Key sampling system and method based on lattice cryptographic algorithm

Through the random sequence generation method of mask index and boundary variable control, the problem of high sampling rejection rate and slow boundary convergence during key sampling of grid cryptography algorithm is solved, and efficient key generation is achieved, suitable for IoT terminals.

CN120263402APending Publication Date: 2025-07-04NANJING UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510426878.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The existing grid cryptography algorithms have problems such as high sampling rejection rate and slow sampling boundary convergence during key sampling. Especially when high dimensional grid spatial parameters are extremely complex, and software implementation is difficult to meet the energy efficiency requirements of resource-constrained scenarios such as IoT terminals.

Method used

The random sequence generation method based on mask index and boundary variables is adopted. Through the mask index module and the random sequence generation module, the Hamming weight distribution of the random sequence is dynamically controlled, and a random sequence that meets the requirements is generated, reducing the probability of rejecting sampling and improving sampling efficiency.

Benefits of technology

It significantly reduces the sampling rejection rate, improves sampling efficiency, reduces computing time and energy consumption, and is suitable for resource-constrained IoT terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263402A_ABST
    Figure CN120263402A_ABST
Patent Text Reader

Abstract

The invention provides a secret key sampling system and method based on a lattice cryptographic algorithm, and the system comprises an obtaining module which is configured to obtain the parameter configuration of a target sequence; the mask index module is configured to execute a mask index operation according to the third boundary variable if the third boundary variable is greater than 0, and obtain a mask index value; the random sequence generation module is configured to select a corresponding boundary variable updating unit to execute variable parameter updating operation on the variable parameter according to the mask index value and the boundary variable so as to obtain a variable parameter updating value and perform assignment on the random sequence according to the selected boundary variable updating unit; if the third boundary variable update value is larger than 0, mask index operation and variable parameter update operation are repeatedly executed according to the variable parameter update value until the third boundary variable update value is smaller than or equal to 0, and a target random sequence is generated; the problems that the sampling rejection rate is high and the sampling boundary convergence is slow in the secret key sampling process of an existing lattice cryptographic algorithm are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information and communication technologies, and in particular, to a key sampling system and method based on lattice cryptography algorithms. Background Art

[0002] In the current field of information security, the rapid development of quantum computing technology is driving Post-Quantum Cryptography (PQC) to become the focus of research. Lattice cryptography algorithms based on the Learning With Errors (LWE) problem, with their theoretical advantages in resisting quantum attacks, are on the one hand widely regarded as the core technical route for constructing encryption systems (such as key exchange and digital signatures) in the post-quantum era; on the other hand, their mathematical structure characteristics also provide key theoretical support for Fully Homomorphic Encryption (FHE) - through the lattice basis hard assumption constructed by the LWE problem, researchers have realized arbitrary complex computing functions on encrypted data, promoting the leap of fully homomorphic encryption from theory to engineering implementation. Although these two directions have different application scenarios (the former focuses on quantum-resistant secure communication, and the latter focuses on direct ciphertext calculation), they both use lattice cryptography as the mathematical basis and have become the forefront technical pillars for coping with quantum threats and data privacy challenges.

[0003] The keys of lattice cryptography algorithms are usually sampled in ways such as centered binomial distribution and constant Hamming weight distribution. For example, the lattice cryptography algorithms NTRU and Scloud+ use constant Hamming weight distribution to sample private keys and generate random numbers that meet specific requirements using their unique statistical characteristics. Taking Scloud+ as an example, its constant Hamming weight distribution sampling usually takes a lot of time when generating l data. Each time sampling is performed, the system needs to compare the sampled data one by one to ensure that the final result meets the condition of "l - 2h zeros, h ones, and h -1s". In addition, the existing solutions use fixed-length random indexes, which leads to a high rejection sampling probability, so often several times more sampling needs to be performed to obtain a valid sequence.

[0004] First, at the algorithm level, the constant Hamming weight distribution sampling requires precise control of the Hamming weight distribution characteristics of the random sequence. However, the currently adopted methods based on rejection sampling or combinatorial number calculation have inherent defects such as slow convergence rate of probability distribution and high computational complexity. Especially when dealing with high-dimensional lattice space parameters, the asymptotic time complexity of the existing sampling algorithms is extremely high, severely restricting the key generation efficiency. Second, at the implementation architecture level, most of the current solutions are implemented in software using general-purpose processors, resulting in a mismatch between the serial execution mode and the inherent parallel characteristics of the sampling process, making it impossible to fully utilize the hardware computing resources; the frequent random access operations of the storage subsystem are incompatible with the processor cache architecture, resulting in a large number of memory access delays; the energy efficiency ratio of software implementation is difficult to meet the application requirements of resource-constrained scenarios such as Internet of Things terminals. Summary of the Invention

[0005] This application provides a key sampling system and method based on lattice cryptography algorithms to solve the technical problems of high sampling rejection rate and slow convergence of sampling boundaries in the current lattice cryptography algorithms during the sampling key process.

