Compact and reusable anti-quantum key packaging method
By adopting non-two power division ring and optimized algorithm technology in the key packaging scheme, the shortcomings of the RLWE key packaging scheme in terms of security strength and computing efficiency are solved, and a more efficient and secure key packaging method is achieved.
Patent Information
- Application Number
- CN202510002871.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-02
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-01-02
AI Technical Summary
The RLWE-based key packaging scheme has problems with security strength and computing efficiency, including security strength jump and low computing efficiency.
Using a non-two power split ring, a key encapsulation scheme based on RLWE problems is designed, and a reusable NTT algorithm and fast multiplication are used to optimize the public key encryption and key encapsulation process.
It effectively alleviates the problem of security intensity jump, improves computing performance, achieves 128, 192, 256 bit security strength, and significantly reduces the size of the first component of the public key and the computing overhead of the XOF sampler.
Smart Images

Figure CN119995850A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a compact and reusable quantum-resistant key encapsulation method. Background Art
[0002] Quantum mechanics and relativity together form the theoretical basis of modern physics. They are not only widely used in the field of physics, but also play an important role in chemistry, materials science, information science and other fields. As a computing device based on the principles of quantum mechanics, quantum computers use the characteristics of quantum superposition and quantum entanglement to demonstrate powerful parallel processing capabilities. Problems that require exponential time to solve on traditional computers can be solved in polynomial time on quantum computers. Their huge computing advantages bring huge application potential while also bringing potential security threats.
[0003] In order to maintain national information security, it is urgent to migrate traditional public key encryption schemes to quantum-resistant cryptographic schemes. Quantum-resistant cryptographic schemes are based on some difficult mathematical problems that are widely believed to be able to resist quantum analysis, mainly including: lattice, encoding, multivariate, homology, and hashing. At present, cryptographic schemes based on structural lattices have achieved a good balance between performance and security, but there are still some problems. Among various lattice problems, the average case LWE problem (Learning with Errors) can be reduced to the worst-case SVP problem. Therefore, quantum-resistant public key cryptography designed based on structured LWE problems has become the mainstream, including ring variants (Ring-LWE) and module variants (Module-LWE). Limited by the power-of-two dimension limitation, the key encapsulation scheme based on RLWE is difficult to achieve 192-bit security strength; the key encapsulation scheme based on MLWE has a large random band, which significantly reduces the computational efficiency of the sampler and polynomial multiplication. Summary of the invention
[0004] The present invention provides a key encapsulation scheme based on the RLWE problem using a non-two power-divided circular ring, which can alleviate the security strength jump problem existing in the conventional RLWE-based public key cryptography scheme, while maintaining the high computing performance of the conventional RLWE-based public key cryptography scheme. The present invention uses the Nussbaumer technique to implement a reusable NTT algorithm, uses the Karatsuba technique to implement fast multiplication on a small convolution ring, and designs a reusable NTT algorithm for a public ring structure, which has the advantages of simple implementation and low resource consumption in software and hardware implementation and optimization.
[0005] The present invention provides a compact and reusable quantum-resistant key encapsulation method, which is characterized by comprising: Based on the RLWE problem on a non-two-power-partitioned ring, a IND-CPA-secure public key encryption scheme is designed. The key encapsulation scheme is enhanced to be IND-CCA secure under the random oracle model using Fujisaki-Okamoto transformation.
[0006] The IND-CPA secure public key encryption scheme includes: Step 1, based on the RLWE problem on a non-two power-divided circular ring, design an IND-CPA secure public key encryption scheme, generate public parameters, public keys and private keys according to security parameters, and publish the public parameters and the public keys; Step 2, based on the obtained public parameters and public key, encrypt the plaintext message into ciphertext using a secret random band; Step 3: decrypt the ciphertext using the private key to obtain the corresponding plaintext.
