Data Encryption / Decryption Method, Key Generation Method, Electronic Device

By generating a k×(k-1) polynomial matrix and inverse element combined with MLWE and NTRU grid difficulties, small-size public keys are generated, which solves the problems of large public key size and high computational complexity, and achieves efficient encryption and anti-quantum computing security.

CN120150952BActive Publication Date: 2025-07-25BEIJING INFOSEC TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510629164.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-07-25
Estimated Expiration
2045-05-15

AI Technical Summary

Technical Problem

In the existing public key cryptographic algorithm based on modulus, the public key size is larger, resulting in a larger encrypted ciphertext size, high computational complexity, and difficult to resist quantum computing attacks.

Method used

By obtaining the first polynomial with inverses, randomly generate a polynomial matrix of k×(k-1), combining difficult problems on MLWE and NTRU grids, generate target public and private keys, lowering the dimensions of the grid, thereby making the public key smaller in size, and enhancing security through compression encoding and hash calculations.

Benefits of technology

The generated public key has a small size and high computing efficiency. It can effectively resist plaintext selection and ciphertext selection attacks, improving data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120150952B_ABST
    Figure CN120150952B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides a data encryption / decryption method, a key generation method, and an electronic device, which are applied to the field of cryptography technology. Obtain a first polynomial with an inverse element. Randomly generate a polynomial matrix of k×(k−1), and based on the MLWE problem, obtain the MLWE public key according to this polynomial matrix. Generate a target public key factor according to the inverse element of the first polynomial and the MLWE public key factor, so as to obtain the target public key, that is, combine the difficult problems on the NTRU lattice and the difficult problems on the MLWE lattice to obtain the target public key, reduce the dimension of the lattice, and thus make the size of the target public key smaller. Furthermore, when using this target public key for encryption, the generated ciphertext has a smaller size, less computational amount, and higher computational efficiency. In addition, this method can effectively resist attack methods such as chosen-plaintext attacks and improve data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cryptography technology, and particularly relates to a data encryption / decryption method, a key generation method, and an electronic device. Background Art

[0002] Currently, most network security protocols use public key cryptography algorithms to achieve mutual authentication between communication parties and establish a shared key, and then use the shared key as the key of the symmetric cryptography algorithm to ensure the confidentiality and integrity of data.

[0003] With the continuous development of quantum computing technology, in the modular lattice-based key encapsulation mechanism standard (Module-Lattice-based Key Encapsulation Mechanism, abbreviated as ML-KEM) based on the modular lattice (Module Learning With Errors, abbreviated as MLWE), based on a randomly generated k×k polynomial matrix A, a target public key factor t is obtained, and the output public key includes the target public key factor t and the polynomial matrix A. However, the size of this public key is relatively large. Therefore, when using this public key for encryption, the size of the generated ciphertext is also relatively large. Summary of the Invention

[0004] Embodiments of this application provide a data encryption / decryption method, a key generation method, and an electronic device, so that the size of the generated public key is relatively small.

[0005] In a first aspect, embodiments of this application provide a key generation method, and the method includes:

[0006] Obtain a first polynomial with an inverse element;

[0007] Randomly generate a k×(k - 1) polynomial matrix, where k is an integer greater than 1;

[0008] Based on the MLWE problem of the modular lattice, generate an MLWE public key and an MLWE private key according to the polynomial matrix; the MLWE public key includes an MLWE public key factor and the polynomial matrix;

[0009] Generate a target public key factor according to the inverse element of the first polynomial and the MLWE public key factor;

[0010] Obtain a target public key according to the target public key factor and the polynomial matrix;

[0011] Obtain a target private key according to the MLWE private key and the first polynomial;

[0012] Determine that the target key pair includes a target public key and a target private key. The target public key is used to encrypt the first data to obtain a target ciphertext; the target private key is used to decrypt the target ciphertext to obtain the first data.

[0013] Optionally, the generating the target public key factor according to the inverse element of the first polynomial and the MLWE public key factor includes:

[0014] Obtain the target public key factor according to the following formula:

[0015]

[0016] where t is the target public key factor; is the MLWE public key factor; is the inverse element of the first polynomial.

[0017] Optionally, the generating the MLWE public key and the MLWE private key based on the MLWE problem according to the polynomial matrix includes:

[0018] Based on the security parameter, randomly generate a second polynomial to generate the MLWE private key;

[0019] Randomly generate a noise vector;

[0020] Generate the MLWE public key according to the MLWE private key, the polynomial matrix and the noise vector.

[0021] Optionally, the obtaining the target private key according to the MLWE private key and the first polynomial includes:

[0022] Compress and encode the MLWE private key in the first compression method to obtain the compressed MLWE private key;

[0023] Obtain the target private key according to the first polynomial and the compressed MLWE private key;

[0024] The obtaining the target public key according to the target public key factor and the polynomial matrix includes:

[0025] Compress and encode the target public key factor in the first compression method to obtain the compressed target public key factor;

[0026] Obtain the target public key according to the compressed target public key factor and the polynomial matrix.

