Post-quantum key packaging method based on modular lattice and lattice coding technology
Through the Barnes-Wall grid-based nested grid code encoding and decoding method and a new error correction mechanism, the security and flexibility of the existing grid-based key packaging algorithm are solved, and efficient and secure key packaging is achieved to meet the needs of multiple security levels.
Patent Information
- Application Number
- CN202510494087.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-19
- Publication Date
- 2025-07-18
AI Technical Summary
The existing grid-based key packaging algorithms have low security, fixed encapsulation key size, and inflexible algorithm parameters, which are difficult to meet the needs of multiple security levels. The performance of the error correction mechanism is lacking and cannot effectively resist quantum attacks.
The scaled nested grid code encoding and decoding method based on Barnes-Wall grid is adopted, combined with the new error correction mechanism and ciphertext compression technology, IND-CPA-secure public key encryption and IND-CCA-secure key packaging methods are constructed to enhance the flexibility and security of the algorithm.
It improves the efficiency of the key packaging algorithm, reduces communication bandwidth consumption and decryption error rate, adapts to the needs of multiple security levels, has good compatibility and security, and meets the needs of efficient communication and high security.
Smart Images

Figure CN120342593A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of post-quantum cryptography, and particularly relates to a post-quantum key encapsulation method based on modular lattices and lattice coding techniques. Background Art
[0002] With the development of quantum computing technology, many difficult problems that cannot be solved by classical algorithms have been broken by quantum algorithms, and classical cryptographic systems have suffered a subversive challenge. Designing post-quantum cryptographic schemes that can resist quantum attacks has become an urgent task. Post-quantum cryptographic schemes based on lattices have been proven to have anti-quantum characteristics and worst-case to average-case security reductions, and have high computational efficiency and good scalability, becoming one of the most promising post-quantum cryptographic technologies currently.
[0003] Currently, NIST has taken ML-KEM as a standardized lattice-based key encapsulation algorithm. However, if it is directly used as an alternative post-quantum cryptographic algorithm in our country, there are problems such as low security, fixed encapsulated key size, and inflexible algorithm parameters, which cannot meet the actual needs of post-quantum cryptographic algorithms in various security levels in our country; traditional error correction or lattice coding error correction requires introducing dimensional redundancy and is difficult to be directly used for modular lattices, and the core error correction mechanism of the ML-KEM algorithm lacks performance; of course, if we can still optimize the design of its core algorithm components based on the design framework of ML-KEM, there will be advantages of better compatibility with international standardized algorithms and module reuse as a whole, and it can be more excellent in terms of security and performance indicators.
[0004] Preliminary Knowledge and Symbol Definitions
[0005] Denote and to represent the set of integers and the set of real numbers respectively. For represents the value of x rounded downwards, and denote Denote q as a positive integer, and the symbol is defined as Denote as the polynomial ring, as its quotient ring and For the ring one of the following polynomial rings can be selected:
[0006] where F2[T][x] / (x N -1), where F2 is a binary finite field; where the polynomial ring is a k×k matrix; where where the polynomial ring is in the form of a matrix; D[x] / (x N -1), where D is a Dedekind domain; where the polynomial ring is a dual special type of binary truncated polynomial with positive integer coefficients; where A[x] / (x N -1), where A = {a + bi + cj + dk|a, b, c, d ∈ K, i 2 = a, j 2 = b, ij = k}; where N is a parameter of the polynomial ring and N is an integer representing the degree of the polynomial. Denote lowercase letters (such as f) to represent or elements in, bold lowercase letters represent vectors, and bold uppercase letters represent matrices. For a vector v (or matrix A), denote to represent v T (or A T ) its transpose.
