Grid-based anti-quantum cryptography distributed decryption method and system

By combining the grid-based anti-quantum cryptography and distributed decryption architecture, and using technologies such as staged decryption and key composite sharing, the computing complexity and security problems of the existing solutions are solved, and efficient and secure distributed decryption of anti-quantum cryptography is achieved, with good scalability and fault tolerance.

CN120238301APending Publication Date: 2025-07-01SHANGHAI DEAN FUTURE QUANTUM TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510389824.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The existing grid-based distributed decryption scheme for quantum cryptography has complex computing, large communication overhead and security challenges in private key share storage and management, and cannot effectively deal with the security threats brought by quantum computing.

Method used

Combining the lattice-based anti-quantum cryptography and distributed decryption architecture, the staged decryption, key composite sharing, fault-tolerant mechanism and quantum random number generation technology are adopted to generate keys through the combined encryption algorithm of LWE and SVP, and the encryption grid is dynamically generated. The private key is segmented using multiple secret sharing schemes, and a dynamic key allocation mechanism is introduced. The nodes cooperate to perform noise processing and grid decryption.

Benefits of technology

Improves security and attack resistance, optimizes performance, has good scalability and fault tolerance, and can effectively deal with large-scale distributed decryption tasks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238301A_ABST
    Figure CN120238301A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of lattice-based anti-quantum cryptography decryption, and particularly relates to a lattice-based anti-quantum cryptography distributed decryption method and system, and the method comprises the steps: S1, an encryption stage, namely encryption based on implicit lattices and multiple problems, S2, key sharing and distribution, and S3, staged distributed decryption. The lattice-based anti-quantum cryptography and a distributed decryption architecture are combined, a unique solution is provided, security threats caused by quantum computing can be effectively handled, performance optimization is achieved, and the security threats caused by quantum computing can be effectively handled through technical means such as staged decryption, secret key composite sharing, a fault-tolerant mechanism and quantum random number generation. The security and the anti-attack capability are improved, and good expansibility and fault-tolerant capability are achieved when a large-scale distributed decryption task is handled.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of lattice-based post-quantum cryptography decryption, and particularly to a distributed decryption method and system for lattice-based post-quantum cryptography. Background Art

[0002] With the development of quantum computers, traditional public-key cryptosystems are facing severe challenges. Lattice-based cryptosystems have become a hot topic in post-quantum cryptography research due to their resistance to quantum computing attacks. Traditional public-key cryptosystems, such as RSA, ECC, etc., are based on the problems of large integer factorization or discrete logarithm, and are vulnerable to quantum algorithm attacks.

[0003] Existing distributed decryption schemes for lattice-based post-quantum cryptography mostly rely on secure multi-party computation, which has problems of high computational complexity and large communication overhead. In addition, the storage and management of private key shares also face security challenges and cannot effectively cope with the security threats brought by quantum computing. Therefore, there is an urgent need to provide a distributed decryption method and system for lattice-based post-quantum cryptography. Summary of the Invention

[0004] The purpose of this part is to outline some aspects of the embodiments of the present invention and briefly introduce some preferred embodiments. Simplifications or omissions may be made in this part, as well as in the abstract and title of the present application, to avoid obscuring the purpose of this part, the abstract, and the title. However, such simplifications or omissions shall not be used to limit the scope of the present invention.

[0005] Therefore, the purpose of the present invention is to provide a distributed decryption method and system for lattice-based post-quantum cryptography, which combines lattice-based post-quantum cryptography with a distributed decryption architecture, provides a unique solution, can effectively cope with the security threats brought by quantum computing, and achieves optimization in performance. Through technical means such as staged decryption, key composite sharing, fault tolerance mechanism, and quantum random number generation, it not only improves security and anti-attack capabilities, but also has good scalability and fault tolerance in dealing with large-scale distributed decryption tasks.

[0006] To solve the above technical problems, according to one aspect of the present invention, the following technical solutions are provided:

[0007] A distributed decryption method for lattice-based post-quantum cryptography, comprising the following steps:

[0008] S1. Encryption stage - Encryption based on implicit lattices and multiple problems;

[0009] S11. Key generation:

[0010] S11-1 Use an encryption algorithm based on the combination of LWE and SVP to generate a key;

[0011] S11-2. Dynamically generate different encryption lattices for each encryption using a pseudo-random lattice generator;

[0012] S11-3. Encrypt the message through the LWE problem, and at the same time add the SVP problem to enhance the anti-quantum ability;

[0013] S12. Encryption process:

[0014] S12-1. Select the message M and the public key PK;

[0015] S12-2. Generate random noise and lattice elements using an implicit lattice structure to generate the encrypted ciphertext C;

