Polynomial matrix acquisition method and device, electronic equipment and storage medium

By sampling multiple polynomial coefficients of a polynomial matrix in parallel and generating the polynomial matrix using pre-computed information, the problem of long time consumption and low efficiency in generating polynomial matrices in post-quantum cryptography algorithms is solved, achieving efficient and low-cost polynomial matrix generation.

CN121485939BActive Publication Date: 2026-05-08BEIJING INFOSEC TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING INFOSEC TECH CO LTD
Filing Date
2026-01-08
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Traditional public-key cryptography algorithms face the threat of quantum computing. Modular lattice-based post-quantum cryptography algorithms are time-consuming, inefficient, computationally expensive, and costly in generating polynomial matrices.

Method used

By acquiring the input seed, utilizing the scalable output function and pre-computed information, and employing multiple intermediate checkpoints to sample multiple polynomial coefficients of the polynomial matrix in parallel, a polynomial matrix is ​​generated.

Benefits of technology

It reduces the time required to generate polynomial matrices, improves efficiency, and lowers computational overhead and cost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121485939B_ABST
    Figure CN121485939B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a polynomial matrix obtaining method and device, electronic equipment and storage medium, and relate to the technical field of information security. The method comprises: obtaining an input seed used to generate a polynomial matrix, the polynomial matrix being used in the process of performing a target task based on a post-quantum cryptography algorithm; performing a sampling operation on a plurality of polynomial coefficients of the polynomial matrix based on the input seed, an expandable output function and pre-computed information to obtain the polynomial matrix, wherein the pre-computed information comprises a plurality of intermediate checkpoints, and each intermediate checkpoint is used to represent an internal state of the expandable output function in the process of performing the sampling operation. The present scheme has the advantages of short time consumption, high effect, small calculation overhead and low cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular to a method, apparatus, electronic device and storage medium for obtaining a polynomial matrix. Background Technology

[0002] With the development of quantum computing, traditional public-key cryptography algorithms (such as elliptic curve cryptography) face security threats. Modular lattice-based post-quantum cryptography algorithms have emerged. When performing tasks such as signing, verifying signatures, key encapsulation, and decapsulation, the core operations of these post-quantum cryptography algorithms all involve generating a polynomial matrix in real time from a seed through an scalable output function. This process is time-consuming, inefficient, computationally expensive, and costly. Summary of the Invention

[0003] This application provides a method, apparatus, electronic device, and storage medium for obtaining polynomial matrices, which is time-efficient, highly effective, computationally inefficient, and cost-effective.

[0004] In a first aspect, embodiments of this application provide a method for obtaining a polynomial matrix, the method comprising:

[0005] Obtain an input seed for generating a polynomial matrix, which is used in the execution of the target task based on a post-quantum cryptography algorithm;

[0006] Based on the input seed, a sampling operation is performed on multiple polynomial coefficients of the polynomial matrix using an extensible output function and pre-computation information to obtain the polynomial matrix. The pre-computation information includes multiple intermediate checkpoints, each of which represents an internal state of the extensible output function during the sampling operation.

[0007] Optionally, the step of performing a sampling operation on multiple polynomial coefficients of the polynomial matrix using an extensible output function and pre-computed information includes:

[0008] Identify multiple target threads, each target thread corresponding to an intermediate checkpoint;

[0009] Based on the scalable output function, sampling operations are performed on multiple polynomial coefficients of the polynomial matrix in parallel by the multiple target threads.

[0010] Optionally, after obtaining the input seed for generating the polynomial matrix, the method further includes:

[0011] Obtain pre-calculated information.

[0012] Optionally, obtaining the pre-calculated information includes:

[0013] Identify multiple intermediate checkpoints that meet the set checkpoint filtering criteria;

[0014] Multiple intermediate checkpoints are stored to form pre-calculated information.

[0015] Optionally, determining multiple intermediate checkpoints that satisfy the set checkpoint filtering conditions includes:

[0016] Determine the number of polynomial coefficients in the target polynomial;

[0017] If it is determined that the sampled target polynomial coefficients satisfy a multiple relationship with the target threshold, then an intermediate checkpoint is determined to correspond to the target polynomial coefficients. The target threshold is determined based on the number of polynomial coefficients and the number of multiple target threads, and the target polynomial coefficients are one of the multiple polynomial coefficients.