[0007] In the present invention, the modular operation is extended from to For a positive integer q, define r′ = r mod ± q to represent the absolutely least complete residue of r, that is, r′ is the unique representative element in the interval . Define r′ = r mod q to represent the non - negative least complete residue of r, that is, r′ is the unique representative element in the interval [0, q]. For define ‖w‖ q,∞ = |w mod ± q| as the infinity norm of w For an N - dimensional vector its 2 - norm is defined as For or a polynomial on, its 2 - norm is defined as Similarly, the 2 - norm of the polynomial vector or is defined
[0008] For a set S, denote to represent randomly and uniformly selecting x from S. For a probability distribution D, x ← D means sampling x according to the distribution. Define the central binomial distribution B with parameter being a positive integer η η : Sample Output For Denote f ← βη denote independently according to B η each coefficient of the sampling polynomial f
[0009] A public-key encryption scheme (PKE) consists of three probabilistic polynomial-time algorithms: Gen, Enc, and Dec, and the plaintext space The key generation algorithm Gen outputs a public-private key pair (pk, sk). The encryption algorithm Enc takes the public key pk and the plaintext as inputs, and then outputs the ciphertext c. In this invention, the random number coin used by the encryption algorithm will be explicitly written when necessary, that is, Enc(pk, m; coin). The deterministic decryption algorithm Dec takes the private key sk and the ciphertext c as inputs, and then outputs the plaintext but outputs the symbol ⊥ when decryption fails. The decryption error rate δ of the public-key encryption algorithm PKE refers to where the expectation calculation is based on (pk, sk) ← Gen, and the probability comes from the random number used by Enc
[0010] A public-key encryption algorithm is indistinguishable under chosen-plaintext attacks (IND-CPA), which means that for any probabilistic polynomial-time adversary its advantage in winning the following IND-CPA game is negligible:
[0011]
[0012] A key encapsulation mechanism (KEM) consists of three probabilistic polynomial-time algorithms: Gen′, Encaps, and Decaps, and the shared key space The key generation algorithm Gen′ outputs a public-private key pair (pk, sk′). The encapsulation algorithm Encaps takes the public key pk as input, and then outputs the ciphertext c and the shared key The deterministic decapsulation algorithm Decaps takes the private key sk′ and the ciphertext c as inputs, and then outputs the shared key but outputs the symbol ⊥ when decapsulation fails. The decapsulation error rate δ of the key encapsulation mechanism KEM refers to Pr[Decaps(sk′, c) ≠ K: (c, K) ← Encaps(pk)] < δ, where the probability comes from (pk, sk′) ← Gen′ and the random number used by Encaps
[0013] A key encapsulation algorithm is indistinguishable under chosen-ciphertext attacks (IND-CCA), which means that it is indistinguishable under chosen-ciphertext attacks for any probabilistic polynomial-time adversary. Its advantage in winning the following IND-CCA games is negligible:
[0014]
[0015] Among them, Decaps(·) is the decapsulation oracle. When the challenge ciphertext c is input * When , Decaps(·) returns ⊥. When other values are entered, Decaps(·) returns the result of decapsulation using the private key.
[0016] The definition of the MLWE difficulty hypothesis is given below. Let k and m be positive integer parameters. The MLWE problem is to distinguish some random samples And some samples In the latter is randomly selected. Consistent across all samples, e i ←β η In each sample, the distribution is β η Newly selected. The MLWE difficulty assumption is that it is difficult to distinguish the above two types of samples, that is, for any probabilistic polynomial time adversary Its advantage in distinguishing the above samples is negligible:
[0017] Summary of the invention
[0018] The object of the present invention is to provide an efficient and compact post-quantum key encapsulation method based on a modular lattice and adopting a novel lattice coding technology.
[0019] The present invention constructs a scaled nested lattice code encoding and decoding method, provides a new error correction mechanism and ciphertext compression technology, breaks through the bandwidth performance limitation of the existing lattice key encapsulation algorithm, reduces the decryption error rate, and provides a lattice-based efficient and compact post-quantum key encapsulation that meets the requirements of efficient communication and high security.
[0020] The post - quantum key encapsulation method based on modular lattices and adopting a new lattice coding technology provided by the present invention specifically includes: a scaling nested lattice code encoding and decoding method based on the Barnes - Wall lattice (including scaling nested lattice code construction, encoding, decoding); an IND - CPA secure public - key encryption method (including key generation, encryption, decryption); an IND - CCA secure key encapsulation method (including key generation, encapsulation, decapsulation).
[0021] (1) The scaling nested lattice code encoding and decoding method based on the Barnes - Wall lattice has the following specific steps:
[0022] (1) Scaling nested lattice code construction, with the specific process as follows:
[0023] The Barnes - Wall lattice is a series of algebraic lattices with dimensions that are powers of 2 (denoted as n = 2 k ), and it can be regarded as a lattice over the Gaussian integers . Scaling the Barnes - Wall lattice is specifically defined as where φ = 1 + i, is the scaling factor, represents the Kronecker product of matrices. The introduction of complex numbers and scaling makes the definition more concise and at the same time enhances the flexibility of subsequent algorithms. Through the mapping it is easy to transform this construction to . Under this mapping, the norm and distance can be naturally defined. According to the definition of BW n (λ), the following properties hold: 1) The minimum square distance satisfies where ρ(BW n (λ)) is the covering radius; 2) 3)
[0024] For two lattices Λ c , Λ f satisfying Denote as the fundamental domain of Λ c , then is called the nested lattice code based on . The nested lattice code can be used to transmit messages over a noisy channel, including two steps: 1) Encoding process: For the received message map it to the lattice point codeword in 2) Decoding process: After receiving the noisy vector x = w + e, this process first uses an error - correction mechanism, taking x as the target vector to obtain the lattice point vector and then map the lattice point back to the message In this method, bounded distance decoding with radius r is adopted as the error correction algorithm. The construction of the scaled nested lattice code based on the Barnes-Wall lattice is given as follows.
[0025] Consider where Λ f = BW n (λ), then we have hold. Take Based on Λ f = BW n (λ) to construct the scaled nested lattice code The number of lattice point codewords in
[0026] (2) Encoding, the specific process is as follows:
[0027] For the input μ-bit message where The encoding process First, make the message m into a bit message by adding 0 to it Then is split into sub-vectors, that is Each sub-vector m j has a length of 2τ - w H (j) bits, where w H (j) represents the Hamming weight of j. After the splitting is completed, each sub-vector m j is mapped to a Gaussian integer to obtain where the mapping ξ l is defined as: For c = (c0, c1,..., c l;1 ), ξ l encodes the lower bits of c as a, and the higher bits as b, that is Finally, calculate w = λ · (vW n mod 2 τ ), to obtain the encoded vector w, which is the lattice point vector in corresponding to the message m.