[0016] S12-3. Transmit the ciphertext C to multiple nodes in the distributed decryption system;

[0017] S2. Key sharing and distribution;

[0018] S21. Composite key sharing;

[0019] S21-1. For the generated private key SK, use a multi-secret sharing scheme to split it into multiple fragments, and each fragment is held by one node;

[0020] S21-2. Each node holds the basic decryption key fragment and also holds additional auxiliary key fragments;

[0021] S22. Key distribution and storage;

[0022] S22-1. Each node stores multiple key fragments, which are used in different types of calculations for decryption, intermediate calculations, and verification;

[0023] S22-2. The system introduces a dynamic key distribution mechanism to dynamically adjust the number of key fragments held by the node according to the load and requirements of the current node;

[0024] S3. Phased distributed decryption.

[0025] As a preferred solution of a distributed decryption method of a lattice-based quantum-resistant cryptography according to the present invention, wherein: the step S3 includes the following decryption phases:

[0026] S31. Noise processing and preliminary decryption:

[0027] S31-1 Node selection:

[0028] Multiple nodes, at least t, extract noise parameters from the ciphertext C and perform noise elimination calculations to remove the noise introduced in the LWE encryption;

[0029] Each node processes different parts of the ciphertext and restores partial message information through local calculations;

[0030] Partial decryption of S31-2:

[0031] The node decrypts the encrypted noise part using its own key fragment to generate an intermediate result I1. The intermediate result I1 contains the structure of the preliminary decryption information but does not contain the complete plaintext;

[0032] S32, Lattice decryption and message recovery:

[0033] S32-1 Node cooperation:

[0034] In the second stage, at least t nodes cooperate to further decrypt the intermediate result I1 using the SVP-related key fragments stored on each node;

[0035] Each node uses its key fragment for lattice decryption to recover part of the plaintext information. The nodes exchange part of the calculation results through a protocol and gradually approach the complete message;

[0036] S32-2 Merge intermediate results:

[0037] Each node merges the decryption results from other nodes through the verification stage to finally form the complete plaintext information.

[0038] A decryption system for the above-mentioned distributed decryption method of lattice-based quantum-resistant cryptography, which includes: a central processing module, a key generation module, an encryption module, a distributed decryption module, a homomorphic computing module, and a communication module:

[0039] The central processing module is used to act as the central control unit of the system, receive the data information transmitted by each subordinate module, and control the coordinated work of each module;

[0040] The key generation module is connected to the central processing module and is used to generate and distribute the public key and the private key shares of homomorphic encryption;

[0041] The encryption module is connected to the central processing module and is used to encrypt the plaintext using the public key;

[0042] The distributed decryption module is connected to the central processing module and includes multiple decryption nodes, which are responsible for partial decryption and ciphertext aggregation, and are responsible for distributing the encrypted ciphertext to multiple computing nodes for parallel decryption. Each node only decrypts a part of the ciphertext and completes the entire decryption process through cooperation;

[0043] The homomorphic computing module is connected to the central processing module and is used to provide homomorphic addition and multiplication operations and support calculations in the ciphertext state.

[0044] As a preferred solution of a distributed decryption system for lattice-based quantum-resistant cryptography according to the present invention, wherein: a key management and distribution module is built in the central processing module, and the key management and distribution module is used to be responsible for key generation, sharing, distribution and management, ensuring the secure and efficient distribution of keys in the distributed decryption system, and preventing single-point attacks or key leakage.

[0045] As a preferred solution of a distributed decryption system for lattice-based quantum-resistant cryptography according to the present invention, wherein: the central processing module is connected to the communication module, and the communication module is used to generate an information transmission channel and link the central processing module, the key generation module, the encryption module, the distributed decryption module and the homomorphic computing module.

[0046] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0047] Combining lattice-based quantum-resistant cryptography with a distributed decryption architecture provides a unique solution, which can effectively address the security threats brought by quantum computing and optimize performance. Through technical means such as staged decryption, key compound sharing, fault tolerance mechanism and quantum random number generation, it not only improves security and anti-attack capabilities, but also has good scalability and fault tolerance when dealing with large-scale distributed decryption tasks. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the present invention will be described in detail below with reference to the drawings and specific embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts. Among them:

[0049] Figure 1 It is a schematic block diagram of the steps of the distributed decryption method of the present invention;

[0050] Figure 2 It is a schematic block diagram of the distributed decryption system of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0051] In order to make the above objects, features and advantages of the present invention more obvious and understandable, the specific embodiments of the present invention will be described in detail below with reference to the drawings.

