Quantum decryption method and device after cooperation of two parties

By co-generating key pairs between the terminal device and the cryptographic machine and adopting distributed decryption computing methods, the problem of insufficient security in the quantum computing environment in the prior art is solved, and an efficient and reliable cryptographic security solution is achieved.

CN120074816AInactive Publication Date: 2025-05-30玉溪市电子政务内网信息技术中心 +1

Patent Information

Application Number
CN202510234448.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-30
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing digital signature and encryption and decryption technologies cannot guarantee security in the quantum computing environment and are difficult to resist quantum computing attacks. The traditional private key storage method has security risks and user experience problems.

Method used

A two-party collaborative post-quantum decryption method is proposed. By co-generating key pairs between the terminal device and the crypto machine, and adopting distributed decryption calculation method, the risk of centralized storage of private keys is avoided, security and user experience are improved, and quantum attack resistance is achieved.

Benefits of technology

It greatly improves the security of keys, reduces user usage costs, optimizes user experience, and has the ability to resist quantum attacks, which is suitable for password security needs of smart terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074816A_ABST
    Figure CN120074816A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of quantum signature, in particular to a two-party collaborative post-quantum decryption method, which comprises the following steps of: generating a collaborative Aigis-sig signature secret key part; a public key and respective private keys are calculated through interaction of the client and the server, and encryption is carried out through the public key to generate a ciphertext; carrying out two-party collaborative decryption calculation; plaintext recovery is completed through cooperation of the client and the server. According to the invention, a two-party cooperative decryption mode is adopted, that is, the server-side cipher machine firstly performs partial decryption, and then the client-side completes the final decryption process. The decryption process is distributed on two different calculation subjects, so that even if an attacker steals data of one of the calculation subjects, the plaintext cannot be directly recovered, and the anti-attack capability is effectively enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of quantum signature technology, and relates to a two-party collaborative post-quantum decryption method and device. Background Art

[0002] With the popularization of intelligent terminals and the rapid development of network technology, emerging services such as mobile payment and mobile office have gradually emerged. When users perform important operations on their smart phones, a large amount of sensitive information is involved. In order to ensure data security and privacy protection, cryptographic technology has become an indispensable means. Currently, digital signature and encryption / decryption technologies mainly rely on terminal devices to store and manage private keys, but this method has many security risks.

[0003] Traditional software implementation solutions usually store the private key of digital signature in the memory of intelligent terminals. This method is vulnerable to malicious attacks such as memory reading, malware injection, side-channel analysis, etc., resulting in the leakage of private keys and seriously affecting data security. In addition, although the private key can be stored in external devices such as hardware security modules (HSMs) or USB Keys to improve key security, these solutions have problems such as high cost, cumbersome operation, and poor user experience, and are not suitable for large-scale promotion.

[0004] In order to improve the security of keys while taking into account user experience and cost control, a solution based on threshold decryption has emerged in recent years. The core idea of this solution is to split the user's decryption private key into two parts, one part is stored in the user's terminal device, and the other part is stored in a cryptographic machine (HSM). The two are independently generated and the final decryption key is restored through interactive calculation during the decryption process, thus realizing distributed decryption. This method not only avoids the risk of centralized storage of private keys and improves security, but also avoids dependence on additional hardware devices and improves user experience.

[0005] In the prior art, Chinese Patent CN201410437599.5, "Signature and Decryption Method and System Based on SM2 Algorithm Suitable for Cloud Computing", proposes a signature and decryption scheme based on the SM2 algorithm. This scheme is applicable to the traditional public key cryptosystem in the cloud computing environment and can improve the security of cloud data. However, this scheme depends on the SM2 algorithm, which belongs to the traditional ECC elliptic curve cryptosystem and cannot guarantee security in the quantum computing environment and is difficult to resist quantum computing attacks. With the development of quantum computing technology, existing SM2 and traditional public key cryptosystems are facing security threats, and there is an urgent need for new cryptographic solutions that can resist quantum attacks. Summary of the Invention

[0006] In view of the above problems, the present invention proposes a two-party collaborative post-quantum decryption method and device. By collaboratively generating a key pair between a terminal device and a cryptographic machine and adopting a distributed decryption calculation method, it can not only enhance the key security, but also reduce the user's usage cost, optimize the user experience, and at the same time have the ability to resist quantum attacks, providing an efficient and reliable solution for the password security of intelligent terminals.