[0028] (3) Decoding, the specific process is as follows:
[0029] The decoding process is divided into two stages. The first stage is the bounded distance decoding process with radius r, and the specific steps are: For the input target vector Solve the bounded distance decoding problem of \(x\) through iteration in First, divide the target vector into two vectors of equal length to obtain \(x=(x_1,x_2)\), where Iteratively solve the following BDD problems with halved dimensions in in dimensions respectively: Then compare the distances between the two candidate vectors \((y_1,y_1 + \varphi z_1)\) and \((y_2+\varphi z_2,y_2)\) with the target vector \(x\), and return the vector with the smaller distance, so as to obtain the solution of the bounded distance decoding problem of \(x\) in The initial condition of iteration is when \(n = 2\),
[0030]
[0031] The second stage of decoding can be regarded as the inverse process of encoding. For the input lattice vector, first calculate Denote where \(v\) j =a j +b j i. Due to the existence of modulo operation in the encoding process, the following calculation is also needed to adjust \(v\) so that it belongs to the set Specifically: for \(j\) from 0 to Calculate Denote \(v\) j ′=a j ′+b j ′i, calculate So as to obtain Take The first \(\mu\) bits of as the message \(m\).
[0032] For the message Denote For the target vector Let If Then \(m = m_0\).
[0033] (2) The IND-CPA secure public key encryption method described above;
[0034] First, let \(\kappa, l, N, q, p, g\) be positive integer parameters, \(n = 2\) k , \(\tau\) is the parameter \(\eta\) of the nested lattice code s , \(\eta\) e , \(\eta\) ct is the parameter of the centered binomial distribution. The message space is defined as where The message can be represented as The coefficients of the polynomial are 0 or 1. The public key encryption method includes:
[0035] (1) Key generation: The specific process is as follows:
[0036] First, generate the key through the key expansion function Gen(seed) A random matrix A on which is the random seed for sampling. Then generate Distribute the polynomial vector tuple (s, e), calculate t∶=As+e, and return the public key pk∶=(seed, t), the private key sk∶=s.
[0037] (2) Encryption: The specific process is as follows:
[0038] Input the public key pk = (seed, t) and the message m to be encrypted. The encryption method first uses the random seed seed to restore the polynomial matrix A, and then generates the dependent The polynomial vector pair (r, e1) of the distribution and the The polynomial e2 of the distribution is used to calculate the first part of the ciphertext. And the second part of the ciphertext Return the ciphertext c∶=(u,v).
[0039] (3) Decryption: The specific process is as follows:
[0040] Input the private key sk = s and the ciphertext to be decrypted c = (u, v), the decryption method is calculated Output the decrypted message m′.
[0041] (III) The IND-CCA secure key encapsulation method comprises the following specific steps:
[0042] By using a variant of the Fujisaki-Okamoto transform A key encapsulation scheme is constructed to enhance the security of IND-CCA in a multi-user setting. Let ι,γ be positive integers. To enhance security, choose ι,γ≥256. Let is a hash function where is the shared key space for key encapsulation, is the random number space used by the encryption method in public key encryption. Defined as The mapping to The part of the output in . is the public key space of public key encryption, let is a fixed-length output function. The key encapsulation method includes:
[0043] (1) Key generation, and the specific process is as follows:
[0044] First, call the key generation method of public key encryption to generate a pair of public and private keys (pk, sk). Then, use a random number generator to generate a random bit string z of length l, and return the public key pk′ := pk of the key encapsulation method and the private key sk′ := (sk, z).
[0045] (2) Encapsulation, and the specific process is as follows:
[0046] Input the public key pk′ = pk of the key encapsulation. Use a random number generator to generate a random message m in the plaintext space Take ID(pk′) || m as the input, and calculate The obtained output is a bit string of length 2γ. Take the first γ bits as the encapsulated key K, and record the last γ bits as coin. Take the public key pk′, the message m, and the random number coin as the input, call the encryption method of public key encryption to return the ciphertext c, and output (c, K), where K is the encapsulation key of the key encapsulation method and c is the ciphertext.
