NTRU-based efficient and compact key packaging, encryption and decryption method

By combining error correction code and compression function under the NTRU assumption and RLWE assumption, the shortcomings of the public key encryption and key encapsulation methods based on the NTRU grid in terms of computing efficiency, ciphertext size and security are solved, and a more efficient and secure key encapsulation solution is achieved.

CN120342618APending Publication Date: 2025-07-18FUDAN UNIVERSITY
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202410061367.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-16
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing public key encryption methods and key encapsulation methods based on NTRU grids have shortcomings in computing efficiency, ciphertext size and security, which are difficult to match LWE solutions, and lack performance balance.

Method used

The NTRU assumption and RLWE assumption based on polynomial rings are used to encode and decode the plain text in combination with the encoding algorithm of error correction code, and the public key and ciphertext are compressed using compression functions. The IND-CCA-secure key encapsulation method is obtained through FO conversion, so as to achieve the efficient key generation, encryption and decryption processes.

Benefits of technology

Proven security under classical and quantum random oracle models, enabling shorter public-private key sizes and ciphertext sizes, improve computing efficiency, and balance security, bandwidth and implementation efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342618A_ABST
    Figure CN120342618A_ABST
Patent Text Reader

Abstract

The invention discloses an efficient and compact key packaging, encryption and decryption method based on NTRU. The invention belongs to the technical field of lattice passwords, and particularly relates to an NTRU-based secret key packaging, encrypting and decrypting method with scalable ciphertext compression and balanced performance. According to the method, a public key compression and scaling ciphertext compression technology is provided for an NTRU password system, only one polynomial is needed in the encryption and decryption process, and the technology is also suitable for other password schemes based on NTRU. The method has the advantages of being shorter in ciphertext size, more flexible in parameter selection, capable of proving security under classical and quantum random oracle models, tighter in theoretical security protocol advantage, higher in known attack resistance, efficient in implementation, negligible in error rate and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of lattice cryptography, and particularly to a public key encryption method and a key encapsulation method based on NTRU, which can resist quantum computer attacks. Background Art

[0002] The currently used public key encryption methods are mainly based on classical mathematical problems and cannot resist quantum computing attacks. Therefore, the cryptography that can resist quantum computer attacks - post-quantum cryptography (PQC) has received extensive attention. According to different underlying difficult mathematical problems, it is divided into five main post-quantum cryptography schemes: hash-based, code-based, lattice-based, multivariate-based, and isogeny-based. Among them, the lattice-based cryptography scheme is considered the most promising cryptography scheme due to its excellent security, small communication bandwidth, and high computing efficiency.

[0003] In the third round of algorithm competitions held by the National Institute of Standards and Technology (NIST) of the United States, 7 out of 15 algorithms are lattice-based schemes. Most of the lattice-based cryptography schemes use ordinary lattices and algebraic structure lattices (ideal lattices, NTRU lattices, and modular lattices). They are mainly instantiated from the following several difficult assumptions: the first type is the learning with errors (LWE) assumption and its variants, and the second type is the NTRU assumption. In the NIST post-quantum cryptography scheme solicitation project, the NTRU lattice-based scheme plays a crucial role. Specifically, the Falcon digital signature is constructed based on the NTRU lattice and is one of the digital signatures proposed for standardization in the NIST post-quantum cryptography scheme standard solicitation. In addition, in the NIST round 3, NTRU Key Encapsulation Mechanism (KEM) (including NTRU-HRSS and NTRUEncrypt) is one of the 4 finalist key encapsulation methods, and NTRU Prime (including SNTRU Prime and NTRULPRime) is one of the 5 candidate key encapsulation methods.

[0004] The public key encryption method aims to protect the confidentiality of information through cryptographic techniques. The key encapsulation method aims to enable two or more parties to negotiate a common session key over an insecure channel. This key will be used in subsequent symmetric cryptography to establish a secure communication channel. Among them, the two-party protocol is the most common case. The key encapsulation method plays an important role in real Internet security protocols (such as SSL / TLS).

[0005] Currently, the NTRU lattice-based public key encryption and key encapsulation methods have started the standardization process. In 2011, the NTRUEncrypt scheme was included in the X9.98 standard and applied to financial service enterprises. Since April 2022, after the international standard OpenSSH updated to version 9.0, OpenSSH has adopted a hybrid mode of the NTRU Prime KEM scheme combined with the X25519 ECDH scheme to resist "capture-then-decrypt" attacks.

[0006] Designing public key encryption methods and key encapsulation methods based on the NTRU lattice is one of the mainstream directions of lattice cryptography. Briefly speaking, the NTRU lattice-based public key encryption methods and key encapsulation methods have the following advantages. (1) There is a strong security guarantee. Since NTRU was proposed, the attacks and cryptanalysis on NTRU have had a very limited impact on the security of the NTRU lattice-based public key encryption methods and key encapsulation methods. (2) The key encapsulation length is flexible. The key length that the NTRU public key encryption method and key encapsulation method can encapsulate increases with the increase in the degree of the polynomial ring, and at the same time, it also increases with the improvement of security. However, the key length of the LWE and its variant schemes depends on the fixed degree of the underlying polynomial ring, so the key length of the encapsulation is also fixed. (3) Most of the NTRU lattice-based public key encryption methods and key encapsulation methods have a simple structure, and the encryption and decryption algorithms only contain one polynomial multiplication, which is convenient for the implementation of encryption and decryption.