[0007] Wherein, the step 1 further comprises: From the collection Select a random seed from and , then through the Performing scalable output functions After operation Converted ; Respectively and , After connection, through the pseudo-random function And the corresponding sampler gets and , and then in the loop Calculation ; right Compression and packaging Operation ,Will As a public key , As a private key ; in, and They are all random seeds. , Represents a constant value used to obtain an independent random oracle, and FastMul represents fast polynomial multiplication.
[0008] Wherein, the step 2 further comprises: Through the public key through and Operation , for the public key Unpack and Unzip and get ; Randomly and , , After connecting, pass the pseudo-random function And the corresponding sampler gets , , , in the ring Calculation and right conduct Compress and package ,right To truncate, Compress and package , ciphertext ; in, Represents the error correction code encoding algorithm.
[0009] Wherein, the step 3 further comprises: Enter private key and ciphertext ,right Unpack and Unzip and get ,right Unpack and Unzip and get ; In the ring Calculation ,use right Subtract the above calculation result and decode to get the message ; in, represents the coefficient truncation technique, Represents the error correction code decoding algorithm.
[0010] The non-two power-divided ring It is a fast polynomial multiplication with compact parameter set and reusable; the underlying algebraic structure of its cryptographic algorithm is in, is a fixed positive integer, It is a parameter that controls the security level of the cryptographic scheme. The compact parameter set includes the dimension and modulus And meet the conditions .
[0011] The reusable fast polynomial multiplication uses the Nussbaumer technique to achieve the following ring isomorphism: in, is a Residue system of order-divided circular integer ring, parameter Satisfy the conditions .
[0012] The fast polynomial multiplication includes the following steps: multiplexing the NTT algorithm through multi-layer ring isomorphism iteration; the first ring isomorphism uses a method similar to the Cooley-Tukey butterfly; the subsequent two rings are isomorphic using a mixed-radix NTT algorithm.
[0013] The fast multiplication on the ring further includes: embedding the ring coefficients into the polynomial ring and homomorphically mapping to the target ring; according to the Chinese remainder theorem, there exists the following ring isomorphism: .
[0014] Among them, the polynomial multiplication is calculated in the two polynomial rings on the right side of the above isomorphic formula. The former only needs three modular multiplication operations, while the latter depends on The value requires 0 to 4 modular multiplication operations; use the Karatsuba algorithm to calculate the overflow term of the polynomial product and combine it with the above two polynomial products to obtain the ring The product result on .
[0015] The present invention provides a compact and reusable quantum-resistant key encapsulation method, which innovatively adopts The non-two-order power-divided circular ring effectively alleviates the security jump problem in the conventional RLWE-based key encapsulation scheme. The selection of parameter sets is more flexible, and it has more compact parameter selection and scheme examples.
[0016] Specifically, compared with the MLWE-based cryptographic scheme, the cryptographic scheme designed in the present invention has the first component of the public key as only , which significantly reduces the cost of XOF and has extremely high computational efficiency. The present invention combines the Nussbaumer technique, the NTT algorithm and the Karastuba technique to propose a fast polynomial multiplication with code reuse characteristics. Isomorphic mappings are common medium-sized subcircular rings on dimensional polynomial ring, its NTT module can be fully reused by different parameter sets, which is very beneficial to the software and hardware implementation and optimization of the algorithm.
