A high-precision sampling method of variance distribution of lattice-based cryptography
Patent Information
- Application Number
- CN202310536016.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-12
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2043-05-12
AI Technical Summary
但是,同时满足生成效率高、宽泛自由的方差、抵抗物理攻击等要求的采样方式并不容易,例如,现有格基密码算法采用的中心二项分布使得分布方差精度选择方面受到限制,而可满足高精度方差折叠高斯分布则容易受到物理攻击的影响
[0103]1、本发明中输出的采样分布能够满足方差要求精度,从而给予格基密码参数选取更广泛的范围与自由度;
Smart Images

Figure CN116582268B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of lattice cryptography, and more specifically, to a sampling method for a high-precision variance distribution of lattice cryptography. Background Technology
[0002] Quantum computing is a strategic high ground for future information technology and has already posed a fatal threat to traditional public-key cryptography such as RSA, DSA, and ECC. Domestic and international cryptography researchers are conducting research on post-quantum cryptography. The National Institute of Standards and Technology (NIST) in the United States has officially launched a call for post-quantum cryptography algorithm standards and completed the selection of four standard algorithms. [1] In post-quantum cryptography, lattice-based cryptography dominates due to its theoretically provable security and superior overall performance in terms of space-time resources. Three out of the four standard algorithms selected by NIST belong to lattice-based cryptography. [1] .
[0003] In existing lattice cryptography [2][3] In cryptography, generating appropriate probability distributions as secret keys or error vectors for cryptographic algorithms is a crucial and fundamental operation, widely used in most influential lattice-based cryptographic algorithms. [4] Newhope [5] CRYSTALS-Kyber [6] Saber [7] Algorithms such as FrodoKEM widely adopt the central binomial distribution. [8] SCloud employs an approximate folded Gaussian distribution. [9] The method employs convolution with a central binomial distribution and a uniform distribution. The central binomial distribution has high generation efficiency, while the folded Gaussian distribution provides a distribution with a more continuous standard deviation. However, it is not easy to find a sampling method that simultaneously satisfies requirements such as high generation efficiency, wide-ranging and flexible variance, and resistance to physical attacks. For example, the central binomial distribution used in existing lattice-based cryptography algorithms limits the choice of distribution variance precision, while the folded Gaussian distribution, which can satisfy high-precision variance, is susceptible to physical attacks.
[0004] References:
[0005] [1]NIST: Post-quantum cryptography pqc, selected algorithms 2022.
[0006] [2]O.Regev.On lattices,learning with errors,random linear codes,andcryptography.Journal of the ACM,56(6):34,2009.Preliminary version in STOC2005。
[0007] [3]Lindner,R.,Peikert,C.:Better key sizes(and attacks)for lwe-basedencryption.In:Kiayias,A.(ed.)Topics in Cryptology–CT-RSA 2011.pp.319–339.Springer Berlin Heidelberg,Berlin,Heidelberg(2011)。
[0008] [4]NIST:Nist,post-quantum cryptography pqc round 3submissions。
[0009] [5]Alkim,E.,Ducas,L., T.,Schwabe,P.:Post-quantum keyExchange—A new hope.In:25th USENIX Security Symposium(USENIX Security 16).pp.327–343.USENIX Association,Austin,TX(Aug 2016)。
[0010] [6]Schwabe et al.,P.:Github-pq-crystals / kyber。
[0011] [7]D’Anvers et al.,J.P.:Saber mlwr-based kem。
[0012] [8]Alkim et al.,E.:Frodokem,practical quantum-secure keyencapsulation from generic lattices。
[0013] [9] Z.Zheng, A.Wang, H.Fan, C.Zhao, C.Liu, X.Zhang, Scloud: Public keyencryption and key encapsulation mechanism based on learning with errors, Cryptology ePrint Archive, Paper 2020 / 095. Summary of the Invention
[0014] The present invention aims to provide a sampling method for high-precision variance distribution of lattice-based cryptography. This sampling method can provide high-precision variance while maintaining constant sampling time, thereby expanding the parameter design range of lattice-based cryptography and resisting corresponding physical attacks.