[0007] However, the NTRU lattice-based public key encryption method and key encapsulation method have the following deficiencies. (1) In terms of computational efficiency. The NTRU lattice-based public key encryption method and key encapsulation method are inferior to the LWE-based scheme in terms of computational efficiency. This is mainly because the latter can use the efficient number-theoretic transform (NTT) to calculate polynomial multiplication. The key generation algorithm of the NTRU scheme involves polynomial division, which is a rather time-consuming operation. (2) In terms of ciphertext size. Reducing the ciphertext size has a positive effect on network protocols (such as TLS) and communication with IoT resource-constrained devices. Although ciphertext compression is a mature technology in the {R, M}LWE-based public key encryption method and key encapsulation method, there is very little relevant research on the NTRU lattice-based public key encryption method and key encapsulation method. (3) Narrow secret value range. In order to make the error rate zero, the traditional NTRU schemes restrict the range of the coefficients of the secret polynomial to {0, -1, 1}. However, this makes it difficult for these NTRU schemes to match the LWE scheme in terms of security. After all, the LWE-based public key encryption method and key encapsulation method can take secret values within [-η, η], where η > 0. (4) The traditional NTRU schemes do not have balanced performance. Specifically, it is difficult for the NTRU scheme to perform evenly in terms of security, bandwidth, error rate, and implementation efficiency, while the LWE scheme can perform evenly in these aspects. Summary of the Invention

[0008] The object of the present invention is to provide a public key encryption method and key encapsulation method CTRU based on NTRU with scalable ciphertext compression, aiming to solve the above problems and perform evenly in terms of security, bandwidth, error rate, and implementation efficiency. The present invention first proposes a public key encryption method based on NTRU that is IND-CPA secure, which is characterized in that based on the NTRU assumption and RLWE assumption on the polynomial ring, the encoding algorithm of the error-correcting code is used to encode the plaintext in the high bits of the ciphertext and the decoding algorithm is used to recover the plaintext, and a compression function is used to compress the public and private keys and the ciphertext. The present invention then uses the FO (Fujisaki-Okamoto) transformation to convert the public key encryption method to obtain an IND-CCA secure key encapsulation method. The advantages of the present invention are: provable security in the classical and quantum random oracle models, more tight security reduction advantages, shorter public and private key sizes, shorter ciphertext sizes, more efficient implementation, etc.

[0009] To achieve the above object, the content of the present invention is generally described herein. The present invention first provides a public-key encryption method CTRU.PKE, which includes a key generation method CTRU.PKE.KeyGen (for generating a public-private key pair), an encryption method CTRU.PKE.Enc (for inputting a plaintext and a public key and outputting a ciphertext), and a decryption method CTRU.PKE.Dec (for inputting a ciphertext and a private key and outputting a plaintext).

[0010] Then, the public-key encryption method CTRU.PKE is extended to a key encapsulation method CTRU.KEM through FO transformation, including the following steps:

[0011] First step, set the common parameters required for all steps of the key encapsulation method according to requirements: positive integers ι and γ, where ι, γ ≥ 256, the public key space PK of CTRU.PKE, the random space COINS of CTRU.PKE.Enc, and the shared key space of CTRU.KEM Hash function Fixed-output length function ID: PK → {0, 1}γ, Output to Partial function of

[0012] Second step, execute the key generation method CTRU.KEM.KeyGen to generate a public-private key pair. The calculation process is as follows: obtain the public key pk and private key sk of CTRU.PKE through CTRU.PKE.KeyGen; uniformly and randomly sample z from {0, 1} ι ; output the public key pk′ of the key encapsulation method: = pk and the private key sk′: = (sk, z);

[0013] Third step, execute the encapsulation method CTRU.KEM.Encaps to obtain a ciphertext and derive a shared key. The calculation process is as follows: input the public key pk′ = pk; randomly sample a plaintext m in the plaintext space M; obtain (K, coin) through ; input the public key pk, the plaintext m, and the random number coin into the encryption method CTRU.PKE.Enc to obtain the ciphertext c; output the ciphertext c and the shared key K;

[0014] Fourth step, execute the decapsulation method CTRU.KEM.Decaps to obtain the shared key. The calculation process is as follows: input the private key sk′: = (sk, z) and the ciphertext c; call the decryption method CTRU.PKE.Dec and input sk and c to decrypt to obtain the plaintext m′; obtain (K′, coin′) through ; obtain through calculation to obtain If the decrypted m′ is not equal to ⊥, and passing pk, m′, and coin′ into the encryption method CTRU.PKE.Enc results in an output equal to c, then output K′, otherwise output

[0015] The technical solution of the present invention will be described in detail herein. The present invention involves two parties: the client and the server. In order for the client to negotiate the same shared key with the server through a public channel, the client and the server need to set the common parameters required for all steps of the key encapsulation method according to the requirements, including the following steps:

[0016] S1. Set the common parameters required for all steps of the public key encryption method CTRU.PKE and the key encapsulation method CTRU.KEM according to the requirements:

[0017] S11. Set the common parameters for all steps of the public key encryption method CTRU.PKE: polynomial ring Ring dimension n, ring modulus q, polynomial quotient ring Polynomial ring Probability distribution ψ on f′ , Ψ g , Ψ r , Ψ e , Invertible elements p, θ, integers q1 and p′ in, plaintext space M = {0, 1} l And each element inside is an l-bit string, a small noise polynomial Polynomial encoding function PolyEncode, polynomial decoding function PolyDecode, ciphertext modulus q2 and q2 ≤ q and q2 ≤ p′, lossless compression algorithm LLCompress, lossless decompression algorithm LLDecompress;