[0007] The present invention is realized through the following technical solutions: A two-party collaborative post-quantum decryption method includes the following steps: S1. Generate the collaborative Aigis-sig signature key part; S2. Calculate the public key and respective private keys through the interaction between the client and the server, and generate a ciphertext through the public key; S3. Perform two-party collaborative decryption calculation; S4. Complete the plaintext recovery through the collaboration between the client and the server.

[0008] Furthermore, the generation process of the signature key includes the following sub-steps: A. The client randomly generates a matrix and calculates the hash value , and sends the hash value to the server cryptographic machine; B. The server cryptographic machine randomly generates a matrix and calculates the hash value , and sends the hash value to the client; C. After the client receives the hash value , it sends the matrix to the server cryptographic machine. After the server cryptographic machine receives the hash value, it sends the matrix to the client; D. The client performs hash value verification. If the hash values are not equal, it terminates. Otherwise, it calculates the matrix to generate the public matrix ; E. The client generates the sub-private keys , , calculates the intermediate value through the sub-private key , and calculates the hash value based on the intermediate value and sends it to the server cryptographic machine; F. The server cryptographic machine generates the sub-private keys, , calculates the intermediate value through the sub-private key , and calculates the hash value based on the intermediate value and send it to the client; G. The client performs a hash value verification. If the hash values are not equal, the process terminates. Otherwise, based on the intermediate value and calculate the public key vector ; H. Based on the public key vector, the client's sub-private key, the server's cryptographic machine sub-private key, and the matrix calculate to obtain the public key, the client's private key, and the server's cryptographic machine sub-private key.

[0009] Furthermore, the public key consists of the matrix and the public key vector , where the public key vector .

[0010] Furthermore, the collaborative decryption calculation includes the following sub-steps: I. The server's cryptographic machine receives the ciphertext, performs partial decoding on the ciphertext by executing ByteDecode decoding to obtain the decoded ciphertext; J. The server's cryptographic machine decrypts the ciphertext using the server's cryptographic machine sub-private key to obtain the partially decrypted ciphertext. The server's cryptographic machine sends the ciphertext and the partially decrypted ciphertext to the client; K. After receiving the ciphertext and the partially decrypted ciphertext, the client performs partial decoding on the ciphertext by executing ByteDecode decoding to obtain the decoded ciphertext; L. The client collaboratively decrypts the ciphertext using the client's sub-private key to recover the plaintext message; Furthermore, the client and the server's cryptographic machine respectively hold sub-private keys, and the server's cryptographic machine first calculates the partial decryption result, and the client completes the final plaintext calculation.

[0011] Furthermore, the construction method of the public key matrix is , where it is obtained by adding the matrices respectively generated by the client and the server's cryptographic machine.

[0012] Furthermore, the calculation formula of the intermediate value is ; The calculation formula of the intermediate value is .

[0013] This solution proposes a collaborative decryption device, including: A client module, used to generate the matrix , calculate the hash value, and generate the sub-private key ; , calculate the intermediate value , and based on the intermediate value and the intermediate value Calculate the public key vector , where the client module is used to receive the ciphertext and the partially decrypted ciphertext, and perform collaborative decryption calculations to finally recover the plaintext; Server cryptography module, used to generate matrix , calculate the hash value, and generate the sub-private key ; , calculate the intermediate value , and calculate the public key vector based on the intermediate value and the intermediate value , The server cryptography module is used to receive the ciphertext, perform partial decryption and send the partially decrypted ciphertext to the client; Public and private key generation module, used to calculate the public key based on the matrix and the public key vector , and calculate the client private key and the server cryptography private key respectively; Encryption module, used to encrypt the plaintext data based on the public key, generate the ciphertext and send it to the server cryptography; Decryption module, used to perform collaborative decryption using the client sub-private key according to the partial decryption result of the server cryptography, and finally recover the plaintext data.