[0006] The first aspect of this application provides a key sampling system based on lattice cryptography algorithms, including:

[0007] An acquisition module, an initialization module, a mask index module, and a random sequence generation module that are electrically connected;

[0008] The acquisition module is configured to acquire the parameter configuration of the target sequence;

[0009] The initialization module is configured to perform initialization processing on the variable parameters according to the parameter configuration; the variable parameters include: a counting variable and a boundary variable; the boundary variable includes: a first boundary variable, a second boundary variable, and a third boundary variable, and the first boundary variable, the second boundary variable, and the third boundary variable respectively represent the index boundaries of elements 0, 1, and -1;

[0010] The mask index module is configured to, if the third boundary variable is greater than 0, perform a mask index operation according to the third boundary variable to obtain a mask index value;

[0011] The random sequence generation module is configured to, according to the mask index value and the boundary variable, select the corresponding boundary variable update unit to perform a variable parameter update operation on the variable parameters, obtain a variable parameter update value, and assign values to the random sequence according to the selected boundary variable update unit; the length of the random sequence is equal to the length of the target sequence;

[0012] If the updated value of the third boundary variable is greater than 0, the masking index operation and the variable parameter update operation are repeatedly executed according to the updated value of the variable parameter until the updated value of the third boundary variable is less than or equal to 0, and a target random sequence is generated; the target random sequence is composed of elements 0, 1, and -1, and the target random sequence is used to generate a key.

[0013] In some embodiments, the parameter configuration includes: the number of elements 1 and -1 in the target sequence and the length of the target sequence.

[0014] In some embodiments, the initialization module is further configured to:

[0015] Set the count variable to 0;

[0016] According to the parameter configuration, set the first boundary variable, the second boundary variable, and the third boundary variable to a first parameter, a second parameter, and a third parameter;

[0017] Wherein, the first parameter is l - 2h; the second parameter is l - h; the third parameter is l;

[0018] In the formula, l is the length of the target sequence, and h is the number of elements 1 and -1 in the target sequence.

[0019] In some embodiments, the masking index module is further configured to:

[0020] If the third boundary variable is greater than 0, determine a mask according to the third boundary variable;

[0021] Obtain a random index value according to the length of the target sequence; the random index value is composed of elements 0 and 1;

[0022] Perform a bitwise AND operation according to the mask and the random index value to obtain a masking index value.

[0023] In some embodiments, the random sequence generation module is further configured to:

[0024] According to the masking index value and the boundary variable, determine whether the first boundary variable is greater than the masking index value. If so, decrement the first boundary variable, the second boundary variable, and the third boundary variable by 1, increment the count variable by 1, and assign 0 to the element at the determined position in the random sequence; the determined position is determined by the count variable;

[0025] If not, determine whether the second boundary variable is greater than the masking index value. If so, decrement the second boundary variable and the third boundary variable by 1, increment the count variable by 1, and assign 1 to the element at the determined position in the random sequence;

[0026] Otherwise, determine whether the third boundary variable is greater than the mask index value. If so, decrement the third boundary variable by 1, increment the count variable by 1, and assign the element at the determined position in the random sequence to -1.

[0027] In some embodiments, after the step of determining whether the third boundary variable is greater than the mask index value, the method further includes:

[0028] Otherwise, determine whether the third boundary variable is greater than 0;

[0029] If so, repeatedly execute the mask index operation and the variable parameter update operation according to the variable parameter until the third boundary variable is less than or equal to 0, and generate a target random sequence.

[0030] In some embodiments, the mask index module includes:

[0031] An input AND gate, several input OR gates, and a first data selector that are electrically connected;

[0032] The input OR gates are configured to receive third boundary variable signals;

[0033] The first data selector is configured to determine a mask according to the third boundary variable signal;

[0034] The input AND gate is configured to perform a bitwise AND operation according to the mask and the random index value to obtain a mask index value.