[0018] Optionally, the post-quantum cryptography algorithm is a lattice-based digital signature algorithm or a key encapsulation algorithm.

[0019] Secondly, embodiments of this application provide a polynomial matrix acquisition device, the device comprising:

[0020] The acquisition module is used to acquire the input seed for generating the polynomial matrix, which is used in the process of executing the target task based on the post-quantum cryptography algorithm;

[0021] A sampling module is used to perform sampling operations on multiple polynomial coefficients of a polynomial matrix based on the input seed, through an extensible output function and pre-computation information, to obtain the polynomial matrix. The pre-computation information includes multiple intermediate checkpoints, each of which represents an internal state of the extensible output function during the sampling operation.

[0022] Thirdly, embodiments of this application also provide an electronic device, the electronic device including: a memory, a processor, and a communication interface; wherein, the memory stores executable code, and when the executable code is executed by the processor, the processor performs the method described in the first aspect above.

[0023] Fourthly, embodiments of this application also provide a non-transitory machine-readable storage medium storing executable code, which, when executed by a processor of an electronic device, causes the processor to perform the method described in the first aspect above.

[0024] Fifthly, embodiments of this application also provide a computer program product, the computer program product comprising: a computer program, which, when executed by a processor of an electronic device, causes the processor to perform the method described in the first aspect above.

[0025] The polynomial matrix acquisition method provided in this application obtains an input seed for generating the polynomial matrix, and based on the input seed, performs sampling operations on multiple polynomial coefficients of the polynomial matrix through an extensible output function and pre-computed information containing multiple intermediate checkpoints. The sampling operation can be performed in parallel based on multiple intermediate checkpoints. Specifically, when a target task needs to be performed based on a post-quantum cryptography algorithm, it is not necessary to generate the polynomial matrix in real time. Instead, the sampling operation is performed in parallel through multiple pre-stored intermediate checkpoints, and then the multiple polynomial coefficients are combined to finally obtain the polynomial matrix. The whole process is time-saving, efficient, computationally inefficient, and low-cost. Attached Figure Description

[0026] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0027] Figure 1 A flowchart illustrating a method for obtaining a polynomial matrix provided in an embodiment of this application;

[0028] Figure 2 Another flowchart of a method for obtaining a polynomial matrix provided in an embodiment of this application;

[0029] Figure 3 This is a schematic diagram of the structure of a polynomial matrix acquisition device provided in an embodiment of this application;

[0030] Figure 4 A schematic diagram of the structure of a pre-computation information transmission system provided in this application embodiment;

[0031] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0032] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0033] With the development of quantum computing, traditional public-key cryptography algorithms (such as elliptic curve cryptography) face security threats. Modular lattice-based post-quantum cryptography algorithms have emerged to address this threat. When performing tasks such as signing, verifying signatures, key encapsulation, and decapsulation, these post-quantum cryptography algorithms involve generating a polynomial matrix in real-time from a seed using an scalable output function. This process is time-consuming, inefficient, computationally expensive, and costly. Therefore, this application provides a method for obtaining a polynomial matrix.

[0034] Figure 1 A flowchart of a method for obtaining a polynomial matrix provided in an embodiment of this application is shown below. Figure 1 As shown, the method includes:

[0035] Step 101: Obtain the input seed used to generate the polynomial matrix, which is used in the process of executing the target task based on the post-quantum cryptography algorithm.

[0036] The post-quantum cryptography algorithm can be either a Module-Lattice-based Digital Signature Algorithm (ML-DSA) or a Module-Lattice-based Key Encapsulation Mechanism (ML-KEM). ML-DSA's primary function is digital signature, providing authentication, data integrity, and non-repudiation in the quantum computing era. ML-KEM's primary function is key encapsulation, a modern public-key encryption paradigm for securely exchanging symmetric keys, which is more efficient and secure than traditional public-key encryption.

[0037] Step 102: Based on the input seed, perform sampling operations on multiple polynomial coefficients of the polynomial matrix through the scalable output function and pre-computation information to obtain the polynomial matrix. The pre-computation information contains multiple intermediate checkpoints, each of which represents an internal state of the scalable output function during the sampling operation.

