Lattice cipher method and device for realizing number-theory transformation based on three steps of matrix operation
By decomposing the number theory transformation in the Kyber encryption algorithm into three steps, the problem of butterfly operation is inefficient on emerging high-performance devices is solved, and the effect of significantly improving the computing efficiency is achieved.
Patent Information
- Application Number
- CN202510275622.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-03-11
- Filing Date
- 2025-03-10
- Publication Date
- 2025-06-10
AI Technical Summary
The existing butterfly operation cannot fully utilize the device performance on emerging high-performance devices, resulting in inefficient computing of the Kyber encryption algorithm.
By decomposing the number theory transformation in the Kyber encryption algorithm into three steps, it uses the first-stage matrix, the second-stage matrix and the third-stage matrix to optimize it, and adapts to devices with high-performance matrix computing capabilities such as AI accelerators.
The packaging efficiency of Kyber encryption algorithm is significantly improved, and the experimental results show that compared with traditional butterfly operation, it has a 12.5x performance advantage.
Smart Images

Figure CN120128323A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of cryptography, and relates to a lattice cryptography method and device for implementing number-theoretic transformation in three steps based on matrix operations. Background Art
[0002] The study of lattice theory originated in the 17th century, but the concept of lattice cryptography was not proposed until 1996 by the American computer scientist Miklós Ajtai. He proved that the average-case hardness of certain lattice problems can be reduced to the worst-case hardness, laying the foundation for the development of lattice cryptography. Since Ajtai's work, significant progress has been made in the field of lattice cryptography. Researchers have proposed various lattice-based encryption schemes, such as the Ajtai-Dwork cryptosystem, the GGH cryptosystem, etc. In recent years, with the rapid development of quantum computing technology, lattice cryptography, as an important candidate for post-quantum cryptography, has received increasing attention.
[0003] Benefiting from the development of artificial intelligence, related applications have become more and more popular. For this reason, some manufacturers have developed their own AI processors or accelerators, such as Google's TPU, Intel's Neural Compute Stick, Tesla's self-driving car chips, and the neural network acceleration engines in many current smartphones, providing strong performance processing capabilities for specific services. These AI acceleration devices usually adopt architectures with low precision, novel data streams, and in-memory computing, and are optimized for specific algorithm operations (such as convolution operations), with performance far higher than that of general-purpose processors. For example, the Tensor Core of NVIDIA Tesla V100 can provide a computing power of 125 Tensor TFLOPS. With the development of technology, such powerful computing power resources will surely become more and more common and easier to access. If the computing power of AI accelerators can be used in other fields besides artificial intelligence applications, such as cryptographic computing, it will surely greatly improve the computing efficiency in this field.
[0004] In 2016, the National Institute of Standards and Technology (NIST) of the United States began to launch the post-quantum cryptography standardization project, and selected Kyber as the winning algorithm for the key encapsulation mechanism in 2022, and then standardized it. Kyber is a key encapsulation algorithm based on module learning with errors, and the operations are carried out in a ring ring.
[0005] In the Kyber encryption scheme, the Number Theoretic Transform (NTT) is used to accelerate polynomial multiplication operations. It transforms the coefficients of a polynomial from the ordinary domain to the NTT domain, and the multiplication between polynomials is optimized from convolution multiplication to element-wise point multiplication. The NTT in Kyber is defined as follows, where ζ = 17 is the primitive root and f is the polynomial to be transformed, is the form after the NTT transformation.
[0006]
[0007]
[0008] The butterfly operation is the main solution for NTT. However, if the butterfly operation is performed on emerging high-performance devices, due to its operation principle not being fully adaptable to emerging high-performance devices, the performance of emerging high-performance devices cannot be fully utilized. Therefore, there is an urgent need for a technical solution to solve the above problems. Summary of the Invention
[0009] In view of the above problems, the present invention provides a lattice cryptography method and device for implementing number theoretic transform in three steps based on matrix operations, which can improve the encapsulation efficiency of the Kyber encryption algorithm.
