A Compact Quantum-Resistant Encryption and Decryption Method and System Based on Supersingular Isogeny
Through a compact quantum-resistant encryption scheme based on supersingular homologs, the Pohlig-Hellman algorithm is used to solve the discrete logarithm problem of elliptic curves, and a compact quantum-resistant encryption method is designed to solve the problem of insufficient security of the public key cryptography system under the threat of quantum computing, and to achieve compactness and efficient encryption and decryption of public keys and ciphertexts.
Patent Information
- Application Number
- CN202310284705.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-22
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2043-03-22
AI Technical Summary
The existing public key cryptography system is insecurity in the face of the threat of quantum computing, especially the cryptography system based on traditional mathematical difficulties faces the risk of being compromised by quantum computers. The existing quantum cryptography algorithms are inefficient and the key and ciphertext sizes are not compact.
A compact anti-quantum encryption scheme based on supersingular homologs was designed, and the discrete logarithmic problem on the elliptic curve was quickly solved using the Pohlig-Hellman algorithm. Through the system initialization, key generation, encryption and decryption processes, the public key and ciphertext are compacted. The supersingular elliptic curve and ideal class calculation are adopted, and the ideal class and point-to-point operation are combined, and the appropriate parameter p is selected to meet different security needs.
It realizes an efficient encryption and decryption process in a quantum computing environment. The public key and ciphertext size are compact, adapting to the needs of different security scenarios and providing high security and efficiency.
Smart Images

Figure CN116405212B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of information security, and in particular, to a compact quantum-resistant encryption scheme based on supersingular isogenies. Background Art
[0002] In 1976, to solve the two most difficult problems in the single-key cryptosystem - key distribution and digital signature, Diffie and Hellman proposed the concept of the public-key cryptosystem. The biggest feature of the public-key cryptography algorithm is that it separates the encryption and decryption capabilities by using two mathematically related keys. One key is public and is used for encryption, which is called the public key, or simply the public key for short. The other key is saved by the user and is used to decrypt the message encrypted by the user's public key, which is called the private key, or simply the private key for short.
[0003] The rapid development of quantum computing technology has posed a serious security threat to the public-key cryptosystem based on traditional mathematical hard problems. Although the computing power of quantum computers is not sufficient to completely break the traditional cryptosystem in a short time, it is urgent to research quantum-resistant cryptographic algorithms. In 2015, the US National Security Agency announced upgrading the cryptography used by the federal government to a quantum-resistant cryptosystem. In April 2016, the US National Institute of Standards and Technology (NIST) launched a global call for quantum-resistant cryptographic algorithms. In July 2020, NIST announced 7 algorithms that entered the third-round review, which has attracted great attention from cryptographers around the world. In 2022, several algorithms have entered the standardization stage. At the same time, European countries and Japan have also carried out research on quantum-resistant cryptography and achieved remarkable results. Quantum-resistant cryptography is gradually becoming the mainstream development direction of future cryptography.
[0004] Isogeny-based cryptosystems are the quantum-resistant cryptosystems that started the latest. The difficult problem in them is to find an l-path in the supersingular isogeny graph. This problem is considered difficult both in classical computers and quantum computers. Isogeny-based schemes can be traced back to the work of Couveignes in 1997. His idea was based on the isogenies of ordinary elliptic curves, but it was not formally published at that time. In the last decade, the proposal of the GGL hash function and the SIDH key exchange protocol has greatly increased the attention to the isogenies of supersingular elliptic curves. The proposal of SIKE (SIDH-based key encapsulation mechanism) marks the entry of the research on the isogenies of supersingular elliptic curves into a new stage. The proposals of CSIDH and SQISign have raised the research on supersingular isogenies to a new height. Compared with the other four quantum-resistant cryptosystems (hash-based, multivariate-based, code-based, and lattice-based), isogeny-based cryptographic algorithms are relatively less efficient, but they can provide the most compact key, ciphertext, and signature sizes. The present invention proposes a compact quantum-resistant public-key encryption scheme based on supersingular isogenies. The Pohlig-Hellman algorithm is an algorithm proposed by Pohlig and Hellman in 1978 to quickly solve the discrete logarithm problem. Specifically, for a composite number n whose factors are all small prime numbers, the Pohlig-Hellman algorithm can effectively solve the discrete logarithm problem on a cyclic group of order n.