[0038] It should be noted that the execution entity of the above polynomial matrix acquisition method can be any party that needs to perform the above target task, such as server, browser, client, etc., which will not be listed here.

[0039] In practical applications, the input seed is a short byte array (such as 32 or 34 bytes) that is usually contained in the public key. Specifically, the input seed can be parsed from the public key certificate or public key data sent by the other party during interaction (such as verifying a signature or decapsulating).

[0040] After obtaining the input seed, sampling operations can be performed on multiple polynomial coefficients of the polynomial matrix based on the input seed, using an extensible output function and pre-computed information, to obtain the polynomial matrix. For ease of understanding, the following example, using a traditional approach, illustrates the solution proposed in this application (assuming the current execution entity is a browser):

[0041] In traditional methods, after obtaining the input seed, the browser needs to start from scratch and sequentially run the Extendable Output Function (XOF) to generate each coefficient of the polynomial matrix step by step. For a large polynomial matrix, this process is extremely slow. Specifically, this Extendable Output Function can be a 128-bit secure version of the KECCAK algorithm (SHAKE128), a 256-bit secure version of the KECCAK algorithm (SHAKE256), or something similar.

[0042] In this application embodiment, the concept of "pre-computation information" is proposed. This pre-computation information can be understood as a data table pre-computed and securely distributed to users by a trusted party (such as a Certificate Authority). This table does not store a complete polynomial matrix, but rather intermediate checkpoints. These intermediate checkpoints represent the internal state of the scalable output function during the sampling process. This internal state (typically a 200-byte data structure) contains all the information needed to continue generating all subsequent random bytes.

[0043] In practice, the browser obtains the pre-computation information corresponding to the input seed along with the input seed. When a polynomial matrix needs to be generated, it no longer performs serial calculations starting from the starting point, but instead generates a polynomial acquisition task. Based on the number of intermediate checkpoints, the polynomial acquisition task is decomposed into multiple subtasks, which are then executed in parallel.

[0044] In this process, multiple target threads can be identified, each corresponding to an intermediate checkpoint. Based on the scalable output function, multiple target threads perform sampling operations (i.e., execute multiple subtasks) on multiple polynomial coefficients of the polynomial matrix in parallel. In practical applications, each intermediate checkpoint is used as the starting point for a thread to identify multiple target threads. Each target thread starts from a corresponding intermediate checkpoint and continues to run the scalable output function, thereby generating the coefficients of the remaining part of the polynomial in parallel. Then, the coefficient fragments generated by all target threads are combined to form a complete polynomial. It can be understood that performing the above operations on each polynomial in the polynomial matrix yields the final polynomial matrix.

[0045] To facilitate understanding, the following examples illustrate the concepts in various application scenarios:

[0046] Suppose that signature verification is required, the browser initiates a polynomial matrix generation task (assuming the pre-computed information provides 3 intermediate checkpoints for each polynomial). At this point, the browser creates 4 target threads:

[0047] Target thread 1: Starting from the initial state, generate polynomial coefficients 0-63.

[0048] Target thread 2: Starting from intermediate checkpoint 1 (corresponding to the position of polynomial coefficient 64), generate polynomial coefficients 65-127.

[0049] Target thread 3: Starting from intermediate checkpoint 2 (corresponding to the position of polynomial coefficient 128), generate polynomial coefficients 129-191.

[0050] Target thread 4: Starting from intermediate checkpoint 3 (corresponding to the position of polynomial coefficient 192), generate polynomial coefficients 193-255.

[0051] It should be understood that by having four target threads work in parallel (i.e., by having multiple target threads perform sampling operations on multiple polynomial coefficients of the polynomial matrix in parallel), the entire polynomial matrix can be generated in the time it would take for a single thread to process 1 / 4 of the data in the traditional approach, thus reducing working time and improving work efficiency.