[0027] Optionally, the obtaining the target private key according to the first polynomial and the compressed MLWE private key includes:

[0028] Generate the first private key according to the first polynomial and the compressed MLWE private key;

[0029] Perform a hash calculation on the target public key to obtain the hashed target public key;

[0030] Obtain a first random number;

[0031] Based on the first private key, the hashed target public key, and the first random number, obtain the target private key.

[0032] In a second aspect, an embodiment of the present application provides a data encryption method, and the method includes:

[0033] Obtain the target public key in the target key pair; wherein, the target key pair includes a target public key and a target private key, the target public key includes a target public key factor and a randomly generated polynomial matrix of k×(k - 1), and the target public key factor is obtained through the following method: obtain a first polynomial with an inverse element; based on the MLWE problem, generate an MLWE public key and an MLWE private key according to the polynomial matrix; the MLWE public key includes an MLWE public key factor and the polynomial matrix; generate the target public key factor according to the inverse of the first polynomial and the MLWE public key factor; the target private key is obtained according to the MLWE private key and the first polynomial;

[0034] Use the target public key to encrypt the first data to obtain a target ciphertext;

[0035] Send the target ciphertext to a first device so that the first device decrypts the target ciphertext using the target private key.

[0036] Optionally, the target private key is obtained through the following method: generate a first private key according to the first polynomial and the compressed MLWE private key; perform a hash calculation on the target public key to obtain the hashed target public key; obtain a first random number; based on the first private key, the hashed target public key, and the first random number, obtain the target private key; after using the target public key to encrypt the first data to obtain the target ciphertext, it further includes:

[0037] Obtain a second random number;

[0038] Based on the hashed target public key and the second random number, obtain a first hash value;

[0039] Generate a shared key according to the first hash value and the target ciphertext;

[0040] The sending the target ciphertext to the first device includes:

[0041] Send the target ciphertext and the shared key to the first device, so that the first device decrypts the target ciphertext using the target private key to obtain second data, and performs a verification operation through the shared key. If the verification passes, determine the second data as the target plaintext of the target ciphertext.

[0042] In a third aspect, an embodiment of the present application provides a data decryption method, and the method includes:

[0043] Receive a target ciphertext sent by a second device, where the target ciphertext is obtained by the second device encrypting first data using a target public key in a target key pair; the target key pair includes a target public key and a target private key, and the target public key is obtained according to a target public key factor and a randomly generated polynomial matrix of k×(k - 1); the target public key factor is obtained in the following manner: obtain a first polynomial with an inverse element; based on the MLWE problem, generate an MLWE public key and an MLWE private key according to the polynomial matrix; the MLWE public key includes an MLWE public key factor and the polynomial matrix; generate a target public key factor according to the inverse element of the first polynomial and the MLWE public key factor; the target private key is obtained according to the MLWE private key and the first polynomial;

[0044] Decrypt the target ciphertext using the target private key to obtain first data.

[0045] Optionally, the receiving the target ciphertext sent by the second device includes:

[0046] Receive a target ciphertext and a shared key sent by the second device;

[0047] The decrypting the target ciphertext using the target private key to obtain first data includes:

[0048] Decrypt the target ciphertext using the target private key to obtain second data;

[0049] Perform a verification operation through the shared key;

[0050] If the verification passes, determine the second data as the first data.

[0051] In a fourth aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor, and a communication interface; wherein, an executable code is stored on the memory, and when the executable code is executed by the processor, the processor executes the method as described in the first aspect.

[0052] Fifth aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor, and a communication interface; wherein, an executable code is stored on the memory, and when the executable code is executed by the processor, the processor is caused to execute the method described in the second aspect.

[0053] Sixth aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor, and a communication interface; wherein, an executable code is stored on the memory, and when the executable code is executed by the processor, the processor is caused to execute the method described in the third aspect.

[0054] Seventh aspect, an embodiment of the present application provides a non-transitory machine-readable storage medium, on which an executable code is stored, and when the executable code is executed by a processor of an electronic device, the processor is enabled to at least implement the method described in the first aspect.

[0055] Eighth aspect, an embodiment of the present application provides a non-transitory machine-readable storage medium, on which an executable code is stored, and when the executable code is executed by a processor of an electronic device, the processor is enabled to at least implement the method described in the second aspect.

[0056] Ninth aspect, an embodiment of the present application provides a non-transitory machine-readable storage medium, on which an executable code is stored, and when the executable code is executed by a processor of an electronic device, the processor is enabled to at least implement the method described in the third aspect.

[0057] Tenth aspect, an embodiment of the present application provides a computer program product, the computer program product includes a computer program, and when the computer program is executed by a processor, it can implement the method described in the first aspect.

[0058] Eleventh aspect, an embodiment of the present application provides a computer program product, the computer program product includes a computer program, and when the computer program is executed by a processor, it can implement the method described in the second aspect.

[0059] Twelfth aspect, an embodiment of the present application provides a computer program product, the computer program product includes a computer program, and when the computer program is executed by a processor, it can implement the method described in the third aspect.