[0035] In some embodiments, if the number of elements 1 and -1 in the target sequence is not equal to one quarter of the length of the target sequence, the initialization module includes:

[0036] An initialization unit, where the initialization unit includes: a first shifter and two first subtractors that are electrically connected; the initialization unit is configured to set the first boundary variable, the second boundary variable, and the third boundary variable to a first parameter, a second parameter, and a third parameter according to the parameter configuration;

[0037] The random sequence generation module includes:

[0038] A register unit, a comparison unit, and a data selection unit that are electrically connected;

[0039] The register unit includes: three second data selectors, three second subtractors, and three registers that are electrically connected; the register unit is configured to store the first boundary variable, the second boundary variable, and the third boundary variable;

[0040] The comparison unit includes three comparators connected electrically; the comparison unit is configured to compare the first boundary variable, the second boundary variable, and the third boundary variable with the mask index value to generate a comparison result signal;

[0041] The data selection unit includes three third data selectors connected electrically, and the third data selector is configured to determine an output result according to the comparison result signal; the output result includes 00, 01, and 11; the target random sequence is composed of the output results.

[0042] In some embodiments, if the number of elements 1 and -1 in the target sequence is equal to one-fourth of the length of the target sequence, the initialization unit includes:

[0043] Two second shifters and an adder connected electrically.

[0044] A second aspect of the present application provides a key sampling method based on a lattice cryptography algorithm, which is applied to a key sampling system based on a lattice cryptography algorithm described in any one of the above first aspects, and includes:

[0045] Obtain the parameter configuration of the target sequence;

[0046] According to the parameter configuration, perform an initialization process on the variable parameters; the variable parameters include: a counting variable and a boundary variable; the boundary variable includes: a first boundary variable, a second boundary variable, and a third boundary variable, and the first boundary variable, the second boundary variable, and the third boundary variable respectively represent the index boundaries of elements 0, 1, and -1;

[0047] If the third boundary variable is greater than 0, perform a mask index operation according to the third boundary variable to obtain a mask index value;

[0048] According to the mask index value and the boundary variable, select a corresponding boundary variable update unit to perform a variable parameter update operation on the variable parameters, obtain a variable parameter update value, and assign values to the random sequence according to the selected boundary variable update unit; the length of the random sequence is equal to the length of the target sequence;

[0049] If the updated value of the third boundary variable is greater than 0, repeat the mask index operation and the variable parameter update operation according to the variable parameter update value until the updated value of the third boundary variable is less than or equal to 0, and generate a target random sequence; the target random sequence is composed of elements 0, 1, and -1, and the target random sequence is used to generate a key.

[0050] The present application provides a key sampling system and method based on lattice cryptography algorithms. The system includes: an acquisition module, an initialization module, a mask index module, and a random sequence generation module that are electrically connected. The acquisition module is configured to acquire parameter configurations of a target sequence. The initialization module is configured to perform initialization processing on variable parameters according to the parameter configurations. The variable parameters include: a count variable and boundary variables. The boundary variables include: a first boundary variable, a second boundary variable, and a third boundary variable. The first boundary variable, the second boundary variable, and the third boundary variable respectively represent index boundaries of elements 0, 1, and -1. The mask index module is configured to, if the third boundary variable is greater than 0, perform a mask index operation according to the third boundary variable to obtain a mask index value. The random sequence generation module is configured to, according to the mask index value and the boundary variables, select corresponding boundary variable update units to perform variable parameter update operations on the variable parameters, obtain variable parameter update values, and assign values to the random sequence according to the selected boundary variable update units. The length of the random sequence is equal to the length of the target sequence. If the updated value of the third boundary variable is greater than 0, the mask index operation and the variable parameter update operation are repeatedly performed according to the variable parameter update values until the updated value of the third boundary variable is less than or equal to 0, and a target random sequence is generated. The target random sequence is composed of elements 0, 1, and -1, and the target random sequence is used to generate a key to improve the calculation speed and reduce energy consumption in the process of sampling keys by unstructured lattice cryptography algorithms. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to more clearly illustrate the technical solutions of the present application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, for those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.

[0052] Figure 1 Process diagram of the key sampling system and method based on lattice cryptography algorithms in the present application;

[0053] Figure 2 Structural schematic diagram of the key sampling system and method based on lattice cryptography algorithms in the present application;

[0054] Figure 3 Structural schematic diagram of the mask index module in the present application;

[0055] Figure 4 Structural schematic diagram of the initialization module and the random sequence generation module in an embodiment of the present application;

[0056] Figure 5 Structural schematic diagram of the initialization module and the random sequence generation module in another embodiment of the present application.

