A method for estimating the resistance of lattice-based encryption algorithms to decryption error attacks.
By calculating the perturbation distributions of public key compression and ciphertext compression in the lattice-based encryption algorithm, as well as the probability distributions of the private key, temporary private key, and error vector, the problem of not considering the impact of public key compression and ciphertext compression in existing technologies is solved, and a more accurate cost estimate for decryption error attacks is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
- Filing Date
- 2023-05-12
- Publication Date
- 2026-05-26
Smart Images

Figure CN116488791B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of lattice-based cryptography, and more specifically, to a method for estimating the ability of a lattice-based encryption algorithm to resist decryption error attacks. Background Technology
[0002] Lattice cryptography is a secure information transmission method in the era of quantum computing, possessing significant application value and playing a leading role in the current international standardization process of public-key cryptography. [1] Among them, the Lindner-Peikert-Regev type of lattice-based encryption algorithm, which is based on the error-learning problem, is an example. [6] This has been a great success. The basic steps of this type of algorithm are described below:
[0003] Key generation phase:
[0004] (1)
[0005] (2)
[0006] (3)
[0007] (4)
[0008] (5) Return the public and private keys
[0009] Encryption phase:
[0010] (1)
[0011] (2)
[0012] (3)
[0013] (4)
[0014] (5)
[0015] (6) Return to ciphertext
[0016] Decryption phase:
[0017] (1)
[0018] (2) Return
[0019] in, Indicates distance The most recent integer, This represents the probability distribution that the private key coordinates satisfy. This represents the probability distribution that the temporary private key coordinates satisfy. 、 、 This represents the probability distribution satisfied by the error vector coordinates. Under most typical parameters, such an encryption scheme has a certain probability of resulting in decryption errors. [2][3][4][5] .
[0020] Based on such encryption algorithms, key encapsulation mechanisms, IND-CCA secure encryption schemes, and key exchange protocols can be constructed. One of the attacker's strategies is to construct ciphertext with incorrect decryption capabilities and then leak key information by decrypting the incorrect ciphertext. [7] Peter Schwabe et al. [3] A strategy for attackers to construct decryption errors is presented, and the computational cost of attackers is initially estimated using this strategy.
[0021] However, the accuracy of existing estimation strategies may be affected by several factors, failing to accurately reflect the computational cost to an attacker obtaining incorrectly decrypted ciphertext. This may lead to an overestimation of attack costs. The main reason is that the original attack strategies do not consider public-key compression and ciphertext compression, nor do they analyze the aforementioned factors. The impact, but The impact on the decryption error rate is significant.
[0022] References:
[0023] [1] National Institute of Standards and Technology - NIST, Post-Quantum CryptographyPQC.
[0024] [2] NIST, Post-Quantum CryptographyPQC Round 3 Submissions.
[0025] [3] Peter Schwabe et al., CRYSTALS cryptographic suite for algebraic lattices.
[0026] [4] D’Anvers, JP., Karmakar, A., Sinha Roy, S., Vercauteren, F. (2018). Saber: Module-LWR Based Key Exchange, CPA-Secure Encryption and CCA-Secure KEM. In: Joux, A., Nitaj, A., Rachidi, T. (eds) Progress in Cryptology– AFRICACRYPT 2018. AFRICACRYPT 2018. Lecture Notes in Computer Science(), vol 10831. Springer, Cham。
[0027] [5] Erdem Alkim et al., FrodoKEM, practical quantum-secure key encapsulation from generic lattices。
[0028] [6] R. Lindner and C. Peikert. Better key sizes (and attacks) for LWE-based encryption. In CT-RSA, pages 319–339. 2011。
[0029] [7] D’Anvers, JP., Guo, Q., Johansson, T., Nilsson, A., Vercauteren, F., Verbauwhede, I. (2019). Decryption Failure Attacks on IND-CCA Secure Lattice-Based Schemes. In: Lin, D., Sako, K. (eds) Public-Key Cryptography – PKC 2019. PKC 2019. Lecture Notes in Computer Science(), vol 11443. Springer, Cham。 Summary of the Invention
[0030] This invention aims to provide a method for estimating the resistance of lattice-based encryption algorithms to decryption error attacks, in order to solve the following problems existing in the prior art: (1) the impact of public key compression and ciphertext compression is not included when estimating the attack cost; (2) the encryption time is not included when estimating the attack cost. The impact on the probability of decryption errors and the computational cost of attacks. These factors may overestimate or underestimate the cost of decryption error attacks, potentially reducing the accuracy of the computational cost for attackers to obtain incorrectly decrypted ciphertext.