[0052] Based on the above, the polynomial matrix acquisition method provided in this application obtains an input seed for generating the polynomial matrix, and performs sampling operations on multiple polynomial coefficients of the polynomial matrix based on the input seed, through an extensible output function and pre-computed information containing multiple intermediate checkpoints. The sampling operation can be performed in parallel based on multiple intermediate checkpoints. Specifically, when a target task needs to be performed based on a post-quantum cryptography algorithm, it is not necessary to generate the polynomial matrix in real time. Instead, the sampling operation is performed in parallel through multiple pre-stored intermediate checkpoints, and then the multiple polynomial coefficients are combined to finally obtain the polynomial matrix. The whole process is time-saving, efficient, computationally inefficient, and cost-effective.

[0053] Figure 2 Another flowchart of a method for obtaining a polynomial matrix provided in an embodiment of this application is shown below. Figure 2 As shown, the method includes:

[0054] Step 201: Obtain the input seed used to generate the polynomial matrix, which is used in the process of executing the target task based on the post-quantum cryptography algorithm.

[0055] Step 202: Obtain pre-calculation information.

[0056] Step 203: Based on the input seed, perform sampling operations on multiple polynomial coefficients of the polynomial matrix through the scalable output function and pre-computation information to obtain the polynomial matrix. The pre-computation information contains multiple intermediate checkpoints, each of which represents an internal state of the scalable output function during the sampling operation.

[0057] For the specific execution process of steps 201 and 203, please refer to the above embodiments, which will not be repeated here.

[0058] For step 202, pre-calculation information can be obtained as follows: identify multiple intermediate checkpoints that meet the set checkpoint filtering conditions; store the multiple intermediate checkpoints to form pre-calculation information. By setting the set checkpoint filtering conditions, polynomial coefficients that do not meet the conditions can be filtered during the generation of polynomial coefficients, and the positions of multiple polynomial coefficients that meet the set checkpoint filtering conditions can be used as the positions of multiple intermediate checkpoints, ensuring the accuracy of the pre-calculation information.

[0059] In specific implementation, the number of polynomial coefficients of the target polynomial is determined; if it is determined that the sampled target polynomial coefficients satisfy a multiple relationship with the target threshold, then an intermediate checkpoint is determined corresponding to the target polynomial coefficients. The target threshold is determined based on the number of polynomial coefficients and the number of multiple target threads, and the target polynomial coefficients are one of multiple polynomial coefficients.

[0060] To facilitate understanding, the processes of ML-DSA and ML-KEM in acquiring pre-computed information are illustrated below with examples:

[0061] For ML-DSA:

[0062] Suppose we need to generate a dimension of polynomial matrix When the number of threads is At that time, the pre-calculated One checkpoint can reduce the theoretical sampling time to the original value. For matrices The process of generating checkpoints for each polynomial in the equation is as follows:

[0063] Input: byte array (i.e., the input seed mentioned above), polynomial matrix dimensionality Number of threads for sampling each polynomial .

[0064] The specific execution process is as follows:

[0065] (1) Let the extended output function XOF be SHAKE128;

[0066] Specifically, SHAKE128 was chosen as the extended output function XOF.

[0067] (2) Initialize the XOF context ;

[0068] Specifically, initialize the XOF context ctx.

[0069] (3) Let ;

[0070] Specifically, the input byte array B is absorbed (input) into ctx. At this point, ctx contains the initial state for generating the entire polynomial matrix.

[0071] (4) For :

[0072] Specifically, the coefficients j of the cyclic polynomial range from 0 to 255, with the aim of generating each coefficient of a 256-term polynomial.

[0073] (4.1)

[0074] Specifically, 3 bytes s are squeezed (output) from the current ctx. This is a key operation that generates random numbers for calculating coefficients and updates the internal state of ctx.

[0075] (4.2)

[0076] Specifically, based on the above three bytes The CoeffFromThreeBytes function is used to calculate a polynomial coefficient â[j].

[0077] (4.3) If (That is, if the polynomial coefficients â[j] are valid), then

[0078] (4.3.1) If , but

[0079] Specifically, check whether the set checkpoint filtering conditions are met. in," This means: do not set it at the beginning of the loop, because the initial state ctx is already a common starting point. "This means: j can be ( Divisible, assuming A value of 4 means that intermediate checkpoints will be set at j = 64, 128, and 192 (because these three positions can be ( (Divisibility). When the set checkpoint filtering conditions are met, the current XOF context state ctx is saved to the pre-computation table array p. Note: This ctx is the state after generating a random number for position j; it represents the new starting point for the coefficients after generating j.