[0005] Therefore, the present invention intends to use the Pohlig-Hellman algorithm to design a compact quantum-resistant encryption scheme based on supersingular isogenies, where the Pohlig-Hellman algorithm is used to quickly solve the discrete logarithm problem on elliptic curves. Summary of the Invention
[0006] Aiming at the defects of the prior art, the present invention proposes a compact quantum-resistant encryption scheme based on supersingular isogenies.
[0007] To achieve the above invention purpose, the technical solution of the present invention provides a compact quantum-resistant encryption and decryption method based on supersingular isogenies, including the following processes.
[0008] System initialization process, including inputting a security parameter λ, a large prime number p = 4*l1l2…l n -1, where l1, l2,…, l n are different small prime numbers, defining a supersingular elliptic curve E0: y p = x 2 + x on F 3 , the endomorphism ring of F p is Z[π], and the system public parameters are (p, {l i} i=1,…,n , E0, Z[π]);
[0009] Key generation process: The user side generates public and private keys. The implementation method is to randomly select an n-dimensional vector a = (a1, a2, …, a n ), a i ∈[-r, r]. According to the corresponding ideal class calculate the image curve E A =[α]E0: y 2 =x 3 +Ax 2 +x. The private key is sk = a, and the public key is pk = A;
[0010] Encryption process: The encryptor encrypts the message m. The implementation process is to randomly select an n-dimensional vector b = (b1, b2, …, b n ), b i ∈[-r, r]. According to the corresponding ideal class calculate the image curve E B =[β]E0: y 2 =x 3 +Bx 2 +x, calculate the ideal class and [γ]=[l1][l2]…[l n . Calculate the image curve E mid =[β′]E A , E AB =[γ]E mid : y 2 =x 3 +Cx 2 +x, and select a point P of order l1…l AB =[γ]E mid in the calculation of E n ; perform the point doubling operation P c =[m]P and calculate Return the ciphertext
[0011] Decryption process: The user side decrypts the received ciphertext c to obtain the plaintext m. The implementation process is to split the ciphertext Verify whether E B is a supersingular elliptic curve. If so, calculate the ideal class and [γ]=[l1][l2]…[l n , and calculate the image curve E mid =[α′]E B and E AB =[γ] mid and select a point P. Solve the discrete logarithm problem m = DL(P c , P) to recover the message m.
[0012] Moreover, the implementation method of the system initialization process includes inputting the security parameter λ, and setting p = 4*l1l2…l n -1 as a large prime number, where l1, l2, …, l n are different small prime numbers, and selecting a supersingular elliptic curve E0: y p = x 2 + x defined over F 3 . Its F p endomorphism ring is Z[π], and the system public parameters are (p, {l i} i=1,…,n , E0, Z[π]).
[0013] Moreover, the user key generation process includes the user generating public and private keys according to the following process
[0014] a) Randomly select an n-dimensional vector a = (a1, a2, …, a n ), a i ∈[-r, r]. Its private key is the ideal class of Z[π] corresponding to the vector a
[0015] b) Calculate the public key E A = [α]E0: y 2 = x 3 + Ax 2 + x, and publish A as the public key; where [α]E0 represents the image curve obtained by the action of the ideal class [α] on the curve E0.
[0016] Moreover, the encryption process includes the encrypting end encrypting the message m according to the following process
[0017] a) The encryptor Bob randomly selects an n-dimensional vector b = (b1, b2, …, b n ), b i ∈[-r, r], corresponding to the ideal class of Z[π] and calculate the image curve E B = [β]E0: y 2 = x 3 + x 2 + x; where [β]E0 represents the image curve obtained by the action of the ideal class [β] on the curve E0;
[0018] b) Calculate the ideal class and calculate the image curve E mid = [β′]E A ;
[0019] c) Calculate the ideal class [γ] = [l1][l2]…[l n , and calculate the image curve E AB = [γ]Emid , and calculate curve E during this process AB with points P of order l1l2…l n on it;
[0020] d) Perform the point multiplication operation P c = [m]P;
[0021] e) Calculate where x(P c ) represents the x - coordinate of point P c ;
[0022] f) Return the ciphertext
[0023] Moreover, the decryption process includes that after receiving the ciphertext c, the client decrypts to obtain the plaintext m according to the following process
[0024] a) Split the ciphertext c into First, verify whether E B : y 2 = x 3 + Bx 2 + x is a supersingular elliptic curve. If not, terminate the decryption;
[0025] b) Calculate the image curve E mid = [α′]E B ;
[0026] c) Calculate the ideal class [γ] = [l1][l2]…[l n , and calculate the image curve E AB = [γ]E mid , and calculate the points P of order l1l2…l AB on E n during this process;
[0027] d) Calculate Restore point P c ;
[0028] e) Use the Pohlig - Hellman algorithm to solve the discrete logarithm problem m = DL(P c , P), so as to obtain m.
