key according to an initial private key and a ring element in a case where the predetermined encoding mode is .​​​ 11. A lattice public key data decryption apparatus based on vector decoding, characterized by, comprising: The receiving module is configured to receive first target ciphertext data sent by a second terminal , wherein the first target ciphertext data is obtained according to a first target public key , a predetermined interference term and a target encoding polynomial , the first target ciphertext data is obtained by using a first predetermined encryption method , the target encoding polynomial is obtained by encoding predetermined plaintext data according to a predetermined encoding mode , a number of terms of the target encoding polynomial is determined according to a predetermined bit length of the predetermined plaintext data , coefficients on each term of the target encoding polynomial are determined according to plaintext data on corresponding bit data positions in the predetermined plaintext data , the predetermined plaintext data represents a message space, and the predetermined plaintext data represents target plaintext data being plaintext data with a bit length of . The decryption module is used to employ a predetermined decryption method. Based on the first target ciphertext data and the first target private key Obtain the target plaintext data The first target private key Determined according to the predetermined encoding method, The decryption module includes a second determining module, configured to determine the target ciphertext data based on the first target ciphertext data. and the first target private key Determine the target decoding polynomial The decoding module is used to decode the target decoding polynomial according to a predetermined decoding method. The target plaintext data is obtained. The predetermined decoding method corresponds to the predetermined encoding method; The first target ciphertext data is obtained according to the first target public key, the random number and the target encoding polynomial, and the first target ciphertext data is determined according to the first target public key, the random number and the target encoding polynomial. According to the first target public key , the predetermined interference term and the target encoding polynomial , the first predetermined encryption method is adopted , and the first target ciphertext data is obtained, including: in the case that the predetermined encoding mode is , the target encoding polynomial , the predetermined interference term includes a random number ; according to the first target public key , the random number and the target encoding polynomial , the first target ciphertext data is obtained , wherein the first target ciphertext data represents a parameter value of a central binomial distribution, the target encoding polynomial is a polynomial with coefficients conforming to the central binomial distribution with the parameter value being the first target ciphertext data , the target encoding polynomial is determined, including: determining , so that for all , there is , and determining ; according to the and the , for all and , determining , according to the , the target encoding polynomial is determined. The decryption module is further configured to determine the first target private key according to the initial private key and the inverse cyclic element in a case where the predetermined encoding mode is . .​​ 12. An electronic device, comprising: comprising: a processor; a memory for storing processor-executable instructions; wherein the processor is configured to execute the instructions to implement the lattice public key data encryption method based on vector decoding as claimed in any one of claims 1 to 4, the lattice public key data decryption method based on vector decoding as claimed in any one of claims 5 to 7.

13. A computer-readable storage medium, characterized in that, When the instructions in the computer-readable storage medium are executed by the processor of the electronic device, the electronic device is enabled to perform the lattice public key data encryption method based on vector decoding as claimed in any one of claims 1 to 4, the lattice public key data decryption method based on vector decoding as claimed in any one of claims 5 to 7.