[0080] (4.3.2) Let

[0081] Specifically, increment j to continue generating the next coefficient.

[0082] Output: Pre-computed table array ,in, It is the data structure represented by the internal state of an expandable output function (such as SHAKE128).

[0083] It should be understood that the pre-calculated table array obtained from the above process For a given polynomial, repeating the above steps multiple times will yield a polynomial matrix A composed of multiple polynomials. It can be understood that generating the entire polynomial matrix A requires generating a total of [number missing] polynomials. There are several intermediate checkpoints. Since each intermediate checkpoint stores the internal state of the SHAKE128, and the internal state is a 5×5 64-bit word array, each internal state occupies 200 bytes. Therefore, it is used to sample the polynomial matrix. The size of the pre-calculation table (i.e., pre-calculation information) based on intermediate checkpoints is Bytes. Similar to storing the entire polynomial matrix. Compared to (polynomial matrix) The size is (bytes), effectively reducing the size of pre-computed information.

[0084] For ML-KEM:

[0085] Suppose we need to generate a dimension of polynomial matrix When the number of threads is At that time, the pre-calculated One checkpoint can reduce the theoretical sampling time to the original value. For polynomial matrices The process of generating intermediate checkpoints for each polynomial in the equation is as follows:

[0086] Input: byte array (i.e., the input seed mentioned above), polynomial matrix dimensionality Number of threads for sampling each polynomial (Assuming) (2).

[0087] The specific execution process is as follows:

[0088] (1) Let the extended output function XOF be SHAKE128;

[0089] Specifically, SHAKE128 was chosen as the extended output function XOF.

[0090] (2) Initialize the XOF context ;

[0091] Specifically, initialize the XOF context ctx.

[0092] (3) Let ;

[0093] Specifically, the input byte array B is absorbed (input) into ctx. At this point, ctx contains the initial state for generating the entire polynomial matrix.

[0094] (4) For :

[0095] Specifically, the coefficients j of the cyclic polynomial range from 0 to 255, with the aim of generating each coefficient of a 256-term polynomial.

[0096] (4.1)

[0097] Specifically, three bytes C[0], C[1], and C[2] are "squeezed" out from XOF.

[0098] (4.2)

[0099] (4.3)

[0100] Specifically, these 3 bytes are decoded into two candidate coefficients. and .

[0101] (4.4) If {examine Is it valid (i.e.) < q, where q is the modulus), if valid, then:

[0102] (4.4.1) Let (Will Assigned to â[j])

[0103] (4.4.2) If , but

[0104] Specifically, check if the intermediate checkpoint has been reached, and set checkpoint filtering conditions. ,in," This means: do not set it at the beginning of the loop, because the initial state ctx is already a common starting point. "This means: j can be ( If the value is divisible by 128, the set checkpoint filtering condition is met. The current ctx and an auxiliary bit are saved to the pre-calculation table array p. The auxiliary bit 0 indicates that the current checkpoint starts from 128. The validity check proceeds. This is the first and only intermediate checkpoint (because μ=2).

[0105] (4.4.3) Let

[0106] Specifically, increment j to continue generating the next coefficient.

[0107] (4.5) If and {if If the polynomial is valid (i.e., d² < q) and the current number of polynomial coefficients (j < 256) has not yet been collected, then:

[0108] (4.5.1) Let (Will Assigned to â[j])

[0109] (4.5.2) If , but

[0110] Specifically, check again whether the intermediate checkpoint has been reached, and set the checkpoint filtering conditions. ,in," This means: do not set it at the beginning of the loop, because the initial state ctx is already a common starting point. "This means: j can be ( If the value is divisible by 128, the set checkpoint filtering condition is met. The current ctx and an auxiliary bit are saved to the pre-calculation table array p. The auxiliary bit 1 indicates that the current checkpoint starts from 128. The validity check proceeds. This is the first and only intermediate checkpoint (because μ=2).

[0111] (4.5.3) Let

[0112] Specifically, increment j to continue generating the next coefficient.

[0113] Output: Pre-computed table array ,in, It is the data structure represented by the internal state of an expandable output function (such as SHAKE128).