[0060] In the data encryption / decryption method and key generation method provided by the embodiments of the present application, a first polynomial with an inverse element is obtained. A polynomial matrix of k×(k - 1) is randomly generated, and based on the MLWE method, an MLWE public key factor is obtained according to the polynomial matrix. According to the inverse element of the first polynomial and the MLWE public key factor, a target public key factor is generated, thereby obtaining a target public key, that is, by combining the difficult problem on the NTRU lattice and the difficult problem on the MLWE lattice, the target public key is obtained, reducing the dimension of the lattice in the algorithm, so that the size of the target public key is smaller. Furthermore, when encrypting using the target public key, the generated ciphertext has a smaller size, less computational complexity, and higher computational efficiency. In addition, this method can effectively resist attack methods such as chosen-plaintext attacks, improving data security. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for the description of the embodiments. Obviously, the following drawings are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0062] Figure 1 It is a flowchart of a key generation method provided by an embodiment of the present application;

[0063] Figure 2 It is an interaction diagram of a data encryption / decryption method provided by an embodiment of the present application;

[0064] Figure 3 It is a flowchart of another key generation method provided by an embodiment of the present application;

[0065] Figure 4 It is an interaction diagram of another data encryption / decryption method provided by an embodiment of the present application;

[0066] Figure 5 It is a schematic structural diagram of an electronic device provided by this embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0067] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts fall within the scope of protection of the present application. In addition, the step timings in the following method embodiments are only examples and are not strictly limited.

[0068] It should be noted that in the case where the embodiments of the present application involve user information, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the embodiments of the present application are all information and data that have been authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or refuse. Additionally, various models involved in the present application (including but not limited to large language models or other models) comply with relevant laws and standards.

[0069] First, explanations will be given to the terms or concepts involved in the embodiments of the present application:

[0070] In cryptography, an attack method refers to various strategies by which a cryptanalyst attempts to break encrypted information or bypass security mechanisms. According to the knowledge level of the cryptanalyst regarding the plaintext, ciphertext, and encryption algorithm, attack methods can be classified into the following four types:

[0071] Ciphertext-Only Attack (COA): It means that the attacker only has the encrypted ciphertext and no additional information about the plaintext or the key.

[0072] Known Plaintext Attack (KPA): It means that the attacker not only has the ciphertext but also knows some plaintext and its corresponding ciphertext.

[0073] Chosen Plaintext Attack (CPA): It means that the attacker can select any plaintext and obtain its encrypted ciphertext.

[0074] Chosen Ciphertext Attack (CCA): It means that the attacker can select any ciphertext and obtain its decrypted plaintext.

[0075] Public-key encryption, also known as asymmetric encryption, is a method of protecting digital communications using a key pair (public key and private key). Different from symmetric encryption (using the same key for encryption and decryption), public-key encryption ensures that these processes are handled by two independent but mathematically related keys.

[0076] A public-key encryption scheme generally includes three stages: key generation, encryption, and decryption.

[0077] Key generation stage: Generate a mathematically related key pair. Among them, the generated public key is publicly shared for encrypting data, while the private key is kept secret for decrypting data.

[0078] Encryption phase: Since the public key is publicly shared, any encryptor can use the public key to encrypt data, obtain the encrypted data, and send the ciphertext to the private key holder. Generally, the unencrypted data can be referred to as plaintext, and the encrypted data can be referred to as ciphertext.

[0079] Decryption phase: The private key holder decrypts the ciphertext with the private key stored by itself to obtain the plaintext.

[0080] This separation eliminates the need for a secure channel to exchange keys, making it a more scalable digital communication solution.

[0081] Based on lattice-based hard problems, such as hard problems on the MLWE lattice, hard problems on the NTRU lattice, etc., since quantum computers cannot effectively solve them either, lattice-based hard problems can be applied to public key encryption schemes to form public key encryption schemes based on the MLWE problem, such as post-quantum cryptographic algorithms (Kyber) or ML-KEM, etc., enabling the public key encryption scheme to withstand attacks from quantum computers. In this application, the hard problem on the MLWE lattice can also be referred to as the MLWE problem, and the hard problem on the NTRU lattice can also be referred to as the NTRU problem.

[0082] The following introduces a public key encryption scheme based on the MLWE problem provided by an embodiment of this application.

[0083] Set security parameters. For example, the security parameters can at least include one of the following: 、 and etc., where is the standard deviation of the Gaussian distribution; is the random number seed; is a relatively small integer.

[0084] Generate a random seed according to the security parameters, and generate a k×k polynomial matrix A based on this random seed. The elements in the polynomial matrix A are polynomial ring elements.

[0085] Randomly generate a polynomial , that is, , indicating that the second polynomial 、N and is generated through the security parameters , where N represents the coefficient of the polynomial , and N is 256 or 512, etc. Exemplarily, the polynomial can be generated through a pseudo-random function. It should be noted that in this application, a horizontal line above a letter representing a quantity indicates that the quantity is a vector.

[0086] Randomly generate a noise vector , namely . Exemplarily, a noise vector e can be generated through a pseudo-random function.

[0087] Calculate the target public key factor of the MLWE public key .