[0014] Advantages of the present invention: (1) A two-party collaborative post-quantum decryption method proposed by the present invention splits the decryption private key into a client private key and a server cryptography private key, and stores them in different entities respectively, so that an attacker cannot obtain the complete private key information through a single-point attack, thus greatly improving the security of the key; (2) A two-party collaborative post-quantum decryption method proposed by the present invention is based on the ML-LWE problem as a security basis, avoiding the security risks of traditional cryptographic schemes based on discrete logarithm or large number factorization problems in the quantum computing environment, and can effectively resist quantum computer attacks to ensure long-term security; (3) A two-party collaborative post-quantum decryption method proposed by the present invention adopts a two-party collaborative decryption method, that is, the server cryptography first performs partial decryption, and then the client completes the final decryption process. Since the decryption process is distributed on two different computing entities, even if an attacker steals the data of one party, the plaintext cannot be directly recovered, effectively enhancing the anti-attack ability; (4) A two-party collaborative post-quantum decryption method proposed by the present invention adopts a distributed decryption architecture to reduce the computing burden of a single terminal. Since the server cryptography calculates the partial decryption result in advance, the client only needs to perform partial decryption calculations to recover the plaintext, thereby reducing the computing pressure on intelligent terminals and making this solution applicable to mobile devices and Internet of Things devices with limited computing power; (5) A two - party collaborative post - quantum decryption device proposed by the present invention can seamlessly interface with existing public - key infrastructures (PKIs), support the smooth transition of traditional encryption systems to post - quantum cryptography schemes, enabling enterprises and users to enhance security without changing the existing architecture, and improving the adaptability and scalability of the system.

[0015] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0016] Figure 1 It is the overall flowchart of a two - party collaborative post - quantum decryption method proposed by the present invention; Figure 2 It is the flowchart of the two - party collaborative generation of the post - quantum signature algorithm Aigis - sig key for a two - party collaborative post - quantum decryption method proposed by the present invention; Figure 3 It is the schematic diagram of two - party collaborative decryption for a two - party collaborative post - quantum decryption method proposed by the present invention; Figure 4 It is the schematic diagram of the terminal device for a two - party collaborative post - quantum decryption device proposed by the present invention; Figure 5 It is the schematic diagram of the readable storage medium for a two - party collaborative post - quantum decryption device proposed by the present invention; In the figure, 200 - terminal device, 210 - memory, 211 - RAM, 212 - cache memory, 213 - ROM, 214 - program / utilities, 215 - program modules, 220 - processor, 230 - bus, 240 - external device, 250 - I / O interface, 260 - network adapter, 300 - program product. Specific implementation manners

[0017] To make the purpose, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below in combination with embodiments and the accompanying drawings. The illustrative embodiments and descriptions thereof of the present invention are only used to explain the present invention and are not intended to limit the present invention.

[0018] Embodiment 1 A two - party collaborative post - quantum decryption method.

[0019] In this embodiment, the parameters are set as follows: represents the degree of the polynomial in the ring R; represents a polynomial ring; respectively represent the matrices The number of rows and columns; Indicates the modulus; Indicates the range of the private key; Indicates the number of perturbation terms in the hash calculation; Indicates the signature range parameter; indicates the signature truncation parameter; is a discrete Gaussian distribution.

[0020] It should be clear that in this embodiment, the client and the server cooperate to complete the key generation and signature process. The client and the server here do not refer to the roles in the traditional network architecture, but rather to the two parties participating in the collaborative signature scheme.

[0021] I. References Figure 1 , the key generation part 1. The client randomly generates a matrix, , and calculates the hash , and sends it to the server; 2. The server randomly generates a matrix, , and calculates the hash, and sends to the client; 3. The client receives , and sends to the server. At the same time, the server receives , and sends to the client; 4. The client verifies . If they are not equal, it terminates. Otherwise, it calculates, and generates the common matrix ; The purpose of the above steps is to generate a common matrix jointly constructed by both parties , to ensure its randomness and anti-tampering property for use in the subsequent key generation process. Specifically: is generated by the client, is generated by the server, and their respective generation processes are independent. The final common matrix is the sum of the random matrices contributed by both parties , so that it can be ensured that a single party cannot fully control the structure, preventing malicious behaviors such as selecting a special matrix to cause the leakage of the private key. The matrix has sufficient randomness, improving security and preventing attackers from pre-computing possible .