[0047] (3) Decapsulation, and the specific process is as follows:
[0048] Input the private key sk′ = (sk, z) of the key encapsulation and the ciphertext c, call the decryption method of public key encryption to return the message m′. Take ID(pk′) || m′ as the input, and calculate The obtained output is a bit string of length 2γ. Take the first γ bits as the key K′, and record the last γ bits as coin′. Take the ciphertext c and the random bit string z as the input, and calculate If the ciphertext returned by calling the encryption method of public key encryption with the public key pk′, the message m′, and the random number coin′ as the input is exactly equal to c, then output K′; otherwise, output
[0049] Compared with the prior art, the positive effects of the present invention are as follows:
[0050] The nested lattice code encoding and decoding method of the present invention provides a new error correction mechanism and ciphertext compression technology, thereby improving the efficiency of the lattice-based key encapsulation algorithm, reducing the communication bandwidth consumption, and effectively reducing the decryption error rate. The parameter selection is flexible, and it can provide parameters under multiple security levels to adapt to different security scenario requirements. This innovative solution establishes a connection and bridge between mathematical low-dimensional lattice coding and cryptographic high-dimensional lattice research, breaks through the bandwidth performance limitations of the existing lattice-based key encapsulation algorithm, meets the requirements of efficient communication and high security, and has good compatibility with international standard algorithms, laying a foundation for the practical deployment of post-quantum cryptography in China. Description of the Drawings
[0051] Figure 1This is the overall block diagram of the method of the present invention.
[0052] Figure 2 This is the flowchart of the encoding and decoding method of the scaled nested lattice code.
[0053] Figure 3 This is the flowchart of key generation in the public key encryption method.
[0054] Figure 4 This is the flowchart of encryption in the public key encryption method.
[0055] Figure 5 This is the flowchart of decryption in the public key encryption method.
[0056] Figure 6 This is the flowchart of key generation in the key encapsulation method.
[0057] Figure 7 This is the flowchart of encapsulation in the key encapsulation method.
[0058] Figure 8 This is the flowchart of decapsulation in the key encapsulation method. Detailed implementation manners
[0059] Example:
[0060] (1) The encoding and decoding method of the scaled nested lattice code based on the Barnes-Wall lattice is as follows:
[0061] (1) Construction of the scaled nested lattice code is as follows:
[0062] The Barnes-Wall lattice is a series of algebraic lattices with dimensions that are powers of 2 (denoted as n = 2 k ), and it can be regarded as a lattice over the Gaussian integers . Scaling the Barnes-Wall lattice is specifically defined as where φ = 1 + i, is the scaling factor, represents the Kronecker product of matrices. The introduction of complex numbers and scaling makes the definition more concise and enhances the flexibility of subsequent algorithms. Through the mapping it is easy to convert this construction to . Under this mapping, the norm and distance can be naturally defined. According to the definition of BW n (λ), the following properties hold: 1) The minimum squared distance satisfies where ρ(BW n (λ)) is the packing radius; 2) 3)
[0063] For two lattices Λc , Λ f Satisfy Denote as Λ c 's fundamental domain, then it is called is based on 's nested lattice code. Nested lattice codes can be used to transmit messages over a noisy channel, including two steps: 1) Encoding process: For the received message map it to the lattice point codeword in 2) Decoding process: After receiving the noisy vector x = w + e, this process first uses an error correction mechanism, taking x as the target vector to obtain the lattice point vector and then map the lattice point back to the message In this method, bounded distance decoding with radius r is used as the error correction algorithm. The construction of scaled nested lattice codes based on Barnes - Wall lattices is given as follows.
[0064] Consider where Λ f = BW n (λ), then there is established. Take Based on Λ f = BW n (λ) to construct the scaled nested lattice code The number of lattice point codewords in In the following (2), (3), the encoding and decoding methods for transmitting messages over a noisy channel will be given. Denote the message space as To ensure the injectivity of encoding, it is necessary to satisfy That is Namely
[0065] (2) Encoding, specifically as follows:
[0066] For the input μ - bit message where Encoding process First, make the message m into a -bit message by adding 0 Then is split into sub - vectors, that is Each sub - vector m j has a length of 2τ - w H (j) bits, where w H (j) represents the Hamming weight of j. After the splitting is completed, each sub - vector m jMap to a Gaussian integer Obtain Among them, the mapping ξ l Is defined as: For c = (c0, c1, …, c l;1 ), ξ l Encodes the lower Bits of c as a, and the higher Bits as b, that is Finally, calculate w = λ·(vW n mod 2 τ ), to obtain the encoded vector w, which is the lattice point vector corresponding to the message m in .
[0067] This encoding process is an injection from the message space To the scaled nested lattice code . In particular, when , the encoding process becomes a bijection.
[0068] (3) Decoding, specifically as follows:
[0069] The decoding process Is divided into two stages. The first stage is the bounded distance decoding process with radius r. The specific steps are: for the input target vector Solve the bounded distance decoding problem of x in By iteration First, divide the target vector into two equal-length vectors to get x = (x1, x2), where In Iteratively solve the following dimension-reduced BDD problems for each dimension:
[0070]
[0071] Then compare the distances between the two candidate vectors (y1, y1 + φz1) and (y2 + φz2, y2) with the target vector x, and return the vector with the smaller distance, so as to obtain the solution of the bounded distance decoding problem of x in . The initial condition for iteration is when n = 2,
[0072] The second stage of decoding can be regarded as the inverse process of encoding. For the input lattice point vector, first calculate Denote Among them, v j = a j + b j i. Due to the existence of modular operations in the encoding process, the following calculation is also needed to adjust v so that it belongs to the set Specifically: for j from 0 to Calculation Let \(v'\) j ' = a j ' + b j 'i, and calculate Thus, we obtain Take The first \(\mu\) bits as the message \(m\).