[0017] Specifically, the key encapsulation method proposed in the present invention provides three sets of compact parameter sets, which respectively achieve 128, 192, and 256-bit security strengths. The underlying sub-circular rings instantiated by these parameter sets share a common ring structure in the sense of isomorphism. The present invention designs a reusable NTT algorithm for the common ring structure, which has the advantages of simple implementation and low resource consumption in software and hardware implementation and optimization. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0019] Figure 1 A design framework diagram of a public key cryptographic scheme in the key encapsulation method provided by the present invention; Figure 2 A workflow diagram of the public key encryption scheme in the key encapsulation method provided by the present invention; Figure 3 A flowchart of the key encapsulation scheme in the key encapsulation method provided by the present invention; Figure 4 A module structure diagram of the public key encryption scheme in the key encapsulation method provided by the present invention; Figure 5 A schematic diagram of fast polynomial multiplication in the key encapsulation method provided by the present invention. DETAILED DESCRIPTION
[0020] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0021] In order to clearly explain the contents of each embodiment of the present invention, the present invention explains the conceptual technical terms appearing therein, specifically: Public-key encryption (PKE) is a public key cipher for data encryption; Key encapsulation mechanism (KEM) is a type of public key cipher for key distribution; Data encapsulation mechanism (DEM) is a type of symmetric cipher for data encryption. Indistinguishability under chosen plaintext attack (IND-CPA) is a security property of the public key encryption scheme, and the adversary in the model only has the ability to passively monitor the channel content; Indistinguishability under chosen ciphertext attack (IND-CCA) is a stronger security property of the public key encryption scheme, and the adversary in the model has the ability to actively tamper with the channel content. Fujisaki-Okamoto conversion is a general technology for enhancing the IND-CPA-secure public key encryption scheme to an IND-CCA-secure public key encryption scheme. The KEM-DEM hybrid encryption paradigm is a method for combining the existing KEM scheme and DEM scheme into a PKE scheme.
[0022] Key Encapsulation Mechanism (KEM) is a modern encryption technology that encapsulates a symmetric key in a ciphertext through an asymmetric encryption algorithm to ensure the secure transmission of the key. In the key encapsulation mechanism, the initiator runs an encapsulation algorithm to generate a session key and the corresponding ciphertext, and encapsulates the session key and sends it to the receiver; the receiver runs the decapsulation algorithm to obtain the same session key as the initiator. This mechanism combines the advantages of symmetric encryption and asymmetric encryption, which not only ensures the encryption speed but also realizes the secure distribution of keys. The KEM mechanism introduces randomness in the process of session key distribution, so that each generated key is unique, which enhances the security of the system. In addition, the KEM key encapsulation mechanism can adopt a lattice-based cryptographic system, which has the ability to resist quantum computing attacks.
[0023] Traditional key encapsulation technology has significant defects in modern network environments. First, the key distribution process is complicated, especially in multi-party communication scenarios, key management becomes extremely cumbersome. Second, traditional technology has limited performance when processing large-scale data transmission and is difficult to adapt to the needs of modern high-speed networks. At the same time, with the improvement of computing power, especially quantum computing power, the security of traditional public key cryptographic algorithms based on large number decomposition and discrete logarithm problems is seriously challenged.
[0024] In general, the present invention proposes a key encapsulation method for the RLWE problem based on a non-two power-divided circular ring, which effectively alleviates the security strength jump problem existing in the traditional RLWE public key cryptographic scheme, and maintains a high computing performance. The method of the present invention generates and publishes public parameters and public keys by designing an IND-CPA secure public key encryption scheme, encrypts plaintext messages into ciphertexts using a secret random band, and decrypts the ciphertexts using a private key to obtain plaintexts. Compared with the scheme based on the MLWE problem, the present invention has a smaller first component of the public key, and the computational overhead based on the XOF sampler is significantly reduced. In addition, the present invention also provides three sets of compact parameter sets, which respectively reach 128, 192, and 256-bit security strengths, thereby enhancing the security of the system.
[0025] Figures 1 to 5 They are respectively a design framework diagram of the public key cryptographic scheme in the key encapsulation method provided by the present invention, a workflow diagram of the public key encryption scheme, a workflow diagram of the key encapsulation scheme, a module structure diagram of the public key encryption scheme, and a schematic diagram of fast polynomial multiplication. Figures 1 to 5 As shown, the present invention provides a compact and reusable quantum-resistant key encapsulation method, including: designing an IND-CPA-secure public key encryption scheme based on the RLWE problem on a non-two power-divided circular ring; utilizing Fujisaki-Okamoto transformation to enhance the key encapsulation scheme to IND-CCA security under a random oracle model.