[0010] A lattice cryptography method for implementing number theoretic transform in three steps based on matrix operations optimizes the conversion between the ordinary domain polynomial f k and the NTT domain polynomial in the Kyber encryption algorithm; wherein,
[0011] The steps of converting the ordinary domain polynomial f k to the NTT domain polynomial include:
[0012] Obtain one first-stage matrix P1, one second-stage matrix P2, and one third-stage matrix P3;
[0013] Obtain the ordinary domain polynomial f k in the Kyber encryption algorithm;
[0014] Fill the coefficients in the ordinary domain polynomial f k into a 16×16 matrix in ascending order of degrees to obtain matrix A; multiply matrix A by the first-stage matrix P1 to obtain matrix B = P1×A;
[0015] Calculate the Hadamard product of matrix B and the second-stage matrix P2 to obtain matrix C;
[0016] Multiply matrix C by the three-stage matrix P3 to obtain matrix D, and use the elements in matrix D as the coefficients of the NTT-domain polynomial ;
[0017] Convert the NTT-domain polynomial to the ordinary-domain polynomial f k . The steps include:
[0018] Obtain one one-stage matrix P1 ′ , one two-stage matrix P2 ′ and one three-stage matrix P3 ′ ;
[0019] Obtain the NTT-domain polynomial in the Kyber encryption algorithm
[0020] Arrange the coefficients in the NTT-domain polynomial in ascending order of degrees and fill them into a 16×16 matrix to obtain matrix A ′ ; Multiply matrix A ′ by the one-stage matrix P1 ′ to obtain matrix B ′ ;
[0021] Calculate the Hadamard product of matrix B ′ and the two-stage matrix P2 ′ to obtain matrix C ′ ;
[0022] Multiply matrix C ′ by the three-stage matrix P3 ′ to obtain matrix D ′ , and use the elements in matrix D ′ as the coefficients of the ordinary-domain polynomial f k .
[0023] Furthermore, the one-stage matrix the two-stage matrix the three-stage matrix wherein, ζ represents the primitive root, br 4 (i) represents reversing the 4-bit input i bit by bit.
[0024] Furthermore, the one-stage matrix the two-stage matrix the three-stage matrix wherein, ζ represents the primitive root, br 4 (i) represents reversing the 4-bit input i bit by bit, represents reversing the 3-bit bit by bit.
[0025] A lattice cryptography device for realizing number-theoretic transform in three steps based on matrix operations, which optimizes the conversion between the ordinary domain polynomial f in the Kyber encryption algorithm k and the NTT domain polynomial . The device includes:
[0026] A data acquisition module, which is used for:
[0027] Obtaining one first-stage matrix P1, one second-stage matrix P2, and one third-stage matrix P3;
[0028] Obtaining the ordinary domain polynomial f in the Kyber encryption algorithm k ;
[0029] and,
[0030] Obtaining one first-stage matrix P1 ′ , one second-stage matrix P2 ′ and one third-stage matrix P3 ′ ;
[0031] Obtaining the NTT domain polynomial in the Kyber encryption algorithm
[0032] An online calculation module, which is used for:
[0033] Filling the coefficients in the ordinary domain polynomial f k into a 16×16 matrix in the order from the lowest degree to the highest degree to obtain matrix A; multiplying matrix A by the first-stage matrix P1 to obtain matrix B = P1×A;
[0034] Calculating the Hadamard product of matrix B and the second-stage matrix P2 to obtain matrix C;
[0035] Multiplying matrix C by the third-stage matrix P3 to obtain matrix D, and taking the elements in matrix D as the coefficients of the NTT domain polynomial ;
[0036] and,
[0037] Filling the coefficients in the NTT domain polynomial into a 16×16 matrix in the order from the lowest degree to the highest degree to obtain matrix A ′ ; multiplying matrix A ′ by the first-stage matrix P1 ′ to obtain matrix B ′ ;
[0038] Multiplying matrix B ′ by the second-stage matrix P2 ′ to calculate the Hadamard product to obtain matrix C′ ;
[0039] Multiply matrix C ′ with the three-stage matrix P3 ′ to obtain matrix D ′ , and use the elements in matrix D ′ as the coefficients of the ordinary domain polynomial f k .
[0040] An electronic device, characterized in that the electronic device includes: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, the three-step calculation method for implementing number theory transformation using matrix operations described in any one of the above is realized.
[0041] A computer-readable storage medium, characterized in that computer program instructions are stored on the computer-readable storage medium, and when the computer program instructions are executed by a processor, the three-step calculation method for implementing number theory transformation using matrix operations described in any one of the above is realized.
[0042] A computer program product, characterized in that when the computer program product runs on a computer device, the computer device is caused to execute the three-step calculation method for implementing number theory transformation using matrix operations described in any one of the above.