[0057] Description of reference numerals:

[0058] 1-acquisition module; 2-initialization module; 21-initialization unit; 211-first shifter; 212-first subtractor; 213-second shifter; 214-adder; 3-mask index module; 31-input AND gate; 32-input OR gate; 33-first data selector; 4-random sequence generation module; 41-register unit; 411-second data selector; 412-second subtractor; 413-register; 42-comparison unit; 421-comparator; 43-data selection unit; 431-third data selector. DETAILED DESCRIPTION

[0059] In order to enable those skilled in the art to better understand the technical solutions in the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without creative work should fall within the scope of protection of the present application.

[0060] Since in some technologies, the lattice cryptographic algorithm has slow calculation speed and high energy consumption in the key sampling process, in order to solve this technical problem, the present application provides a key sampling system and method based on the lattice cryptographic algorithm. The key sampling system and method based on the lattice cryptographic algorithm are described below:

[0061] For example, in the current field of information security, with the continuous development of quantum computing technology, post-quantum cryptography has rapidly emerged and become a research hotspot. In this context, lattice cryptography algorithms based on the Learning With Errors (LWE) problem have attracted much attention as the core technical route to combat quantum computing attacks. Scloud+, as a representative solution in this field, is a lattice key encapsulation mechanism based on the LWE problem. As a highly innovative key encapsulation mechanism, Scloud+ is expected to become one of China's future post-quantum cryptography standards.

[0062] Scloud+ uses a constant Hamming weight distribution for private key sampling and generates random numbers that meet specific requirements by leveraging its unique statistical properties. This innovative measure not only enhances the security of the encryption process but also significantly improves the resistance to quantum computing attacks. The constant Hamming weight distribution requires that the elements in the data sample only contain 0, 1, and -1, and the number of 1s and -1s must be the same. Taking a sequence of length l (or an array containing l elements) as an example, the sequence needs to contain l - 2h 0s, and h 1s and -1s each to meet the requirements of the constant Hamming weight distribution. Existing constant Hamming weight distribution sampling (such as the open-source version of Scloud+) usually consumes a large amount of time when generating l data. Each time of sampling, the system needs to compare the sampled data one by one to ensure that the final result meets the condition of "l - 2h 0s, h 1s, and h -1s". In addition, the existing scheme uses a fixed-length random index, which leads to a high rejection sampling probability, so often several times more sampling is required to obtain a valid sequence.

[0063] However, in the process of moving towards practical application, the key encapsulation mechanism of Scloud+ faces two major challenges. The first is at the algorithm level: Constant Hamming distribution sampling requires precise control of the Hamming weight distribution characteristics of the random sequence. However, traditional methods based on rejection sampling or combinatorial number calculation have inherent defects such as slow convergence speed of probability distribution and high computational complexity. Especially when dealing with high-dimensional lattice space parameters, the asymptotic time complexity of existing sampling algorithms is extremely high, severely restricting the key generation efficiency. The second is at the implementation architecture level: Most current schemes are implemented using general-purpose processors in software, which leads to three prominent contradictions. First, the serial execution mode does not match the inherent parallel characteristics of the sampling process, making the hardware computing resources unable to be fully utilized; second, the frequent random access operations of the storage subsystem are incompatible with the processor cache architecture, resulting in a large amount of memory access latency; finally, the energy efficiency ratio of software implementation is difficult to meet the application requirements of resource-constrained scenarios such as Internet of Things terminals.

[0064] As Figure 2 shown, it is the structural schematic diagram of the key sampling system based on lattice cryptography algorithm in this application.

[0065] To address the above problems, the first aspect of this application provides a key sampling system based on lattice cryptography algorithm, including:

[0066] An acquisition module 1, an initialization module 2, a masked index module 3, and a random sequence generation module 4 that are electrically connected.

[0067] As Figure 1 shown, it is the process diagram of the key sampling system based on lattice cryptography algorithm in this application.

[0068] Acquisition module 1, configured to acquire the parameter configuration of the target sequence; the parameter configuration includes: the number h of elements 1 and -1 in the target sequence and the length l of the target sequence.

[0069] Initialization module 2, configured to initialize the variable parameters according to the parameter configuration; the variable parameters include: a counting variable i and boundary variables; the boundary variables include: a first boundary variable A second boundary variable A third boundary variable The first boundary variable A second boundary variable A third boundary variable respectively represent the index boundaries of elements 0, 1, and -1.