[0015] This invention provides a high-precision variance distribution sampling method for lattice-based cryptography, comprising step A, which includes the following sub-steps:
[0016] Step A1: Generate sampling unit t using the central binomial distribution. i ;
[0017] Step A2: Generate selection unit a through random uniform distribution i ;
[0018] Step A3: Based on the selected unit a i The value of the output sample Or sampling
[0019] Furthermore, the sampling method for the high-precision variance distribution of the lattice-based cryptography further includes step B, which comprises the following sub-steps:
[0020] Step B1: Run steps A1 to A3 k times to obtain samples.
[0021] Step B2: Sampling Summation yields the sample.
[0022] Step B3: Output sample s B .
[0023] The present invention also provides a sampling method for high-precision variance distribution of lattice-based cryptography, including step C, which includes the following sub-steps:
[0024] Step C1: Generate sampling unit t using the central binomial distribution. i ;
[0025] Step C2: Specify the expansion coefficient c i;
[0026] Step C3: Calculate and output the samples
[0027] Furthermore, the sampling method for the high-precision variance distribution of lattice-based cryptography further includes step D, which comprises the following sub-steps:
[0028] Step D1: Run steps C1 to C3 k times to obtain samples.
[0029] Step D2: Sampling Summation yields the sample.
[0030] Step D3: Output sample s D .
[0031] Furthermore, step D also includes a parallel implementation method for the following scenario:
[0032] Step X1: Generate a k-bit non-negative integer c using a uniform distribution, i.e., c = c1x1 + c2x2 + ... + c k x k Where the expansion coefficients are c1=1, c2=2,…,c i =2 i-1 ,…,c k =2 k-1 And x1, x2, ..., x k For multiple runs of the random bit x in step C1 i ;
[0033] Step X2: Generate a k-bit non-negative integer d using a uniform distribution, i.e., d = c1y1 + c2y2 + ... + c k y k Where the expansion coefficients are c1=1, c2=2,…,c i =2 i-1 ,…,c k =2 k-1 And y1, y2, ..., y k For multiple runs of the random bit y in step C1 i ;
[0034] Step X3: Calculate the sample Output sample T.
[0035] The present invention also provides a sampling method for high-precision variance distribution of lattice-based cryptography, including step E, which includes the following sub-steps:
[0036] Step E1: Generate small variance samples using the method from step A. Alternatively, small variance samples can be generated via step B. m =s B ;
[0037] Step E2: Generate large variance samples using the method from step C. Alternatively, a large variance sample S can be generated through step D. M =s D ;
[0038] Step E3: Calculate the sum s of small variance sampling and large variance sampling. E =s m +D M Output s E ;
[0039] Step A includes the following sub-steps:
[0040] Step A1: Generate sampling unit t using the central binomial distribution. i ;
[0041] Step A2: Generate selection unit a through random uniform distribution i ;
[0042] Step A3: Based on the selected unit a i The value of the output sample Or sampling
[0043] Step B includes the following sub-steps:
[0044] Step B1: Run steps A1 to A3 k times to obtain samples.
[0045] Step B2: Sampling Summation yields the sample.
[0046] Step B3: Output sample s B ;
[0047] Step C includes the following sub-steps:
[0048] Step C1: Generate sampling unit t using the central binomial distribution. i ;
[0049] Step C2: Specify the expansion coefficient c i ;
[0050] Step C3: Calculate and output the samples
[0051] Step D includes the following sub-steps:
[0052] Step D1: Run steps C1 to C3 k times to obtain samples.
[0053] Step D2: Sampling Summation yields the sample.
[0054] Step D3: Output sample s D .
[0055] The present invention also provides a sampling method for high-precision variance distribution of lattice-based cryptography, including step F, which includes the following sub-steps:
[0056] Step F1: Generate unbiased sample r:
[0057] Unbiased sampling is generated through step A. or
[0058] Unbiased sampling r = s is generated through step B. B ,or
[0059] Unbiased sampling is generated through step C. or
[0060] Unbiased sampling r = s is generated through step D. D ,or
[0061] Unbiased sampling r = s is generated through step E. E ;
[0062] Step F2: Specify the deviation m, calculate the sampling R = r + m, and output the sampling R;
[0063] Step A includes the following sub-steps:
[0064] Step A1: Generate sampling unit t using the central binomial distribution. i ;
[0065] Step A2: Generate selection unit a through random uniform distribution i ;
[0066] Step A3: Based on the selected unit a i The value of the output sample Or sampling
[0067] Step B includes the following sub-steps:
[0068] Step B1: Run steps A1 to A3 k times to obtain samples.