[0088] Output the MLWE key pair: MLWE public key pk = ( , A), and MLWE private key sk = .

[0089] However, the public key generated in this embodiment has a large size. As a result, during the public key encryption process, the computational complexity is relatively high, and the size of the generated ciphertext is also large, making the computational efficiency of the public key encryption scheme not high.

[0090] Therefore, to overcome the shortcomings of the above embodiment, the embodiment of the present application provides a key generation scheme that can make the public key have a smaller size. A polynomial matrix of k×(k - 1) is randomly generated, and the MLWE public key factor is obtained based on this polynomial matrix. By combining the difficult problems on the NTRU lattice and the difficult problems on the MLWE lattice, the target public key is obtained, reducing the dimension of the lattice in the algorithm, thereby making the size of the target public key smaller. Furthermore, when using this target public key for encryption, the size of the generated ciphertext is smaller, the amount of calculation is smaller, and the computational efficiency is higher.

[0091] The following introduces and explains the new public key encryption scheme provided by the embodiment of the present application.

[0092] Please refer to Figure 1 , Figure 1 which is a flowchart of a key generation method provided by the embodiment of the present application. As Figure 1 shown, the method of this embodiment is executed by an electronic device, which can be a computer, a tablet device, a smart wearable device, or a server, etc. The method includes the following steps.

[0093] 101. Obtain a first polynomial with an inverse element.

[0094] 102. Randomly generate a polynomial matrix of k×(k - 1), where k is an integer greater than 1.

[0095] 103. Based on the MLWE problem, generate an MLWE public key and an MLWE private key according to the polynomial matrix; the MLWE public key includes the MLWE public key factor and the polynomial matrix.

[0096] 104. Generate a target public key factor according to the inverse element of the first polynomial and the MLWE public key factor.

[0097] 105. Obtain the target public key according to the target public key factor and the polynomial matrix.

[0098] 106. Obtain a target private key according to the MLWE private key and the first polynomial.

[0099] 107. Determine that the target key pair includes a target public key and a target private key. The target public key is used to encrypt the first data to obtain a target ciphertext; the target private key is used to decrypt the target ciphertext to obtain the first data.

[0100] In practical applications, optionally, during the key generation process, security parameters can be determined in advance. For example, the security parameters can at least include one of the following: , and etc. Among them, is the standard deviation of the Gaussian distribution; is the random number seed; is a relatively small integer.

[0101] Obtain a first polynomial with an inverse element. Among them, the obtained first polynomial can be a first polynomial with an inverse element obtained based on the NTRU problem.

[0102] Optionally, the method for obtaining the first polynomial can be: randomly generate a polynomial , which can be expressed as . Among them, the polynomial can be generated by a pseudo-random function. Generate the first polynomial , , among which, is a prime number, usually is relatively small, can take 2 or 3.

[0103] Randomly generate a polynomial matrix A of k×(k - 1), and the elements of the polynomial matrix A are polynomial ring elements.

[0104] Optionally, the polynomial matrix A can be generated through the generated random seed d. , and satisfy , where n can be 256.

[0105] In addition, based on the MLWE problem, according to the polynomial matrix, generate an MLWE public key factor and an MLWE private key.

[0106] Optionally, a second polynomial can be randomly generated based on the security parameters to generate an MLWE private key. Randomly generate a noise vector. According to the MLWE private key, the polynomial matrix, and the noise vector, generate an MLWE public key. Specifically, randomly generate a second polynomial , , indicating through the security parameter , N, and Generate a second polynomial , where N is an integer such as 256 or 512. The second polynomial is the MLWE private key. Optionally, the second polynomial can be generated by a pseudo-random function. Randomly generate a noise vector , which can also be called an error vector , , indicating that the noise vector is generated by the security parameter , N, and . After that, based on the polynomial matrix A, the noise vector and the second polynomial , obtain the MLWE public key factor , where .

[0107] After that, generate the target public key factor according to the inverse of the first polynomial and the MLWE public key factor. Combine the form of the target public key factor with the form of the public key based on the NTRU problem.

[0108] Optionally, obtain the target public key factor according to the following formula (1):

[0109] Formula (1)

[0110] where t is the target public key factor; is the MLWE public key factor; is the first polynomial, represents the inverse of the first polynomial.

[0111] So far, it is determined that the target key pair contains the target public key and the target private key. The target public key is used to encrypt the first data to obtain the target ciphertext; the target private key is used to decrypt the target ciphertext to obtain the first data.

[0112] Optionally, the output target key pair can be in the following form: the target public key in the target key pair , where t is the target public key factor and A is a k×(k - 1) polynomial matrix. The target private key in the target key pair , where s is the second polynomial and f is the first polynomial.

[0113] The above introduced a key generation method provided by the present application. The generated target public key in the target key pair can be publicly shared, while the target private key is privately stored. The first device can encrypt the first data based on the target public key in the generated target key pair to obtain the target ciphertext. The first device sends the target ciphertext to the second device that stores the target private key. The second device decrypts the target ciphertext based on the target private key in the generated target key pair to obtain the first data.

