Joint encryption coding method based on McEliece and polarization code under wiretap model

Through the joint encryption encoding method based on McEliece and polarized code, using Monte Carlo optimization and high-order constellation symbol modulation, the freezing bits of the public key matrix and polarized code are dynamically optimized, and the problem of resisting quantum computing attacks and ciphertexts are easily analyzed in a low signal-to-noise environment is solved, and efficient and secure communication is achieved.

CN120498672APending Publication Date: 2025-08-15FUZHOU UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510656282.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

The existing technology has insufficient ability to resist quantum computing attacks in a low signal-to-noise environment, the static encryption rules are easily cracked, and the statistical characteristics of ciphertexts are easily analyzed by eavesdroppers, making it difficult to meet the communication needs of low-latency and low-power scenarios.

Method used

Using a joint encryption encoding method based on McEliece and polarization code, a Gaussian distribution public key matrix is generated through the Monte Carlo optimization algorithm, and the reliable channel position is determined using the Bhattacharyya parameter of the polarization code, high-order constellation symbol modulation and non-uniform energy distribution are performed, and the frozen bits of the polarization code are embedded to achieve dynamically optimized physical layer hidden transmission.

Benefits of technology

It improves communication capabilities in low signal-to-noise ratio environments and security under quantum computing attacks, enhances ciphertext concealment, reduces the average transmission power, adapts to the channel state, and improves channel capacity utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498672A_ABST
    Figure CN120498672A_ABST
Patent Text Reader

Abstract

The invention relates to a joint encryption coding method based on McEliece and a polarization code under a wiretap model, and the method comprises the steps: a transmitting end generates an McEliece public key matrix of which the row weight obeys discrete Gaussian distribution based on a Monte Carlo optimization algorithm, and enables the probability distribution of an encrypted ciphertext symbol modulated by a high-order constellation symbol to approach the Gaussian characteristic; determining a reliable channel position by using a Bhatpacarya parameter of the polarization code, embedding an encrypted ciphertext bit into a high-reliability information bit of the polarization code, and encoding a dynamically optimized public key parameter to a frozen bit of the polarization code to realize hidden transmission of a physical layer; and the receiving end recovers the original plaintext from the noise-containing channel through cooperative processing of private key decryption and polar code decoding. According to the method, the communication capability in a low signal-to-noise ratio environment can be improved, and meanwhile, the security of information under quantum computing attacks is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computing technology, and in particular to a joint encryption coding method based on McEliece and polar codes under a wiretap model. Background Art

[0002] With the rapid development of quantum computing technology, traditional public key cryptography systems (such as RSA and ECC) face potential threats from quantum attacks. Research on quantum-resistant cryptographic systems has become crucial for ensuring future communication security. In the field of physical layer security, the wiretap secure transmission method based on polarization codes has attracted much attention due to its error correction performance close to the Shannon limit. Existing technologies mainly improve anti-eavesdropping capabilities through dynamic obfuscation structures (such as chain encryption and two-dimensional obfuscation) and nonlinear obfuscation modules (such as S-box), but they still have the following limitations:

[0003] 1. Static encryption rules and long-term security risks. Existing solutions (such as the "Physical Layer Confidential Communication Transmission Method for Wiretap Channels Based on Polar Codes") increase the difficulty for eavesdroppers to crack through frame-level dynamic encryption mechanisms (such as cross-frame key transfer and multi-level obfuscation within the group). However, its encryption logic relies on fixed preset positions (such as S sets) and replacement rules, and can be easily cracked by eavesdroppers through pattern learning after long-term multi-frame interaction. In addition, multi-layer obfuscation operations (such as secondary intra-frame obfuscation + inter-frame obfuscation) lead to a significant increase in encoding and decoding complexity, making it difficult to meet the requirements of low-latency and low-power scenarios.

[0004] 2. Insufficient static obfuscation parameters and anti-analysis capabilities. Another existing solution (such as the "Polar Code-Based AWGN-Wiretap Channel Anti-Eavesdropping Security Structure") uses linear obfuscation (XOR device, interleaver) and nonlinear obfuscation (S-box) to enhance resistance to differential attacks. However, the obfuscation parameters are fixed and can be easily cracked by eavesdroppers through statistical correlation analysis after long-term use. Furthermore, the hardware implementation complexity of static interleaving patterns and nonlinear S-boxes is relatively high, making them difficult to adapt to the resource constraints of low-power devices.