[0069] Step B2: Sampling Summation yields the sample.
[0070] Step B3: Output sample s B ;
[0071] Step C includes the following sub-steps:
[0072] Step C1: Generate sampling unit t using the central binomial distribution. i ;
[0073] Step C2: Specify the expansion coefficient c i ;
[0074] Step C3: Calculate and output the samples
[0075] Step D includes the following sub-steps:
[0076] Step D1: Run steps C1 to C3 k times to obtain samples.
[0077] Step D2: Sampling Summation yields the sample.
[0078] Step D3: Output sample s D ;
[0079] Step E includes the following sub-steps:
[0080] Step E1: Generate small variance samples using the method from step A. Alternatively, small variance samples can be generated via step B. m =s B ;
[0081] Step E2: Generate large variance samples using the method from step C. Alternatively, a large variance sample S can be generated through step D. M =s D ;
[0082] Step E3: Calculate the sum s of small variance sampling and large variance sampling. E =s m +S M Output s E .
[0083] This invention also provides a sampling method for high-precision variance distribution of lattice-based cryptography, comprising the following steps:
[0084] Step 1: Input the mean m, variance σ, and the accuracy requirement for generating the sampling variance ∈;
[0085] Step 2: Determine the sampling units and select the unit list;
[0086] Step 3: Sample according to each group of sampling units and selection units in the sampling unit and selection unit list, and output the sampled unit s. i ;
[0087] Step 4: Unit sampling s i Summing yields the sampled data t;
[0088] Step 5: Add the mean m to the sampled data t to obtain the sample s;
[0089] Step 6: Output sample s.
[0090] Furthermore, the method for determining the sampling unit and selection unit list in step 2 specifically includes:
[0091]
[0092] Where v represents a rational number approximating the variance σ according to the specified precision requirement, v1 is a positive integer, and v i (2≤i≤k) is 0 or 1 such that |v-σ|<∈; k represents the number of decimal places of v according to the binary expansion rules plus 1;
[0093] List L = [(v i ,i-1):v i [≠0,1≤i≤k] is a list of sampling units and selection units, indicating that for 1≤i≤k, if v i ≠0, then (v i v in i-1) i i is a sampling unit, and i-1 is a selection unit.
[0094] Furthermore, step 3 includes the following sub-steps:
[0095] Step 3.1: Input a set of sampling units and selection units (v) from the sampling unit and selection unit list L. i ,i-1);
[0096] Step 3.2: From the variance v i / 2 of the distribution sampling t i ;
[0097] Step 3.3: Select i-1 uniformly randomly distributed bits. If these i-1 bits constitute a specific i-1 constant, then the output unit samples s. i =t i Otherwise, the output unit samples s i =0.
[0098] Furthermore, step 3.2 includes the following sub-steps:
[0099] Step 3.2.1: Obtain the expression Among them, u j (1≤j≤l) are all positive integers;
[0100] Step 3.2.2: For each u j (1≤j≤l), select two uniformly randomly distributed bits a0, a1, and calculate the integer w. j =a0-a1;
[0101] Step 3.2.3: Output sampling
[0102] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are:
[0103] 1. The sampling distribution output in this invention can meet the variance requirement accuracy, thus giving lattice-based cryptography parameters a wider range and greater freedom of selection;
[0104] 2. The implementation of this invention can be based on the central binomial distribution as a basic module, and the sampling implementation has high spatial and temporal efficiency;
[0105] 3. By fixing the variance, this invention can achieve sampling in constant time, and can better resist physical attacks;
[0106] 4. This invention allows lattice-based cryptography to select a trade-off strategy between the precision of sampling variance and sampling time. Attached Figure Description
[0107] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings in the embodiments will be briefly described below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0108] Figure 1 This is a flowchart of the sampling method for the high-precision variance distribution of lattice-based cryptography in Embodiment 1 of the present invention.
[0109] Figure 2 This is a flowchart of the sampling method for the high-precision variance distribution of lattice-based cryptography in Embodiment 2 of the present invention.