[0031] The present invention provides a method for estimating the resistance of a lattice-based encryption algorithm to decryption error attacks, comprising the following steps:
[0032] Step 1: Calculate the distribution table of perturbations generated by public-key compression and ciphertext compression;
[0033] Step 2: Calculate the mean and variance of the probability distributions satisfied by the private key, temporary private key, and error vector coordinates based on the distribution table;
[0034] Step 3: Traverse the probability distribution values that the error vector coordinates satisfy during the encryption phase of the lattice-based encryption algorithm, and calculate the attacker's computational cost and attack strategy corresponding to the perturbation value of each plaintext loading unit.
[0035] Step 4: Based on the attacker's computational cost and attack strategy, obtain an estimate of the computational cost of the decryption error attack and the attack strategy.
[0036] In some preferred embodiments, the method for calculating the distribution table of perturbations generated by public-key compression and ciphertext compression in step 1 includes:
[0037] right Calculate separately Upper probability distribution Distribution table, exist The probability values are:
[0038]
[0039] in, Indicates distance The most recent integer; Indicates distance The most recent integer, Represents a set The number of elements; Modulus The remaining class ring.
[0040] In some preferred embodiments, the statistical calculation in step 2 includes:
[0041] Statistically calculate the probability distribution satisfied by the private key coordinates mean With variance ;
[0042] Statistically calculate the probability distribution satisfied by the temporary private key coordinates mean With variance ;
[0043] The probability distribution satisfied by the coordinates of the statistically calculated error vector mean With variance ;
[0044] The probability distribution satisfied by the coordinates of the statistically calculated error vector mean With variance ;
[0045] The probability distribution satisfied by the coordinates of the statistically calculated error vector mean With variance .
[0046] In some preferred embodiments, step 3 includes the following sub-steps:
[0047] Step 3.1: Determine the threshold for correct and incorrect decryption using the lattice-based encryption algorithm. ;
[0048] Step 3.2: Detect the operation of the lattice-based encryption algorithm. Dimension of vector space ;
[0049] Step 3.3: Determine the critical value Hegeki cryptography algorithm operation Dimension of vector space Calculate the expected value function of attack cost;
[0050] Step 3.4: Calculate and return the probability distribution satisfied by the error vector coordinates using the attack cost expected value function. Fixed value The corresponding attacker's computational cost and attack strategies .
[0051] In some preferred embodiments, the method for calculating the expected value function of attack cost in step 3.3 includes:
[0052]
[0053] In variables and Under the conditions, and Find the minimum value at that point ,in, , , Represents an exponential function. represents the natural logarithm function, and erfc represents the complement error function.
[0054] In some preferred embodiments, the method for calculating the expected value function of attack cost in step 3.3 includes:
[0055] Step 3.3.1: Determine the critical value Calculate the boundary values of the intervals where the lattice-based encryption algorithm decrypts correctly and incorrectly:
[0056]
[0057]
[0058] in, and These are probability distributions The minimum and maximum values that can be achieved;
[0059] Step 3.3.2: Calculate the attack cost expectation approximation function:
[0060]
[0061] In variables and Under the conditions and Find the minimum value at that point ,in, , , Represents an exponential function. This represents the natural logarithm function.