[0005] 3. Poor compatibility between ciphertext statistical characteristics and channel noise. Existing technologies do not fully consider the compatibility between ciphertext statistical characteristics and the natural channel noise distribution. Eavesdroppers can identify encrypted signals by analyzing the distribution characteristics (such as uniformity) of ciphertext symbols and launch targeted attacks. Furthermore, existing solutions suffer from insufficient channel capacity utilization in low signal-to-noise ratio scenarios, making it difficult to balance security and transmission efficiency.

[0006] To address the above problems, there is an urgent need for a new joint encryption coding scheme that can not only resist quantum computing attacks, but also dynamically optimize and adapt the channel state and improve the concealment of ciphertext. Summary of the Invention

[0007] The purpose of the present invention is to provide a joint encryption coding method based on McEliece and polar codes under the wiretap model, which can improve the communication capability in a low signal-to-noise ratio environment and enhance the security of information under quantum computing attacks.

[0008] To achieve the above objectives, the technical solution adopted by the present invention is: a joint encryption coding method based on McEliece and polar codes under the wiretap model. The transmitter generates a McEliece public key matrix with row weights obeying a discrete Gaussian distribution based on a Monte Carlo optimization algorithm, so that the probability distribution of the encrypted ciphertext symbols after modulation by high-order constellation symbols approaches the Gaussian characteristics. The Bhattacharyya parameters of the polar code are then used to determine the reliable channel position, the encrypted ciphertext bits are embedded in the high-reliability information bits of the polar code, and the dynamically optimized public key parameters are encoded into the frozen bits of the polar code to achieve physical layer covert transmission. The receiver recovers the original plaintext from the noisy channel through the collaborative processing of private key decryption and polar code decoding.

[0009] Furthermore, in the public key matrix generation stage, a binary matrix G′∈{0, 1} that satisfies the target Gaussian distribution characteristics is generated through a dynamic search algorithm. k×n ; Weight of each row w i According to the discretized Gaussian distribution N(μ, σ 2 ) random sampling, and ensure that the weight value is within the set range through truncation operation; the goal of the Monte Carlo optimization algorithm is to minimize the difference between the encrypted symbol distribution and the ideal Gaussian distribution; by calculating the simulated symbol probability P sim (s) and the target distribution P target KL divergence D of (s) KL :

[0010]

[0011] When D KL When it is lower than the preset threshold, the current matrix is output as the optimal solution, otherwise the distribution parameters are adjusted iteratively; the Monte Carlo closed-loop feedback mechanism dynamically adjusts the Gaussian parameters according to the channel conditions to ensure that the encrypted signal always adapts to the channel capacity limit and security requirements, and finds the optimal solution public key matrix G′ while saving the generator matrix G, permutation matrix P and reversible matrix S required for the private key.

[0012] Furthermore, let the even-numbered rows of the public key matrix G have weights w 2t Obey Gaussian distribution N(μ, σ 2 ), the probability of generating bit 1 in the information bit is p = 1 / max(w i ), according to the McEliece encryption rule, each bit of the ciphertext c i The probability of being 1 is approximately:

[0013] P(c i =1)≈p·w i

[0014] Because of w 2t ~N(μ,σ 2 ), and p=1 / max(w i ), then p·w 2t The distribution of is scaled to the interval [0, 1], but still maintains the Gaussian shape;

[0015] Odd row weight w 2t-1 Set to uniform distribution so that P(c 2t-1 =1)≈0.5 ensures the symmetry of symbol probability.

[0016] Furthermore, in the encryption and modulation stage, the plaintext m∈{0,1} k The ciphertext bitstream is generated by the following matrix multiplication:

[0017] c=mG′mod 2

[0018] The ciphertext is divided into two consecutive ciphertext bits (c 2t-1 , c 2t ) packets are mapped into 4-PAM symbol streams, the rules of which are:

[0019] 00→-3,01→-1,

[0020] 11→1, 110→3,

[0021] Assuming that the parity bits are independent, the symbol probability is calculated by the joint probability:

[0022] P(-3)=P(00)=P(c 2t-1 =0)·P(c 2t =0) = 0.5·(1-pw 2t ),

[0023] P(-1)=P(01)=0.5·pw 2t ,

[0024] P(1)=P(11)=0.5·pw 2t ,

[0025] P(3)=P(10)=0.5·(1-pw 2t )

[0026] Since the even row weight w 2t Obey Gaussian distribution, pw 2t It also exhibits Gaussian properties, so that the probability of each symbol satisfies:

[0027]

[0028] Therefore, the distribution shape of the symbol probability is directly determined by the Gaussian distribution of the even-numbered row weights.