[0022] The sum of the hash values exchange can prevent a malicious party from modifying its own matrix after receiving the matrix of the other party. Since the server only publishes after the client sends, preventing the server from selecting a specific after knowing , the server sends , and then the client publishes , preventing the client from modifying after knowing . Therefore, through this commitment and revelation method, it is ensured that the matrices of both parties are independently and randomly generated and cannot be unilaterally manipulated.

[0023] In this embodiment, by splicing the identity matrix , the matrix can retain the characteristics of linear transformation during the calculation process, making the key generation and signature calculation more stable and avoiding possible numerical instability problems. In addition, when using ML-LWE as the security basis, the matrix needs to conform to a specific structure to ensure that it is difficult to be cracked by quantum algorithms. Adding to form enables it to be better used to construct public-private key pairs resistant to quantum attacks.

[0024] 5. The client randomly generates a sub-private key , and calculates an intermediate value , and calculates a hash value , and sends it to the server; 6. The server randomly generates a sub-private key , and calculates an intermediate value , and calculates a hash value , and sends it to the client; In the two-party collaborative key generation process, and are used as intermediate calculation values to ensure the correctness of the public key vector , and at the same time provide additional security to prevent the risk of unilateral key leakage.

[0025] 7. The client verifies . If it does not hold, the program is terminated. Otherwise, calculate ; 8. Output the public key , the client private key, and the server private key .

[0026] The above steps construct public-private key pairs based on the ML-LWE problem, avoiding the security risks of traditional cryptographic schemes based on discrete logarithm or large number factorization problems in the quantum computing environment and effectively resisting quantum computing attacks.

[0027] II. Reference Figure 2 , the two-party collaborative decryption part encrypts the plaintext to generate the ciphertext , the ciphertext is sent to the server cipher machine. After the server cipher machine receives the ciphertext, the following operations are performed: I. The server cipher machine receives the ciphertext and performs partial decoding 1. The server cipher machine uses the decoding method ByteDecode in the FIPS 203 standard to perform partial decoding on the ciphertext respectively to obtain the decoded ciphertext ; 2. The server cipher machine uses its partial private key to decrypt the ciphertext to obtain the partial ciphertext, that is ; where represents matrix transpose; 3. The server cipher machine sends the ciphertext and the partially decrypted ciphertext to the client, that is, sends and to the client; II. The client receives the ciphertext data and performs collaborative decryption 1. The client receives the ciphertext data and sent by the server cipher machine, and uses the decoding method ByteDecode in the FIPS 203 standard to perform partial decoding on the ciphertext respectively to obtain the decoded ciphertext ; 2. The client uses its partial private key to perform collaborative decryption to restore the plaintext message: .

[0028] Embodiment 2 In the system initialization stage, the client and the server cipher machine respectively generate their own initial data, including information such as random matrices and hash values. The system calculates public and private keys to ensure the security of subsequent encryption and decryption.

[0029] The specific steps are as follows: The client generates a random matrix and calculates a hash value, which will be used as the basis for key derivation. The server cipher machine also generates a random matrix and calculates a hash value.

[0030] The system calculates public and private keys: Combining the matrices of the client and the server cipher machine, the final public key is generated. Based on the public key, the private key of the client and the private key of the server cipher machine are generated, ensuring that both of them can only hold partial private keys and cannot decrypt the data alone. When there is data to be encrypted, the system will use the public key for encryption processing to ensure that the data will not be leaked during transmission and storage.

[0031] The encryption process is as follows: The encryption module reads the plaintext data to be encrypted, performs encryption calculations using the public key, generates a pair of ciphertexts after encryption, and sends the ciphertexts to the server cryptograph for storage or further processing. When decrypting data is required, the server cryptograph first performs partial decryption and sends the partial decryption result to the client. The specific process is as follows: The server cryptograph receives the ciphertext and performs preliminary processing on it, including standard decoding to ensure consistent data formats. The server cryptograph uses its own partial private key to perform partial decryption on the ciphertext, generating a partially decrypted ciphertext. The server cryptograph sends the ciphertext and the partial decryption result to the client to let the client complete the final decryption.

[0032] The client performs collaborative decryption After receiving the partial decryption result from the server cryptograph, the client uses its own private key to perform the final decryption to restore the plaintext data.