[0026] The Fujisaki-Okamoto transformation is a cryptographic technique used to convert a public key encryption scheme that is only resistant to chosen ciphertext attacks (IND-CPA) into a public key encryption scheme that is resistant to chosen ciphertext attacks and chosen key attacks (IND-CCA). Through the Fujisaki-Okamoto transformation, an encryption scheme that originally only has IND-CPA security can be upgraded to IND-CCA security, which means that the encryption scheme can resist more complex attacks, including those in which the attacker may try to obtain the encryption scheme key.
[0027] The random oracle model is an idealized model used in cryptography to analyze and design cryptographic systems. In this model, all hash functions and random number generators are assumed to be ideal random functions, that is, the hash values or random numbers they output are completely random and unpredictable.
[0028] In the random oracle model, the analysis of the security of cryptographic schemes can be simplified because the hash function can be assumed to be perfect, which makes security proofs more direct and clear. And the security of many cryptographic systems can be strengthened because attackers cannot exploit any non-randomness of the hash function to launch attacks.
[0029] The key encapsulation method includes: step 1, using security parameters, based on the RLWE problem on a non-two power-divided circular ring, designing an IND-CPA secure public key encryption scheme, generating public parameters, public keys and private keys, and publishing the public parameters and the public keys; step 2, based on the obtained public parameters and public keys, using a secret random band to encrypt the plaintext message into ciphertext; step 3, decrypting the ciphertext using the private key to obtain the corresponding plaintext.
[0030] Among them, the RLWE problem based on non-two-power-divided circular rings refers to the use of non-two-power-divided circular rings (i.e., the dimension of the circular ring is not a power of 2) as a basis to construct the RLWE (Ring-Learning with Errors) problem in cryptography, especially in the field of lattice cryptography. The RLWE problem is a difficult mathematical problem that is considered difficult to solve even in the face of quantum computers. It has mature security analysis and is therefore widely used in the design of quantum-resistant cryptographic algorithms.
[0031] In a public key encryption scheme, "public parameters" usually refer to information known to all parties, which is used to initialize the algorithm, such as a specific mathematical problem instance or system parameters. The "public key" is the key used in the encryption process, which can be made public to anyone and is used to encrypt information, ensuring that only the recipient with the corresponding "private key" can decrypt it. The "private key" is the key used to decrypt the information, which must be kept secret and only known to the intended recipient.
[0032] A secret random band usually refers to a random number or random value used in the encryption process, which is kept secret and unique for each encryption. The random value is used in conjunction with the public key in the encryption process, ensuring that even if an attacker has the public key, the plaintext cannot be predicted or decrypted because the random value used for encryption is unknown. This design increases the security of encryption, making the encryption scheme remain secure even in the face of a chosen ciphertext attack (i.e., an attacker can obtain part of the ciphertext and the corresponding plaintext).
[0033] The step 1 further comprises: Select a random seed from and , then through Performing scalable output functions After operation Converted ; respectively and , After connection, through the pseudo-random function And the corresponding sampler gets and , and then in the loop Calculation right Compression and packaging Operation ,Will As a public key , As a private key ; in, and They are all random seeds. , Represents a constant value used to obtain an independent random oracle. Represents fast polynomial multiplication.
[0034] Among them, the For randomly selected Generates a scalable random output, which is then passed through Transformation, to generate the polynomial in the public key Provides the necessary randomness to ensure public key security.
[0035] Among them, the The function here is to convert The output is converted to a suitable The value to be operated on , this conversion ensures a smooth transition from random seeds to ring elements.
[0036] Among them, the from Generate secret polynomial and error terms , these values are directly related to the generation of public keys. Provides the necessary pseudo-randomness to keep the encryption scheme secure and resistant to various cryptanalytic attacks.