[0029] Furthermore, after encryption and modulation, the symbol stream is encoded using polar codes to optimize transmission reliability. Based on channel polarization theory, polar codes decompose the original channel into multiple subchannels through polarization transformation. High-reliability subchannels, or good channels, are used to transmit information bits, while low-reliability subchannels, or bad channels, are fixed as frozen bits. For polar codes with code length N, the reliability of each subchannel is evaluated using the Bhattacharyya parameter, which is defined as:

[0030]

[0031] Where W:χ→γ represents a symmetric binary input discrete memoryless channel (B-DMC), the input alphabet is χ, the output alphabet is γ, and the transition probability W(y|x) represents the conditional probability that the output symbol y∈γ will be output after the input symbol x∈χ is transmitted through the channel.

[0032] Sub-channel W i is defined as:

[0033]

[0034] The above formula shows that when the received signal is known and previous input Under the condition that the i-th sub-channel is sensitive to the current input u i The transition probability of is the sequence of input bits from the 1st to the i-1th;

[0035] By setting a threshold N = {1, 2, ..., N}, N-bit channels are divided into good channels and bad channels, and the index sets of good channels and bad channels are respectively:

[0036] G(W,β)={i∈[N]:Z(W i )<2 -Nβ}

[0037] B(W,β)={i∈[N]:Z(W i )≥2 -Nβ}

[0038] The good channels G(W, β) are selected as information bits, and the rest are classified as bad channels B(W, β) as frozen bits. When the code length N→∞, the proportion of information bits approaches the channel symmetric capacity C(W), that is:

[0039]

[0040] Achieve transmission efficiency close to the Shannon limit.

[0041] Furthermore, the high-order constellation modulation is 4-PAM modulation. The encrypted 4-PAM symbol stream is first converted into a binary bit sequence. Based on the channel polarization result of the polar code, the bit stream is embedded in high-reliability information bits, and the structural parameters of the public key matrix are encoded into frozen bits to ensure that the receiving end can synchronously decrypt using the private key. The symbol probability distribution satisfies the non-uniform energy distribution rule, allocating low transmission energy to the high-probability symbol {-1, 1} and high transmission energy to the low-probability symbol {-3, 3}. The energy distribution ratio satisfies:

[0042]

[0043] Among them, E s is the symbol energy, and P(s) is the symbol probability. By non-uniform energy distribution, the average transmit power is reduced while maintaining the anti-noise performance.

[0044] Furthermore, at the receiving end, the received signal is processed by the polar code decoding module, and the ciphertext symbol stream and the public key parameters embedded in the frozen bits are separated from the channel output using the continuous cancellation list decoding algorithm SCL; the SCL algorithm maintains the likelihood metric of multiple candidate paths. Dynamically expand the path and select the most likely decoding result, where Indicates u i The decoding estimate of i calculate:

[0045]

[0046] in, is the decoded sequence from the 1st to the i-1th bit, and y is the received signal; by screening the high-reliability information bits, the binary bit sequence corresponding to the ciphertext symbol stream is extracted;

[0047] The ciphertext bit stream then enters the 4-PAM demodulation module, where it performs an inverse conversion based on the preset symbol mapping rule, restoring the symbol value to the original bit pair. The mapping rule is:

[0048] -3→00, -1→01,

[0049] 1→11, 3→10,

[0050] During the demodulation process, the minimum Euclidean distance criterion is used to determine the closest legal symbol s from the noisy received symbol s. The decision formula is:

[0051]

[0052] Finally, the demodulated ciphertext bit stream is input into the McEliece decryption module, which uses the private key to perform decryption operations. The decryption process recovers the plaintext m by solving a system of linear equations or a fast algorithm based on the characteristics of sparse matrices:

[0053] m=cG' -1 Mod 2

[0054] Among them, G′ -1 is the inverse matrix of the public key matrix; the public key parameter hash value embedded in the frozen bit is used to verify the matrix consistency and prevent tampering attacks.

[0055] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory, wherein the processor implements the above method when executing the computer program.