[0033] The decryption process is as follows: The client receives the data, including the complete ciphertext and the partial decryption result provided by the server cryptograph. The client uses the decoding method to parse the ciphertext to ensure data consistency. The client uses its own private key in combination with the partial decryption result of the server cryptograph to perform the final decryption to restore the original plaintext data. The client successfully obtains the plaintext data and the decryption process is completed.

[0034] The application scenarios of this implementation include: Cloud storage security: Even if the cloud server stores encrypted data, it cannot be decrypted alone, ensuring user data privacy.

[0035] Financial data protection: Ensuring that neither financial institutions nor users can decrypt sensitive information alone, enhancing data security.

[0036] Post-quantum cryptography: Combining advanced encryption algorithms to improve the defense against quantum computing attacks.

[0037] Enterprise data sharing: Used for data sharing between different departments or collaborating institutions, ensuring that both parties must collaborate to decrypt the data and preventing information leakage.

[0038] Embodiment 3 Reference Figure 4 , based on Embodiment 1, this embodiment proposes a terminal device of a two-party collaborative post-quantum decryption device. The terminal device 200 includes at least one memory 210, at least one processor 220, and a bus 230 connecting different platform systems.

[0039] The memory 210 may include a readable medium in the form of volatile memory, such as RAM 211 and / or cache memory 212, and may further include ROM 213.

[0040] Among them, the memory 210 also stores a computer program, which can be executed by the processor 220, so that the processor 220 executes any one of the above applications of the two-party collaborative post-quantum decryption device in the embodiments of the present application. The specific implementation manner is consistent with the implementation manner and the achieved technical effects described in the embodiments of the above application, and some contents will not be elaborated. The memory 210 may further include a program / utilities 214 having a set (at least one) of program modules 215. Such program modules include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.

[0041] Correspondingly, the processor 220 may execute the above computer program and may also execute the program / utilities 214.

[0042] The bus 230 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any bus structure in a variety of bus structures.

[0043] The terminal device 200 may also communicate with one or more external devices 240, such as a keyboard, a pointing device, a Bluetooth device, etc., and may also communicate with one or more devices capable of interacting with the terminal device 200, and / or communicate with any device (such as a router, a modem, etc.) that enables the terminal device 200 to communicate with one or more other computing devices. Such communication may be carried out through the I / O interface 250. And, the terminal device 200 may also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 260. The network adapter 260 may communicate with other modules of the terminal device 200 through the bus 230. It should be understood that although not shown in the figure, other hardware and / or software modules may be used in combination with the terminal device 200, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage platforms, etc.

[0044] Embodiment 3 Reference Figure 5, this embodiment proposes a readable storage medium for a two-party collaborative post-quantum decryption device. Instructions are stored on the computer-readable storage medium, and when executed by a processor, these instructions implement any of the above two-party collaborative post-quantum decryption devices. The specific implementation manner is consistent with the implementation manners and the achieved technical effects described in the embodiments of the above application, and some content will not be elaborated again.

[0045] Figure 5 Fig. 4 shows the program product 300 provided in this embodiment for implementing the above application. It can be a portable compact disc read-only memory (CD-ROM) and includes program code, and can run on a terminal device, such as a personal computer. However, the program product 300 of the present invention is not limited thereto. In this embodiment, the readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. The program product 300 can adopt any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0046] A computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, in which a readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable storage medium may also be any readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing. The program code for performing the operations of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, executed as a stand-alone software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., using an Internet service provider to connect through the Internet).

[0047] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments, and what is described in the above embodiments and the specification is only to illustrate the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and all such changes and improvements fall within the scope of the present invention claimed. The scope of protection of the present invention is defined by the appended claims and their equivalents.

Claims

1. A two-party collaborative post-quantum decryption method, characterized in that: The following steps are involved: S1. Generate the collaborative Aigis-sig signature key part; S2, calculate the public key and their respective private keys through the interaction between the client and the server, and encrypt the ciphertext using the public key; S3, perform collaborative decryption calculation between two parties; S4. Complete plaintext recovery through collaboration between the client and the server.

