Method and system for evaluating security of a cryptographic system based on principal ideal lattice problem

By pre-computing the principal ideal set S using Galois groups, the complexity of security assessment for principal ideal lattice cryptosystems is solved, enabling fast and accurate security assessment and quantifying the cryptosystem's resistance to attacks.

CN119966604BActive Publication Date: 2026-04-24SHANDONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHANDONG UNIV
Filing Date
2025-01-27
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing ideal lattice cryptosystems lack systematic security assessment methods. Existing methods are complex and computationally difficult, making it hard to assess the cryptosystem's resistance to attacks under different conditions.

Method used

A pre-computation method based on Galois groups is used to generate a set of principal ideals S for the number field K. The security of the cryptosystem is evaluated by determining whether the prime ideal I is in the set S or by calculating whether the prime ideal I is the principal ideal, and recording the time difference.

Benefits of technology

By pre-computing the Galois group, the distribution of the principal ideal in the number field K is quickly determined, which optimizes the evaluation process, reduces complexity, provides time difference-based evaluation metrics, quantifies anti-attack capabilities, and improves evaluation efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966604B_ABST
    Figure CN119966604B_ABST
Patent Text Reader

Abstract

The present disclosure relates to the technical field of network security, and provides a method and system for evaluating the security of a cryptographic system based on a principal ideal lattice problem, comprising the following steps: generating parameters of the cryptographic system to be evaluated, including a number field K corresponding to the cryptographic system and a selected prime ideal I, and recording the initial time; performing pre-computation based on the Galois group on the number field K of the obtained cryptographic system, determining the principal ideals in the number field K, and constructing a principal ideal set S; when it is determined that the prime ideal I corresponding to the cryptographic system is in the set S or the prime ideal I is a principal ideal through calculation, recording the current time, and obtaining the evaluation result of the cryptographic system based on the difference between the current time and the initial time. The present disclosure can effectively and quickly evaluate the security of the relevant lattice cryptographic scheme based on the method of judging whether a given prime ideal is a principal ideal through classical computation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of cybersecurity technology, specifically to a method and system for security assessment of cryptographic systems based on the subjective ideal lattice problem. Background Technology

[0002] The statements in this section are merely background information relating to this disclosure and do not necessarily constitute prior art.

[0003] In 1994, Shor proposed an algorithm based on quantum computers that could efficiently solve the problems of large integer factorization and discrete logarithms. The advent of quantum computers rendered traditional cryptographic systems based on large integer factorization and discrete logarithm problems (such as RSA and ECC) insecure. Therefore, researching cryptographic systems resistant to quantum computer attacks is of great significance. Currently, cryptographic systems resistant to quantum attacks are generally considered to fall into several categories, including lattice-based cryptography, code-based cryptography, and multivariate-based cryptography; these are also known as post-quantum cryptography.

[0004] Among these cryptosystems, lattice-based cryptosystems have attracted widespread attention due to their solid theoretical foundation and flexibility in adapting to various application scenarios. However, cryptographic schemes constructed using integer lattices face the problem of low efficiency. To improve efficiency, researchers have introduced difficult problems based on ideal lattices on algebraic integer rings. Cryptographic schemes based on ideal lattices on algebraic integer rings, by combining the algebraic structure of the algebraic integer rings and the complexity of ideal lattices with difficult computational problems (such as ISVP and Ring-LWE), have designed efficient, secure, and quantum-resistant cryptographic schemes. Cryptosystems based on ideal lattices on algebraic integer rings inherit the security reduction of integer lattice schemes while possessing potential efficiency advantages. Related research has demonstrated that ideal lattice problems on algebraic integer rings include the ideal shortest vector problem, the ideal nearest vector problem, and the learning error problem. These problems have a reduction from worst-case to average-case, which provides strong security guarantees for ideal lattice-based cryptographic schemes. In cryptographic schemes based on ideal lattices on algebraic integer rings, their security relies on a fundamental assumption: solving ideal lattice problems on algebraic integer rings is computationally very difficult. This means that if the ideal lattice problem becomes easy to solve efficiently, then cryptographic schemes designed based on this problem will lose their security.