[0056] The present invention also provides a computer-readable storage medium storing a computer program, wherein the computer program implements the above method when executed by a processor.

[0057] Compared with existing technologies, the present invention has the following beneficial effects: To address the problems of insufficient channel capacity utilization and susceptibility of ciphertext statistical characteristics to eavesdroppers in low signal-to-noise ratio scenarios in existing quantum-resistant encryption schemes, this invention proposes a joint encryption coding method based on the deep coupling of the McEliece quantum-resistant public key system and polarization codes. Through Gaussian distribution adaptation and dynamic matrix optimization, this method prevents illegal eavesdroppers from recovering complete information from the eavesdropped channel, ensuring one-way transparency of the information to legitimate recipients. This method more rationally utilizes the characteristics and principles of both McEliece encryption and polarization code encoding technologies. Compared with traditional polarization code-based wiretap channels, this method can fully utilize the system's communication potential in low signal-to-noise ratio environments while enhancing the security of information under quantum computing attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] Figure 1 is a flowchart of the implementation of the joint encryption coding method according to an embodiment of the present invention;

[0059] Figure 2 1 is a flowchart of the implementation of public key matrix generation and encryption-modulation combination in an embodiment of the present invention;

[0060] Figure 3 1 is a diagram illustrating the implementation principle of polar code encoding in an embodiment of the present invention;

[0061] Figure 4 This is a processing flow chart of the receiving end in an embodiment of the present invention. DETAILED DESCRIPTION

[0062] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0063] It should be noted that the following detailed descriptions are exemplary and are intended to provide further explanation of the present application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which the present application belongs.

[0064] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present application. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprise" and / or "include" are used in this specification, they indicate the presence of features, steps, operations, devices, components and / or combinations thereof.

[0065] This embodiment provides a joint encryption coding method based on McEliece and polarization code under the wiretap model, such as Figure 1 As shown, at the transmitter, Alice, a Monte Carlo optimization algorithm is first used to generate a McEliece public key matrix with row weights following a discrete Gaussian distribution. This ensures that the probability distribution of the encrypted ciphertext symbols after modulation by high-order constellation symbols approaches Gaussian characteristics. The Bhattacharyya parameters of the polarization code are then used to determine the reliable channel location. The encrypted ciphertext bits are then embedded in the high-reliability information bits of the polarization code, and the dynamically optimized public key parameters are encoded into the frozen bits of the polarization code to achieve covert physical layer transmission. Furthermore, a non-uniform symbol mapping strategy is incorporated to concentrate high-probability symbols at low energy levels, optimizing transmit power efficiency. At the receiver, Bob, private key decryption and polarization code decoding are collaboratively processed to recover the original plaintext from the noisy channel. Unable to obtain the Gaussian weight distribution of the public key matrix or the mapping rules for the polarization code information bits, an eavesdropper would have difficulty extracting valid information from the encrypted signal, whose statistical characteristics approach those of noise. This scheme achieves both quantum security and channel capacity through the deep coupling of encryption and channel coding.

[0066] Figure 2 This diagram illustrates the Monte Carlo optimization-based public key matrix generation process and the core logic of the McEliece encryption-modulation joint processing. The module on the left uses a dynamic search algorithm to generate a public key matrix that satisfies the target Gaussian distribution characteristics, while the main process on the right completes the conversion from plaintext to encrypted symbol streams.

[0067] Generating a public key matrix with Gaussian-distributed row weights essentially involves transferring the weight distribution to symbol probabilities through a linear mapping and leveraging the superposition property of Gaussian distributions (the central limit theorem) to bring the overall symbol distribution closer to the target. Monte Carlo search optimizes parameters during this process to ensure that the mathematical conditions are strictly met.

[0068] In the public key matrix generation phase, a binary matrix G′∈{0, 1} that satisfies the target Gaussian distribution characteristics is generated through a dynamic search algorithm. k×n . Each row has a weight w i According to the discretized Gaussian distribution N(μ, σ 2 ) random sampling, and ensure that the weight value is within the set range through truncation operation. The core goal of the Monte Carlo optimization algorithm is to minimize the difference between the encrypted symbol distribution and the ideal Gaussian distribution; by calculating the simulated symbol probability P sim (s) and the target distribution p target KL divergence D of (s) KL :

[0069]

[0070] When D KL If the value falls below a preset threshold, the current matrix is output as the optimal solution. Otherwise, iterative adjustments to the distribution parameters continue. A Monte Carlo closed-loop feedback mechanism dynamically adjusts the Gaussian parameters based on channel conditions, ensuring that the encrypted signal always meets channel capacity limits and security requirements. While finding the optimal public key matrix G′, the generator matrix G, permutation matrix P, and reversible matrix S required for the private key are also saved.