2. A two-party collaborative post-quantum decryption method according to claim 1, characterized in that: The generation process of the signature key includes the following sub-steps: A. Client randomly generates matrix And calculate the hash value , the hash value Send to the server cipher machine; B. Randomly generate matrix for server-side cipher machine And calculate the hash value , the hash value Send to the client; C. The client receives the hash value Then, the matrix Sent to the server cipher machine, the server cipher machine receives the hash value Then, the matrix Send to the client; D. The client performs hashing Verify, if the hash values ​​are not equal, terminate, otherwise calculate the matrix Generate a common matrix ; E. The client generates a sub-private key , , through the child private key , Calculate the intermediate value , according to the median value Calculating the hash value And send it to the server cipher machine; F. The server-side cipher generates a sub-private key , , through the child private key , Calculate the intermediate value , according to the median value Calculating the hash value And send it to the client; G. Client performs hashing Verify, if the hash values ​​are not equal, terminate, otherwise according to the intermediate value and Calculate the public key vector ; H, according to the public key vector, the client sub-private key, the server cipher sub-private key, the matrix Calculate the public key, client private key and server cipher machine private key.

3. A two-party collaborative post-quantum decryption method according to claim 2, characterized in that: The public key is represented by the matrix and the public key vector Composition, where the public key vector .

4. A two-party collaborative post-quantum decryption method according to claim 1, characterized in that: The collaborative decryption calculation includes the following sub-steps: I. The server-side cipher machine receives the ciphertext, performs ByteDecode decoding on the ciphertext to partially decode it, and obtains the decoded ciphertext; J. The server-side cipher machine decrypts the ciphertext using the server-side cipher machine private key to obtain a partially decrypted ciphertext, and the server-side cipher machine sends the ciphertext and the partially decrypted ciphertext to the client; K. After receiving the ciphertext and the partially decrypted ciphertext, the client performs ByteDecode decoding on the ciphertext to partially decode it and obtain the decoded ciphertext; L. The client uses the client's sub-private key to collaboratively decrypt the ciphertext and recover the plaintext message.

5. A two-party collaborative post-quantum decryption method according to claim 4, characterized in that: The client and server cryptographic machines respectively hold sub-private keys, and the server cryptographic machine first calculates the partial decryption result, and the client completes the final plaintext calculation.

6. A two-party collaborative post-quantum decryption method according to claim 2, characterized in that: The public key matrix The construction method is ,in The matrices generated by the client and server cipher machines respectively and Add together.

7. A two-party collaborative post-quantum decryption method according to claim 2, characterized in that: The median value The calculation formula is ; The intermediate value The calculation formula is .

8. A two-party collaborative post-quantum decryption method according to any one of claims 1 to 7, characterized in that: It also includes a collaborative decryption device, the collaborative decryption device comprising: Client module for generating matrices , calculate hash value, generate child private key ; , calculate the middle value , and according to the median value And the intermediate value calculates the public key vector ,The client module is used to receive the ciphertext and part of the decrypted ciphertext and perform collaborative decryption calculation to finally recover the plaintext; Server-side cipher module, used to generate matrices , calculate hash value, generate child private key ; , calculate the middle value , and according to the median value and the median Calculate the public key vector , The server-side cryptographic machine module is used to receive ciphertext, perform partial decryption and send the partially decrypted ciphertext to the client; Public and private key generation module for matrix-based and the public key vector Calculate the public key, and calculate the client private key and the server cipher machine private key respectively; The encryption module is used to encrypt the plaintext data based on the public key, generate the ciphertext and send it to the server-side cipher machine; The decryption module is used to perform collaborative decryption based on the partial decryption results of the server-side cipher machine using the client's sub-private key, and finally restore the plaintext data.

Citation Information

Patent Citations

  • Signing and decrypting method and system applied to cloud computing and based on SM2 algorithm

    CN104243456A

  • Data encryption and decryption method and device based on Kubernetes

    CN114866229A

  • Collaborative signature and decryption method and device, electronic equipment and storage medium

    CN116823260A

  • Post-quantum signature method and device

    CN118631455A

  • Two-party collaborative Aigis-sig post-quantum signature method

    CN120074817A

Cited By

  • Cooperative encryption and decryption method and system based on NTRU algorithm

    CN121173598A

  • A collaborative encryption / decryption method and system based on the NTRU algorithm

    CN121173598B

  • SM2 collaborative signature, encryption and decryption system and method fusing anti-quantum characteristics

    CN121283626A