[0114] The method provided by the embodiments of the present application obtains a first polynomial with an inverse element. Randomly generate a polynomial matrix of k×(k - 1), and based on the MLWE method, obtain the MLWE public key factor according to this polynomial matrix. Generate the target public key factor according to the inverse element of the first polynomial and the MLWE public key factor, so as to obtain the target public key, that is, by combining the difficult problems on the NTRU lattice and the difficult problems on the MLWE lattice, the target public key is obtained, reducing the dimension of the lattice, so that the size of the target public key is smaller. Furthermore, when using this target public key for encryption, the generated ciphertext has a smaller size, less computational amount, and higher computational efficiency. In addition, this method can effectively resist attack methods such as chosen-plaintext attacks, improving data security.

[0115] In some embodiments, step 105 can be implemented through the following steps: Compress and encode the target public key factor in the first compression method to obtain the compressed target public key factor. Obtain the target public key according to the compressed target public key factor and the polynomial matrix.

[0116] Step 106 can be implemented through the following steps: Compress and encode the MLWE private key in the first compression method to obtain the compressed MLWE private key. Obtain the target private key according to the first polynomial and the compressed MLWE private key.

[0117] In practical applications, the first compression method can be various compression methods, and the present application is not limited to a certain compression method. Exemplarily, compress and encode the target public key factor t, that is , where encode represents compression encoding. Compress and encode the MLWE private key , that is . Among them, " " represents a connection relationship.

[0118] In this embodiment, through the method of compression encoding, the sizes of the target public key and the target private key are further reduced. Furthermore, when using this target public key for encryption, the generated ciphertext has a smaller size, less computational amount, and higher computational efficiency.

[0119] Based on the target public key generated in the above embodiments, the following introduces a data encryption / decryption method provided by the embodiments of the present application.

[0120] Please refer to Figure 2 , Figure 2 , which is an interaction diagram of a data encryption / decryption method provided by an embodiment of the present application. As Figure 2 shown, in this embodiment, the device that stores the target private key, that is, the device that can decrypt the ciphertext encrypted with the target public key, is called the first device. The first device can be the same as or different from the target key pair generation device. The execution device of the data encryption method is called the second device. The method provided in this embodiment includes the following steps.

[0121] 201. The second device obtains the target public key in the target key pair. Among them, the target key pair includes a target public key and a target private key. The target public key includes a target public key factor and a randomly generated polynomial matrix of k×(k - 1). The target public key factor is obtained through the following method: obtain a first polynomial with an inverse element; based on the MLWE problem, generate an MLWE public key and an MLWE private key according to the polynomial matrix; the MLWE public key includes an MLWE public key factor and a polynomial matrix; generate the target public key factor according to the inverse element of the first polynomial and the MLWE public key factor; the target private key is obtained according to the MLWE private key and the first polynomial.

[0122] 202. The second device encrypts the first data with the target public key to obtain a target ciphertext.

[0123] 203. The second device sends the target ciphertext to the first device.

[0124] It should be noted that the generation method of the target key pair has been described in the above embodiment and will not be elaborated here.

[0125] In practical applications, if the second device needs to send the first data to the first device and does not want other devices to obtain the first data during the sending process, it can obtain the target public key shared by the first device. And encrypt the first data with the target public key to obtain a target ciphertext. Then send the target ciphertext to the first device. Although the data channel for sending the target ciphertext to the first device is publicly available, since the first data has been encrypted, only the target private key can decrypt it. Therefore, the data security can also be guaranteed during the transmission process. The first device decrypts the target ciphertext with the target private key to obtain the first data.

[0126] In some embodiments, the process of the second device encrypting the first data with the target public key is as follows:

[0127] The second device randomly generates a third polynomial. The third polynomial is a vector. For example, the third polynomial r can be expressed as .

[0128] The second device randomly generates a fourth polynomial, and the fourth polynomial is a scalar. For example, the fourth polynomial e2 can be expressed as .

[0129] The second device calculates respectively according to the first data m and .

[0130] The second device performs compression encoding on u and v respectively, that is , .

[0131] The second device outputs the target ciphertext c, , where, " " represents a concatenation relationship.

[0132] Correspondingly, the first device decrypts the target ciphertext as follows:

[0133] The first device receives the target ciphertext c, .

[0134] The first device decodes c1 to obtain u, where .

[0135] The first device decodes c2 to obtain v, where .

[0136] The first device decrypts through the target private key sk ( ), and obtains the first data m, mod p.

[0137] In this embodiment, a first polynomial with an inverse element is obtained. A polynomial matrix of k×(k - 1) is randomly generated, and based on the MLWE method, an MLWE public key factor is obtained according to the polynomial matrix. According to the inverse element of the first polynomial and the MLWE public key factor, a target public key factor is generated, thereby obtaining a target public key. That is, by combining the difficult problem on the NTRU lattice and the difficult problem on the MLWE lattice, the target public key is obtained, the dimension of the lattice is reduced, and thus the size of the target public key is smaller. Furthermore, when the second device uses the target public key for encryption, the generated ciphertext has a smaller size, less computational complexity, and higher computational efficiency. In addition, it effectively resists attack methods such as chosen-plaintext attack during the ciphertext transmission process, improving data security.