[0062] In some preferred embodiments, the method for calculating the expected value function of attack cost in step 3.3 includes:
[0063] Step 3.3.1: Determine the critical value Calculate the boundary values of the intervals where the lattice-based encryption algorithm decrypts correctly and incorrectly:
[0064]
[0065] in, It is a probability distribution The minimum achievable value;
[0066] Step 3.3.2: Calculate the attack cost expectation approximation function:
[0067]
[0068] In variables and Under the conditions and Find the minimum value at that point ,in, , , Represents an exponential function. This represents the natural logarithm function.
[0069] In some preferred embodiments, the method for calculating the expected value function of attack cost in step 3.3 includes:
[0070] Step 3.3.1: Determine the critical value Calculate the boundary values of the intervals where the lattice-based encryption algorithm decrypts correctly and incorrectly:
[0071]
[0072] in, These are probability distributions The maximum value that can be achieved;
[0073] Step 3.3.2: Calculate the attack cost expectation approximation function:
[0074]
[0075] In variables and Under the conditions and Find the minimum value at that point ,in, , , Represents an exponential function. This represents the natural logarithm function.
[0076] In some preferred embodiments, the method for calculating the expected value function of attack cost in step 3.3 includes:
[0077] Calculate the lower bound function of the expected attack cost:
[0078]
[0079] In variables and Under the conditions and Find the minimum value at that point ,in, , , Represents an exponential function. represents the natural logarithm function, and erfc represents the complement error function.
[0080] In some preferred embodiments, the method for calculating the expected value function of attack cost in step 3.3 includes:
[0081] Calculate the lower bound function of the expected attack cost:
[0082]
[0083] In variables and Under the conditions and Find the minimum value at that point ,in, , , Represents an exponential function. represents the natural logarithm function, and erfc represents the complement error function.
[0084] In some preferred embodiments, the method for obtaining the estimated computational cost of a decryption error attack and the attack strategy in step 4, based on the attacker's computational cost and attack strategy, includes:
[0085] Based on the attacker's computational cost and attack strategy obtained in step 3, search for the probability distribution. subset of values Make in Time function:
[0086]
[0087] Find the minimum value. ,Right now:
[0088]
[0089] Obtain an estimate of the computational cost and attack strategy for decryption error attacks:
[0090] by As a measure of the computational cost of decryption error attacks, among which, It is a process of encrypting and decrypting plaintext. Number of units;
[0091] The attacker's attack strategy is as follows and That is, the attacker searches for suitable data during the encryption phase to make it possible. The value of Located in set Internally, simultaneously satisfying the encryption stage vector The length is not shorter than And the encryption stage vector The length is not shorter than ,in, Representing vectors dimensionality Representing vectors The dimension of.
[0092] In some preferred embodiments, the method for obtaining the estimated computational cost of a decryption error attack and the attack strategy in step 4, based on the attacker's computational cost and attack strategy, includes:
[0093] Based on the attacker's computational cost and attack strategy obtained in step 3, find... Make the probability distribution Fixed value The cost of an attack is minimized at that time. ;
[0094] with minimum value As a measure of the computational cost of decryption error attacks, among which, It is a process of encrypting and decrypting plaintext. Number of units;
[0095] The attacker's attack strategy is as follows That is, the attacker searches for suitable data during the encryption phase to make it possible. The value is Simultaneously satisfying the encryption stage vector The length is not shorter than And the encryption stage vector The length is not shorter than ,in, Representing vectors dimensionality Representing vectors The dimension of.
[0096] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are:
[0097] 1. This invention incorporates the impact of public key compression and ciphertext compression, which are beyond the attacker's control, into the calculation rule for estimating attack costs, thus more accurately reflecting the factors that need to be considered in actual attacks.