[0110] Figure 3 This is a flowchart of the sampling method for the high-precision variance distribution of lattice-based cryptography in Embodiment 3 of the present invention.
[0111] Figure 4 This is a flowchart of the sampling method for the high-precision variance distribution of lattice-based cryptography in Embodiment 4 of the present invention.
[0112] Figure 5This is a flowchart of the sampling method for the high-precision variance distribution of lattice-based cryptography in Embodiment 5 of the present invention.
[0113] Figure 6 This is a flowchart of the sampling method for the high-precision variance distribution of lattice-based cryptography in Embodiment 6 of the present invention.
[0114] Figure 7 This is a flowchart of the sampling method for the high-precision variance distribution of lattice-based cryptography in Embodiment 7 of the present invention.
[0115] Figure 8 This is a flowchart of sampling based on the sampling unit and the selection unit in Embodiment 7 of the present invention. Detailed Implementation
[0116] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0117] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.
[0118] Example 1
[0119] like Figure 1 As shown, this embodiment proposes a sampling method for high-precision variance distribution of lattice-based cryptography, including step A, which includes the following sub-steps:
[0120] Step A1: Generate sampling unit t using the central binomial distribution. i Among them, the sampling unit t is generated. i One method could be to select two uniformly randomly distributed bits x. i ,y i Calculate the sampling unit t i =x i -y i .
[0121] Step A2: Generate selection unit a through random uniform distribution i Among them, the generation selection unit a i One method could be to select a randomly distributed number of bits l i Composition of selection unit a i .
[0122] Step A3: Based on the selected unit a i The value of the output sample Or sampling For example: when selecting unit a i If the value is a specific number or belongs to a specified set of numbers, then the output sample is... Otherwise, output sampling
[0123] Example 2
[0124] like Figure 2 As shown in Example 1, this example proposes a sampling method for high-precision variance distribution of lattice-based cryptography, including step B, which includes the following sub-steps:
[0125] Step B1: Run steps A1 to A3 k times to obtain samples. Among them, steps A1, A2, and A3 allow for the selection of unit a at each step. i Number of bits l i different.
[0126] Step B2: Sampling Summation yields the sample.
[0127] Step B3: Output sample s B .
[0128] It should be noted that the number of bits used in step A2 is related to... i Zero is allowed, meaning that this selection unit step does not require random numbers and the corresponding step A3 outputs a constant value.
[0129] Example 3
[0130] like Figure 3 As shown, this embodiment proposes a sampling method for high-precision variance distribution of lattice-based cryptography, including step C, which includes the following sub-steps:
[0131] Step C1: Generate sampling unit t using the central binomial distribution. i Among them, the sampling unit t is generated. i One method could be to select two uniformly randomly distributed bits x. i ,y i Calculate the sampling unit t i =x i -y i .
[0132] Step C2: Specify the expansion coefficient c i ;
[0133] Step C3: Calculate and output the samples
[0134] Example 4
[0135] like Figure 4 As shown in Example 3, this example proposes a sampling method for high-precision variance distribution of lattice-based cryptography, including step D, which includes the following sub-steps:
[0136] Step D1: Run steps C1 to C3 k times to obtain samples. Among them, steps C1, C2, and C3 allow for an expansion coefficient c each time. i different.
[0137] Step D2: Sampling Summation yields the sample.
[0138] Step D3: Output sample s D .
[0139] In particular, step D also includes a parallel implementation for the following scenario:
[0140] Step X1: Generate a k-bit non-negative integer c using a uniform distribution, i.e., c = c1x1 + c2x2 + ... + c k x k Where the expansion coefficients are c1=1, c2=2,…,c i =2 i-1 ,…,c k =2 k-1 And x1, x2, ..., x k For multiple runs of the random bit x in step C1 i ;
[0141] Step X2: Generate a k-bit non-negative integer d using a uniform distribution, i.e., d = c1y1 + c2y2 + ... + c k y k Where the expansion coefficients are c1=1, c2=2,…,c i =2 i-1 ,…,c k =2 k-1 And y1, y2, ..., y k For multiple runs of the random bit y in step C1 i ;
[0142] Step X3: Calculate T = cd, and output the sampled value T. This is equivalent to having constant expansion coefficients c1 = 1, c2 = 2, ..., cd. i =2 i-1 ,…,c k =2k-1 Under the condition of running steps D1 to D2, that is
[0143]
[0144] Example 5
[0145] like Figure 5 As shown, based on Examples 1 to 4, this example proposes a sampling method for high-precision variance distribution of lattice-based cryptography, including step E, which includes the following sub-steps:
[0146] Step E1: Generate small variance samples using the method from step A. Alternatively, small variance samples can be generated via step B. m =s B ;
[0147] Step E2: Generate large variance samples using the method from step C. Alternatively, a large variance sample S can be generated through step D. M =s D ;
[0148] Step E3: Calculate the sum s of small variance sampling and large variance sampling. E =s m +S M Output s E .