[0071] Assume that the even-numbered rows of the public key matrix G have weights w 2t Obey Gaussian distribution N(μ, σ 2 ), the probability of generating bit 1 in the information bit is p = 1 / max(w i ), according to the McEliece encryption rule, each bit of the ciphertext c i The probability of being 1 is approximately:

[0072] P(c i =1)≈p·w i

[0073] Because of w 2t ~N(μ,σ 2 ), and p=1 / max(w i ), then p·w 2t The distribution is scaled to the interval [0, 1], but still maintains the Gaussian shape.

[0074] The weight of odd rows is w 2t-1 Set to low and uniform distribution (such as fixed to 1), so that P(c 2t-1 =1)≈0.5 ensures the symmetry of symbol probability.

[0075] In the encryption and modulation stage, the plaintext m∈{0,1} k The ciphertext bitstream is generated by the following matrix multiplication:

[0076] c=mG'mod 2

[0077] The ciphertext is divided into two consecutive ciphertext bits (c 2t-1 , c 2t ) packets are mapped into 4-PAM symbol streams, the rules of which are:

[0078] 00→-3, 01→-1,

[0079] 11→1, 110→3,

[0080] Assuming that the parity bits are independent (guaranteed by row weight design), the symbol probability is calculated by the joint probability:

[0081] P(-3)=P(00)=P(c 2t-1 =0)·P(c 2t =0) = 0.5·(1-pw 2t ),

[0082] P(-1)=P(01)=0.5·pw 2t ,

[0083] P(1)=P(11)=0.5·pw 2t ,

[0084] P(3)=P(10)=0.5·(1-pw 2t )

[0085] Since the even row weight w 2t Obey Gaussian distribution, pw 2t It also exhibits Gaussian properties, so that the probability of each symbol satisfies:

[0086]

[0087] Therefore, the distribution shape of the symbol probability is directly determined by the Gaussian distribution of the even-numbered row weights.

[0088] The central limit theorem shows that when the public key matrix code length n→∞, even if there is a slight deviation in the probability of a single symbol, the probability distribution of a large number of independently generated symbols s will approach a Gaussian distribution. Therefore, although the symbol has only four discrete values, when the number of symbols is large enough, its probability distribution can be viewed as a discrete sampling of a continuous Gaussian distribution.

[0089] In addition, high-probability symbols (such as -1 and 1) are concentrated in the low-energy region, and low-probability symbols (such as -3 and 3) are distributed in the high-energy region, thereby achieving power efficiency optimization.

[0090] like Figure 3As shown in Figure 1, after encryption and modulation are complete, polar codes are used to encode the symbol stream to further optimize transmission reliability. Polar codes are based on channel polarization theory and decompose the original channel into multiple subchannels through polarization transformation. High-reliability subchannels (good channels) are used to transmit information bits, while low-reliability subchannels (bad channels) are fixed as frozen bits. Specifically, for a polar code with code length N, the reliability of each subchannel is evaluated using the Bhattacharyya parameter, which is defined as:

[0091]

[0092] where W:χ→γ represents a symmetric binary input discrete memoryless channel (B-DMC) with the input alphabet χ and the output alphabet γ. The transition probability W(y|x) represents the conditional probability that the output symbol y∈γ will be an input symbol x∈χ after being transmitted through the channel.

[0093] Sub-channel W i is defined as:

[0094]

[0095] The above formula shows that when the received signal is known and previous input Under the condition that the i-th sub-channel is sensitive to the current input u i The transition probability of is the sequence of input bits from the 1st to the i-1th bit.

[0096] By setting a threshold N = {1, 2, ..., N}, N-bit channels are divided into good channels and bad channels, and the index sets of good channels and bad channels are respectively:

[0097] G(W,β)={i∈[N]:Z(W i )<2 -Nβ}

[0098] B(W,β)={i∈[N]:Z(W i )≥2 -Nβ}

[0099] The good channels G(W, β) are selected as information bits, and the rest are classified as bad channels B(W, β) as frozen bits. When the code length N→∞, the proportion of information bits approaches the channel symmetric capacity C(W), that is:

[0100]

[0101] Achieve transmission efficiency close to the Shannon limit.