[0029] On the other hand, the present invention provides a compact quantum - resistant encryption and decryption system based on supersingular isogeny for implementing a compact quantum - resistant encryption and decryption method based on supersingular isogeny as described above.
[0030] Compared with the prior art, the present invention has the following advantages and beneficial effects:
[0031] 1. A compact quantum-resistant encryption scheme based on supersingular isogenies is designed.
[0032] 2. In this scheme, the parameter p can be flexibly selected as long as the factors of p - 1 are small prime numbers, and the appropriate parameter p can be chosen according to the security and efficiency requirements of different scenarios.
[0033] 3. The public key and ciphertext sizes are relatively compact. The public key size is only log p bits, and the ciphertext size is 2 log p bits. Description of the Drawings
[0034] Figure 1 It is a schematic diagram of the compact quantum-resistant encryption scheme based on supersingular isogenies according to the embodiment of the present invention. Detailed Implementation Manner
[0035] To better understand the technical solution of the present invention, the present invention will be further described in detail below with reference to the drawings and embodiments.
[0036] The present invention designs a compact quantum-resistant encryption scheme based on supersingular isogenies, combines the Pohlig-Hellman algorithm, has flexible parameter selection, is suitable for different security requirements in different scenarios, and the public key and ciphertext sizes are very compact.
[0037] The specific symbol descriptions are as follows. In the embodiment of the present invention, the CSIDH-512 parameter is used for initialization, and appropriate parameters can be selected according to the application scenario during actual use:
[0038] λ: Security parameter.
[0039] p: Large prime number.
[0040] l i : Prime factor of p - 1, which is an Elkies prime number in the embodiment of the present invention.
[0041] n: Number of Elkies prime numbers.
[0042] F q : Finite field of order q.
[0043] [a,b]: Geometric meaning of integer x satisfying a ≤ x ≤ b
[0044] E: Elliptic curve, which refers to a supersingular elliptic curve and is represented by Montgomery curve in the present invention.
[0045] a: n-dimensional vector, used to represent an ideal class.
[0046] r: Value range of vector components.
[0047] [α]: Ideal class corresponding to the vector.
[0048] [α]E: Image curve after the action of the ideal class.
[0049] P: Point on the elliptic curve.
[0050] [k]P: k - multiple point of point P.
[0051] Z[π]: Endomorphism ring of the elliptic curve F p Endomorphism ring.
[0052] Cl(O): Ideal class group of the ring O.
[0053] φ: E1→E2: Isogeny from the supersingular elliptic curve E1 to E2.
[0054] H: Hash function.
[0055] f E (x): Randomization function, returns where bin(x) represents the binary expansion of x, and j(E) represents the j - invariant of the elliptic curve E.
[0056] g E (x): Inverse function of f E , returns
[0057] m: Message to be encrypted.
[0058] c: Ciphertext.
[0059] DL(P,Q): Solve the discrete logarithm problem P = [x]Q on the elliptic curve and return x.
[0060] See Figure 1 , the embodiment of the present invention proposes a compact quantum - resistant encryption method based on supersingular isogeny, and the specific process is as follows:
[0061] 1) Setup (System initialization)
[0062] Input the security parameter λ, let p = 4*l1l2…l n -1 be a large prime number, where l1, l2, …, l n are different small prime numbers, select a supersingular elliptic curve E0: y p = x 2 + x, defined over F 3 with the endomorphism ring Z[π], and the system public parameters are (p, {l p} i , E0, Z[]). This process can be pre - performed by the system management side. i=1,…,n 2) KeyGen (Key generation)
[0063] 2) KeyGen (Key generation)
[0064] The user side generates a public-private key pair. The implementation method is to randomly select an n-dimensional vector a = (a1, a2, …, a n ), a i ∈ [-r, r]. According to its corresponding ideal class calculate the image curve E A = [α]E0: y 2 = x 2 + Ax 2 + x. The private key is sk = a, and the public key is pk = A;
[0065] In the embodiment, the user side generates a public-private key pair according to the following process:
[0066] a) Randomly select an n-dimensional vector a = (a1, a2, …, a n ), a i ∈ [-r, r]. Its private key is the ideal class of Z[π] corresponding to the vector a
[0067] b) Calculate the public key E A = [α]E0: y 2 = x 3 + Ax 2 + x corresponding to its private key, and publish the coefficient A of the image curve as the public key. Where [α]E0 represents the image curve obtained by the action of the ideal class [α] on the curve E0.