[0149] Steps A, B, C, and D are described in accordance with Examples 1 to 4, and will not be repeated here. It should be noted that the number of bits used in step A2 is... i Zero is allowed, meaning that this selection unit step does not require random numbers and the corresponding step A3 outputs a constant value.
[0150] Example 6
[0151] like Figure 6 As shown, based on Examples 1 to 5, this embodiment proposes a sampling method for high-precision variance distribution of lattice-based cryptography, including step F, which includes the following sub-steps:
[0152] Step F1: Generate unbiased sample r:
[0153] Unbiased sampling is generated through step A. or
[0154] Unbiased sampling r = s is generated through step B. B ,or
[0155] Unbiased sampling is generated through step C. or
[0156] Unbiased sampling r = s is generated through step D. D ,or
[0157] Unbiased sampling r = s is generated through step E. E ;
[0158] Step F2: Specify the deviation m, calculate the sampling R = r + m, and output the sampling R.
[0159] Steps A, B, C, D, and E are described in accordance with Examples 1 to 5, and will not be repeated here. It should be noted that the number of bits used in step A2 is... i Zero is allowed, meaning that this selection unit step does not require random numbers and the corresponding step A3 outputs a constant value.
[0160] Example 7
[0161] like Figure 7 As shown, this embodiment proposes a sampling method for high-precision variance distribution of lattice-based cryptography, including the following steps:
[0162] Step 1: Input the mean m, variance σ, and the accuracy requirement for generating the sampling variance ∈;
[0163] Step 2: Determine the sampling units and the list of selected units, specifically:
[0164]
[0165] Where v represents a rational number approximating the variance σ according to the specified precision requirement, v1 is a positive integer, and v i (2≤i≤k) is 0 or 1 such that |v-σ|<∈; k represents the number of decimal places of v according to the binary expansion rules plus 1;
[0166] List L = [(v i ,i-1):v i ≠0,1≤i≤k] is the list of sampling units and selection units; specifically, for 1≤i≤k, if v i ≠0, then (v i v in i-1) i i is a sampling unit, and i-1 is a selection unit;
[0167] Step 3: Sample according to each group of sampling units and selection units in the sampling unit and selection unit list, and output the sampled unit s. i ,like Figure 8 As shown, the specific steps include the following:
[0168] Step 3.1: Input a set of sampling units and selection units (v) from the sampling unit and selection unit list L.i ,i-1);
[0169] Step 3.2: From the variance v i / 2 of the distribution sampling t i ;
[0170] Step 3.3: Select i-1 uniformly randomly distributed bits. If these i-1 bits form a specific i-1 constant (e.g., 2^i, 10^i), then... i-1 -1, that is, all i-1 bits are 1), then the output unit samples s i =t i Otherwise, the output unit samples s i =0.
[0171] Step 3.2 may include the following sub-steps:
[0172] Step 3.2.1: Obtain the expression Among them, u j (1≤j≤l) are all positive integers;
[0173] Step 3.2.2: For each u j (1≤j≤l), select two uniformly randomly distributed bits a0, a1, and calculate the integer w. j =a0-a1;
[0174] Step 3.2.3: Output sampling
[0175] As some preferred embodiments, step 3.2 may (partially) use parallel computing, and the order may (partially) be interchanged; the technical solution of the present invention is still applicable.
[0176] Step 4: Unit sampling s i Summing yields the sampled data t, i.e.:
[0177]
[0178] Step 5: Add the mean m to the sampled data t to obtain the sample s, that is:
[0179] s=t+m
[0180] Step 6: Output sample s.