[0005] The inventors discovered in their research that existing subjective ideal lattice cryptosystems still lack systematic security assessment methods, and accurately evaluating their security remains a challenge. Existing security assessment methods are complex and computationally difficult, lacking a systematic assessment method based on the subjective ideal lattice problem, making it difficult to assess the cryptosystem's resistance to attacks under different conditions. Summary of the Invention

[0006] To address the aforementioned issues, this disclosure proposes a method and system for security evaluation of cryptosystems based on the master ideal lattice problem. By applying the class field property of algebraic number fields, it provides a method based on classical computation to determine whether a given prime ideal is a master ideal, enabling efficient and rapid evaluation of the security of related lattice cryptographic schemes.

[0007] To achieve the above objectives, the present disclosure adopts the following technical solution:

[0008] One or more embodiments provide a method for security evaluation of cryptosystems based on the master ideal lattice problem, including the following steps:

[0009] For the cryptosystem to be evaluated, generate the parameters of the cryptosystem, including the number field K corresponding to the cryptosystem and the selected prime ideal I, and record the initial time.

[0010] Pre-computation based on Galois group is performed on the number field K of the obtained cryptosystem to determine the principal ideals in the number field K and construct the set of principal ideals S;

[0011] When it is determined that the prime ideal I corresponding to the cryptosystem is in the set S, or when it is determined by calculation that the prime ideal I is the principal ideal, the current time is recorded, and the evaluation result of the cryptosystem is obtained based on the difference between the current time and the initial time.

[0012] One or more embodiments provide a security evaluation system for cryptosystems based on the master ideal lattice problem, including:

[0013] The parameter extraction module is configured to generate parameters for the cryptosystem to be evaluated, including the number field K corresponding to the cryptosystem and the selected prime ideal I, and record the initial time.

[0014] The pre-computation module is configured to perform pre-computation based on the Galois group on the number field K of the obtained cryptosystem, determine the principal ideals in the number field K, and construct the set of principal ideals S;

[0015] The evaluation module is configured to record the current time when it is determined that the prime ideal I corresponding to the cryptosystem is in the set S or when it is determined by calculation that the prime ideal I is the principal ideal, and obtain the evaluation result of the cryptosystem based on the difference between the current time and the initial time.

[0016] An electronic device includes a memory and a processor, as well as computer instructions stored in the memory and running on the processor, which, when executed by the processor, perform the steps in the aforementioned method for security assessment of a cryptosystem based on the subjective ideal lattice problem.

[0017] A computer-readable storage medium for storing computer instructions, which, when executed by a processor, perform the steps in the aforementioned method for security assessment of a cryptosystem based on the subjective ideal lattice problem.

[0018] Compared with the prior art, the beneficial effects of this disclosure are as follows:

[0019] The security of the cryptosystem disclosed herein is assessed by analyzing the correlation between its parameters and the prime ideal lattice problem. Generating a number field K and prime ideal I reveals the fundamental structure of the cryptosystem. Through pre-computation of the Galois group, the distribution of prime ideals in the number field K can be quickly determined, and a set of prime ideals S can be constructed. Whether a system is a prime ideal is directly determined by checking if its prime ideals are in this set; this step optimizes the computationally complex operations in the assessment process. When determining if prime ideal I is a prime ideal, the computational cost is quantified by recording the time difference, thereby assessing the cryptosystem's resistance to attacks on the prime ideal lattice problem.

[0020] The advantages of this disclosure, as well as its additional advantages, will be described in detail in the following specific embodiments. Attached Figure Description

[0021] The accompanying drawings, which form part of this disclosure, are used to provide a further understanding of this disclosure. The illustrative embodiments of this disclosure and their descriptions are used to explain this disclosure and do not constitute a limitation thereof.

[0022] Figure 1 This is a flowchart of the cryptographic system security assessment method of Embodiment 1 of this disclosure;

[0023] Figure 2 This is a block diagram of the cryptographic system security assessment system of Embodiment 1 of this disclosure. Detailed Implementation

[0024] The present disclosure will be further described below with reference to the accompanying drawings and embodiments.

[0025] It should be noted that the following detailed descriptions are exemplary and intended to provide further illustration of this disclosure. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.