[0037] Among them, the To calculate polynomials and the secret polynomial The product of , get the polynomial in the public key This fast multiplication operation improves the efficiency of the algorithm while maintaining the security of the encryption scheme.
[0038] Among them, for the polynomial Compress and pack to generate compact public keys This operation not only reduces the size of the public key, making it easier to store and transmit, but also ensures the practicality of the public key in various application scenarios.
[0039] The step 2 further comprises: Extensible output function and Operation , for the public key Unpack and Unzip and get ; Randomly bring With constant value , , After connecting, pass the pseudo-random function And the corresponding sampler gets , , , in the ring Calculation and ;right conduct Compress and package ,right To truncate, Compress and package , ciphertext ; in, Represents the error correction code encoding algorithm.
[0040] Wherein, the random band With different constant values , , The purpose of the connection is to generate multiple different random seeds, which are then passed through and samplers generate different random polynomials , , , in order to increase the randomness and diversity of the encryption process, so that the ciphertext generated by each encryption is unique, thus enhancing the security of the encryption scheme.
[0041] The sampler is used to The random polynomial generated by the random seed is extracted appropriately. The use of the sampler ensures that the generated random polynomial meets the ring The mathematical structure requirements on the encryption scheme are to maintain the security and correctness of the encryption scheme.
[0042] Among them, in the ring Calculation and The purpose is to use the algebraic structure of the ring to perform encryption operations; this method of calculation not only uses the mathematical properties of the ring to enhance security, but also The fast polynomial multiplication improves the efficiency of the encryption process.
[0043] Among them, and Compression and packaging are performed to convert the encryption result into a format suitable for transmission and storage. The compression operation reduces the size of the data, while the packaging operation ensures the integrity and availability of the data. The truncation operation may be to remove unnecessary information and further reduce the size of the ciphertext, making the ciphertext more compact and easier to transmit in the network.
[0044] The step 3 further includes: inputting a private key and ciphertext ,right Unpack and Unzip and get ,right Unpack and Unzip and get ; In the ring Calculation ,use right Subtract the above calculation result and decode to get the message ; Among them, the represents the coefficient truncation technique, Represents the error correction code decoding algorithm.
[0045] In the decryption process, and Unpacking and decompression are performed to restore the polynomial used in the encryption process. and This step is fundamental to the decryption process, as it allows the decryption algorithm to access the polynomial structure used during encryption and recover the original message.
[0046] Wherein, the truncation operation For the ring The purpose is to reduce the length of the coefficient vector to make it consistent with the scale of the original message, thereby reducing the ciphertext size.
[0047] Among them, the Operation is used from minus the truncated As a result, the original message is restored In the RLWE scheme, since error terms are introduced in the encryption process, a decoding algorithm is necessary, which can tolerate a certain degree of error and recover the original correct information from the noisy data.
[0048] Wherein, the non-two power-divided circular ring It is a fast polynomial multiplication with compact parameter set and reusable; the underlying algebraic structure of its cryptographic algorithm is Among them, the is a fixed positive integer, It is a parameter that controls the security level of the cryptographic scheme.
[0049] The non-two power-divided ring The design of the algorithm uses a compact parameter set and reusable fast polynomial multiplication. A compact parameter set means that the values of each parameter are smaller, which helps to reduce the complexity of the algorithm and improve efficiency. In cryptography, the design of the parameter set is crucial to the performance and security of the algorithm. A compact parameter set can reduce the burden of storage and calculation, making the algorithm more suitable for resource-constrained environments, such as mobile devices or embedded systems.
[0050] The reusable fast polynomial multiplication means that the algorithm can be efficiently reused in different contexts and operations, without the need to implement specialized polynomial multiplication for different modules or cryptographic instances, which is conducive to the modular implementation of the algorithm and can significantly improve the resource utilization and overall performance of the algorithm. In addition, fast polynomial multiplication also helps to reduce power consumption and computational latency, which is particularly important for application scenarios that require fast response.