[0098] 2. Since the perturbation data of the plaintext corresponding data unit during encryption has a significant impact on the probability of decryption errors, this invention introduces this perturbation data when estimating the attack cost to examine its impact on the attacker's computational workload. This invention takes into account relevant factors as much as possible in order to more accurately estimate the cost of decryption error attacks. Attached Figure Description
[0099] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings in the embodiments will be briefly described below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0100] Figure 1 This is a flowchart illustrating a method for estimating the ability of a lattice-based encryption algorithm to resist decryption error attacks in an embodiment of the present invention.
[0101] Figure 2 This is a flowchart illustrating the calculation of attack cost and attack strategy based on the perturbation value of the fixed plaintext loading unit in an embodiment of the present invention. Detailed Implementation
[0102] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0103] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.
[0104] Example
[0105] like Figure 1 As shown in the figure, this embodiment proposes a method for estimating the ability of a lattice-based encryption algorithm to resist decryption error attacks, including the following steps:
[0106] Step 1: Calculate the distribution table of perturbations generated by public-key compression and ciphertext compression. Specifically, for... Calculate separately Upper probability distribution Distribution table, exist The probability values are:
[0107]
[0108] in, Indicates distance The most recent integer; Indicates distance The most recent integer, Represents a set The number of elements; Modulus The remaining class ring, often taking the representative element or .
[0109] Step 2: Calculate the mean and variance of the probability distribution satisfied by the coordinates of the private key, temporary private key, and error vector, based on the distribution table. Specifically, this includes:
[0110] Statistically calculate the probability distribution satisfied by the private key coordinates mean With variance ;
[0111] Statistically calculate the probability distribution satisfied by the temporary private key coordinates mean With variance ;
[0112] The probability distribution satisfied by the coordinates of the statistically calculated error vector mean With variance ;
[0113] The probability distribution satisfied by the coordinates of the statistically calculated error vector mean With variance ;
[0114] The probability distribution satisfied by the coordinates of the statistically calculated error vector mean With variance .
[0115] Step 3: Traverse the probability distribution satisfied by the error vector coordinates during the encryption phase of the lattice-based encryption algorithm. Calculate the probability distribution based on the value of . Fixed value The corresponding attacker's computational cost and attack strategy. Specifically, it includes the following sub-steps:
[0116] Step 3.1: Determine the threshold for correct and incorrect decryption using the lattice-based encryption algorithm. ;generally Nearest integers, where, For modulus, For each The number of plaintext bits loaded in the unit;
[0117] Step 3.2: Detect the operation of the lattice-based encryption algorithm. Dimension of vector space ;
[0118] Step 3.3: Determine the critical value Hegeki cryptography algorithm operation Dimension of vector space Calculate the expected value function of attack cost;
[0119] Step 3.4: Calculate and return the probability distribution satisfied by the error vector coordinates using the attack cost expected value function. Fixed value The corresponding attacker's computational cost and attack strategies .
[0120] Step 3.3 can be implemented in the following ways:
[0121] Method 1, the method for calculating the expected value function of attack cost in step 3.3 includes:
[0122]
[0123] In variables and Under the conditions, and Find the minimum value at that point ,in, , , Represents an exponential function. represents the natural logarithm function, and erfc represents the complementary error function.
[0124] Method 2, the method for calculating the expected value function of attack cost in step 3.3 includes:
[0125] Step 3.3.1: Determine the critical value Calculate the boundary values of the intervals where the lattice-based encryption algorithm decrypts correctly and incorrectly:
[0126]
[0127]
[0128] in, and These are probability distributions The minimum and maximum values that can be achieved;
[0129] Step 3.3.2: Calculate the attack cost expectation approximation function:
[0130]
[0131] In variables and Under the conditions and Find the minimum value at that point ,in, , , Represents an exponential function. This represents the natural logarithm function.
[0132] Method 3, the method for calculating the expected value function of attack cost in step 3.3 includes:
[0133] Step 3.3.1: Determine the critical value Calculate the boundary values of the intervals where the lattice-based encryption algorithm decrypts correctly and incorrectly:
[0134]
[0135] in, It is a probability distribution The minimum achievable value;
[0136] Step 3.3.2: Calculate the attack cost expectation approximation function:
[0137]
[0138] In variables and Under the conditions and Find the minimum value at that point ,in, , , Represents an exponential function. This represents the natural logarithm function.