[0114] It should be understood that the pre-calculated table array obtained from the above process For a given polynomial, repeating the above steps multiple times will yield a polynomial matrix A composed of multiple polynomials. It can be understood that generating the entire polynomial matrix A requires generating a total of [number missing] polynomials. There are several intermediate checkpoints. Since each intermediate checkpoint stores the internal state of the SHAKE128, and the internal state is a 5×5 64-bit word array, each internal state occupies 200 bytes. Therefore, it is used to sample the polynomial matrix. The size of the pre-calculation table (i.e., pre-calculation information) based on intermediate checkpoints is Bytes. Similar to storing the entire polynomial matrix. Compared to (polynomial matrix) The size is (bytes), effectively reducing the size of pre-computed information.

[0115] Based on the above, by pre-generating pre-calculated information (i.e., multiple intermediate checkpoints) and storing these intermediate checkpoints in the pre-calculation table, the size of the pre-calculation table is reduced while ensuring the execution speed of the target task, thus saving storage resources.

[0116] Figure 3 This is a schematic diagram of the structure of a polynomial matrix acquisition device provided in an embodiment of this application, as shown below. Figure 3 As shown, the device includes an acquisition module 31 and a sampling module 32.

[0117] The acquisition module 31 is used to acquire the input seed for generating the polynomial matrix, which is used in the process of executing the target task based on the post-quantum cryptography algorithm;

[0118] The sampling module 32 is used to perform sampling operations on multiple polynomial coefficients of the polynomial matrix based on the input seed, through an expandable output function and pre-computation information, to obtain the polynomial matrix. The pre-computation information includes multiple intermediate checkpoints, each of which represents an internal state of the expandable output function during the sampling operation.

[0119] Optionally, the sampling module 32 is specifically used to: determine multiple target threads, each target thread corresponding to an intermediate checkpoint; and perform sampling operations on multiple polynomial coefficients of the polynomial matrix in parallel through the multiple target threads based on the scalable output function.

[0120] Optionally, the acquisition module 31 is further configured to: acquire pre-calculated information.

[0121] Optionally, the acquisition module 31 is further configured to: determine multiple intermediate checkpoints that satisfy the set checkpoint filtering conditions; store the multiple intermediate checkpoints to form pre-calculated information; and determine the number of polynomial coefficients of the target polynomial; if it is determined that the sampled target polynomial coefficients satisfy a multiple relationship with a target threshold, then the target polynomial coefficients correspond to an intermediate checkpoint, wherein the target threshold is determined based on the number of polynomial coefficients and the number of multiple target threads, and the target polynomial coefficients are one of the multiple polynomial coefficients.

[0122] Optionally, the post-quantum cryptography algorithm is a lattice-based digital signature algorithm or a key encapsulation algorithm.

[0123] Figure 3 The device shown can perform the steps in the foregoing embodiments. For detailed execution process and technical effects, please refer to the description in the foregoing embodiments, which will not be repeated here.

[0124] Based on the above, a mature and trusted mechanism is essential for the reliable distribution of the pre-computation table. This solution utilizes extended fields of Public Key Infrastructure (PKI) to distribute the pre-computation table. PKI is a technology system that uses public key technology and digital certificates to ensure information system security and verify the identity of digital certificate holders. PKI technology is currently a feasible and effective solution for comprehensively addressing security issues, and can be used for security services such as identity authentication, non-repudiation of operations, information transmission, storage integrity, and confidentiality. Its core is the use of digital certificates issued by Certificate Authorities (CAs) conforming to the X.509 standard, securely binding an entity's identity to its public key.

[0125] A key feature of the X.509 v3 certificate standard is its strong extensibility, which uses the "Extensions" field to carry additional information. Each extension contains a unique object identifier (OID), a critical flag, and an extension value (extnValue) for storing data. This mechanism allows for the definition of private or custom extensions to meet specific application needs, and is well supported by mainstream cryptographic libraries and cloud service providers.

[0126] This application utilizes this mechanism. Specifically, in this embodiment, the pre-computed information can be encoded and stored in a custom X.509 certificate extension. When a Certificate Authority (CA) issues a certificate, its digital signature covers the entire certificate content, including all extensions. This means that the authenticity and integrity of the pre-computed table are strongly guaranteed by the CA's signature, and any tampering will result in signature verification failure.