[0102] In this embodiment, the high-order constellation modulation is 4-PAM modulation. The encrypted 4-PAM symbol stream is first converted into a binary bit sequence. Based on the channel polarization result of the polarization code, the bit stream is embedded in high-reliability information bits (such as index [800, 1023]). The structural parameters of the public key matrix (such as the hash value of the row weight sequence) are encoded into frozen bits to ensure that the receiving end can decrypt synchronously with the private key. The power allocation strategy further combines the symbol probability distribution to ensure that the symbol probability distribution satisfies the non-uniform energy distribution rule. Low transmission energy is allocated to the high-probability symbol {-1, 1}, and high transmission energy is allocated to the low-probability symbol {-3, 3}. The energy allocation ratio satisfies:

[0103]

[0104] Among them, E s is the symbol energy, and P(s) is the symbol probability. By non-uniform energy distribution, the average transmit power is reduced while maintaining the anti-noise performance.

[0105] The deep coupling of polarization codes with McEliece encryption not only achieves efficient error correction through channel polarization but also enhances anti-eavesdropping capabilities through the covert transmission mechanism of frozen bits. Unable to obtain the polarization code information bit mapping rules and the public key parameters of the frozen bits, eavesdroppers find it difficult to extract valid information from encrypted signals whose statistical characteristics approximate Gaussian noise.

[0106] Figure 4 The flowchart of the receiver recovering the original plaintext from the noisy received signal through multi-stage processing. At the receiver, the received signal is first processed by the polar code decoding module, and the succesive cancellation list decoding algorithm (SCL) is used to separate the ciphertext symbol stream and the public key parameters embedded in the frozen bits from the channel output. The SCL algorithm maintains the likelihood metric of multiple candidate paths. ( Indicates u i The decoding estimate value) dynamically expands the path and selects the most likely decoding result; the path metric calculation is based on the log-likelihood ratio (LLR i )calculate:

[0107]

[0108] in, is the decoded sequence from the 1st to the i-1th bit, and y is the received signal; by screening the high-reliability information bits, the binary bit sequence corresponding to the ciphertext symbol stream is extracted.

[0109] The ciphertext bit stream then enters the 4-PAM demodulation module, where it performs an inverse conversion based on the preset symbol mapping rule, restoring the symbol value to the original bit pair. The mapping rule is:

[0110] -3→00, -1→01,

[0111] 1→11, 3→10,

[0112] During the demodulation process, the minimum Euclidean distance criterion is used to determine the closest legal symbol s from the noisy received symbol s. The decision formula is:

[0113]

[0114] Finally, the demodulated ciphertext bitstream is input into the McEliece decryption module, which uses the private key (which contains the structured information of the public key matrix G, such as the support set and permutation matrix) to perform the decryption operation. The decryption process recovers the plaintext m by solving a system of linear equations or a fast algorithm based on the characteristics of sparse matrices:

[0115] m=cG' -1 Mod 2

[0116] Among them, G′ -1 is the inverse matrix of the public key matrix (must meet the reversibility condition). The public key parameter hash value embedded in the frozen bit is used to verify the matrix consistency and prevent tampering attacks.

[0117] The entire process ensures that legitimate recipients can accurately restore plaintext from noisy channels through high-reliability decoding of polar codes, robust judgment of symbol inverse mapping, and McEliece's quantum-resistant decryption mechanism. However, eavesdroppers, lacking the mapping rules between the private key and the polar code information bits, are unable to crack the statistical characteristics and coding structure of the ciphertext.

[0118] This invention provides a joint encryption coding method based on McEliece and polarization codes under the wiretap model. This method uses a Monte Carlo optimization algorithm to generate a public key matrix that conforms to a Gaussian distribution, utilizes high-order constellation symbol modulation to reduce average transmit power, and uses the high-reliability information bits of the polarization code to achieve encrypted signal transmission. This method first generates a McEliece public key matrix with discrete Gaussian row weights through Monte Carlo optimization search and uses it to generate the encrypted signal. The encrypted signal is mapped to high-order constellation symbols, making the symbol probability distribution approach a Gaussian distribution. Non-uniform energy distribution is also performed to reduce average transmit power. The parameters of the public key matrix are then dynamically optimized and encoded into frozen bits, which are then transmitted using the high-reliability information bits of the polarization code. The error correction capability of the polarization code in an additive white Gaussian noise channel is leveraged to further enhance communication stability. The receiving end decrypts the ciphertext using a private key and recovers the information using the polarization code decoding structure, ensuring that only legitimate recipients can successfully decrypt the information. This method achieves both quantum security and channel capacity improvements through the deep coupling of encryption and channel coding.