[0018] S12. Set the common parameters for all steps of the key encapsulation method CTRU.KEM: positive integers ι, γ and ι, γ ≥ 256 are satisfied, public key space PK of CTRU.PKE, random space COINS of CTRU.PKE.Enc, shared key space of CTRU.KEM Hash function Fixed output length function ID: PK → {0, 1}γ, Output to Partial function of

[0019] The client needs to call the key generation method CTRU.KEM.KeyGen of CTRU.KEM of the present invention to generate a public-private key pair, retain the private key, and transmit the public key to the server, including the following steps:

[0020] S2. Execute the key generation method CTRU.KEM.KeyGen to generate the public and private key pairs of CTRU.KEM. The calculation process is as follows:

[0021] S21. By calling the key generation method CTRU.PKE.KeyGen of CTRU.PKE, calculate the public key pk and private key sk of CTRU.PKE. The calculation process of CTRU.PKE.KeyGen is as follows:

[0022] S211. Sample and generate a polynomial f′ from the Ψ f′ distribution, and sample and generate a polynomial g from the Ψ g ;

[0023] S212. Calculate

[0024] S213. If f is irreversible, repeat the above two steps of S211 and S212; otherwise, go to S214;

[0025] S214. Calculate or or or use the lossless compression algorithm LLCompress to compress g / f to calculate h = LLCompress(g / f), or remove several low bits of each dimension of g / f to obtain the public key h, where q1 ≤ q is an integer;

[0026] S215. Output h as the public key pk of CTRU.PKE, and LLCompress(f) as the private key sk of CTRU.PKE;

[0027] S22. Uniformly and randomly sample z from {0, 1} ι ;

[0028] S23. Obtain the public key pk′ of the key encapsulation method: = pk and the private key sk′: = (sk, z), retain the private key, and transmit the public key to the server;

[0029] After receiving the public key, the server calls the encapsulation method CTRU.KEM.Encaps of CTRU.KEM of the present invention, inputs the public key, obtains the ciphertext and the shared key, and transmits the ciphertext to the client, including the following steps:

[0030] S3. Execute the encapsulation method CTRU.KEM.Encaps to obtain the ciphertext and derive the shared key. The calculation process is as follows:

[0031] S31. Input the public key pk′ = pk;

[0032] S32. Randomly sample a plaintext m in the plaintext space M;

[0033] S33. Through calculate to obtain (K, coin);

[0034] S34. Pass the public key pk, the plaintext m, and the random number coin into the encryption method CTRU.PKE.Enc of the public key encryption method CTRU.PKE, and calculate to obtain the ciphertext c, where the encryption method CTRU.PKE.Enc is used to encrypt the plaintext to obtain the ciphertext, and the calculation process is as follows:

[0035] S341. Input the plaintext m ∈ M, and calculate for the public key pk Or calculate by decompressing h using the lossless decompression algorithm LLDecompress

[0036] S342. Sample and generate a polynomial from the Ψ r distribution or Sample and generate a polynomial from the Ψ e distribution or

[0037] S343. Calculate or or or For these cases, there is no need to sample and generate e; or where p′ ≤ q is an integer;

[0038] S344. Calculate the ciphertext or or or or

[0039] S345. Use the lossless compression algorithm LLCompress to compress and calculate c: = LLCompress(c), and output the ciphertext c;

[0040] S35. Obtain the ciphertext c and the shared key K, retain the shared key, and transmit the ciphertext to the client;

[0041] After receiving the ciphertext, the client calls the decapsulation method CTRU.KEM.Decaps of the present invention, inputs the private key and the ciphertext, and obtains the shared key, including the following steps:

[0042] S4. Execute the decapsulation method CTRU.KEM.Decaps to obtain the shared key, and the calculation process is as follows:

[0043] S41. Input the private key sk′ := (sk, z) and the ciphertext c;

[0044] S42. Decrypt the ciphertext c using the decryption method CTRU.PKE.Dec of the public key encryption method CTRU.PKE by passing in sk and c to obtain the plaintext m′. The decryption method CTRU.PKE.Dec is used to obtain the plaintext, and the calculation process is as follows:

[0045] S421. Input the private key sk = LLDecompress(f), the ciphertext

[0046] S422. Calculate

[0047] S423. Calculate

[0048] S424. Output the plaintext m′;

[0049] S43. Calculate (K′, coin′) through ;

[0050] S44. Calculate through

[0051] S45. If the decrypted m′ is not equal to ⊥, and when pk, m′, and coin′ are passed into the encryption method CTRU.PKE.Enc of the public key encryption method CTRU.PKE, and the output obtained by executing steps S341 to S345 is equal to c, then output K′ as the shared key; otherwise, output as the shared key.

[0052] Furthermore, in step S1, the polynomial ring can be chosen from one of the following polynomial rings: any cyclotomic polynomial ring containing wherein where F2 is a binary finite field; where the polynomial ring is a k×k matrix; where where where the polynomial ring is constructed based on the matrix ring; D[x] / (x n - 1), where D is a Dedekind domain; where the polynomial ring is a dual special type of binary truncated polynomial with positive integer coefficients; where A[x] / (x n -1), where A = {a + bi + cj + dk | a, b, c, d ∈ K, i2 = a, j2 = b, ij = k}.