[0070] Specifically, the initialization module 2 is further configured to:

[0071] Set the counting variable i to 0; according to the parameter configuration, set the first boundary variable A second boundary variable A third boundary variable as the first parameter is l - 2h; the second parameter is l - h; the third parameter is l; where, the first parameter is l - 2h; the second parameter is l - h; the third parameter is l.

[0072] In the formula, l is the length of the target sequence, and h is the number of elements 1 and -1 in the target sequence.

[0073] Mask index module 3, configured to perform a mask index operation according to the third boundary variable to obtain a mask index value if the third boundary variable is greater than 0; when perform a mask index operation.

[0074] Specifically, the mask index module 3 is further configured to:

[0075] If the third boundary variable is greater than 0, determine a mask according to the third boundary variable; It is indicated that the mask mask consists of ones, is the ceiling symbol. For example, when then at this time, the binary representation of the mask is mask = 0b1111.

[0076] Obtain a random index value according to the length of the target sequence; the random index value consists of elements 0 and 1; idx full is the full-size random index, that is, the random index value, and its bit width is Parse(Rnd out ) is the output of a pseudo-random function, which is a string of random binary numbers composed of elements 0 and 1. Each time the above steps are executed, a random value of full assigned bits is assigned to idx.

[0077] According to the mask and the random index value, perform a bitwise AND operation to obtain a mask index value. The mask index value is obtained by performing a bitwise AND operation on the random index value idx full and the mask mask. Using the mask index can effectively limit the maximum value of the index, thereby reducing the rejection rate of sampling to improve sampling efficiency. Through calculation, with the proposed mask index, the theoretical rejection rate of sampling is 25%, which is much smaller than the rejection rate of the existing scheme.

[0078] Exemplarily, for example, if 600 elements need to be sampled for the secret key, without using the mask index value for limitation, it may be necessary to collect more than 1000 times to complete the sampling of 600 elements. If the mask index value provided by this application is used for limitation, on average, 750 times of collection are required to complete the sampling work of 600 elements, greatly improving the sampling efficiency.

[0079] The random sequence generation module 4 is configured to select a corresponding boundary variable update unit according to the mask index value and the boundary variable to perform a variable parameter update operation on the variable parameter, obtain a variable parameter update value, and assign a value to the random sequence according to the selected boundary variable update unit; the length of the random sequence is equal to the length of the target sequence; it can be understood that the random sequence is a blank sequence with the same length as the target sequence, and the boundary variable update unit assigns a value to it. Among them, the i-th element s[i] of the random sequence s is respectively assigned 0, 1, and -1.

[0080] If the third boundary variable update value is greater than 0, then repeat the mask index operation and the variable parameter update operation according to the variable parameter update value until the third boundary variable update value is less than or equal to 0, and generate a target random sequence; the target random sequence is composed of elements 0, 1, and -1, and the target random sequence is used to generate a secret key.

[0081] Specifically, the random sequence generation module 4 is further configured to:

[0082] According to the mask index value idx mask and the boundary variable, determine whether the first boundary variable is greater than the mask index value idx mask , if so, then use the first boundary variable as the second boundary variable Third boundary variable Decrease by 1, increment the counting variable i by 1, and assign the element at the determination position in the random sequence to 0; the determination position is determined by the counting variable i; the i-th element s[i] of the random sequence s is respectively assigned 0.

[0083] Exemplarily, if then s[i] = 0,

[0084] If not, determine whether the second boundary variable is greater than the mask index value. If so, then decrease the second boundary variable Third boundary variable Decrease by 1, increment the counting variable i by 1, and assign the element at the determination position in the random sequence to 1; the i-th element s[i] of the random sequence s is respectively assigned 1.

[0085] Exemplarily, if then s[i] = 1,

[0086] If not, determine whether the third boundary variable is greater than the mask index value. If so, then decrease the third boundary variable by 1, increment the counting variable by 1, and assign the element at the determination position in the random sequence i to -1. The i-th element s[i] of the random sequence s is respectively assigned -1.