[0026] It should be noted that the terminology used herein is for descriptive purposes only and is not intended to limit the exemplary embodiments according to this disclosure. As used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise. Furthermore, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof. It should be noted that, without conflict, the various embodiments and features within those embodiments can be combined with each other. The embodiments will now be described in detail with reference to the accompanying drawings.

[0027] Example 1

[0028] In one or more of the technical solutions disclosed in the embodiments, such as Figure 1 As shown, a method for security assessment of cryptosystems based on the subjective ideal lattice problem includes the following steps:

[0029] Step 1: For the cryptosystem to be evaluated, generate the parameters of the cryptosystem, including the number field K corresponding to the cryptosystem and the selected prime ideal I, and record the initial time.

[0030] Step 2: Perform pre-computation based on Galois group on the number field K of the obtained cryptosystem to determine the principal ideal in the number field K and construct the set of principal ideals S;

[0031] Step 3: When it is determined that the prime ideal I corresponding to the cryptosystem is in the set S or when it is determined by calculation that the prime ideal I is the principal ideal, record the current time. Based on the difference between the current time and the initial time, obtain the evaluation result of the cryptosystem.

[0032] In the above method, the security of the cryptosystem is assessed by analyzing the correlation between its parameters and the principal ideal lattice problem. Generating the number field K and the prime ideal I reveals the fundamental structure of the cryptosystem. Through pre-computation of the Galois group, the distribution of the principal ideals in the number field K can be quickly determined, and the set of principal ideals S can be constructed. This step optimizes the computationally complex operations in the evaluation process. When determining that the prime ideal I is the principal ideal, the computational cost is quantified by recording the time difference, thereby assessing the cryptosystem's resistance to attacks on the principal ideal lattice problem.

[0033] Compared to existing methods, this implementation significantly reduces complexity and computational difficulty. Specifically: by pre-computing based on Galois groups, it can quickly screen and process principal ideals in the number field K, reducing redundant calculations and improving evaluation efficiency; it provides an evaluation index based on time difference, which can quantify the resistance to attacks under different conditions; and it constructs a systematic evaluation framework based on the principal ideal lattice problem, filling the gap in the application of existing methods to the principal ideal lattice problem.

[0034] In step 1, based on the cryptosystem to be evaluated, a number field K = Q(α) with an expansion degree of d is generated; this number field will serve as one of the basic parameters of the cryptosystem; and a prime ideal I is selected from the algebraic integer ring K for subsequent calculation and evaluation.

[0035] K = Q(α) indicates that the field Q is a rational number field constructed by adding element α;

[0036] The pre-calculation process in step 2 includes the following steps;

[0037] The pre-computation phase consists of several steps and aims to prepare for subsequent security assessments. The following is a detailed description of the specific steps.

[0038] Step 21: Calculate the Hilbert class field H of the number field K with respect to the Galois group of K, including the following steps:

[0039] In this step, the input is the number field K, and the output is the Galois group of H relative to K;

[0040] Step 21-1: Selecting Prime Ideal Factor Basis: Select prime ideal factor basis P1, P2, ..., P t , used to construct the Hilbert class field of the number field K;

[0041] The Hilbert class field H is an extension field containing the number field K. The Hilbert class field is the smallest extension field containing the number field K. Its ideal class group is trivial, that is, every ideal in the Hilbert class field H can be represented by an ideal in K.

[0042] Step 21-2: For the selected factor basis, generate the relational matrix M of the factor basis through algebraic operations:

[0043] Matrix M describes the relationships between factor bases;

[0044] Specifically, the relational matrix M of the factor basis is used to describe the relationship between these factor basis. The columns of the matrix represent each prime ideal in the factor basis, and each row represents the decomposition of a certain ideal in the number field in these factor basis. That is, each row of matrix M represents the representation of an ideal under the factor basis, i.e., the linear combination coefficient of the factor basis ideals.

[0045] The process of generating M is as follows: an ideal is expressed as a product or summation of ideals in a factor basis, and an ideal is obtained by algebraic operations, which can be used to obtain the representation of other ideals in the number field. These representations are then organized into a relational matrix M.

[0046] Step 21-3: Calculate the Smith Normal Form: Simplify the relation matrix M and calculate its Smith Normal Form, thereby obtaining the Galois group Z / q1×Z / q2×...×Z / q s ;

[0047] Among them, for Z / q i , 1≤i=1,2,3……s, where Z represents the modulus q i The ring of integers, that is, the set of integers ordered by q i The set after taking the modulo.