[0043] Compared with the prior art, the positive effects of the present invention are as follows:
[0044] For the first time, the NTT calculation of Kyber is decomposed into matrix operations to adapt to devices with high-performance matrix operation capabilities, such as emerging AI accelerators (Tensor Core, etc.). The mainstream technology for the NTT calculation of existing Kyber is butterfly operation, which is not the optimal choice on emerging high-performance devices. Decomposing the NTT calculation into matrix operations has significant performance advantages through experiments. Description of the Drawings
[0045] Figure 1 It is a block diagram of the three-step calculation method for implementing number theory transformation using matrix operations according to the present invention.
[0046] Figure 2 It is a calculation flow chart of the offline calculation module according to the present invention.
[0047] Figure 3 It is a calculation flow chart of the online calculation module according to the present invention. Detailed Embodiments
[0048] The present invention will be further described in detail below with reference to the drawings.
[0049] Lattice cryptography methods generally mainly include three stages: key generation, encryption, and decryption. The following is a detailed explanation of the steps of the Kyber encryption algorithm.
[0050] I. Key generation stage.
[0051] In the key generation stage, by inputting a random value d, the encryption key ek PKE and the decryption key dk PKE are obtained. Specifically, the key generation stage includes the following steps 1.1 to 1.9.
[0052] Step 1.1: After concatenating the random value d and the parameter k, input them into the pseudorandom generator G to obtain the first random seed ρ and the second random seed σ. Among them, the parameter k is the module dimension (e.g., k = 2 in Kyber-512).
[0053] Step 1.2: Initialize the first counter to 0 for subsequent calls to the pseudorandom function.
[0054] Step 1.3: Construct a k×k matrix where each element in this matrix is where ∥ represents the concatenation operation, and i, j are the row number and column number of the matrix , and SampleNTT is a hash function.
[0055] Step 1.4: Generate a polynomial s of length k. Among them, the generation process of each element in the polynomial s includes:
[0056] Step 1.4.1: Call the pseudorandom function and input the second random seed σ and the value N of the first counter 1 to generate a random value
[0057] Step 1.4.2: Generate a small polynomial for this random value through the central binomial distribution sampling function and use this small polynomial as the element s[i]; among them, the range of this small polynomial is [-η 1 , η 1 ;
[0058] Step 1.4.3: For each generated element, let N 1 = N 1 +1 and re-execute Step 1.4.1.
[0059] Step 1.5: Generate a polynomial e of length k. The generation method of the polynomial e is the same as that of the polynomial s, so it will not be elaborated here.
[0060] Step 1.6: Convert polynomial s and polynomial e to the NTT domain to obtain polynomial and polynomial where NTT represents converting a polynomial in the ordinary domain to a polynomial in the NTT domain.
[0061] Step 1.7: Generate polynomial
[0062] Step 1.8: Generate the encryption key where ByteEncode l represents encoding an l-bit integer into a byte sequence.
[0063] Step 1.9: Generate the decryption key where represents decoding a byte sequence into a sequence of l-bit integers.
[0064] II. Encryption phase.
[0065] The encryption phase mainly includes the following steps 2.1 to 2.11.
[0066] Step 2.1: Initialize the second counter to 0.
[0067] Step 2.2: Decode the encryption key ek PKE to extract polynomial and the first random seed ρ.
[0068] Step 2.3: Reconstruct the matrix based on the first random seed ρ
[0069] Step 2.4: Generate polynomial y; where each element of polynomial y where N 2 is the value of the second counter, and r is an input random sequence.
[0070] Step 2.5: Generate polynomial e 1 and polynomial e 2 ; where each element of polynomial e 1
[0071] e 1 [i] ranges from [-η 1 , η 1 , and each element of polynomial e 2 e 2 [i] ranges from [-η2 , η 2 .
[0072] Step 2.6: Convert the vector y to the NTT domain to obtain the vector
[0073] Step 2.7: Calculate the polynomial where NTT -1 represents converting the polynomial in the NTT domain to a polynomial in the ordinary domain.
[0074] Step 2.8: Decode and decompress the message m to be encrypted to obtain the polynomial μ.
[0075] Step 2.9: Calculate the polynomial
[0076] Step 2.10: Compress and encode the polynomials u and v respectively to obtain the byte sequence c 1 and the byte sequence c 2 .
[0077] Step 2.11: Concatenate the byte sequence c 1 and the byte sequence c 2 to obtain the ciphertext c of the message m.
[0078] III. Decryption phase.
[0079] Step 3.1: Split the ciphertext c into the byte sequence c 1 and the byte sequence c 2 ;
[0080] Step 3.2: Decompress and decode the byte sequences c 1 and c 2 respectively to obtain the polynomials u ′ and the polynomial v ′ .