[0139] Method four, the method for calculating the expected value function of attack cost in step 3.3 includes:
[0140] Step 3.3.1: Determine the critical value Calculate the boundary values of the intervals where the lattice-based encryption algorithm decrypts correctly and incorrectly:
[0141]
[0142] in, These are probability distributions The maximum value that can be achieved;
[0143] Step 3.3.2: Calculate the attack cost expectation approximation function:
[0144]
[0145] In variables and Under the conditions and Find the minimum value at that point ,in, , , Represents an exponential function. This represents the natural logarithm function.
[0146] Method 5, the method for calculating the expected value function of attack cost in step 3.3 includes:
[0147] Calculate the lower bound function of the expected attack cost:
[0148]
[0149] In variables and Under the conditions and Find the minimum value at that point ,in, , , Represents an exponential function. represents the natural logarithm function, and erfc represents the complementary error function.
[0150] Method 6, the method for calculating the expected value function of attack cost in step 3.3 includes:
[0151] Calculate the lower bound function of the expected attack cost:
[0152]
[0153] In variables and Under the conditions and Find the minimum value at that point ,in, , , Represents an exponential function. represents the natural logarithm function, and erfc represents the complementary error function.
[0154] Step 4: Based on the attacker's computational cost and attack strategy, obtain an estimate of the computational cost of the decryption error attack and the attack strategy.
[0155] Step 4 can be implemented in the following two ways:
[0156] Method 1:
[0157] Based on the attacker's computational cost and attack strategy obtained in step 3, search for the probability distribution. subset of values Make in Time function:
[0158]
[0159] Find the minimum value. ,Right now:
[0160]
[0161] Obtain an estimate of the computational cost and attack strategy for decryption error attacks:
[0162] by As a measure of the computational cost of decryption error attacks, among which, It is a process of encrypting and decrypting plaintext. Number of units;
[0163] The attacker's attack strategy is as follows and That is, the attacker searches for suitable data during the encryption phase to make it possible. The value of Located in set Internally, simultaneously satisfying the encryption stage vector The length is not shorter than (here Representing vectors (dimensionality) and encryption stage vector The length is not shorter than (here Representing vectors (dimensionality).
[0164] Method 2:
[0165] Based on the attacker's computational cost and attack strategy obtained in step 3, find... Make the probability distribution Fixed value The cost of an attack is minimized at that time. ;
[0166] with minimum value As a measure of the computational cost of decryption error attacks, among which, It is a process of encrypting and decrypting plaintext. Number of units;
[0167] The attacker's attack strategy is as follows That is, the attacker searches for suitable data during the encryption phase to make it possible. The value is Simultaneously satisfying the encryption stage vector The length is not shorter than (here Representing vectors (dimensionality) and encryption stage vector The length is not shorter than (here Representing vectors (dimensionality).
[0168] Furthermore, in other embodiments, in the estimation method for the resistance of the lattice-based encryption algorithm to decryption error attacks provided by the technical solution of this invention, the threshold value used to determine whether decryption is correct or incorrect is... This is the usual situation. In specific solutions, adjustments can be made or more detailed depictions can be made. For example, the upper and lower boundaries can be depicted in detail separately. The technical solution of this invention is still applicable.
[0169] Furthermore, in other embodiments, in the estimation method for the resistance of the lattice-based encryption algorithm to decryption error attacks provided by the technical solution of the present invention, the computational cost of the attack is calculated according to the computational complexity metric, or it can be adjusted to be solved by operating on the logarithm of the computational amount (with a base of 2), and the technical solution of the present invention is still applicable.
[0170] Furthermore, in other embodiments, in the estimation method for the resistance of the lattice-based encryption algorithm to decryption error attacks provided by the technical solution of the present invention, the approximate approximation of the erfc representation of the complementary error function or the replacement of the upper (lower) bound function can be selected according to the actual accuracy requirements, and the technical solution of the present invention is still applicable.