[0138] The above embodiments introduce the key generation and encryption / decryption processes that can resist chosen-plaintext attack. Next, a method for key generation and encryption / decryption processes that can resist chosen-ciphertext attack provided by this application is introduced.

[0139] Please refer to Figure 3 , Figure 3The flowchart of another key generation method provided by the embodiments of the present application is as follows. Figure 3 As shown, the method of this embodiment is executed by an electronic device, which may be a computer, a tablet device, a smart wearable device, or a server, etc. The method includes the following steps.

[0140] 301. Obtain a first polynomial that has an inverse element.

[0141] 302. Randomly generate a polynomial matrix of k×(k - 1), where k is an integer greater than 1.

[0142] 303. Based on the MLWE problem, generate an MLWE public key and an MLWE private key according to the polynomial matrix; the MLWE public key includes an MLWE public key factor and the polynomial matrix.

[0143] 304. Generate a target public key factor according to the inverse element of the first polynomial and the MLWE public key factor.

[0144] 305. Compress and encode the target public key factor in a first compression manner to obtain a compressed target public key factor.

[0145] 306. Obtain a target public key according to the compressed target public key factor and the polynomial matrix.

[0146] 307. Compress and encode the MLWE private key in a first compression manner to obtain a compressed MLWE private key.

[0147] 308. Generate a first private key according to the first polynomial and the compressed MLWE private key.

[0148] 309. Perform a hash calculation on the target public key to obtain a hashed target public key.

[0149] 310. Obtain a first random number.

[0150] 311. Obtain a target private key according to the first private key, the hashed target public key, and the first random number.

[0151] 312. Determine that the target key pair includes a target public key and a target private key. The target public key is used to encrypt the first data to obtain a target ciphertext; the target private key is used to decrypt the target ciphertext to obtain the first data.

[0152] It should be noted that steps 301 - 308 and step 312 are similar to the steps of the above embodiment, and will not be elaborated here.

[0153] In practical applications, after generating the target public key, perform a hash calculation on the target public key to obtain a hashed target public key. Obtain the target private key through the obtained first random number, the first private key, and the hashed target public key.

[0154] In some embodiments, the first random number may be a 32-byte random number z, . The target private key sk may be: , where is the first private key, pk is the target public key, represents the hashed target public key, and z is the first random number.

[0155] In this embodiment, by processing the private key with the random number and the hashed public key, the final private key is obtained, making the private key not easily cracked. It can cope with attack methods such as chosen-ciphertext attack and improve data security.

[0156] Based on the target public key generated by the above Figure 3 illustrated embodiment, a data encryption / decryption method provided by an embodiment of the present application will be introduced below.

[0157] Please refer to Figure 4 , Figure 4 which is an interaction diagram of another data encryption / decryption method provided by an embodiment of the present application. As Figure 4 shown, in this embodiment, the device that stores the target private key is called the first device, and the first device may be the same as or different from the target key pair generation device. The execution device of the data encryption method is called the second device. The method provided in this embodiment includes the following steps.

[0158] 401. The second device obtains the target public key in the target key pair. Among them, the target key pair includes the target public key and the target private key. The target public key includes the target public key factor and a randomly generated polynomial matrix of k×(k - 1). The target public key factor is obtained through the following method: obtaining a first polynomial with an inverse element; based on the MLWE problem, generating an MLWE public key and an MLWE private key according to the polynomial matrix; the MLWE public key includes the MLWE public key factor and the polynomial matrix; generating the target public key factor according to the inverse element of the first polynomial and the MLWE public key factor; the target private key is obtained through the following method: generating the first private key according to the first polynomial and the compressed MLWE private key; performing a hash calculation on the target public key to obtain the hashed target public key; obtaining the first random number; obtaining the target private key according to the first private key, the hashed target public key, and the first random number.

[0159] 402. The second device encrypts the first data using the target public key to obtain the target ciphertext.

[0160] 403. The second device obtains the second random number.

[0161] 404. The second device obtains the first hash value according to the hashed target public key and the second random number.

[0162] 405. The second device generates a shared key based on the first hash value and the target ciphertext.

[0163] 406. The second device sends the target ciphertext and the shared key to the first device.

[0164] 407. The first device decrypts the target ciphertext using the target private key to obtain the second data.

[0165] 408. The first device performs a verification operation using the shared key to determine whether the verification is passed.

[0166] If yes, continue to execute step 409; if no, continue to execute step 410.

[0167] 409. The first device determines the second data as the first data.

[0168] It should be noted that steps 401 and 402 are similar to the steps in the above embodiments and will not be elaborated here.

[0169] In practical applications, the second device encrypts the first data using the target public key to obtain the target ciphertext. At the same time, according to the hashed target public key and the second random number, the first hash value is obtained, and a shared key is generated based on the first hash value and the target ciphertext. The second device sends the target ciphertext and the shared key to the first device together.