[0053] Furthermore, the optional parameters of the ring dimension n in step S1 include {512, 576, 648, 701, 768, 864, 972, 1024, 1152, 1296, 1373}, the optional parameters of q include {7681, 3457} or a power of 2 or other integers; Ψ f′ , Ψ g , Ψ r , Ψ e are all distributions on the ring R, where each distribution can be obtained by synthesizing two or more distributions; p is an invertible element in, and an integer p = 2 or 3 that satisfies gcd(q, p) = 1 can be selected, or p = 1 - x n′ can be selected, n′ is an integer, which can be 512; θ can be selected as 1 or other integers; q2 is a ciphertext compression parameter, which can be set to {2 13 , 2 12 , 2 11 , 2 10 , 2 9 , 2 8 , p′, q}; each plaintext m ∈ M can be regarded as a polynomial of degree l, where l can be an integer less than or equal to n / 2, and the polynomial coefficients are in {0, 1} or {0, 1, 2} or {-1, 0, 1}.

[0054] Furthermore, the lossless compression algorithm LLCompress used in step S1 can select the following algorithm: the dimensions of the modulus vector Q and the polynomial coefficient vector H are n, and each integer coefficient of Q and H satisfies 0 ≤ h i < q i < 2 14 , if n = 0, then the vector S is empty, if n = 1, then the integers are all encoded in low bytes, and the corresponding number of bytes is selected according to the size of the integer; if n ≥ 2, then S can be obtained recursively, where the lengths of the sub-vectors H′ and Q′ are both For each pair of integers (h i , h i+1 ) mod q, they can be combined into a new integer in the manner of Subsequently is reduced to and satisfies ​Finally, output the compressed vector S; for the coefficient vector H, each coefficient can be divided into the lower 3 bits and the higher 7 bits in a way that 5 10-bit coefficients are stored using 48 bits, where the higher 7 bits of the 5 coefficients are jointly placed in 33 bits, and the lower 3 bits of the 5 coefficients are jointly placed in 15 bits; or other lossless compression algorithms.

[0055] Further, the lossless decompression algorithm LLDecompress adopted in step S1 can select the following algorithm: sequentially recover the integer pairs (h , h i , h i+1 ) mod q from , calculate the quotient of the division of i+1 by q with remainder as h i , and finally merge all the integer pairs (h i , h i+1 ) mod q to obtain the coefficient vector H of dimension n; in the 48 bits for storing every 5 10-bit coefficients, divide the higher 33 bits into the higher 7 bits of 5 coefficients, divide the lower 15 bits into the lower 3 bits of 5 coefficients, merge the lower 3 bits and the higher 7 bits of 5 pairs to obtain every 5 coefficients, and finally merge all the 5 coefficient pairs to obtain the coefficient vector H of dimension n; or other lossless decompression algorithms.

[0056] Further, the polynomial encoding function PolyEncode adopted in step S1 and the polynomial decoding function PolyDecode adopted in step S1 can be constructed based on scaled E8 lattice encoding or other error-correcting codes or no error-correcting codes.

[0057] Further, the FO conversion adopted in steps S1 - S4 can select other FO conversions with implicit rejection, or FO conversions with explicit rejection, or FO conversions with additional hash functions, or FO conversions that restore the original random numbers, or other FO conversions and their variants. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] In order to more clearly illustrate the technical solutions in the present invention, the following will briefly introduce the drawings required for the description of the present invention. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0059] Figure 1 It is a flowchart of the client and server in the embodiment of the present invention for exporting the shared key;

[0060] Figure 2 It is a flowchart of the key generation method of CTRU.KEM in the embodiment of the present invention;

[0061] Figure 3 Flow chart of the key generation method of CTRU.PKE in the embodiment of the present invention;

[0062] Figure 4 Flow chart of the encapsulation method of CTRU.KEM in the embodiment of the present invention;

[0063] Figure 5 Flow chart of the encryption method of CTRU.PKE in the embodiment of the present invention;

[0064] Figure 6 Flow chart of the decapsulation method of CTRU.KEM in the embodiment of the present invention;

[0065] Figure 7 Flow chart of the decryption method of CTRU.PKE in the embodiment of the present invention. Detailed implementation manners

[0066] In order to enable the personnel in the technical field to better understand the solution of the present application, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present invention.

[0067] In the present application, referring to "embodiment" means that the specific features, structures or characteristics described in combination with the embodiment may be included in at least one embodiment of the present application. The phrase appears in various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described in the present application can be combined with other embodiments.

[0068] Figure 1 Flow chart of the client and the server in the embodiment of the present invention for exporting the shared key. As Figure 1 shown, the present invention can be used to construct a post-quantum secure network transmission protocol to negotiate and export a shared key for both communication parties, which involves the public key encryption method and the key encapsulation method of the present invention.

[0069] In order for the client to negotiate the same shared key with the server through a public channel, it is necessary to set the common parameters required for all steps of the key encapsulation method with the server according to the requirements, including the following steps:

[0070] S1. Set the common parameters required for all steps of the public key encryption method CTRU.PKE and the key encapsulation method CTRU.KEM according to the requirements:

[0071] S11. Set the common parameters for all steps of the public-key encryption method CTRU.PKE: polynomial ring Ring dimension n, ring modulus q, polynomial quotient ring Polynomial ring Probability distribution ψ on f′ , Ψ g , Ψ r , Ψ e , Invertible element p in, plaintext space M = {0, 1} l And each element inside is an l-bit string, polynomial encoding function PolyEncode, polynomial decoding function PolyDecode, ciphertext modulus q2;

[0072] S12. Set the common parameters for all steps of the key encapsulation method CTRU.KEM: positive integers ι, γ and ι = γ = 256, public-key space PK of CTRU.PKE, random space COINS of CTRU.PKE.Enc, shared-key space of CTRU.KEM Hash function Fixed-output length function ID: PK → {0, 1} γ , Output to Partial function to