[0171] As described above, for lattice-based encryption algorithms of the Lindner-Peikert-Regev type, this invention proposes an estimation method for the algorithm's resistance to decryption error attacks. This method addresses the attacker's strategy of actively searching for a long temporary private key and error vector during the encryption phase to more easily obtain ciphertext with decryption errors. The estimation method quantifies the minimum computational cost and corresponding attack strategy in a probabilistic sense for such attacks. Furthermore, the method provided by this invention is computationally achievable and feasible. Compared with previous methods, this invention has the following new features and advantages:
[0172] 1. This invention incorporates the impact of public key compression and ciphertext compression, which are beyond the attacker's control, into the calculation rule for estimating attack costs, thus more accurately reflecting the factors that need to be considered in actual attacks.
[0173] 2. Since the perturbation data of the plaintext corresponding data unit during encryption has a significant impact on the probability of decryption errors, this invention introduces this perturbation data when estimating the attack cost to examine its impact on the attacker's computational workload. This invention takes into account relevant factors as much as possible in order to more accurately estimate the cost of decryption error attacks.
[0174] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A method for estimating the resistance of a lattice-based encryption algorithm to decryption error attacks, characterized in that, Includes the following steps: Step 1: Calculate the distribution table of perturbations generated by public-key compression and ciphertext compression; Step 2: Calculate the mean and variance of the probability distributions satisfied by the private key, temporary private key, and error vector coordinates based on the distribution table; Step 3: Traverse the probability distribution values that the error vector coordinates satisfy during the encryption phase of the lattice-based encryption algorithm, and calculate the attacker's computational cost and attack strategy corresponding to the perturbation value of each plaintext loading unit. Step 4: Based on the attacker's computational cost and attack strategy, obtain an estimate of the computational cost of the decryption error attack and the attack strategy itself; The method for calculating the distribution table of perturbations generated by public-key compression and ciphertext compression in step 1 includes: right Calculate separately Upper probability distribution Distribution table, exist The probability values are: in, Indicates distance The most recent integer; Indicates distance The most recent integer, Represents a set The number of elements; Modulus The remaining class ring; Step 3 includes the following sub-steps: Step 3.1: Determine the threshold for correct and incorrect decryption using the lattice-based encryption algorithm. ; Step 3.2: Detect the operation of the lattice-based encryption algorithm. Dimension of vector space ; Step 3.3: Determine the critical value Hegeki cryptography algorithm operation Dimension of vector space Calculate the expected value function of attack cost; Step 3.4: Calculate and return the probability distribution satisfied by the error vector coordinates using the attack cost expected value function. Fixed value The corresponding attacker's computational cost and attack strategies ; Step 4 involves obtaining estimates of the computational cost of a decryption error attack and the attack strategy based on the attacker's computational cost and attack strategy. The methods include: Based on the attacker's computational cost and attack strategy obtained in step 3, search for the probability distribution. subset of values So that in Time function: Find the minimum value. ,Right now: Obtain an estimate of the computational cost and attack strategy for decryption error attacks: by As a measure of the computational cost of decryption error attacks, among which, It is a process of encrypting and decrypting plaintext. Number of units; The attacker's attack strategy is as follows and That is, the attacker searches for suitable data during the encryption phase to enable the existence of... The value of Located in set Internally, simultaneously satisfying the encryption stage vector The length is not shorter than And the encryption stage vector The length is not shorter than ,in, Representing vectors dimensionality Representing vectors The dimension of.
2. The method for estimating the resistance of the lattice-based encryption algorithm to decryption error attacks according to claim 1, characterized in that, The statistical calculations in step 2 include: Statistically calculate the probability distribution satisfied by the private key coordinates mean With variance ; Statistically calculate the probability distribution satisfied by the temporary private key coordinates mean With variance ; The probability distribution satisfied by the coordinates of the statistically calculated error vector mean With variance ; The probability distribution satisfied by the coordinates of the statistically calculated error vector mean With variance ; The probability distribution satisfied by the coordinates of the statistically calculated error vector mean With variance .