[0181] Application example:
[0182] Let χ be the probability distribution corresponding to the sampling of the high-precision variance distribution of the above lattice-based cipher. The following is a lattice-based encryption scheme that uses this distribution. This lattice-based encryption scheme consists of three parts: key generation, encryption, and decryption.
[0183] The key generation phase includes the following steps:
[0184] Step G1: Uniformly select the remaining ring types A k×l matrix A.
[0185] Step G2: Perform l independent samplings according to the sampling method (or part of the steps) of the high-precision variance distribution of a lattice-based cipher described above. The upper l-dimensional vector s1.
[0186] Step G3: Perform k independent samplings according to any of the sampling methods (or some steps of the method) for high-precision variance distribution of lattice-based cryptography described in any of the above embodiments 1 to 6 to obtain a k-dimensional vector e1.
[0187] Step G4: Calculate b = As1 + e1, output public key pk = (A, e1), private key sk = s1.
[0188] Input plaintext pt and public key pk. The encryption phase includes the following steps:
[0189] Step H1: Perform k independent samplings according to the sampling method (or part of the steps) of the high-precision variance distribution of the lattice-based cipher described above to obtain a k-dimensional vector s2.
[0190] Step H2: Perform l independent samplings according to the sampling method (or part of the steps) of the high-precision variance distribution of a lattice-based cipher described above. The upper l-dimensional vector e2.
[0191] Step H3: Sample according to the sampling method (or part of the steps) of the high-precision variance distribution of the lattice-based cipher described above to obtain e3.
[0192] Step H4: Calculate c1 = A T s² + e², c² = b T s2+e3+Encode(pt), where Encode(pt) represents the encoding or placement method of the plaintext. Output ciphertext ct = (c1, c2).
[0193] Input the ciphertext ct and the private key sk. The decryption process includes the following steps:
[0194] Step L1: Calculate and output Decode(c2-s) T c1), where Decode is the decoding or inverse setting method corresponding to Encode.
[0195] The above-described lattice-based encryption scheme is an application example of this invention. Variants of this lattice-based encryption scheme and other cryptographic schemes can still use the sampling method proposed in this invention.
[0196] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A sampling method for high-precision variance distribution of lattice-based cryptography, characterized in that, This includes step A, which comprises the following sub-steps: Step A1: Generate sampling units using the central binomial distribution ; Step A2: Generate selection units through random uniform distribution ; Step A3: Based on the selected unit The value of the output sample Or sampling .
2. The sampling method for high-precision variance distribution of lattice-based cryptography according to claim 1, characterized in that, It also includes step B, which comprises the following sub-steps: Step B1: Run Steps A1 to A3 are used to obtain samples. ; Step B2: Sampling Summation yields the sample. ; Step B3: Output sampling .
3. A sampling method for high-precision variance distribution of lattice-based cryptography, characterized in that, This includes step C, which comprises the following sub-steps: Step C1: Generate sampling units using the central binomial distribution ; Step C2: Specify the expansion coefficient ; Step C3: Calculate and output the samples .
4. The sampling method for high-precision variance distribution of lattice-based cryptography according to claim 3, characterized in that, It also includes step D, which includes the following sub-steps: Step D1: Run Steps C1 through C3 are used to obtain samples. ; Step D2: Sampling Summation yields the sample. ; Step D3: Output sampling .
5. The sampling method for high-precision variance distribution of lattice-based cryptography according to claim 4, characterized in that, Step D also includes a parallel implementation for the following scenarios: Step X1: Generate through uniform distribution non-negative integer bits ,Right now The expansion coefficient and For multiple runs of the random bits in step C1 ; Step X2: Generate through uniform distribution non-negative integer bits ,Right now The expansion coefficient and For multiple runs of the random bits in step C1 ; Step X3: Calculate the sample Output sampling .