[0052] Many specific details are set forth in the following description in order to provide a thorough understanding of the present invention. However, the present invention may be practiced in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0053] Secondly, the present invention will be described in detail with reference to the schematic diagrams. When describing the embodiments of the present invention in detail, for the convenience of explanation, the cross-sectional views showing the device structure will be enlarged locally not in accordance with the general scale, and the schematic diagrams are only examples and should not limit the scope of protection of the present invention herein. In addition, in actual production, three-dimensional spatial dimensions including length, width, and depth should be included.

[0054] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.

[0055] The present invention provides a distributed decryption method and system for lattice-based post-quantum cryptography. By combining homomorphic encryption and secret sharing technologies, efficient and secure post-quantum cryptography distributed decryption is achieved, providing new ideas for post-quantum cryptography, as well as optimizing homomorphic encryption algorithms and designing more efficient secret sharing schemes. Please refer to Figure 1-2 ;

[0056] A distributed decryption method for lattice-based post-quantum cryptography includes the following steps:

[0057] S1. Encryption stage - Encryption based on implicit lattices and multiple hard problems;

[0058] S11. Key generation:

[0059] S11-1. Use an encryption algorithm based on the combination of LWE and SVP to generate a key;

[0060] S11-2. Use a pseudo-random lattice generator to dynamically generate different encryption lattices for each encryption;

[0061] S11-3. Encrypt the message through the LWE problem and add the SVP problem to enhance the post-quantum resistance ability;

[0062] S12. Encryption process:

[0063] S12-1. Select a message M and a public key PK;

[0064] S12-2. Use the implicit lattice structure to generate random noise and lattice elements to generate the encrypted ciphertext C;

[0065] S12-3. Transmit the ciphertext C to multiple nodes in the distributed decryption system;

[0066] S2. Key sharing and distribution;

[0067] S21. Composite key sharing;

[0068] S21-1. For the generated private key SK, use a multiple secret sharing scheme to split it into multiple fragments, and each fragment is held by a node;

[0069] S21-2. Each node holds a basic decryption key fragment and also holds additional auxiliary key fragments;

[0070] S22. Key distribution and storage;

[0071] S22-1. Each node stores multiple key fragments, which are used in different types of calculations for decryption, intermediate calculations, and verification;

[0072] S22-2. The system introduces a dynamic key distribution mechanism to dynamically adjust the number of key fragments held by a node according to the load and requirements of the current node;

[0073] S3. Phased distributed decryption;

[0074] Step S3 includes the following decryption phases:

[0075] S31. Noise processing and preliminary decryption:

[0076] S31-1 Node selection:

[0077] Multiple nodes, at least t, extract noise parameters from the ciphertext C, perform noise elimination calculations to remove the noise introduced in LWE encryption;

[0078] Each node processes different parts of the ciphertext and restores partial message information through local calculations;

[0079] S31-2 Partial decryption:

[0080] The node uses its own key fragment to decrypt the encrypted noise part, generating an intermediate result I1. The intermediate result I1 contains the structure of the preliminary decryption information but does not contain the complete plaintext;

[0081] S32. Lattice decryption and message recovery:

[0082] S32-1 Node cooperation:

[0083] In the second stage, at least t nodes cooperate to further decrypt the intermediate result I1 using the SVP-related key fragments stored on each node;

[0084] Each node uses its key fragment for lattice decryption to recover partial plaintext information. The nodes exchange partial calculation results through a protocol and gradually approach the complete message;

[0085] S32-2 Merging intermediate results:

[0086] Each node merges the decryption results from other nodes through a verification phase to finally form the complete plaintext information;

[0087] A system for a distributed decryption method of lattice-based quantum-resistant cryptography, comprising a central processing module, a key generation module, an encryption module, a distributed decryption module, a homomorphic computing module, and a communication module:

[0088] The central processing module is used to execute as the central control unit of the system, receive data information transmitted by each subordinate module, and control the collaborative work of each module;

[0089] The key generation module, connected to the central processing module, is used to execute the generation and distribution of public keys and private key shares for homomorphic encryption;

[0090] The encryption module, connected to the central processing module, is used to execute the encryption of plaintext using the public key;

[0091] The distributed decryption module, connected to the central processing module, includes multiple decryption nodes, responsible for partial decryption and ciphertext aggregation, and is responsible for distributing the encrypted ciphertext to multiple computing nodes for parallel decryption. Each node only decrypts a part of the ciphertext, and completes the entire decryption process through cooperation;

[0092] The homomorphic computing module, connected to the central processing module, is used to execute the provision of homomorphic addition and multiplication operations, supporting calculations in the ciphertext state;

[0093] The central processing module is built-in with a key management and distribution module, which is used to execute the generation, sharing, distribution, and management of keys, ensure the secure and efficient distribution of keys in the distributed decryption system, and prevent single-point attacks or key leakage;