3. The method for estimating the resistance of the lattice-based encryption algorithm to decryption error attacks according to claim 2, characterized in that, The method for calculating the expected value function of attack cost in step 3.3 includes: In variables and Under the conditions, and Find the minimum value at that point ,in, , , Represents an exponential function. represents the natural logarithm function, and erfc represents the complement error function.
4. The method for estimating the resistance of the lattice-based encryption algorithm to decryption error attacks according to claim 2, characterized in that, The method for calculating the expected value function of attack cost in step 3.3 includes: Step 3.3.1: Determine the critical value Calculate the boundary values of the intervals where the lattice-based encryption algorithm decrypts correctly and incorrectly: in, and These are probability distributions The minimum and maximum values that can be achieved; Step 3.3.2: Calculate the attack cost expectation approximation function: In variables and Under the conditions and Find the minimum value at that point ,in, , , Represents an exponential function. This represents the natural logarithm function.
5. The method for estimating the resistance of the lattice-based encryption algorithm to decryption error attacks according to claim 2, characterized in that, The method for calculating the expected value function of attack cost in step 3.3 includes: Step 3.3.1: Determine the critical value Calculate the boundary values of the intervals where the lattice-based encryption algorithm decrypts correctly and incorrectly: in, It is a probability distribution The minimum achievable value; Step 3.3.2: Calculate the attack cost expectation approximation function: In variables and Under the conditions and Find the minimum value at that point ,in, , , Represents an exponential function. This represents the natural logarithm function.
6. The method for estimating the resistance of the lattice-based encryption algorithm to decryption error attacks according to claim 2, characterized in that, The method for calculating the expected value function of attack cost in step 3.3 includes: Step 3.3.1: Determine the critical value Calculate the boundary values of the intervals where the lattice-based encryption algorithm decrypts correctly and incorrectly: in, These are probability distributions The maximum value that can be achieved; Step 3.3.2: Calculate the attack cost expectation approximation function: In variables and Under the conditions and Find the minimum value at that point ,in, , , Represents an exponential function. This represents the natural logarithm function.
7. The method for estimating the resistance of the lattice-based encryption algorithm to decryption error attacks according to claim 2, characterized in that, The method for calculating the expected value function of attack cost in step 3.3 includes: Calculate the lower bound function of the expected attack cost: In variables and Under the conditions and Find the minimum value at that point ,in, , , Represents an exponential function. represents the natural logarithm function, and erfc represents the complement error function.
8. The method for estimating the resistance of the lattice-based encryption algorithm to decryption error attacks according to claim 2, characterized in that, The method for calculating the expected value function of attack cost in step 3.3 includes: Calculate the lower bound function of the expected attack cost: In variables and Under the conditions and Find the minimum value at that point ,in, , , Represents an exponential function. represents the natural logarithm function, and erfc represents the complement error function.
9. The method for estimating the resistance of the lattice-based encryption algorithm to decryption error attacks according to any one of claims 2-8, characterized in that, Step 4, which involves obtaining an estimate of the computational cost of a decryption error attack and the attack strategy based on the attacker's computational cost and attack strategy, also includes: Based on the attacker's computational cost and attack strategy obtained in step 3, find... Make the probability distribution Fixed value The cost of an attack is minimized at that time. ; with minimum value As a measure of the computational cost of decryption error attacks, among which, It is a process of encrypting and decrypting plaintext. Number of units; The attacker's attack strategy is as follows That is, the attacker searches for suitable data during the encryption phase to enable the existence of... The value is Simultaneously satisfying the encryption stage vector The length is not shorter than And the encryption stage vector The length is not shorter than ,in, Representing vectors dimensionality Representing vectors The dimension of.