[0081] Step 3.3: Decode the decryption key dk PKE to obtain the polynomial
[0082] Step 3.4: Calculate the polynomial
[0083] Step 3.5: Compress and byte-encode the polynomial w to obtain the message m.
[0084] It can be seen that in the Kyber encryption algorithm, the ordinary domain polynomial f and the NTT domain polynomial are subjected to multiple and Transformation. However, since the existing butterfly algorithm cannot be applied to emerging high-performance devices, the efficiency of the Kyber encryption algorithm is low. Therefore, the present invention optimizes the and transformations.
[0085] As Figure 1 shown, the present invention can achieve the online conversion of polynomial coefficients between the ordinary domain and the NTT domain as shown in Figure 2 based on one first-stage matrix P1, one second-stage matrix P2, and one third-stage matrix P3 obtained from the offline calculation module. Figure 3 shown.
[0086] In one embodiment, taking as the calculation target, f represents a polynomial in the ordinary domain, represents a polynomial in the NTT domain, and the steps are as follows:
[0087] 1) Offline calculate one 16×16 pre-calculation matrix P1, and the elements in this matrix are defined as follows:
[0088]
[0089] where br 4 (i) represents reversing the 4-bit i input bit by bit.
[0090] 2) Offline calculate one 16×16 pre-calculation matrix P2, and the elements in this matrix are defined as follows:
[0091]
[0092] 3) Offline calculate one 16×16 pre-calculation matrix P3, and the elements in this matrix are defined as follows:
[0093]
[0094] where, represents reversing the 3-bit bit by bit.
[0095] 4) Select one polynomial f in the ordinary domain in the Kyber encryption algorithm.
[0096] 5) Fill the coefficients in the polynomial f into a 16×16 matrix in ascending order of degrees, denoted as matrix A.
[0097] 6) Calculate the matrix product of matrix A and the first-stage matrix P1 to obtain matrix B = P1×A.
[0098] 7) Calculate the Hadamard product of matrix B and the second-stage matrix P2 to obtain matrix C = B⊙P2, where ⊙ represents multiplying the corresponding elements of the matrices.
[0099] 8) Calculate the matrix product of matrix C and the three - stage matrix P3 to obtain matrix D = C×P3.
[0100] 9) The elements in D are the coefficients of the NTT - domain representation of the polynomial f .
[0101] In another embodiment, taking as the calculation target, the steps are as follows:
[0102] 1) Calculate an offline 16×16 pre - calculation matrix P1, and the elements in this matrix are defined as follows:
[0103]
[0104] 2) Calculate an offline 16×16 pre - calculation matrix P2, and the elements in this matrix are defined as follows:
[0105]
[0106] 3) Calculate an offline 16×16 pre - calculation matrix P3, and the elements in this matrix are defined as follows:
[0107]
[0108] 4) Select an NTT - domain polynomial in the Kyber encryption algorithm
[0109] 5) Fill the coefficients in the polynomial into a 16×16 matrix in the order from the lowest - degree to the highest - degree, denoted as matrix A.
[0110] 6) Calculate the matrix product of matrix A and the first - stage matrix P1 to obtain matrix B = P1×A.
[0111] 7) Calculate the Hadamard product of matrix B and the second - stage matrix P2 to obtain matrix C = B⊙P2, where ⊙ represents multiplying the corresponding elements of the matrices.
[0112] 8) Calculate the matrix product of matrix C and the three - stage matrix P3 to obtain matrix D = C×P3.
[0113] 9) The elements in D are the coefficients of the polynomial in the ordinary domain representation f.
[0114] In addition, the inventors also conducted experimental verifications on the traditional butterfly operation and the present invention respectively on NVIDIA RTX3080 @ 1.8GHz. The results show that for one NTT calculation, the traditional butterfly operation takes 107.81 ns, while the transformation method proposed in the present invention takes 8.61 ns. The experimental data prove that based on the high-performance processor Tensor Core, the transformation method proposed in the present invention has a 12.5-fold performance advantage over the traditional butterfly operation.
[0115] In summary, polynomial multiplication over lattices is the basic calculation of lattice-based cryptographic algorithms and also the performance bottleneck of algorithm implementation. And NTT is the mainstream acceleration algorithm for accelerating polynomial multiplication.
[0116] Using the technology proposed in the present invention and based on high-performance computing devices, multiple ordinary domain polynomials can be converted into NTT domain representations or multiple NTT domain representation polynomials can be converted into ordinary domain representations in a batch processing manner. This high-performance NTT implementation technology can effectively accelerate the calculation of polynomial multiplication over lattices and directly reduce the calculation time of the post-quantum key encapsulation mechanism algorithm Kyber.