[0073] The client needs to call the key generation method CTRU.KEM.KeyGen of the present invention to generate a public-private key pair, retain the private key and transmit the public key to the server, including the following steps:

[0074] S2. Execute the key generation method CTRU.KEM.KeyGen to generate a public-private key pair of CTRU.KEM, and the calculation process is as shown in the appendix Figure 2 As follows:

[0075] S21. By calling the key generation method CTRU.PKE.KeyGen of CTRU.PKE, calculate the public key pk and private key sk of CTRU.PKE, where the calculation process of CTRU.PKE.KeyGen is as shown in the appendix Figure 3 As follows:

[0076] S211. Sample to generate polynomial f' from the Ψ f′ distribution, and sample to generate polynomial g from Ψ g ;

[0077] S212. Calculate

[0078] S213. If f is irreversible, repeat the above two steps S211 and S212; otherwise, go to S214;

[0079] S214. Calculate

[0080] S215. Output h as the public key pk of CTRU.PKE and f as the private key sk of CTRU.PKE;

[0081] S22. Uniformly and randomly sample z from {0, 1} ι ;

[0082] S23. Obtain the public key pk′ of the key encapsulation method: = pk and the private key sk′: = (sk, z), retain the private key, and transmit the public key to the server;

[0083] After receiving the public key, the server calls the encapsulation method CTRU.KEM.Encaps of the CTRU.KEM of the present invention, inputs the public key, obtains the ciphertext and the shared key, and transmits the ciphertext to the client, including the following steps:

[0084] S3. Execute the encapsulation method CTRU.KEM.Encaps to obtain the ciphertext and derive the shared key. The calculation process is as shown in the appendix Figure 4 as follows:

[0085] S31. Input the public key pk′ = pk;

[0086] S32. Randomly sample the plaintext m in the plaintext space M;

[0087] S33. Calculate (K, coin) through ;

[0088] S34. Input the public key pk, the plaintext m, and the random number coin into the encryption method CTRU.PKE.Enc of the public key encryption method CTRU.PKE, and calculate the ciphertext c. The encryption method CTRU.PKE.Enc is used to encrypt the plaintext to obtain the ciphertext. The calculation process is as shown in the appendix Figure 5 as follows:

[0089] S341. Input the plaintext m ∈ M and the public key pk = h;

[0090] S342. Sample and generate polynomials r from the Ψ Sample and generate polynomials e from the Ψ

[0091] S343. Calculate σ = hr + e ∈ R q ;

[0092] S344, Compute the ciphertext

[0093] S345, Output the ciphertext c;

[0094] S35, Obtain the ciphertext c and the shared key K, retain the shared key, and transmit the ciphertext to the client;

[0095] After receiving the ciphertext, the client invokes the decapsulation method CTRU.KEM.Decaps of the present invention, inputs the private key and the ciphertext, and obtains the shared key, including the following steps:

[0096] S4, Execute the decapsulation method CTRU.KEM.Decaps to obtain the shared key, and the calculation process is as shown in the appendix Figure 6 as follows:

[0097] S41, Input the private key sk′ := (sk, z) and the ciphertext c;

[0098] S42, Decrypt the ciphertext c by calling the decryption method CTRU.PKE.Dec of the public key encryption method CTRU.PKE and passing in sk and c to obtain the plaintext m′, where the decryption method CTRU.PKE.Dec is used to obtain the plaintext, and the calculation process is as shown in the appendix Figure 7 as follows:

[0099] S421, Input the private key sk = f and the ciphertext c;

[0100] S422, Calculate

[0101] S423, Calculate

[0102] S424, Output the plaintext m′;

[0103] S43, Calculate (K′, coin′) through ;

[0104] S44, Calculate through

[0105] S45, If the decrypted m′ is not equal to ⊥, and when pk, m′ and coin′ are passed into the encryption method CTRU.PKE.Enc of the public key encryption method CTRU.PKE and the output obtained by executing steps S341 to S345 is equal to c, then output K′ as the shared key, otherwise output as the shared key.

[0106] Further, the polynomial encoding function PolyEncode adopted in step S344 and the polynomial decoding function PolyDecode adopted in step S423 are constructed based on the scaled E8 lattice encoding. The specific construction of the scaled E8 lattice is E8 = λ·[C ∪ (C + c)], where the scaling factor can be or or or or or c = (0, 1, 0, 1, 0, 1, 0, 1), C = {(x1, x1, x2, x2, x3, x3, x4, x4) ∈ {0, 1} 8 |∑x i ≡ 0 mod 2}. The polynomial encoding function PolyEncode is when the scaling factor is of two, and the plaintext is divided into l / 2 quadruples in the form of (m 4i , m 4i+1 , m 4i+2 , m 4i+3 ) ∈ {0, 1} 4 quadruples, i ∈ {0, 1,..., l / 2 - 1}; and all quadruples are input into the function for E′8 lattice encoding to obtain octuples (v 8i , v 8i+1 ,..., v 8i+7 ), and finally output The polynomial decoding function PolyDecode is when the scaling factor is of on, the input is divided into n / 8 octuples in the form of (v 8i , v 8i+1 ,..., v 8i+7 ), and each octuple passes through the function to obtain (m 4i , m 4i+1 , m 4i+2 , m 4i+3 ), where