[0073] For the message Let For the target vector Let If Then \(m = m_0\).
[0074] (2) The IND - CPA secure public - key encryption method described in (1) is as follows:
[0075] Let \(\kappa, l, N, q, p, g\) be positive - integer parameters, \(n = 2 k , \(\tau\) be the parameter of the nested lattice code, \(\eta s , \(\eta e , \(\eta ct be the parameters of the centered binomial distribution. The message space is defined as where The message can be represented as a polynomial over \(
[0076] (1) Key generation, the specific steps are as follows:
[0077] First, generate a random matrix \(A\) over using the key - expansion function Gen(seed), where is the sampled random seed. Then generate a polynomial - vector pair \((s, e)\) that follows the distribution, calculate \(t := As+e\), and return the public key \(pk := (seed, t)\), and the private key \(sk := s\).
[0078] (2) Encryption, the specific steps are as follows:
[0079] Input the public key \(pk=(seed, t)\) and the message \(m\) to be encrypted. The encryption method first restores the polynomial matrix \(A\) using the random seed \(seed\), then generates a polynomial - vector pair \((r, e_1)\) that follows the distribution and a polynomial \(e_2\) that follows the distribution respectively, and calculate the first - part ciphertext and the second - part ciphertext Return the ciphertext \(c := (u, v)\).
[0080] (3) Decryption, and the specific steps are as follows:
[0081] Input the private key sk = s and the ciphertext c = (u, v) to be decrypted, and the decryption method calculates Output the decrypted message m'.
[0082] The above public key encryption method satisfies IND-CPA security under the MLWE hardness assumption. Specifically, for any probabilistic polynomial-time adversary there exists a probabilistic polynomial-time adversary such that:
[0083]
[0084] Let Err = e T r - s T e1 - s T ∈ + e2, where Divide the coefficient vector of Err into n-dimensional sub-vectors, and let (Err) i represent the i-th sub-vector. Then the decryption error rate of the above IND-CPA secure public key encryption can be expressed as
[0085] In step (1), is a polynomial ring. Denote the ring as a general ring. Then is its quotient ring and where q is a positive integer; for the ring one of the following polynomial rings can be selected:
[0086] where F2[T][x] / (x N - 1), where F2 is a binary finite field; where the polynomial ring is a k×k matrix; where where the polynomial ring is in matrix form; D[x] / (x N - 1), where D is a Dedekind domain; where the polynomial ring is a dual special type of binary truncated polynomial with positive integer coefficients; where A[x] / (x N - 1), where A = {a + bi + cj + dk|a, b, c, d ∈ K, i 2 = a, j 2= b, ij = k}; where the ring parameter N represents the degree of the polynomial.
[0087] In step (2), the is a ciphertext compression function, which is defined as follows: For By map it to the range of {0, 1, …, 2 d - 1}, where For the polynomial and the polynomial vector The compression function calculates their corresponding coefficients respectively.
[0088] Among them, the PolyEncode(m) used is a polynomial encoding function, which is defined as follows: For the input message polynomial Consider the scaled nested lattice code Divide the coefficient vector of the message m into μ0 bit vectors. For Perform Encoding to obtain the lattice vector where is the scaled nested lattice encoding function; Map this complex vector to an n-dimensional vector:
[0089]
[0090] Finally, output the encoded polynomial
[0091] Among them, the used is the scaled nested lattice encoding function, which is defined as follows: For the input μ-bit message where The encoding process First, make the message m into bit message by adding 0 to it. Then is split into sub-vectors, that is Each sub-vector m j has a length of 2τ - w H (j) bits, where w H (j) represents the Hamming weight of j; After the splitting is completed, each sub-vector m j is mapped to a Gaussian integer to obtain Among them, the mapping ξ l is defined as: For c = (c0, c1, …, cl;1 ),ξ l Encode the lower bits of c as a, and the higher bits as b, that is Finally, calculate w = λ·(vW n mod 2 τ ), to obtain the encoded vector w, which is the lattice point vector corresponding to the message m in .
[0092] In the step (3), the PolyDecode(w) used is a polynomial decoding function, and its specific process is as follows: For the input target polynomial Consider of the nested lattice code Divide the coefficient vector of the polynomial w into n-dimensional sub-vectors. For the j-th n-dimensional sub-vector (w nj , w nj:1 , …, w nj:n;1 ), Correspond it to the complex vector on :
[0093]
[0094] Take x j as the target vector for decoding to obtain where is the scaled nested lattice decoding function, and finally output the decoded polynomial:
[0095]
[0096] Among them, the used is the scaled nested lattice decoding algorithm, and its definition is as follows: For the input target vector First, solve the bounded distance decoding problem of x in by iteration Then calculate Denote where v j = a j + b j i, and then make the following calculation to adjust v so that it belongs to the set Specifically: For j from 0 to Calculate Denote v j ′ = a j ′ + b j ′i, calculate Thus obtain Take The first μ bits are used as the message m.