[0170] After receiving the target ciphertext and the shared key, the first device decrypts the target ciphertext using the target private key to obtain the second data. After verification through the shared key, the verification result can include passing the verification and failing the verification. Among them, if the verification passes, it means that the target ciphertext has not been tampered with during the transmission process, and the second data can be regarded as the first data. If the verification fails, it means that the target ciphertext may have been tampered with during the transmission process, and the second data is not the first data.

[0171] In some embodiments, the shared key can be obtained in the following manner:

[0172] The second device generates a 32-byte second random number m, and the generation process can be expressed as: , and calculates the hash value of the second random number m, which can be expressed as .

[0173] The second device generates the first hash value , where is a hash function, that is , can take 32 or 64. is the hashed target public key.

[0174] The second device generates the shared key K , where c is the target ciphertext.

[0175] Correspondingly, the process of the first device performing the verification operation using the shared key is as follows:

[0176] First, encode the key: , , . Decrypt the target ciphertext using the private key to obtain the second data .

[0177] The first device generates a second hash value , where is a hash function, that is , takes 32 or 64.

[0178] The first device encrypts the second data according to the second hash value to obtain the first ciphertext. Compare the first ciphertext with the target ciphertext. If they are the same, it means the target ciphertext has not been tampered with, and the verification passes. If they are different, it means the target ciphertext has been tampered with, and the verification fails. Further, if they are the same, output the shared key , otherwise, output . Thus, it can be determined whether the verification passes through the form of the output shared key.

[0179] In this embodiment, verification using the shared key can cope with attack methods such as chosen-ciphertext attack and improve data security.

[0180] Figure 5 FIG. is a schematic structural diagram of an electronic device provided by an embodiment of the present application. The electronic device can be the electronic device that executes the key generation method described above, or the first device or the second device. As Figure 5 shown, in practice, the electronic device includes: a memory 21 and a processor 22.

[0181] The memory 21 is used to store computer programs and can be configured to store various other data to support operations on the electronic device. Examples of these data include instructions for any application program or method operating on the electronic device, data structures, contact data, phone book data, messages, pictures, videos, etc.

[0182] The processor 22 is coupled to the memory 21 and is used to execute the computer programs in the memory 21 to implement the prompt word input method provided in the foregoing embodiment.

[0183] Further, as Figure 5 shown, the electronic device further includes: other components such as a communication component 23, a display 24, a power supply component 25, an audio component 26, etc.Figure 5 Only some components are schematically shown, which does not mean that the electronic device only includes Figure 5 the components shown. The electronic device of this embodiment can be implemented as a terminal device such as a desktop computer, a laptop computer, a smart phone or an IOT device, or can also be a server device such as a conventional server, a cloud server or a server array.

[0184] The above-mentioned memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random-Access Memory (SRAM), Electrically Erasable Programmable Read Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic memory, flash memory, a magnetic disk or an optical disc.

[0185] The above-mentioned communication component is configured to facilitate communication between the device where the communication component is located and other devices in a wired or wireless manner. The device where the communication component is located can access a wireless network based on a communication standard, such as a mobile communication network such as 2G, 3G, 4G / LTE, 5G, or a combination thereof. In an exemplary embodiment, the communication component receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel.

[0186] The above-mentioned display includes a screen, and the screen can include a Liquid Crystal Display (LCD) and a Touch Panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from a user. The touch panel includes one or more touch sensors to sense touches, swipes and gestures on the touch panel. The touch sensors can not only sense the boundaries of touch or swipe actions, but also detect the duration and pressure associated with the touch or swipe operation.

[0187] The above-mentioned power supply component supplies power to various components of the device where the power supply component is located. The power supply component can include a power management system, one or more power supplies, and other components associated with generating, managing and distributing power for the device where the power supply component is located.

[0188] The above audio component can be configured to output and / or input audio signals. For example, the audio component includes a microphone (MIC). When the device where the audio component is located is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode, the microphone is configured to receive external audio signals. The received audio signals can be further stored in a memory or transmitted via a communication component. In some embodiments, the audio component further includes a speaker for outputting audio signals.

[0189] Accordingly, an embodiment of the present application further provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it causes the processor to be able to implement the steps in the above method embodiments. Among them, the computer-readable storage medium can be implemented by volatile or non-volatile or a combination thereof, and can be removable or non-removable. Examples of computer-readable storage media include, but are not limited to, phase-change random access memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium.

[0190] Accordingly, an embodiment of the present application further provides a computer program product. The computer program product includes a computer program or instructions. When the computer program or instructions are executed by a processor, it causes the processor to be able to implement the steps in the above method embodiments. It should be understood that each process or a combination of multiple processes in the above method flow can be implemented by the computer program or instructions. In addition, these computer programs or instructions can be applied to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices, so that the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices can be used as devices to implement the corresponding functions in the above method embodiments.