[0048] The Galois group is the group of all automorphisms in the extension of a number field. In number theory, given a number field K and its extension H, the Galois group describes all automorphisms of H with respect to K.

[0049] In this embodiment, by performing a Smith Normal Form transformation on matrix M, the relationship between the number field K and the Hilbert class field H is extracted, and the structure of the number field K can be effectively revealed.

[0050] Step 22: Based on the obtained Galois group, calculate the polynomial f i (x), such that the factor field K[x] / (f i (x) is the Galois group of the number field K, which is Z / q. i It includes the following steps:

[0051] In this step, the input is 1≤i≤s, representing the stage index for computation, and the parameter q... i =p r Where p is a prime number, representing different prime factors used in different computational stages; the output is a polynomial f. i (x), the factor field K[x] / (f) over the number field K i (x)) Galois group and Z / q i Related;

[0052] Step 22-1: Construct a set containing multiple roots of unity as the extended field k;

[0053] Step 22-2: Construct the class field of k using the Kummer method;

[0054] The Kummer method itself was originally proposed by Kummer to construct class fields of certain specific number fields, that is, to study the properties of algebraic number fields by extending the field, especially to study the ideal structure of the field.

[0055] Step 22-3: Standardize the obtained class domains to obtain standardized class domains, and calculate the polynomial f based on the class domains.i (x)=a m x m +a m-1 x m-1 +...+a0;

[0056] Specifically, the elements in the number field are standardized;

[0057] In this step, the extended field is obtained through normalization techniques. This normalization step is to make the elements of the extended field conform to certain specific criteria, which facilitates further analysis of the properties of its Galois group.

[0058] In this step, for polynomial f i (x) is a factor field K[x] / (f) over the number field K. i The structure of the Galois group is constructed on (x) and further studied using the Kummer method and normalization steps.

[0059] Step 23: Calculate polynomial f based on the polynomial and its derivative. i The discriminant Δ(f) of (x) i (x) includes the following steps:

[0060] Specifically, for 1≤i≤s, compute the polynomial f i (x)=a m x m +a m-1 x m-1 The discriminant Δ(f) of +...+a0 i (x));

[0061] Step 23.1: Calculate polynomial f i The derivative of (x);

[0062] f i ′(x)=a m-1 mx m-1 +a m-1 (m-1)x m-2 +...+a1.

[0063] Step 23.2: Based on the polynomial and its derivative, calculate the discriminant as follows:

[0064] Δ(f i (x))=Res(f i (x),f i ′(x)).

[0065] Here, Res(.) represents the result of two polynomials.

[0066] Step 24: Selecting the principal ideal: using the discriminant Δ(f) iThe ideal decomposition of (x) is used to select all relevant principal ideals in the number field K and construct the set of principal ideals S.

[0067] It is possible to compute the discriminant Δ(f) containing all divisible polynomials. i The ideals of (x) (1≤i≤s) are selected by the principal ideal criterion, and the principal ideals are constructed into a set S. That is, the set S contains the ideals that are consistent with the discriminant Δ(f). i (x) is related to and determined to be the primary ideal;

[0068] Specifically, the process of constructing set S includes the following steps:

[0069] Step 24.1: Initialize S as an empty set.

[0070] Step 24.2: For 1≤i≤s, change the polynomial discriminant Δ(f) i (x) is decomposed into the product of prime ideals;

[0071] Step 24.3: For each prime ideal that appears in the product, use the existing classical algorithm to determine whether it is a principal ideal. If it is, add it to the set S to obtain the final set of principal ideals S.

[0072] Step 3 is the online computation stage. Based on the pre-computed set of principal ideals S, it is determined whether the prime ideal I corresponding to the cryptosystem is a principal ideal. If the prime ideal I is in the set of principal ideals S, then the principal ideal of the cryptosystem is found.