[0097] Among them, the adopted is the scaled nested lattice bounded distance decoding algorithm, which is defined as follows: For the input target vector Solve the bounded distance decoding problem of x in by iteration. First, divide the target vector into two vectors of equal length to obtain x=(x1, x2), where In dimensions, iteratively solve the following dimension-reduced BDD problems:
[0098]
[0099] Then compare the distances between the two candidate vectors (y1, y1 + φz1) and (y2 + φz2, y2) with the target vector x, and return the vector with the smaller distance, so as to obtain the solution of the bounded distance decoding problem of x in The initial condition of the iteration is when n = 2,
[0100]
[0101] Among them, the optional parameters of the polynomial dimension N include {256, 384, 512, 576}, the optional parameter of the nested lattice code dimension n is a power of 2, the optional parameters of l and τ are positive integers, the optional parameters of q include {3329, 3457} or a power of 2, and the optional parameters of p and g are a power of 2 or q.
[0102] (3) The IND-CCA secure key encapsulation method is as follows:
[0103] Construct a key encapsulation scheme by using a variant of the Fujisaki-Okamoto transform to enhance the security of IND-CCA in a multi-user setting. Let ι and γ be positive integers. To enhance security, choose ι, γ ≥ 256. Let be a hash function, where is the shared key space for key encapsulation, is the random number space used in the encryption method of public key encryption. Define as the part of the output that maps to in. Let be the public key space of public key encryption, and let be the output fixed-length function. The key encapsulation method includes:
[0104] (1) Key generation, and the specific steps are as follows:
[0105] First, call the key generation method of public key encryption to generate a pair of public and private keys (pk, sk). Then, use a random number generator to generate a random bit string z of length ι, and return the public key pk′ of the key encapsulation method: = pk and the private key sk′: = (sk, z).
[0106] (2) Encapsulation, the specific steps are as follows:
[0107] Input the public key pk′ = pk of the key encapsulation, use a random number generator to generate a random message m in the plaintext space Take ID(pk′)||m as the input, and calculate The obtained output is a bit string of length 2γ. Take its first γ bits as the encapsulated key K, and record the last γ bits as coin. Take the public key pk′, the message m, and the random number coin as the input, call the encryption method of public key encryption to return the ciphertext c, and output (c, K), where K is the encapsulation key of the key encapsulation method and c is the ciphertext.
[0108] (3) Decapsulation, the specific steps are as follows:
[0109] Input the private key sk′ = (sk, z) of the key encapsulation and the ciphertext c, call the decryption method of public key encryption to return the message m′, take ID(pk′)||m′ as the input, and calculate The obtained output is a bit string of length 2γ. Take its first γ bits as the key K′, and record the last γ bits as coin′. Take the ciphertext c and the random bit string z as the input, and calculate If the ciphertext returned by calling the encryption method of public key encryption with the public key pk′, the message m′, and the random number coin′ as the input is exactly equal to c, then output K′, otherwise output
[0110] The IND-CCA security of the above key encapsulation method in the random oracle model and the quantum random oracle model is as follows: Let be the min-entropy of ID(pk), that is For any (quantum) adversary can make at most q D decapsulation queries and q H (quantum) random oracle queries. There exists a (quantum) adversary with approximately the same running time as such that:
[0111] (1) In the classical random oracle model, there is
[0112]
[0113] (2) In the quantum random oracle model, there is
[0114]
[0115] Among them, q HD := q H + q D + 1.
[0116] The key encapsulation method provided by the present invention has flexible parameter selection and can provide target security strengths and bandwidths that meet various standards. The method parameters include the ring modulus q, the polynomial dimension N, the matrix dimension l, the ciphertext moduli p, g, the scaled nested lattice code parameters n, τ, and the central binomial distribution sampling parameter η s , η e , η ct , parameters, the public key size, ciphertext size, and encapsulation key size are |pk|, |ct|, |K| respectively, and sec.c and sec.q respectively represent the classical and quantum security strengths of the method based on the underlying MLWE hard problem under these parameters.