[0119] This embodiment further provides an electronic device, including a memory, a processor, and a computer program stored in the memory, wherein the processor implements the above method when executing the computer program.

[0120] This embodiment further provides a computer-readable storage medium storing a computer program, which implements the above method when executed by a processor.

[0121] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0122] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0123] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0124] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0125] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any other manner. Any person skilled in the art may utilize the above-disclosed technical content to modify or modify the present invention into equivalent embodiments. However, any simple modifications, equivalent variations, and modifications to the above embodiments that do not depart from the technical content of the present invention and are based on the technical essence of the present invention remain within the scope of protection of the present invention.

Claims

1. A joint encryption coding method based on McEliece and polar codes under the wiretap model, characterized in that: The transmitter generates a McEliece public key matrix with row weights following a discrete Gaussian distribution based on a Monte Carlo optimization algorithm, so that the probability distribution of the encrypted ciphertext symbols after modulation by high-order constellation symbols approaches the Gaussian characteristic. The Bhattacharyya parameters of the polarization code are then used to determine the reliable channel location. The encrypted ciphertext bits are embedded in the high-reliability information bits of the polarization code, and the dynamically optimized public key parameters are encoded into the frozen bits of the polarization code to achieve physical layer covert transmission. The receiver recovers the original plaintext from the noisy channel through the collaborative processing of private key decryption and polarization code decoding.

2. The joint encryption coding method based on McEliece and polar codes under the wiretap model according to claim 1 is characterized in that: In the public key matrix generation phase, a binary matrix G′∈{0, 1} that satisfies the target Gaussian distribution characteristics is generated through a dynamic search algorithm. k×n ; Weight of each row w i According to the discretized Gaussian distribution N(μ, σ 2 ) random sampling, and ensure that the weight value is within the set range through truncation operation; the goal of the Monte Carlo optimization algorithm is to minimize the difference between the encrypted symbol distribution and the ideal Gaussian distribution; by calculating the simulated symbol probability P sim (s) and the target distribution P target KL divergence D of (s) KL : When D KL When it is lower than the preset threshold, the current matrix is output as the optimal solution, otherwise the distribution parameters are adjusted iteratively; the Monte Carlo closed-loop feedback mechanism dynamically adjusts the Gaussian parameters according to the channel conditions to ensure that the encrypted signal always adapts to the channel capacity limit and security requirements, and finds the optimal solution public key matrix G′ while saving the generator matrix G, permutation matrix P and reversible matrix S required for the private key.

3. The joint encryption coding method based on McEliece and polarization code under the wiretap model according to claim 2 is characterized in that Public key matrix G even row weight w 2t Obey Gaussian distribution N(μ, σ 2 ), the probability of generating bit 1 in the information bit is p = 1 / max(w i ), according to the McEliece encryption rule, each bit of the ciphertext c i The probability of being 1 is approximately: P(c i =1)≈p·w i Because of w 2t ~N(μ,σ 2 ), and p=1 / max(w i ), then p·ω 2t The distribution of is scaled to the interval [0, 1], but still maintains the Gaussian shape; Odd row weight w 2t-1 Set to uniform distribution so that P(c 2t-1 =1)≈0.5 ensures the symmetry of symbol probability.

4. The joint encryption coding method based on McEliece and polar codes under the wiretap model according to claim 3 is characterized in that: In the encryption and modulation stage, the plaintext m∈{0,1} k The ciphertext bitstream is generated by the following matrix multiplication: c=mG′mod 2 The ciphertext is divided into two consecutive ciphertext bits (c 2t-1 , c 2t ) packets are mapped into 4-PAM symbol streams, the rules of which are: 00→-3,01→-1, 11→1,10→3, Assuming that the parity bits are independent, the symbol probability is calculated by the joint probability: P(-3)=P(00)=P(c 2t-1 =0)·P(c 2t =0)=0.5·(1-pw 2t ), P(-1)=P(01)=0.5·pw 2t , P(1)=P(11)=0.5·pw 2t , P(3)=P(10)=0.5·(1-pw 2t ) Since the even row weight w 2t Obey Gaussian distribution, pw 2t It also exhibits Gaussian properties, so that the probability of each symbol satisfies: Therefore, the distribution shape of the symbol probability is directly determined by the Gaussian distribution of the even-numbered row weights.