[0073] During the online computation phase, pre-computation has been completed. Determining whether a given prime ideal I is a principal ideal involves the following steps:

[0074] Step 31: If the prime ideal I corresponding to the cryptosystem divides a certain polynomial discriminant Δ(f) i (x))(1≤i≤s), further determine whether I is in the pre-calculated principal ideal set S. If it is in the set S, return "yes", then determine that the prime ideal I is a principal ideal, record the current time, and end; otherwise, return "no", execute the next step, and determine whether the prime ideal I is a principal ideal by calculation;

[0075] Step 32: For 1≤i≤s, determine the polynomial f i (x) After performing the modulo operation on the prime ideal I, is it completely decomposed? If there is a polynomial that is not completely decomposed, then the prime ideal I is not the principal ideal, and return "No"; otherwise, the prime ideal I is the principal ideal, and return "Yes" to record the current time.

[0076] polynomial f i (x) Taking the modulo operation on the prime ideal I is: f i(x)(mod I), calculate polynomial f i (x) is the remainder after dividing by the ideal I.

[0077] In this step, the master ideal set is first generated based on the number field constructed by the cryptosystem. It is then directly determined whether the prime ideal I is in the set. Elements belonging to the set are the master ideals. The specific calculation process of master ideal judgment is only performed on prime ideals that do not belong to the set. This greatly reduces the amount of computation, avoids repeated calculations, and improves the efficiency and accuracy of cryptosystem evaluation.

[0078] In step 3, the evaluation result of the cryptographic system is obtained based on the difference between the current time and the initial time. Based on the cryptographic parameters generated by the cryptographic system, and using the above scheme to determine the subjective ideal lattice, the less time is used for the determination and the smaller the difference between the current time and the initial time, the lower the security of the cryptographic system's scheme parameters, and vice versa.

[0079] The method described above for determining whether a given prime ideal is a principal ideal, with pre-computation, utilizes existing efficient algorithms based on quantum computers. However, large-scale scalable quantum computers are not currently in use. In this embodiment, given cryptographic system parameters, the method can quickly determine the principal ideal lattice problem and rapidly ascertain the security strength of the cryptographic system parameters.

[0080] Example 2

[0081] Based on Embodiment 1, this embodiment provides a cryptographic system security evaluation system based on the subjective ideal lattice problem, such as... Figure 2 As shown, it includes:

[0082] The parameter extraction module is configured to generate parameters for the cryptosystem to be evaluated, including the number field K corresponding to the cryptosystem and the selected prime ideal I, and record the initial time.

[0083] The pre-computation module is configured to perform pre-computation based on the Galois group on the number field K of the obtained cryptosystem, determine the principal ideals in the number field K, and construct the set of principal ideals S;

[0084] The evaluation module is configured to record the current time when it is determined that the prime ideal I corresponding to the cryptosystem is in the set S or when it is determined by calculation that the prime ideal I is the principal ideal, and obtain the evaluation result of the cryptosystem based on the difference between the current time and the initial time.

[0085] It should be noted that each module in this embodiment corresponds one-to-one with each step in embodiment 1, and their specific implementation process is the same, so it will not be repeated here.

[0086] Example 3

[0087] This embodiment provides an electronic device, including a memory and a processor, as well as computer instructions stored in the memory and running on the processor. When the processor executes the computer instructions, it completes the steps in the cryptographic system security assessment method based on the subjective ideal lattice problem of Embodiment 1.

[0088] Example 4

[0089] This embodiment provides a computer-readable storage medium for storing computer instructions. When the computer instructions are executed by a processor, they complete the steps in the security evaluation method for a cryptographic system based on the subjective ideal lattice problem in Embodiment 1.

[0090] The above description is merely a preferred embodiment of this disclosure and is not intended to limit this disclosure. Various modifications and variations can be made to this disclosure by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

[0091] While the specific embodiments of this disclosure have been described above in conjunction with the accompanying drawings, this is not intended to limit the scope of protection of this disclosure. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art without creative effort based on the technical solutions of this disclosure are still within the scope of protection of this disclosure.