[0117] The efficient and compact key encapsulation method based on lattice coding described in the present invention has recommended parameter sets at the classical 128, 192, 256, 384, and 512 security levels as shown in Table 1, but is not limited to the parameter selection in the following table:
[0118] Table 1 Recommended Parameter Sets of the Method of the Present Invention
[0119]
Claims
1. A post-quantum key encapsulation method based on modular lattices and lattice coding, characterized in that Including: A method for encoding and decoding a scaled nested lattice code based on the Barnes-Wall lattice; an IND-CPA secure public key encryption method; an IND-CCA secure key encapsulation method; wherein: (1) The method for encoding and decoding a scaled nested lattice code based on the Barnes-Wall lattice is as follows: (1) Construction of the scaled nested lattice code, the specific process is as follows: Let the Barnes-Wall lattice be a series of algebraic lattices with dimensions that are powers of 2 (denoted as n = 2 k ), regarded as a lattice over the Gaussian integers ; the Barnes-Wall lattice is scaled, specifically defined as: where φ = 1 + i, is a scaling factor, represents the Kronecker product of matrices; For two lattices Λ c , Λ f satisfying Denote as the fundamental domain of Λ c , then is called a nested lattice code based on . The construction of the scaled nested lattice code based on the Barnes-Wall lattice is as follows: Consider where Λ f = BW n (λ), then there is hold; take Based on Λ f = BW n (λ) to construct a scaled nested lattice code The number of lattice codewords in In the following (2)(3), an encoding and decoding method for propagating messages in a noisy channel using c(n,λ) will be given. Denote the message space as To ensure the injectivity of the encoding, it is necessary to satisfy That is (2) Encoding, the specific process is as follows: For the input μ-bit message where the encoding process first makes it a bit message by adding 0 to the message m then is split into sub-vectors, that is each sub-vector m j has a length of 2τ - w H (j) bits, where w H (j) represents the Hamming weight of j; after the splitting is completed, each sub-vector m j is mapped to a Gaussian integer to obtain where the mapping ξ l is defined as: For c = (c0, c1, …, c l-1 ), ξ l encodes the lower bits of c as a, and the higher bits as b, that is Finally, calculate w = λ·(vW n mod 2 τ ), to obtain the encoded vector w, which is the lattice point vector in corresponding to the message m; (3) Decoding, the specific process is as follows: Decoding process It is divided into two stages: The first stage is a bounded - distance decoding process with a radius of r, specifically: for the input target vector Solve for x iteratively in the bounded - distance decoding problem First, divide the target vector into two vectors of equal length to obtain x=(x1, x2), where In dimensions, iteratively solve the following BDD problems with halved dimensions: Then compare the distances between the two candidate vectors \((y1, y1 + \varphi z1)\) and \((y2 + \varphi z2, y2)\) with the target vector \(x\), and return the vector with the smaller distance, so as to obtain the solution to the bounded distance decoding problem of \(x\) in , and the initial condition for iteration is when \(n = 2\). The second stage is regarded as the inverse process of encoding. For the input lattice vector, first calculate Denote where v j = a j + b j i. Due to the existence of modular operations in the encoding process, the following calculation is also needed to adjust v so that it belongs to the set Specifically: for j from 0 to Calculate: Let \(v\) j ′ = a j ′ + b j ′i, calculate Thus, we obtain Take the first \(\mu\) bits as the message \(m\); For a message Record For a target vector Let If Then m = m0; (2) The IND-CPA secure public key encryption method is as follows: Let κ, l, N, q, p, g be positive integer parameters, n = 2 k , τ be the parameter of the nested lattice code, η s , η e , η ct be the parameter of the central binomial distribution; the message space is defined as where the message is represented as a polynomial with coefficients 0 or 1 over; the public-key encryption method includes: (1) Key generation, the specific process is: First, generate a random matrix A on through the key expansion function Gen(seed), where is the sampled random seed; then generate a polynomial vector binary pair (s, e) distributed according to Calculate t := As + e, and return the public key pk := (seed, t), and the private key sk := s; (2) Encryption, the specific process is: Input the public key pk = (seed, t) and the message m to be encrypted. The encryption method first restores the polynomial matrix A using the random seed seed, and then generates the polynomial vector binary pair (r, e1) distributed according to and the polynomial e2 distributed according to respectively. Calculate the first part of the ciphertext and the second part of the ciphertext Return the ciphertext c := (u, v), where Compress q,p and Compress q,g are ciphertext compression functions, and PolyEncode is a polynomial encoding function; (3) Decryption, the specific process is: Input the private key sk = s and the ciphertext c = (u, v) to be decrypted. The decryption method calculates Output the decrypted message m'. Here, PolyDecode is a polynomial decoding function; (3) The IND-CCA secure key encapsulation method is as follows: By using a variant of the Fujisaki-Okamoto transformation Construct a key encapsulation scheme; Let ι, γ be positive integers. To enhance security, choose ι, γ ≥ 256; Let be a hash function, where is the shared key space for key encapsulation, is the random number space used by the encryption method in public key encryption; Let be defined as the part of the output that maps to ; Let be the public key space of public key encryption, and let be an output fixed-length function; The key encapsulation method includes: (1) Key generation, the specific process is: First, call the key generation method of public key encryption to generate a pair of public and private keys (pk, sk), then use a random number generator to generate a random bit string z of length ι, and return the public key pk' := pk and private key sk' := (sk, z) of the key encapsulation method; (2) Encapsulation, the specific process is: The input public key pk' for key encapsulation is pk. Use a random number generator to generate a random message m in the plaintext space Take ID(pk')||m as the input and calculate The output obtained is a bit string of length 2γ. Take the first γ bits as the encapsulated key K, and denote the last γ bits as coin. Using the public key pk', the message m, and the random number coin as the input, call the encryption method of public-key encryption to return the ciphertext c, and output (c, K), where K is the encapsulation key of the key encapsulation method and c is the ciphertext; (3) Decapsulation, the specific process is: Input the private key sk′ = (sk, z) of key encapsulation and the ciphertext c, call the decryption method of public-key encryption to return the message m′, and use ID(pk′)||m′ as the input to calculate The obtained output is a bit string of length 2γ. Take the first γ bits as the key K′ and the last γ bits as coin′; use the ciphertext c and the random bit string z as the input to calculate If the ciphertext returned by calling the encryption method of public-key encryption with the public key pk′, the message m′, and the random number coin′ as the input is exactly equal to c, then output K′, otherwise output 2. The post-quantum key encapsulation method according to claim 1, wherein In step (1) of the IND-CPA secure public key encryption method, is a polynomial ring. Denote the ring as a general ring, then is its quotient ring and where q is a positive integer; for the ring choose one of the following polynomial rings: where F2[T][x] / (x N - 1), where F2 is a binary finite field; where the polynomial ring is a k×k matrix; where where the polynomial ring is in matrix form; D[x] / (x N - 1), where D is a Dedekind domain; where the polynomial ring is a dual special type of binary truncated polynomial with positive integer coefficients; where A[x] / (x N - 1), where A = {a + bi + cj + dk|a, b, c, d ∈ K, i 2 = a, j 2 = b, ij = k}; where the ring parameter N represents the degree of the polynomial.