[0051] Specifically, the cyclotomic polynomial of the ring is The order It is shaped like For an integer of ,definition is the module of the ring of circular integers Remaining system.
[0052] The ring Sampling algorithm on , the steps are: the selected parameters Make is an even number, defined , first in the expansion ring For each coefficient according to the parameter The central binomial distribution of is sampled independently, and the sampling results are recorded as . Then calculate and output , it is a ring , and its canonical embedding is This ensures that the RLWE instance satisfies the reduction theorem.
[0053] The compact parameter set includes the dimensions and modulus And meet the conditions .
[0054] Preferably, dimension Fixed selection , modulus Fixed selection , satisfying the condition . For the three security strengths, set , and the corresponding ideal lattice dimensions are Based on the asymmetric RLWE assumption, the secret and noise are taken from central binomial distributions with different parameters. Relatively small, the distribution parameter The value is only or , so that its sampler only consumes less entropy. In addition, according to the derivation formula of decryption failure rate, the appropriate compression parameters are selected , which can significantly reduce the size of public keys and ciphertexts.
[0055] The reusable fast polynomial multiplication uses the Nussbaumer technique to achieve the following ring isomorphism: in, is a Residue system of order-divided circular integer ring, parameter Satisfy the conditions .
[0056] The parameters selected Satisfy the conditions ,therefore Existence Second primitive unit root According to the Chinese remainder theorem, using factorization ,as well as and , there are the following ring isomorphisms, The fast polynomial multiplication includes the following steps: realizing the reuse of the NTT algorithm through multi-layer ring isomorphism iteration; wherein, the first ring isomorphism uses a method similar to the Cooley-Tukey butterfly; the subsequent two rings are isomorphic and use the mixed-radix NTT algorithm.
[0057] Through the iteration of multiple layers of ring isomorphism, the ring isomorphism and its inverse mapping only require quasi-linear computational complexity. is a fixed integer, so the NTT algorithm can be fully reused by algorithm instances of different security levels. For software and hardware implementation and optimization, the code reuse feature makes the public key cryptographic scheme designed by the present invention more advantageous; especially for FPGA or ASIC design, this feature can significantly reduce the number of logic gates and area size.
[0058] The fast multiplication on the ring further includes: embedding the ring coefficients into the polynomial ring and homomorphically mapping to the target ring; according to the Chinese remainder theorem, there exists the following ring isomorphism, Specifically, combining the above four ring isomorphisms, we get , that is, ring Addition and multiplication on are equivalent to Ring Parallel addition and multiplication on . , the present invention uses basic textbook multiplication, requiring only four non-scalar multiplications and one scalar multiplication. The present invention uses the Karatsuba technique to achieve the ring Fast multiplication on: First, the ring The coefficients are embedded in the polynomial ring Then homomorphically map to .because and are relatively prime. According to the Chinese remainder theorem, there are the following ring isomorphisms: .
[0059] In the ring To calculate polynomial multiplication in , only three modular multiplication operations are required. Compute polynomial multiplication in: If ,So , so only one modular multiplication operation is required; if , then yes , using textbook multiplication requires four modular multiplication operations.
[0060] The polynomial ring The polynomial multiplication on is as follows: calculate the polynomial multiplication in the two polynomial rings on the right side of the above isomorphic formula; use the Karatsuba algorithm to calculate the overflow term of the polynomial product, and combine it with the two polynomial products to obtain the product result of the polynomial ring.
[0061] Specifically, given two polynomials and , using the above ring embedding, ring homomorphism and ring isomorphism, we can calculate To restore it to , and then recover to , the overflow term still needs to be calculated The present invention first calculates , and then calculate it with The product of: , only one modular multiplication operation is required; for , the present invention uses the Karatsuba algorithm, which requires three modular multiplication operations. Finally, for The above algorithm takes 5 modular multiplication operations. The above algorithm takes 10 modular multiplication operations.
[0062] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.