[0107] Further, the adopted scaled E8 lattice encoding algorithm and decoding algorithm are constructed as follows. The encoding algorithm of the scaled E8 lattice encoding is to input a 4-bit binary string k, calculate and output λ·(kH mod 2), where H is a 4×8 binary matrix generated by C and c. The decoding algorithm is the solution to the closest vector problem based on the scaled E8 lattice. To solve the closest vector problem in E8, the closest vector problem of x and x - λc on the lattice C′ = λ·C is solved instead. First, input Calculate (k0, TotalCost0) = Decode c′ (x), (k1, TotalCost1) = Decode c′ (x - λc), assign the smaller subscript of TotalCost0 and TotalCost1 to b, and get (k0, k1, k2, k3): = k b , and output

[0108] Furthermore, the Decode C′ algorithm in the algorithm is defined as follows to solve the closest vector problem of the lattice C′. Given For every two components in x, determine whether they are close to (0, 0) or (λ, λ). If close to (0, 0), assign k = 0. If close to (λ, λ), assign k = 1. If ∑k i mod 2 = 0, it indicates that λ·(k0, k1, k2, k2, k3, k3) is the closest vector. However, ∑k i mod 2 may also be equal to 1. In this case, select the second closest vector λ·(k0′, k1′, k2′, k2′, k3′, k3′), where (k0, k1, k2, k3) and (k0′, k1′, k2′, k3′) differ by at most 1 bit. The detailed definition of the DecodeC′ algorithm is as follows: First, input Assign positive infinity to mind, 0 to mini, and calculate Compare the sizes of c0 and c1, and assign the subscript of the smaller one to k i . Calculate TotalCost = TotalCost + c ki . If then calculate, mini = i, where i ∈ {0, 1, 2, 3}. After calculating all k0, k1, k2, k3, determine whether k0 + k1 + k2 + k3 mod 2 is equal to 1. If it is equal to 1, calculate k mini = 1 - k mini , and TotalCost = TotalCost + mind. Finally, get k: = (k0, k1, k2, k3) ∈ {0, 1} 4 , and the algorithm returns (k, TotalCost).

[0109] Furthermore, the Decode C′ algorithm, for any 8-dimensional vector that is close enough to a given lattice point in the scaled E8 lattice under the l2-norm metric, can be decoded into the same 4-bit string that generates the lattice point. Specifically, for any given k1 ∈ {0, 1} 4 , define For any define If ||v2 - v1|| 2λ,2 < λ, then k1 = k2.

[0110] Furthermore, the public key encryption method CTRU.PKE described above is IND-CPA secure under the NTRU hardness assumption and the RLWE hardness assumption. Among them, for any adversary A, there exist adversaries B and C such that

[0111] Furthermore, the key encapsulation method CTRU.KEM described above is IND-CCA secure in the classical and quantum random oracle models. Among them, let l be the min-entropy of ID(pk), l = H ∞ (ID(pk)), where pk is the public key of the CTRU.PKE scheme. For any adversary A, it can perform at most q D decapsulation queries, q H (quantum) random oracle queries. There exists an adversary B with approximately the same running time as A. Under the random oracle ROM, it satisfies Under the quantum random oracle QROM, it satisfies where q HD : = q H + q D + 1.

[0112] To further elaborate on the technical solution of the present invention, the following further details the cryptographic system of the present invention in combination with specific parameters.

[0113] This implementation can provide target security strengths that meet NIST recommendations Levels I, III, and V. This implementation gives the first set of specific example parameters. The modulus q of the polynomial ring can be set to 3457, and the plaintext space modulus p = 2 is selected. The underlying polynomial ring Ψ is a probability distribution, and B2 is a centered binomial distribution with parameter 2. The public key size is |pk|, the ciphertext size is |ct|, B.W. is the communication bandwidth, "C" and "Q" respectively represent the estimated security levels in classical and quantum settings in bits, and δ represents the error rate. The present invention provides the parameters shown in Table 1 below for reference, but is not limited to the parameter selection in the following table.

[0114] Table 1

[0115]

[0116] This implementation gives the parameters of the second set of specific examples. The modulus q of the polynomial ring can be set to 641, the ciphertext modulus is q2, and p = 1 - x is selected. 512 . The underlying polynomial ring (Ψ f′ = Ψ g , Ψ r ) is a probability distribution, B1 is a centered binomial distribution with parameter 1, and T 1 / 5 and T 1 / 6 are respectively ternary distributions with the probability of non-zero elements equal to 1 / 5 and 1 / 6. The present invention provides the parameters shown in Table 2 below for reference, but is not limited to the parameter selection in the following table.

[0117] Table 2

[0118]

[0119] Compared with the prior art, the positive effects of the present invention are as follows:

[0120] 1. More efficient: The key generation, encryption, and decryption algorithms of CTRU have a simple structure and only require one polynomial in the encryption / decryption process. Therefore, the sampling of public and private keys is very efficient.

[0121] 2. Shorter ciphertext length: This CTRU key encapsulation scheme constructs ciphertexts based on RLWE instances and compresses each coefficient from to where q2 is called the ciphertext compression modulus. And q2 is adjustable, which depends on how many bits need to be discarded from the ciphertext. Compared with other NTRU-based schemes, this CTRU scheme has a shorter key length. For example, compared with NTRU-HRSS, CTRU-768 can reduce the ciphertext size to 7% and 15% respectively, corresponding to the cases where q2 is taken as 2 11 and 2 10 .