[0087] Exemplarily, if idx mask <C nt-1 , then s[i] = -1,

[0088] After the step of determining whether the third boundary variable is greater than the mask index value, the following is further included:

[0089] If not, determine whether the third boundary variable is greater than 0; if so, repeat the mask index operation and the variable parameter update operation according to the variable parameter until the third boundary variable is less than or equal to 0, and generate a target random sequence. If the obtained third boundary variable or the updated value of the third boundary variable is greater than 0, then abandon this sampling, obtain a new mask index value and complete the subsequent steps. Assign all elements 0, 1, -1 to the random sequence to obtain a target random sequence and complete the acquisition of the key.

[0090] The present application provides a key sampling system based on lattice cryptography algorithms, which can avoid comparing the sampled data during each sampling and greatly reduce the probability of rejection sampling through dynamic bit-width indexing, thereby improving the sampling efficiency. It mainly solves the problems of high sampling rejection rate and slow convergence of sampling boundaries in the sampling process of the constant Hamming weight distribution in unstructured lattice cryptography algorithms, especially in Scloud+.

[0091] The present application provides a key sampling system and method based on lattice cryptography algorithms. The specific algorithm is as follows:

[0092] Input: The number of 1 / -1 in the target sequence: h, the length of the target sequence: l

[0093] Output: The sampled target random sequence: s = {0, 1, -1} l

[0094]

[0095]

[0096] As Figure 3 shown, it is a schematic structural diagram of the mask index module in the present application.

[0097] In this embodiment, the mask index module 3 includes:

[0098] An input AND gate 31 electrically connected to several input OR gates 32 and a first data selector 33; the input OR gates 32 are configured to receive the third boundary variable signal; the first data selector 33 is configured to determine the mask according to the third boundary variable signal; the input AND gate 31 is configured to perform a bitwise AND operation according to the mask and the random index value to obtain the mask index value.

[0099] Exemplarily, the boundary variable That is, the maximum bit-width of the boundary variable is determined by l. Taking the bit-width of l equal to 4 as an example, the device for calculating the mask mask is as Figure 3 shown. This part includes a two-input OR gate, a three-input OR gate, a four-input OR gate, and four two-input data selectors. The highest bit of the input signal directly controls the first data selector, and the output result constitutes the highest bit of mask. The highest bit and the second-highest bit of the input signal are ORed and then control the second data selector, and the output result constitutes the second-highest bit of mask. And so on, until the lowest bit of the input signal.

[0100] As Figure 4 shown, it is a schematic structural diagram of the initialization module and the random sequence generation module in an embodiment of the present application.

[0101] In this embodiment, if the number of elements 1 and -1 in the target sequence is not equal to one-fourth of the length of the target sequence, the initialization module 2 includes:

[0102] An initialization unit 21, the initialization unit includes: a first shifter 211 and two first subtractors 212 connected electrically; the initialization unit 21 is configured to, according to the parameter configuration, set the first boundary variable The second boundary variable The third boundary variable To the first parameter as l - 2h; the second parameter as l - h; the third parameter as l; the random sequence generation module 4 includes: a register unit 41, a comparison unit 42, and a data selection unit 43 connected electrically; the register unit 41 includes: three second data selectors 411, three second subtractors 412, and three registers 413 connected electrically; the register unit 41 is configured to store the first boundary variable The second boundary variable The third boundary variable The comparison unit 42 includes: three comparators 421 connected electrically; the comparison unit 42 is configured to compare the first boundary variable The second boundary variable The third boundary variable With the mask index value idx mask To generate a comparison result signal; the comparison result signal is used to control the data selection unit 43 to generate 00 or 01 or 11. The data selection unit 43 includes: three third data selectors 431 connected electrically, and the third data selector 431 is configured to determine the output result according to the comparison result signal; the output result includes 00, 01, 11; the target random sequence is composed of the output result.

[0103] The devices of the initialization module and the random sequence generation module are as Figure 4 Shown. For simplicity, the state machine and the circuit of the control signal are omitted in this part. When h ≠ l / 4, this part includes a shifter, five subtractors, four two-input data selectors, two three-input data selectors, three registers, three comparators, and a two-input AND gate. One shifter cooperating with two subtractors can expand the input signals l and h into the initial values of the boundary variables . After passing through three data selectors, the three initial values are recorded in three registers. When sampling, the data in the registers is decremented by 1 every cycle. The input AND gate performs a bitwise AND operation on the full-size random index idx full And the mask mask to obtain the mask index idx mask . The mask index idx maskCompare with three boundary variables one by one through three comparators to determine whether the final output is 00, 01 or 11, where 11 is the two's complement form of -1.

[0104] As Figure 5 shown, it is a schematic structural diagram of the initialization module and the random sequence generation module in another embodiment of the present application.