5. The joint encryption coding method based on McEliece and polar codes under the wiretap model according to claim 4 is characterized in that: After encryption and modulation, polar codes are used to encode the symbol stream to optimize transmission reliability. Based on channel polarization theory, polar codes decompose the original channel into multiple subchannels through polarization transformation. High-reliability subchannels, or good channels, are used to transmit information bits, while low-reliability subchannels, or bad channels, are fixed as frozen bits. For polar codes with code length N, the reliability of each subchannel is evaluated using the Bhattacharyya parameter, which is defined as: Where W:χ→γ represents a symmetric binary input discrete memoryless channel (B-DMC), the input alphabet is χ, the output alphabet is γ, and the transition probability W(y|x) represents the conditional probability that the output symbol y∈γ will be output after the input symbol x∈χ is transmitted through the channel. Sub-channel W i is defined as: The above formula shows that when the received signal is known and previous input Under the condition that the i-th sub-channel is sensitive to the current input u i The transition probability of is the sequence of input bits from the 1st to the i-1th; By setting a threshold N-bit channels are divided into good channels and bad channels. The index sets of good channels and bad channels are: G(W,β)={i∈[N]:Z(W i )<2 -Nβ } B(W,β)={i∈[N]:Z(W i )≥2 -Nβ } The good channels G(W, β) are selected as information bits, and the rest are classified as bad channels B(W, β) as frozen bits. When the code length N→∞, the proportion of information bits approaches the channel symmetric capacity C(W), that is: Achieve transmission efficiency close to the Shannon limit.

6. The joint encryption coding method based on McEliece and polar codes under the wiretap model according to claim 5 is characterized in that: The high-order constellation modulation is 4-PAM modulation. The encrypted 4-PAM symbol stream is first converted into a binary bit sequence. Based on the channel polarization result of the polar code, the bit stream is embedded in high-reliability information bits. The structural parameters of the public key matrix are encoded into frozen bits to ensure that the receiving end can synchronously decrypt using the private key. The symbol probability distribution satisfies the non-uniform energy distribution rule. Low transmission energy is allocated to the high-probability symbol {-1, 1}, and high transmission energy is allocated to the low-probability symbol {-3, 3}. The energy distribution ratio satisfies: Among them, E s is the symbol energy, and P(s) is the symbol probability. By non-uniform energy distribution, the average transmit power is reduced while maintaining the anti-noise performance.

7. The joint encryption coding method based on McEliece and polar codes under the wiretap model according to claim 1 is characterized in that: At the receiving end, the received signal is processed by the polar code decoding module, and the ciphertext symbol stream and the public key parameters embedded in the frozen bits are separated from the channel output using the continuous cancellation list decoding algorithm SCL; the SCL algorithm maintains the likelihood metric of multiple candidate paths. Dynamically expand the path and select the most likely decoding result, where Indicates u i The decoding estimate of ; the path metric is calculated based on the log-likelihood ratio LLRi: in, is the decoded sequence from the 1st to the i-1th bit, and y is the received signal; by screening the high-reliability information bits, the binary bit sequence corresponding to the ciphertext symbol stream is extracted; The ciphertext bit stream then enters the 4-PAM demodulation module, where it performs an inverse conversion based on the preset symbol mapping rule, restoring the symbol value to the original bit pair. The mapping rule is: -3→00,-1→01, 1→11,3→10, During the demodulation process, the minimum Euclidean distance criterion is used to determine the closest legal symbol s from the noisy received symbol s. The decision formula is: Finally, the demodulated ciphertext bit stream is input into the McEliece decryption module, which uses the private key to perform decryption operations. The decryption process recovers the plaintext m by solving a system of linear equations or a fast algorithm based on the characteristics of sparse matrices: m=cG′ -1 mod 2 Among them, G′ -1 is the inverse matrix of the public key matrix; the public key parameter hash value embedded in the frozen bit is used to verify the matrix consistency and prevent tampering attacks.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

9. A computer-readable storage medium, characterized in that A computer program is stored, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.