Claims

1. A method for security evaluation of cryptosystems based on the subjective ideal lattice problem, characterized in that, Includes the following steps: For the cryptosystem to be evaluated, generate the parameters of the cryptosystem, including the number field K corresponding to the cryptosystem and the selected prime ideal I, and record the initial time. Pre-computation based on Galois group is performed on the number field K of the obtained cryptosystem to determine the principal ideals in the number field K and construct the set of principal ideals S; When it is determined that the prime ideal I corresponding to the cryptosystem is in the set S or when it is determined by calculation that the prime ideal I is the principal ideal, the current time is recorded, and the evaluation result of the cryptosystem is obtained based on the difference between the current time and the initial time. The process for determining whether the prime ideal I corresponding to the cryptosystem is the principal ideal is as follows: Step 31: If the prime ideal I corresponding to the cryptosystem is divisible by a certain polynomial discriminant... ( Further determine whether I is in the pre-calculated set of principal ideals S. If it is in set S, then determine that the prime ideal I is a principal ideal; otherwise, proceed to the next step and determine whether the prime ideal I is a principal ideal through calculation. Step 32: For Determine the polynomial Ideal After performing the modulo operation, is the polynomial completely factored? If there is a polynomial that is not completely factored, then the prime ideal... Not the primary ideal; otherwise, the basic ideal. It is the ideal of the Lord.

2. The method for security evaluation of cryptosystems based on the subjective ideal lattice problem as described in claim 1, characterized in that, The pre-calculation process includes the following steps: Calculate the Hilbert class field H of the number field K relative to the Galois group of K; Based on the obtained Galois group, the polynomial is calculated. This makes the factor domain The Galois group relative to the number field K is ; Based on the obtained polynomial and its derivative, to calculate the polynomial discriminant ; By discriminant The ideal decomposition of K is used to select all relevant principal ideals in the number field K and construct the set of principal ideals S.

3. The method for security evaluation of cryptosystems based on the subjective ideal lattice problem as described in claim 2, characterized in that, Calculating the Hilbert class field H of a number field K with respect to the Galois group of K involves the following steps: Select the ideal factor basis; For the selected prime ideal factor basis, the relational matrix M of the factor basis is generated through algebraic operations: The relation matrix M is simplified and transformed, and its Smith canonical form is calculated, thus yielding the Galois group.

4. The method for security evaluation of cryptosystems based on the subjective ideal lattice problem as described in claim 2, characterized in that, The polynomial was calculated. The process includes the following steps: Construct a set containing multiple roots of unity as the extended field. ; The class field of k is constructed using the Kummer method; The obtained class domains are standardized to obtain standardized class domains, and polynomials are calculated based on these class domains. .

5. The method for security evaluation of cryptosystems based on the subjective ideal lattice problem as described in claim 2, characterized in that, The process of constructing the principal ideal set S includes the following steps: Initialize S as an empty set; right The polynomial discriminant Decompose into the product of prime ideals; For each prime ideal that appears in the product, we use an existing classical algorithm to determine whether it is a principal ideal. If it is, we add it to the set S to obtain the final set of principal ideals S.

6. The method for security evaluation of cryptosystems based on the subjective ideal lattice problem as described in claim 1, characterized in that: The smaller the difference between the current time and the initial time, the lower the security of the cryptographic system's scheme parameters, and vice versa.

7. A security evaluation system for cryptosystems based on the subjective ideal lattice problem, employing the security evaluation method for cryptosystems based on the subjective ideal lattice problem as described in any one of claims 1-6, characterized in that, include: The parameter extraction module is configured to generate parameters for the cryptosystem to be evaluated, including the number field K corresponding to the cryptosystem and the selected prime ideal I, and record the initial time. The pre-computation module is configured to perform pre-computation based on the Galois group on the number field K of the obtained cryptosystem, determine the principal ideals in the number field K, and construct the set of principal ideals S; The evaluation module is configured to record the current time when it is determined that the prime ideal I corresponding to the cryptosystem is in the set S or when it is determined by calculation that the prime ideal I is the principal ideal, and obtain the evaluation result of the cryptosystem based on the difference between the current time and the initial time.

8. An electronic device, characterized in that, It includes a memory and a processor, as well as computer instructions stored in the memory and running on the processor, which, when executed by the processor, perform the steps in the method for security assessment of a cryptosystem based on the subjective ideal lattice problem as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, Used to store computer instructions, which, when executed by a processor, complete the steps in the security assessment method for a cryptographic system based on the subjective ideal lattice problem as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Decoding method and system with precomputation

    CN115225206A

  • Password based key exchange from ring learning with errors

    US20180302218A1