[0063] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0064] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A compact and reusable quantum-resistant key encapsulation method, characterized in that: include: Based on the RLWE problem on a non-two-power-partitioned ring, a IND-CPA-secure public key encryption scheme is designed. The key encapsulation scheme is enhanced to be IND-CCA secure under the random oracle model using Fujisaki-Okamoto transformation.
2. The method according to claim 1, characterized in that The IND-CPA secure public key encryption scheme includes: Step 1, generating public parameters, a public key and a private key according to security parameters, and publishing the public parameters and the public key; Step 2, based on the obtained public parameters and public key, encrypt the plaintext message into ciphertext using a secret random band; Step 3: decrypt the ciphertext using the private key to obtain the corresponding plaintext.
3. The method according to claim 2, characterized in that The step 1 further comprises: From the collection Select a random seed from and , then through the Performing scalable output functions After operation Converted ; Respectively and , After connection, through the pseudo-random function And the corresponding sampler gets and , and then in the loop Calculation ; right Compression and packaging Operation ,Will As a public key , As a private key ; in, and They are all random seeds. , Represents a constant value used to obtain an independent random oracle, and FastMul represents fast polynomial multiplication.
4. The method according to claim 2, characterized in that: The step 2 further comprises: Through the public key Extensible output function and numerical conversion functions Operation , for the public key Unpack and Unzip and get ; Randomly With constant value , , After connecting, pass the pseudo-random function And the corresponding sampler gets , , , in the ring Calculation and ; right conduct Compress and package ,right To truncate, Compress and package , ciphertext ; in, Represents the error correction code encoding algorithm.
5. The method according to claim 2, characterized in that: The step 3 further comprises: Enter private key and ciphertext ,right Unpack and Unzip and get ,right Unpack and Unzip and get ; In the ring Calculation ,use right Subtract the above calculation result and decode to get the message ; in, represents the coefficient truncation technique, Represents the error correction code decoding algorithm.
6. The method according to claim 3, characterized in that: The non-two power-divided ring Fast polynomial multiplication with compact parameter set and reusable; The underlying algebraic structure of its cryptographic algorithm is in, is a fixed positive integer, It is a parameter that controls the security level of the cryptographic scheme; The compact parameter set includes the dimensions and modulus And meet the conditions .
7. The method according to claim 6, characterized in that include: The reusable fast polynomial multiplication described above uses the Nussbaumer technique to achieve the following ring isomorphism in, is a Residue system of order-divided circular integer ring, parameter Satisfy the conditions .
8. The method according to claim 6, characterized in that The fast polynomial multiplication method comprises the following steps: Through multi-layer ring isomorphism iteration, the reuse of NTT algorithm is realized; Among them, the first ring isomorphism uses a method similar to the Cooley-Tukey butterfly; The subsequent two rings are isomorphic and use the mixed-radix NTT algorithm.
9. The method according to claim 7, characterized in that: The fast multiplication on the ring further includes: The ring Embedding into a polynomial ring Then map it to the target ring ; According to the Chinese Remainder Theorem (CRT), there are the following ring isomorphisms: 。 10. The method according to claim 9, characterized in that The polynomial ring is used to perform the following processing: In the two polynomial rings on the right side of the above isomorphic formula, the former only needs three modular multiplication operations, while the latter depends on The value requires 0 to 4 modular multiplication operations; Using the Karatsuba algorithm, calculate the overflow term of the polynomial product and combine it with the two polynomial products above to obtain the ring The product result on .
Citation Information
Patent Citations
Secret key packaging, encrypting and decrypting method based on NTRU grid
CN116318695A
IND-CPA safe anti-quantum key packaging method and system
CN116684069A
Anti-quantum key packaging method and system capable of being used for TLS protocol
CN116684070A
Executing a cryptographic operation
US20200313886A1
Cited By
Lightweight hybrid encryption transmission method and system capable of resisting quantum attack
CN120675692A