[0191] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than limiting them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A key generation method, characterized in that, The method includes: Obtain a first polynomial that has an inverse element; Randomly generate a polynomial matrix of k×(k - 1), where k is an integer greater than 1; Based on the modular lattice MLWE problem, generate an MLWE public key and an MLWE private key according to the polynomial matrix; the MLWE public key includes an MLWE public key factor and the polynomial matrix; Generate a target public key factor according to the inverse element of the first polynomial and the MLWE public key factor; Obtain a target public key according to the target public key factor and the polynomial matrix; Obtain a target private key according to the MLWE private key and the first polynomial; Determine that the target key pair includes a target public key and a target private key. The target public key is used to encrypt first data to obtain a target ciphertext; the target private key is used to decrypt the target ciphertext to obtain the first data.

2. The method according to claim 1, characterized in that The generating a target public key factor according to the inverse element of the first polynomial and the MLWE public key factor includes: Obtain the target public key factor according to the following formula: where t is the target public key factor; is the MLWE public key factor; is the inverse element of the first polynomial.

3. The method according to claim 1, wherein The generating an MLWE public key and an MLWE private key based on the modular lattice MLWE problem according to the polynomial matrix includes: Based on a security parameter, randomly generate a second polynomial to generate an MLWE private key; Randomly generate a noise vector; Generate an MLWE public key according to the MLWE private key, the polynomial matrix, and the noise vector.

4. The method according to any one of claims 1 to 3, characterized in that, The obtaining a target private key according to the MLWE private key and the first polynomial includes: Compress and encode the MLWE private key in a first compression manner to obtain a compressed MLWE private key; Obtain a target private key according to the first polynomial and the compressed MLWE private key; The obtaining a target public key according to the target public key factor and the polynomial matrix includes: Compress and encode the target public key factor in the first compression manner to obtain a compressed target public key factor; Obtain the target public key according to the compressed target public key factor and the polynomial matrix.

5. The method according to claim 4, wherein The obtaining a target private key according to the first polynomial and the compressed MLWE private key includes: Generate a first private key according to the first polynomial and the compressed MLWE private key; Perform a hash calculation on the target public key to obtain a hashed target public key; Obtain a first random number; Obtain a target private key according to the first private key, the hashed target public key, and the first random number.

6. A data encryption method, characterized in that, The method includes: Obtain the target public key in the target key pair; wherein, the target key pair includes a target public key and a target private key, the target public key includes a target public key factor and a randomly generated polynomial matrix of k×(k - 1), and the target public key factor is obtained by the following method: Obtain a first polynomial with an inverse element; Based on the MLWE problem, generate an MLWE public key and an MLWE private key according to the polynomial matrix; The MLWE public key includes an MLWE public key factor and the polynomial matrix; Generate a target public key factor according to the inverse element of the first polynomial and the MLWE public key factor; The target private key is obtained according to the MLWE private key and the first polynomial; Encrypt the first data using the target public key to obtain a target ciphertext; Send the target ciphertext to a first device so that the first device decrypts the target ciphertext using the target private key.

7. The method according to claim 6, characterized in that, The target private key is obtained by the following method: Generate a first private key according to the first polynomial and the compressed MLWE private key; Perform a hash calculation on the target public key to obtain the hashed target public key; Obtain a first random number; Obtain the target private key according to the first private key, the hashed target public key, and the first random number; After encrypting the first data using the target public key to obtain a target ciphertext, it further includes: Obtain a second random number; Obtain a first hash value according to the hashed target public key and the second random number; Generate a shared key according to the first hash value and the target ciphertext; The sending the target ciphertext to the first device includes: Send the target ciphertext and the shared key to the first device so that the first device decrypts the target ciphertext using the target private key to obtain second data, and performs a verification operation through the shared key. If the verification passes, determine the second data as the target plaintext of the target ciphertext.

8. A data decryption method, characterized in that, The method includes: Receive the target ciphertext sent by a second device, where the target ciphertext is obtained by encrypting the first data using the target public key in the target key pair; the target key pair includes a target public key and a target private key, and the target public key is obtained according to a target public key factor and a randomly generated polynomial matrix of k×(k - 1); the target public key factor is obtained by the following method: Obtain a first polynomial with an inverse element; Based on the MLWE problem, generate an MLWE public key and an MLWE private key according to the polynomial matrix; The MLWE public key includes an MLWE public key factor and the polynomial matrix; Generate a target public key factor according to the inverse element of the first polynomial and the MLWE public key factor; The target private key is obtained according to the MLWE private key and the first polynomial; Decrypt the target ciphertext using the target private key to obtain the first data.

9. The method according to claim 8, wherein The receiving the target ciphertext sent by the second device includes: Receive the target ciphertext and the shared key sent by the second device; The decrypting the target ciphertext using the target private key to obtain the first data includes: Decrypt the target ciphertext using the target private key to obtain second data; Perform a verification operation through the shared key; If the verification is passed, determine the second data as the first data.

10. An electronic device, characterized in that, Comprising: A memory, a processor, and a communication interface; wherein, executable code is stored on the memory, and when the executable code is executed by the processor, the processor executes the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • NTRU encryption method based on R-LWE and security certification method thereof

    CN110545179A

  • Secret key packaging, encrypting and decrypting method based on NTRU grid

    CN116318695A