[0122] 3. Tighter reduction bounds: Based on the NTRU assumption and the RLWE assumption, CTRU.PKE can achieve IND-CPA security, while most NTRU-based PKEs can only achieve OW-CPA security. The IND-CCA reduction advantage of CTRU.KEM is tighter than that of NTTRU and the scheme. For example, in the quantum setting, the CCA reduction bound of CTRU.KEM is while the bound of NTTRU is and the bound of

[0123] is

[0124] where ∈ is the advantage for the underlying hardness assumption and q′ is the total number of queries. Although NTRU-HRSS has a tight CCA reduction bound, the additional random recovery method used in it is relatively complex, which slows down the encryption process of NTRU-HRSS. -128 4. Stronger security against some existing attacks. CTRU has stronger security in both traditional and quantum models compared to other NTRU-based schemes. For the NTRU attack, the recommended security bits for CTRU-768 are 181 and 164, while NTRU-HRSS only has 136 and 124.

[0124] 5. Negligible error rate. The present invention uses a dense scaled 8-dimensional lattice coding algorithm, enabling a lower error rate when recovering the plaintext. Previous lattice coding algorithms were only applicable to integers. The present invention extends it to the real number domain and provides a corresponding decoding algorithm. The new decoding algorithm has a tighter correctness bound. Based on these technologies, the error rate of CTRU can be controlled low enough to be negligible. Specifically, when compressing the ciphertext by 1 bit and 2 bits, the error rate is lower than 2 -128 .

Claims

1. A key encapsulation, encryption and decryption method based on NTRU, characterized in that It includes a public-key encryption method CTRU.PKE with chosen-plaintext security and a key encapsulation method CTRU.KEM with chosen-ciphertext security, and the steps are as follows: S1. Set the common parameters required for all steps of the public key encryption method CTRU.PKE and the key encapsulation method CTRU.KEM according to the requirements: polynomial ring Ring dimension n, ring modulus q, polynomial quotient ring Polynomial ring Probability distribution ψ on f′ , Ψ g , Ψ r , Ψ e , Invertible elements p, θ in, integers q1 and p′, plaintext space M = {0, 1} l And each element inside is an l-bit string, a small noise polynomial Polynomial encoding function PolyEncode, polynomial decoding function PolyDecode, ciphertext modulus q2 and q2 ≤ q and q2 ≤ p′, lossless compression algorithm LLCompress, lossless decompression algorithm LLDecompress; positive integers ι, γ and ι, γ ≥ 256, public key space PK of CTRU.PKE, random space COINS of CTRU.PKE.Enc, shared key space of CTRU.KEM Hash function Fixed output length function ID: PK → {0, 1} γ , Output to Partial function of S2. Execute the key generation method CTRU.KEM.KeyGen to generate a public-private key pair. The calculation process is as follows: Calculate the public key pk and private key sk of CTRU.PKE through the key generation method CTRU.PKE.KeyGen; Among them, the calculation process of CTRU.PKE.KeyGen is as follows: Sample a polynomial f′ from the ψ f′ distribution to generate a polynomial f′, and sample a polynomial g from Ψ g ; Calculate If f is irreversible, repeat the above two steps; Calculate or or or use the lossless compression algorithm LLCompress to compress g / f to calculate h = LLCompress(g / f), or remove several low bits of each dimension of g / f to obtain the public key h, where q1 ≤ q is an integer; Output h as the public key pk and LLCompress(f) as the private key sk; After obtaining \(pk\) and \(sk\), uniformly and randomly sample \(z\) from \(\{0, 1\}\) ι ; output the public key \(pk' := pk\) and private key \(sk' := (sk, z)\) of the key encapsulation method; S3. Execute the encapsulation method CTRU.KEM.Encaps to obtain the ciphertext and the exported shared key. The calculation process is as follows: Input the public key pk′ = pk; randomly sample the plaintext m in the plaintext space M; through calculate to obtain (K, coin); input the public key pk, the plaintext m and the random number coin into the encryption method CTRU.PKE.Enc, and calculate to obtain the ciphertext c; Among them, the calculation process of CTRU.PKE.Enc is as follows: Given the plaintext m ∈ M, calculate for the public key pk Or calculate by decompressing h using the lossless decompression algorithm LLDecompress Sample from Ψ r distribution to generate a polynomial Or Sample from Ψ e to generate a polynomial Or Calculate Or Or Or In this case, there is no need to sample to generate e; or where p′ ≤ q is an integer; calculate the ciphertext Or Or Or Or Use the lossless compression algorithm LLCompress to compress and calculate c := LLCompress(c), and output the ciphertext c; After obtaining the ciphertext c; Output the ciphertext c and the shared key K; S4. Execute the decapsulation method CTRU.KEM.Decaps to obtain the shared key. The calculation process is as follows: Input the private key sk′:=(sk, z) and the ciphertext c; Decrypt the ciphertext c by calling the decryption method CTRU.PKE.Dec and passing in sk and c to obtain the plaintext m′; Among them, the calculation process of CTRU.PKE.Dec is as follows: Input the private key sk = LLDecompress(f), and the ciphertext Calculate Calculate Output the plaintext m'; After obtaining the plaintext m′, through calculate to obtain (K′, coin′); through calculate to obtain If the decrypted m′ is not equal to ⊥, and passing pk, m′ and coin′ into the encryption method CTRU.PKE.Enc results in an output equal to c, then output K′; otherwise output 2. The method according to claim 1, characterized in that, In step S1, the polynomial ring One of the following polynomial rings can be selected: including and Any cyclotomic polynomial ring including them where F2[T][x] / (x n -1), where F2 is a binary finite field; where the polynomial ring is a k×k matrix; where where the polynomial ring is constructed based on the matrix ring; D[x] / (x n -1), where D is a Dedekind domain; where the polynomial ring is a dual special type of binary truncated polynomial with positive integer coefficients; where A[x] / (x n -1), where A = {a + bi + cj + dk|a, b, c, d ∈ K, i 2 = a, j 2 = b, ij = k}.