6. A sampling method for high-precision variance distribution of lattice-based cryptography, characterized in that, This includes step E, which comprises the following sub-steps: Step E1: Generate small variance samples using the method from step A. Alternatively, small variance samples can be generated through step B. ; Step E2: Generate large variance samples using the method from step C. Alternatively, large variance samples can be generated through step D. ; Step E3: Calculate the sum of small variance sampling and large variance sampling. Output ; Step A includes the following sub-steps: Step A1: Generate sampling units using the central binomial distribution ; Step A2: Generate selection units through random uniform distribution ; Step A3: Based on the selected unit The value of the output sample Or sampling ; Step B includes the following sub-steps: Step B1: Run Steps A1 to A3 are used to obtain samples. ; Step B2: Sampling Summation yields the sample. ; Step B3: Output sampling ; Step C includes the following sub-steps: Step C1: Generate sampling units using the central binomial distribution ; Step C2: Specify the expansion coefficient ; Step C3: Calculate and output the samples ; Step D includes the following sub-steps: Step D1: Run Steps C1 through C3 are used to obtain samples. ; Step D2: Sampling Summation yields the sample. ; Step D3: Output sampling .
7. A sampling method for high-precision variance distribution of lattice-based cryptography, characterized in that, This includes step F, which comprises the following sub-steps: Step F1: Generate unbiased samples : Unbiased sampling is generated through step A. ; or Unbiased sampling is generated through step B. ,or Unbiased sampling is generated through step C. ,or Unbiased sampling is generated through step D. ,or Unbiased sampling is generated through step E. ; Step F2: Specify the deviation Calculate sampling Output sampling ; Step A includes the following sub-steps: Step A1: Generate sampling units using the central binomial distribution ; Step A2: Generate selection units through random uniform distribution ; Step A3: Based on the selected unit The value of the output sample Or sampling ; Step B includes the following sub-steps: Step B1: Run Steps A1 to A3 are used to obtain samples. ; Step B2: Sampling Summation yields the sample. ; Step B3: Output sampling ; Step C includes the following sub-steps: Step C1: Generate sampling units using the central binomial distribution ; Step C2: Specify the expansion coefficient ; Step C3: Calculate and output the samples ; Step D includes the following sub-steps: Step D1: Run Steps C1 through C3 are used to obtain samples. ; Step D2: Sampling Summation yields the sample. ; Step D3: Output sampling ; Step E includes the following sub-steps: Step E1: Generate small variance samples using the method from step A. Alternatively, small variance samples can be generated through step B. ; Step E2: Generate large variance samples using the method from step C. Alternatively, large variance samples can be generated through step D. ; Step E3: Calculate the sum of small variance sampling and large variance sampling. Output .
8. A sampling method for high-precision variance distribution of lattice-based cryptography, characterized in that, The steps include the following: Step 1: Input the mean of the distribution ,variance And the accuracy requirements for generating the sampling variance. ; Step 2: Determine the sampling units and select the unit list; Step 3: Sample each group of sampling units and selection units in the sampling unit and selection unit lists respectively, and sample the output unit. ; Step 4: Cell Sampling Sum to obtain the sampled data ; Step 5: Sampling Data Add mean Get samples ; Step 6: Output sampling .
9. The sampling method for high-precision variance distribution of lattice-based cryptography according to claim 8, characterized in that, The method for determining the sampling unit and selection unit list in step 2 specifically includes: in, v This indicates that the specified precision requirements are met. Approximation variance rational numbers, is a positive integer, It is 0 or 1. , making ; k express v Add 1 to the number of decimal places in the binary expansion according to the binary rules; List This is a list of sampling units and selection units, representing the... ,if ,So middle It is a sampling unit. It is a selection unit.
10. The sampling method for high-precision variance distribution of lattice-based cryptography according to claim 9, characterized in that, Step 3 includes the following sub-steps: Step 3.1: Input the sampling unit and select the unit list. A set of sampling units and selection units ; Step 3.2: From the variance Distribution sampling ; Step 3.3: Select A uniformly randomly distributed set of bits, if this Each bit constitutes a specific If it is a constant, then the output unit samples... Otherwise, the output unit samples. .
11. The sampling method for high-precision variance distribution of lattice-based cryptography according to claim 10, characterized in that, Step 3.2 includes the following sub-steps: Step 3.2.1: Obtain the expression ,in, All are positive integers. ; Step 3.2.2: For each , Select two uniformly randomly distributed bits. Calculate integers ; Step 3.2.3: Output sampling = .
Citation Information
Patent Citations
Error sampling method for lattice public key password
CN109889321A
Post-quantum password authentication key exchange method based on modulo error learning
CN113094721A