[0117] After considering the specification and practicing the present disclosure, those skilled in the art will readily think of other embodiments of the present disclosure. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include common general knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and examples are only regarded as exemplary, and the present disclosure is not limited to the exact structures already described and shown in the drawings, and various modifications and changes can be made without departing from its scope.
Claims
1. A lattice cryptographic method based on three steps of matrix operation to achieve number theory transformation, characterized in that: For the general field polynomial f in the Kyber encryption algorithm k With NTT field polynomial Optimize the conversion between The general field polynomial f k Convert to NTT domain polynomial The steps include: Obtain a one-stage matrix P1, a two-stage matrix P2, and a three-stage matrix P3; Get the general field polynomial f in the Kyber encryption algorithm k ; The general field polynomial f k Fill the coefficients in the 16×16 matrix from low to high order to obtain the matrix A; Multiply the matrix A by the first-stage matrix P1 to obtain the matrix B = P1 × A; Calculate the Hadamard product of matrix B and the second-stage matrix P2 to obtain matrix C; Multiply the matrix C with the three-stage matrix P3 to obtain the matrix D, and use the elements in the matrix D as the NTT domain polynomial The coefficient of NTT field polynomial Convert to a general field polynomial f k The steps include: Obtain a one-stage matrix P1′, a two-stage matrix P2′, and a three-stage matrix P3′; Get the NTT field polynomial in the Kyber encryption algorithm The NTT field polynomial Fill the coefficients in the 16×16 matrix from low to high order to obtain the matrix A′; Multiply the matrix A′ by the first-stage matrix P1′ to obtain the matrix B′; Calculate the Hadamard product of matrix B′ and the second-stage matrix P2′ to obtain matrix C′; Multiply the matrix C′ by the three-stage matrix P3′ to obtain the matrix D′, and use the elements in the matrix D′ as the general field polynomial f k The coefficient of .
2. The method according to claim 1, characterized in that The first stage matrix The two-stage matrix The three-stage matrix in, ζ represents the primitive root, and br4(i) means reversing the input 4 bits i bit by bit.
3. The method according to claim 1, characterized in that The first stage matrix The two-stage matrix Three-stage matrix in, ζ represents the primitive root, br4(i) represents reversing the input 4 bits i bit by bit, Indicates 3 bits Bit-by-bit reverse order.
4. A lattice cryptographic device for realizing number theory transformation based on three steps of matrix operation, characterized in that: For the general field polynomial f in the Kyber encryption algorithm k With NTT field polynomial The conversion between the two is optimized, and the device comprises: Data acquisition module, used to: Obtain a one-stage matrix P1, a two-stage matrix P2, and a three-stage matrix P3; Get the general field polynomial f in the Kyber encryption algorithm k ; and, Obtain a one-stage matrix P1′, a two-stage matrix P2′, and a three-stage matrix P3′; Get the NTT field polynomial in the Kyber encryption algorithm Online computing modules for: The general field polynomial f k Fill the coefficients in the 16×16 matrix from low to high order to obtain the matrix A; Multiply the matrix A by the first-stage matrix P1 to obtain the matrix B = P1 × A; Calculate the Hadamard product of matrix B and the second-stage matrix P2 to obtain matrix C; Multiply the matrix C with the three-stage matrix P3 to obtain the matrix D, and use the elements in the matrix D as the NTT domain polynomial The coefficient of and, NTT field polynomial Fill the coefficients in the 16×16 matrix from low to high order to obtain the matrix A′; Multiply the matrix A′ by the first-stage matrix P1′ to obtain the matrix B′; Calculate the Hadamard product of matrix B′ and the second-stage matrix P2′ to obtain matrix C′; Multiply the matrix C′ by the three-stage matrix P3′ to obtain the matrix D′, and use the elements in the matrix D′ as the general field polynomial f k The coefficient of .
5. An electronic device, characterized in that: The electronic device comprises: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, the lattice cryptographic method for realizing number theory transformation based on three steps of matrix operation as described in any one of claims 1 to 3 is implemented.
6. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer program instructions, which, when executed by a processor, implement the lattice cryptographic method for realizing number theory transformation based on three steps of matrix operations as described in any one of claims 1 to 3.
7. A computer program product, characterized in that When the computer program product runs on a computer device, the computer device executes the lattice cryptographic method for implementing number theory transformation based on three steps of matrix operations as described in any one of claims 1 to 3.