[0105] In this embodiment, if the number of elements 1 and -1 in the target sequence is equal to one-fourth of the length of the target sequence, the initialization unit 21 includes:

[0106] Two second shifters 213 and an adder 214 that are electrically connected. Compared with the circuit structure when h≠l / 4 through the above structure, the area of the circuit structure is reduced, thereby reducing the cost of the circuit structure.

[0107] The second aspect of the present application provides a key sampling method based on lattice cryptography algorithm, which is applied to a key sampling system based on lattice cryptography algorithm described in any of the above embodiments, including:

[0108] Obtain the parameter configuration of the target sequence;

[0109] According to the parameter configuration, initialize the variable parameters; the variable parameters include: a counting variable and boundary variables; the boundary variables include: a first boundary variable, a second boundary variable, and a third boundary variable, and the first boundary variable, the second boundary variable, and the third boundary variable respectively represent the index boundaries of elements 0, 1, and -1;

[0110] If the third boundary variable is greater than 0, perform a mask index operation according to the third boundary variable to obtain a mask index value;

[0111] According to the mask index value and the boundary variables, select the corresponding boundary variable update unit to perform a variable parameter update operation on the variable parameters, obtain a variable parameter update value, and assign values to the random sequence according to the selected boundary variable update unit; the length of the random sequence is equal to the length of the target sequence;

[0112] If the updated value of the third boundary variable is greater than 0, repeat the mask index operation and the variable parameter update operation according to the variable parameter update value until the updated value of the third boundary variable is less than or equal to 0, and generate a target random sequence; the target random sequence is composed of elements 0, 1, and -1, and the target random sequence is used to generate a key.

[0113] It should be noted that the effects of the above method embodiments can refer to the effects of the above system embodiments, and will not be elaborated here.

[0114] The above specific embodiments have further elaborated in detail the objectives, technical solutions and beneficial effects of the embodiments of the present application. It should be understood that the above are only the specific embodiments of the embodiments of the present application, and are not used to limit the protection scope of the embodiments of the present application. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of the embodiments of the present application shall be included within the protection scope of the embodiments of the present application.

Claims

1. A key sampling system based on lattice cryptography algorithms, characterized in that Including: An electrically connected acquisition module (1), an initialization module (2), a mask index module (3), and a random sequence generation module (4); The acquisition module (1) is configured to acquire the parameter configuration of the target sequence; The initialization module (2) is configured to perform initialization processing on the variable parameters according to the parameter configuration; The variable parameters include: a count variable and boundary variables; the boundary variables include: a first boundary variable, a second boundary variable, and a third boundary variable, and the first boundary variable, the second boundary variable, and the third boundary variable respectively represent the index boundaries of elements 0, 1, and -1; The mask index module (3) is configured to perform a mask index operation according to the third boundary variable and obtain a mask index value if the third boundary variable is greater than 0; The random sequence generation module (4) is configured to select a corresponding boundary variable update unit according to the mask index value and the boundary variables to perform a variable parameter update operation on the variable parameters, obtain a variable parameter update value, and assign a value to the random sequence according to the selected boundary variable update unit; the length of the random sequence is equal to the length of the target sequence; If the updated value of the third boundary variable is greater than 0, repeat the mask index operation and the variable parameter update operation according to the variable parameter update value until the updated value of the third boundary variable is less than or equal to 0, and generate a target random sequence; the target random sequence is composed of elements 0, 1, and -1, and the target random sequence is used to generate a key.

2. The key sampling system based on lattice cryptography algorithm according to claim 1, characterized in that, The parameter configuration includes: the number of elements 1 and -1 in the target sequence and the length of the target sequence.

3. The key sampling system based on lattice cryptography algorithm according to claim 2, characterized in that, The initialization module (2) is further configured to: Set the count variable to 0; According to the parameter configuration, set the first boundary variable, the second boundary variable, and the third boundary variable to a first parameter, a second parameter, and a third parameter; Wherein, the first parameter is l - 2h; the second parameter is l - h; the third parameter is l; In the formula, l is the length of the target sequence, and h is the number of elements 1 and -1 in the target sequence.

4. A key sampling system based on lattice cryptography algorithm according to claim 1, characterized in that, The mask index module (3) is further configured to: Determine a mask according to the third boundary variable if the third boundary variable is greater than 0; Obtain a random index value according to the length of the target sequence; the random index value is composed of elements 0 and 1; Perform a bitwise AND operation according to the mask and the random index value to obtain a mask index value.