[0094] The central processing module is connected to the communication module, and the communication module is used to execute the generation of an information transmission channel, linking the central processing module, the key generation module, the encryption module, the distributed decryption module, and the homomorphic computing module;

[0095] Although the present invention has been described above with reference to the embodiments, various improvements can be made to it and its components can be replaced with equivalents without departing from the scope of the present invention. In particular, as long as there is no structural conflict, the various features in the embodiments disclosed in the present invention can be combined with each other in any way, and the exhaustive description of these combinations is not given in this specification only for the sake of saving space and resources. Therefore, the present invention is not limited to the specific embodiments disclosed in the text, but includes all technical solutions falling within the scope of the claims.

Claims

1. A distributed decryption method for lattice-based quantum-resistant cryptography, characterized in that: Includes the following steps: S1, encryption phase - encryption based on implicit lattice and multiple puzzles; S11. Key generation: S11-1 generates keys using an encryption algorithm based on a combination of LWE and SVP; S11-2, using a pseudo-random grid generator to dynamically generate a different encryption grid for each encryption; S11-3, encrypt the message through the LWE problem, and add the SVP problem to enhance the quantum resistance; S12, encryption process: S12-1. Select message M and public key PK; S12-2, using the implicit lattice structure to generate random noise and lattice elements, and generate encrypted ciphertext C; S12-3, transmitting the ciphertext C to multiple nodes in the distributed decryption system; S2, key sharing and distribution; S21, composite key sharing; S21-1. For the generated private key SK, a multiple secret sharing scheme is used to divide it into multiple fragments, each fragment holds a node; S21-2. Each node holds a basic decryption key fragment and an additional auxiliary key fragment; S22, key distribution and storage; S22-1. Each node stores multiple key fragments, which are used in different types of calculations for decryption, intermediate calculations, and verification; S22-2, the system introduces a dynamic key distribution mechanism to dynamically adjust the number of key fragments held by the node according to the current node load and demand; S3, staged distributed decryption.

2. A distributed decryption method for lattice-based quantum-resistant cryptography according to claim 1, characterized in that: The step S3 includes the following decryption stages: S31, Noise processing and preliminary decryption: S31-1 Node Selection: Multiple nodes, at least t, extract noise parameters from the ciphertext C and perform noise elimination calculations to remove the noise introduced in the LWE encryption; Each node processes different parts of the ciphertext and restores part of the message information through local calculations; S31-2 partial decryption: The node uses its own key fragment to decrypt the encrypted noise part and generates an intermediate result I1, which contains the structure of the preliminary decrypted information but does not contain the complete plaintext; S32, lattice decryption and message recovery: S32-1 Node Collaboration: In the second stage, at least t nodes cooperate to further decrypt the intermediate result I1 using the SVP-related key fragment stored on each node; Each node uses its key fragment to perform lattice decryption and recover part of the plaintext information. Nodes exchange partial calculation results through the protocol and gradually approach the complete message. S32-2 Merge intermediate results: Each node merges the decryption results from other nodes through the verification phase to finally form the complete plaintext information.

3. A decryption system applied to the distributed decryption method of lattice-based quantum-resistant cryptography according to claim 1-2, characterized in that: include: Central processing module, key generation module, encryption module, distributed decryption module, homomorphic computing module and communication module: The central processing module is used to act as the central control unit of the system, receive data information transmitted by each subordinate module, and control the coordinated work of each module; A key generation module, connected to the central processing module, for executing generation and distribution of public keys and homomorphically encrypted private key shares; An encryption module, connected to the central processing module, for executing encryption of plain text using a public key; The distributed decryption module is connected to the central processing module and includes multiple decryption nodes. It is responsible for partial decryption and ciphertext aggregation, and is responsible for distributing the encrypted ciphertext to multiple computing nodes for parallel decryption. Each node only decrypts part of the ciphertext, and the entire decryption process is completed through collaboration; The homomorphic computing module is connected to the central processing module and is used to perform homomorphic addition and multiplication operations and support calculations in the encrypted state.

4. A system for distributed decryption of lattice-based quantum-resistant cryptography according to claim 3, characterized in that: The central processing module has a built-in key management and distribution module, which is used to execute the generation, sharing, distribution and management of keys, ensure the safe and efficient distribution of keys in the distributed decryption system, and prevent single point attacks or key leakage.

5. A system for distributed decryption of lattice-based quantum-resistant cryptography according to claim 4, characterized in that: The central processing module is connected to the communication module, and the communication module is used to execute the generation of an information transmission channel, linking the central processing module, the key generation module, the encryption module, the distributed decryption module and the homomorphic computing module.