[0068] 3) Encryption
[0069] In the embodiment, the encrypting side encrypts the message m according to the following process:
[0070] a) The encryptor randomly selects an n-dimensional vector b = (b1, b2, …, b n ), b i ∈ [-r, r], corresponding to the ideal class of Z[π] and calculates the image curve E B = [β]E0: y 2 = x 3 + Bx 2 +
[0071] x. Where [β]E0 represents the image curve obtained by the action of the ideal class [β] on the curve E0, and B is the coefficient of the image curve.
[0072] b) Calculate the ideal class and calculate the image curve E mid = [β′]E A .
[0073] c) Calculate the ideal class [γ] = [l1][l2]…[ln , and calculate the image curve E AB = [γ]E mid : y 2 = x 3 + Cx 2 + x, and calculate the curve E AB with order l1l2…l n of the point P
[0074] d) Perform the point doubling operation P c = [m]P
[0075] e) Calculate the randomization function where x(P c ) represents the x - coordinate of the point P c
[0076] f) Return the ciphertext
[0077] 4) Decryption
[0078] After receiving the ciphertext c, the client decrypts it to obtain the plaintext m according to the following process
[0079] a) Split the ciphertext c into
[0080] b) First, verify that E B : y 2 = x 3 + Bx 2 + x is a supersingular elliptic curve. If not, terminate the decryption
[0081] c) Calculate the ideal class and calculate the image curve E mid = [α′]E B
[0082] d) Calculate the ideal class [γ] = [l1][l2]…[l n , and calculate the image curve E AB = [γ]E mid : y 2 = x 3 + Cx 2 + x, and calculate the point P of order l1l2…l AB on E n
[0083] e) Calculate to recover the point P c is the inverse function of the randomization function
[0084] f) Solve the discrete logarithm problem m = DL(P c , P) using the Pohlig-Hellman algorithm to obtain m.
[0085] For the convenience of understanding the technical effects of the present invention, the following verifies the correctness:
[0086] · After receiving the ciphertext C, the user calculates
[0087]
[0088]
[0089] The curve calculated by the encryptor is
[0090]
[0091]
[0092] Therefore, the E calculated by the user and the encryptor mid and E AB are the same. Therefore, when the selected point P is the same, the user can correctly decrypt the message m through the Pohlig-Hellman algorithm, and the correctness is proved.
[0093] Such as Figure 1 is a schematic diagram of the compact quantum-resistant encryption scheme based on supersingular isogeny of the embodiment of the present invention, where α, β, α ′ , ′, all correspond to the parameters in the scheme.
[0094] In specific implementation, the method proposed by the technical solution of the present invention can be automatically run by those skilled in the art using computer software technology. The system device for implementing the method, such as a computer-readable storage medium storing the corresponding computer program of the technical solution of the present invention and a computer device including running the corresponding computer program, should also be within the protection scope of the present invention.
[0095] In some possible embodiments, a compact quantum-resistant encryption system based on supersingular isogeny is provided, including a processor and a memory. The memory is used to store program instructions, and the processor is used to call the stored instructions in the memory to execute the above-mentioned compact quantum-resistant encryption method based on supersingular isogeny.
[0096] In some possible embodiments, a compact quantum-resistant encryption system based on supersingular isogeny is provided, including a readable storage medium. A computer program is stored on the readable storage medium, and when the computer program is executed, the above-mentioned compact quantum-resistant encryption method based on supersingular isogeny is implemented.
[0097] As described above, it is only the preferred specific implementation manner of the present invention, and the protection scope of the present invention is not limited thereto. Any simple change or equivalent replacement of the technical solutions that can be obviously obtained by those skilled in the art within the technical scope disclosed by the present invention shall fall within the protection scope of the present invention.