3. The post-quantum key encapsulation method according to claim 1, wherein In step (2) of the IND-CPA secure public key encryption method, the is a ciphertext compression function, which is defined as follows: For through map it to the range of {0, 1, …, 2 d - 1}, where For polynomial and polynomial vector The compression function calculates their corresponding coefficients respectively.
4. The post-quantum key encapsulation method according to claim 1, characterized in that, PolyEncode(m) used in step (2) of the IND-CPA secure public-key encryption method is a polynomial encoding function, which is defined as follows: For the input message polynomial Consider the scaled nested lattice code Divide the coefficient vector of the message m into μ0 bit vectors. For perform encoding to obtain the lattice vector where is the scaled nested lattice encoding function; map this complex vector to an n-dimensional vector Finally, output the encoded polynomial 5. The post-quantum key encapsulation method according to claim 4, wherein In the IND-CPA secure public key encryption method, the one adopted in the step (2) is a scaled nested lattice encoding function, which is defined as follows: for the input μ-bit message where Encoding process First, make the message m become bit message by adding 0 Then is split into sub-vectors, namely Each sub-vector m j has a length of 2τ - w H (j) bits, where w H (j) represents the Hamming weight of j; after the split is completed, each sub-vector m j is mapped to a Gaussian integer to obtain where the mapping ξ l is defined as: For c = (c0, c1, …, c l-1 ), ξ l encodes the lower bits of c as a, and the upper bits as b, that is Finally, calculate w = λ · (vw n mod 2 τ ) to obtain the encoded vector w, which is the lattice point vector in corresponding to the message m.
6. The post-quantum key encapsulation method according to claim 1, characterized in that, The PolyDecode(w) adopted in step (3) of the IND-CPA secure public key encryption method is a polynomial decoding function, and its specific process is as follows: for the input target polynomial Consider the nested lattice code Divide the coefficient vector of the polynomial w into m n-dimensional sub-vectors. For the j-th n-dimensional sub-vector correspond it to the complex vector on Decode x j as the target vector to obtain: Among them, is a scaled nested lattice decoding function, and finally outputs a decoded polynomial:
7. The post-quantum key encapsulation method according to claim 6, wherein In step (3) of the IND-CPA secure public key encryption method, the scaled nested lattice decoding algorithm is adopted, and its definition is as follows: For the input target vector First, solve the bounded distance decoding problem of x in by iteration Then calculate Denote where v j = a j + b j i, and then make the following calculation to adjust v so that it belongs to the set Specifically: for j from 0 to Calculate: Let \(v\) j ′ = a j ′ + b j ′i and calculate Thus, we obtain Take the first \(\mu\) bits as the message \(m\).
8. The post-quantum key encapsulation method according to claim 7, wherein In step (3) of the IND-CPA secure public key encryption method, the scaled nested lattice bounded distance decoding algorithm is adopted, and its definition is as follows: for the input target vector iteratively solve the bounded distance decoding problem of x in First, divide the target vector into two vectors of equal length to obtain x = (x1, x2), where in iteratively solve the following BDD problems with halved dimensions respectively in dimensions: Then compare the distances between the two candidate vectors \((y1, y1 + \varphi z1)\) and \((y2 + \varphi z2, y2)\) with the target vector \(x\), and return the vector with the smaller distance, so as to obtain the solution to the bounded distance decoding problem of \(x\) in , and the initial condition for iteration is when \(n = 2\), 9. The post-quantum key encapsulation method according to claim 1, wherein In the IND-CPA secure public key encryption method, the polynomial dimension N is selected from {256, 384, 512, 576}, the nested lattice code dimension n is selected as a power of 2, l and τ are positive integers, q is selected from {3329, 3457} or a power of 2, and p, g are selected as a power of 2 or q.
Citation Information
Cited By
Lightweight anti-quantum key agreement protocol method and system for edge computing
CN121485935A