5. The key sampling system based on lattice cryptography algorithm according to claim 1, characterized in that, The random sequence generation module (4) is further configured to: Judge whether the first boundary variable is greater than the mask index value according to the mask index value and the boundary variables. If so, decrease the first boundary variable, the second boundary variable, and the third boundary variable by 1, increase the count variable by 1, and assign 0 to the element at the determined position in the random sequence; the determined position is determined by the count variable; If not, judge whether the second boundary variable is greater than the mask index value. If so, decrease the second boundary variable and the third boundary variable by 1, increase the count variable by 1, and assign 1 to the element at the determined position in the random sequence; Otherwise, determine whether the third boundary variable is greater than the mask index value. If so, decrement the third boundary variable by 1, increment the count variable by 1, and assign the element at the determined position in the random sequence to -1.

6. The key sampling system based on lattice cryptography algorithm according to claim 5, characterized in that, After the step of determining whether the third boundary variable is greater than the mask index value, the following is further included: Otherwise, determine whether the third boundary variable is greater than 0; If so, repeatedly execute the mask index operation and the variable parameter update operation according to the variable parameter until the third boundary variable is less than or equal to 0 to generate a target random sequence.

7. A key sampling system based on lattice cryptography algorithm according to claim 4, characterized in that, The mask index module (3) includes: An input AND gate (31) electrically connected, and a plurality of input OR gates (32) and a first data selector (33); The input OR gate (32) is configured to receive a third boundary variable signal; The first data selector (33) is configured to determine a mask according to the third boundary variable signal; The input AND gate (31) is configured to perform a bitwise AND operation according to the mask and the random index value to obtain a mask index value.

8. A key sampling system based on lattice cryptography algorithm according to claim 1, characterized in that, If the number of elements 1 and -1 in the target sequence is not equal to one-fourth of the length of the target sequence, the initialization module (2) includes: An initialization unit (21), and the initialization unit includes: a first shifter (211) and two first subtractors (212) electrically connected; the initialization unit (21) is configured to set the first boundary variable, the second boundary variable, and the third boundary variable to a first parameter, a second parameter, and a third parameter according to the parameter configuration; The random sequence generation module (4) includes: A storage unit (41), a comparison unit (42), and a data selection unit (43) electrically connected; The storage unit (41) includes: three second data selectors (411), three second subtractors (412), and three registers (413) electrically connected; the storage unit (41) is configured to store the first boundary variable, the second boundary variable, and the third boundary variable; The comparison unit (42) includes: three comparators (421) electrically connected; the comparison unit (42) is configured to compare the first boundary variable, the second boundary variable, and the third boundary variable with the mask index value to generate a comparison result signal; The data selection unit (43) includes: three third data selectors (431) electrically connected, and the third data selector (431) is configured to determine an output result according to the comparison result signal; the output result includes 00, 01, 11; the target random sequence is composed of the output result.

9. A key sampling system based on lattice cryptography algorithm according to claim 8, characterized in that, If the number of elements 1 and -1 in the target sequence is equal to one-fourth of the length of the target sequence, the initialization unit (21) includes: Two second shifters (213) and an adder (214) electrically connected.

10. A key sampling method based on lattice cryptography algorithms, applied to a key sampling system based on lattice cryptography algorithms according to any one of claims 1 to 9 above, characterized in that, Includes: Obtain the parameter configuration of the target sequence; According to the parameter configuration, perform an initialization process on the variable parameter; The variable parameters include: a counting variable and boundary variables; the boundary variables include: a first boundary variable, a second boundary variable, and a third boundary variable, and the first boundary variable, the second boundary variable, and the third boundary variable respectively represent the index boundaries of elements 0, 1, and -1; If the third boundary variable is greater than 0, perform a mask index operation according to the third boundary variable to obtain a mask index value; According to the mask index value and the boundary variables, select the corresponding boundary variable update unit to perform a variable parameter update operation on the variable parameters, obtain a variable parameter update value, and assign values to the random sequence according to the selected boundary variable update unit; the length of the random sequence is equal to the length of the target sequence; If the updated value of the third boundary variable is greater than 0, repeat the mask index operation and the variable parameter update operation according to the variable parameter update value until the updated value of the third boundary variable is less than or equal to 0, and generate a target random sequence; the target random sequence is composed of elements 0, 1, and -1, and the target random sequence is used to generate a key.