3. The method according to claim 1, wherein The optional parameters of the loop dimension n in step S1 include {512, 576, 648, 701, 768, 864, 972, 1024, 1152, 1296, 1373}, the optional parameters of q include {7681, 3457} or a power of 2 or other integers; Ψ f′ , Ψ g , Ψ r , Ψ e are all distributions on the loop , where each distribution can be obtained by combining two or more distributions; p is an invertible element in, an integer p = 2 or 3 that satisfies gcd(q, p) = 1 can be selected, or p = 1 - x n′ , n' is an integer, which can be 512; θ can be selected as 1 or other integers; q2 is a ciphertext compression parameter and can be set to a value in {2 13 , 2 12 , 2 11 , 2 10 , 2 9 , 2 8 , p′, q}; each plaintext m ∈ M can be regarded as a polynomial of degree l, where l can be an integer less than or equal to n / 2, and the polynomial coefficients are in {0, 1} or {0, 1, 2} or {-1, 0, 1}.

4. The method according to claim 1, wherein The lossless compression algorithm LLCompress used in step S1 can select the following algorithms: The dimensions of the modulus vector Q and the polynomial coefficient vector H are n, and each integer coefficient of Q and H satisfies 0 ≤ h i < q i < 2 14 , if n = 0, then the vector S is empty, if n = 1, then the integers are all encoded in low bytes, and the corresponding number of bytes is selected according to the size of the integers; if n ≥ 2, then S can be obtained recursively, where the lengths of the sub-vectors H' and Q' are both For each pair of integers (h i , h i+1 ) mod q, they can be combined into a new integer in the manner of Subsequently q is reduced to and satisfies Finally, the compressed vector S is output; for the coefficient vector H, the way of storing 5 10-bit coefficients with 48 bits can be used. Each coefficient is divided into the lower 3 bits and the higher 7 bits. The higher 7 bits of the 5 coefficients are placed together in 33 bits, and the lower 3 bits of the 5 coefficients are placed together in 15 bits; or other lossless compression algorithms.​ 5. The method according to claim 1, wherein The lossless decompression algorithm LLDecompress used in step S1 can select the following algorithms: sequentially recover integer pairs (h from i , h i+1 ) mod q, calculate the quotient of with respect to q in the division with remainder as h i+1 , and the remainder as h i . Finally, all the integer pairs (h i , h i+1 ) mod q are combined to obtain a coefficient vector H of dimension n; in every 48 bits storing 5 10-bit coefficients, the upper 33 bits are divided into the upper 7 bits of 5 coefficients, and the lower 15 bits are divided into the lower 3 bits of 5 coefficients. The lower 3 bits and the upper 7 bits of 5 pairs are combined to obtain every 5 coefficients. Finally, all the 5 coefficient pairs are combined to obtain a coefficient vector H of dimension n; or other lossless decompression algorithms.

6. The method according to claim 1, characterized in that, The polynomial encoding function PolyEncode adopted in step S1 and the polynomial decoding function PolyDecode adopted in step S1 can be constructed based on the scaled E8 lattice encoding or other error-correcting codes or without error-correcting codes.

7. The method according to claim 6, wherein For the polynomial encoding function PolyEncode, the construction based on the scaled E8 lattice coding is on a scaling factor of and divides the plaintext into l / 2 quadruples of the form (m , m 4i , m 4i+1 , m 4i+2 , m 4i+3 ) ∈ {0, 1} 4 , where i ∈ {0, 1,..., l / 2 - 1}; And input all the quadruples into the function for E′8 lattice encoding to obtain the octuple (v 8i , v 8i+1 ,..., v 8i+7 ), and finally output 8. The method according to claim 6, wherein For the polynomial decoding function PolyDecode, the construction based on the scaled E8 lattice is on the scale factor of of , and the input is divided into n / 8 octuples of the form (v 8i , v 8i+1 ,..., v 8i+7 ). Each octuple passes through the function to obtain (m 4i , m 4i+1 , m 4i+2 , m 4i+3 ), where 9. The method according to any one of claims 7 and 8, characterized in that For the scaled E8 lattice code, the specific construction of the scaled E8 lattice is E8 = λ·[C ∪ (C + c)], where the scaling factor can be or or or or or c = (0, 1, 0, 1, 0, 1, 0, 1), C = {(x1, x1, x2, x2, x3, x3, x4, x4) ∈ {0, 1} 8 | ∑x i ≡ 0 mod 2}.

10. The method according to any one of claims 7 and 8, characterized in that For the scaled E8 lattice code, the encoding algorithm of the scaled E8 lattice code is to input a 4-bit binary string k, calculate and output Decoding algorithm is the solution to the closest vector problem based on the scaled E8 lattice. Its input is an 8-dimensional vector Output a 4-bit binary string 11. The method according to claim 1, characterized in that, The FO transformation adopted in steps S1-S4 can be other FO transformations with implicit rejection, or FO transformations with explicit rejection, or FO transformations with additional hash functions, or FO transformations for restoring the original random numbers, or other FO transformations and their variants.

Citation Information

Cited By

  • Efficient key encapsulation method based on modular fault-tolerant rounding problem

    CN121567316A

  • Security analysis method of NTRU private key under any Hamming weight

    CN121727742A

  • A method for secure analysis of NTRU private keys under arbitrary Hamming weights

    CN121727742B

  • Secret key packaging method and device

    CN122226285A

  • Post-quantum identification key packaging method and device

    CN122247622A