Claims
1. A compact quantum-resistant encryption and decryption method based on supersingular isogeny, characterized in that: including the following processes, The system initialization process includes inputting the security parameter λ, the large prime number p=4*l1l2…l n -1, where l1, l2, ..., l n For different small prime numbers, defined in the finite field F p Supersingular elliptic curve E0:y on 2 =x 3 +x,F p The self-isomorphism ring is Z[π], and the system public parameters are (p,{l i } i=1,…,n ,E0,Z[π]); a key generation process, in which the user side generates public and private keys, and the implementation method is to randomly select an n-dimensional vector a=(a1,a2,…,a n ), a i ∈[-r,r], calculate the image curve E according to the corresponding ideal class A =[α]E0: y 2 =x 3 +Ax 2 +x, the private key is sk = a, the public key pk = A; r is the value range of the vector components; an encryption process, in which the encryptor encrypts the message m, and the implementation process is to randomly select an n-dimensional vector b = (b1,b2,…,b n ),b i ∈[-r,r], calculate the image curve E according to the corresponding ideal class B =[β]E0:y 2 =x 3 +Bx 2 +x, calculate the ideal class and [γ]= [l1][l2]…[l n , calculate the image curve E in two steps mid =[β′]E A , E AB =[γ]E mid : y 2 =x 3 +Cx 2 +x, and when calculating E AB =[γ]E mid , select a point P with order l1…l n ; perform the point doubling operation P c =[m]P and calculate Return the ciphertext where x(Pc) represents the x - coordinate of the point Pc; The decryption process is that the client decrypts the received ciphertext c to obtain the plaintext m. The implementation process is to split the ciphertext Verify E B Whether it is a supersingular elliptic curve. If so, calculate the ideal class And [γ] = [l1][l2]…[l n , and calculate the image curve E mid = [α′]E B And E AB = [γ]E mid And select the point P, solve the discrete logarithm problem m = DL(P c ,P) to recover the message m.
2. The compact quantum-resistant encryption and decryption method based on supersingular isogeny according to claim 1, wherein: the key generation process includes the user generating public and private keys according to the following process a) Randomly select an n-dimensional vector a = (a1, a2, …, a n ), a i ∈[-r, r], and its private key is the ideal class of Z[π] corresponding to the vector a b) Calculate the public key E2 = [α]E0:y corresponding to its private key 2 = x 3 + Ax 2 + x, and publish A as the public key; where [α]E0 represents the image curve obtained by the action of the ideal class [α] on the curve E0.
3. The compact quantum-resistant encryption and decryption method based on supersingular isogeny according to claim 2, wherein: the encryption process includes the encrypting end encrypting the message m according to the following process a) Encrypter Bob randomly selects an n-dimensional vector b = (b1, b2, …, b n ), b i ∈[-r, r], corresponding to the ideal class of Z[π] and calculates the image curve E B = [β]E0: y 2 = x 3 + Bx 2 + x; where [β]E0 represents the image curve obtained by the action of the ideal class [β] on the curve E0; b) Calculate the ideal class and calculate the image curve E mid = [β′]E A ; c) Calculate the ideal class [γ] = [l1][l2]…[l n , and calculate the image curve E AB = [γ]E mid , and calculate the points P of order l1l2…l AB on the curve E n during this process; d) Perform the double point operation P c = [m]P; e) Calculate where x(P c ) represents the x-coordinate of point P c ; f) Return the ciphertext 4. The compact quantum-resistant encryption and decryption method based on supersingular isogeny according to claim 3, characterized in that: The decryption process includes that after receiving the ciphertext c, the client decrypts it to obtain the plaintext m according to the following process: a) Split the ciphertext c into First, verify E B : y 2 = x 3 + Bx 2 + x is a supersingular elliptic curve. If not, terminate decryption; b) and calculate the image curve E after the action of [α′] mid = [α′]E B ; c) Calculate the ideal class [γ] = [l1][l2]…[l n , and calculate the image curve E AB = [γ]E mid , and calculate the points P of order l1l2…l AB on E n during this process; d) Calculation Recovery point P c ; e) Solve the discrete logarithm problem \(m = DL(P c , P)\) using the Pohlig-Hellman algorithm to obtain \(m\).
5. A compact quantum-resistant encryption and decryption system based on supersingular isogeny, characterized in that: used to implement a compact quantum-resistant encryption and decryption method based on supersingular isogeny as described in any one of claims 1-4.