[0127] Besides utilizing certificate extensions, another feasible approach is to distribute pre-computed data using the Online Certificate Status Protocol (OCSP). OCSP is a protocol in the PKI system used for real-time querying of certificate revocation status. Its request and response formats also support extended fields, allowing custom data to be carried. Theoretically, when a client verifies a certificate, it can send a request to the OCSP responder. The responder, while returning the certificate status, will also return the pre-computed table via custom extensions. The advantage of this method is that it separates the pre-computed data from the certificate body, avoiding excessive certificate size and enabling dynamic data updates.

[0128] Figure 4 This is a schematic diagram of a pre-calculated information transmission system provided in an embodiment of this application. Figure 4As shown, the system includes: Certificate Authority (CA), certificate holders, and dependents.

[0129] In practical applications, the CA uses the public key in the digital certificate applied for by the certificate subject user to generate the corresponding pre-computation information and stores it; or, the OCSP server, in conjunction with the CA and / or Certificate Transparency (CT) server, obtains the pre-computation table and the status of the digital certificate required by the requester and stores them.

[0130] In the first implementation, the CA receives the digital certificate application materials submitted by the certificate subject user, which include identity verification materials and the public key that the certificate subject user wishes to bind to the digital certificate. The CA reviews the identity verification materials, extracts the public key after the review is passed, uses the public key to calculate the corresponding pre-computed information, and stores it in the digital certificate as an extension item.

[0131] In the second implementation, there are three methods for distributing pre-computed information using OCSP:

[0132] Method 1: CA stores pre-computed public key information and digital certificate status: The CA calculates pre-computed public key information and stores it in the CA database; the OCSP server establishes a connection with the CA database. When the OCSP server receives an OCSP request from a requester, it parses the OCSP request; it adds extensible information that can be processed by the OCSP server to the OCSP request, including a public key pre-computation information request and a digital certificate status request; the OCSP server parses the public key pre-computation information request and digital certificate status request from the OCSP request, retrieves the latest status of the specified digital certificate and the corresponding pre-computation information by querying the CA database, and temporarily stores it in the OCSP database. In the next stage, the OCSP server responds to the request for digital certificate status and pre-computation information; the OCSP database is located in the OCSP server.

[0133] Method 2: The OCSP server stores the pre-computation information of the public key, and the CA stores the status of the digital certificate. The OCSP server obtains the public key from the digital certificate from the CA or from the CT server and stores it in the OCSP database. The CT server is a server used for auditing and monitoring the issuance and use of certificates. The OCSP server calculates the pre-computation information of the public key and stores it in the OCSP database. The OCSP server establishes a connection with the CA database. When the OCSP server receives an OCSP request from a requester, it parses the OCSP request. The OCSP server parses the request for the pre-computation information of the public key and the request for the digital certificate status from the OCSP request. By querying the CA database, it obtains the latest status of the specified digital certificate and temporarily stores it in the OCSP database. It also retrieves the pre-computation information of the public key and the latest status of the digital certificate by querying the OCSP database. In the next stage, the OCSP server responds to the request for the digital certificate status and pre-computation information.

[0134] Method 3: The OCSP server stores the pre-computation information of the public key and the status of the digital certificate: The OCSP server obtains the status of the digital certificate and the public key from the CA database, or the public key of the digital certificate can also be obtained from the CT server. The obtained status and public key of the digital certificate are stored in the OCSP server; the OCSP server calculates the pre-computation table of the public key and stores it in the OCSP database; when the OCSP server receives the OCSP request from the requester, it parses the OCSP request; the OCSP server parses the request for the pre-computation information of the public key and the request for the digital certificate status from the OCSP request, obtains the pre-computation information of the public key and the latest status of the digital certificate by querying the OCSP database, and in the next stage, the OCSP server responds to the request for the digital certificate status and pre-computation information.

[0135] The CA then distributes the pre-computed information to the corresponding certificate holder, or the OCSP server transmits the pre-computed information and the status of the digital certificate to the corresponding requester.

[0136] As one implementation method, the CA distributes pre-computed information to the corresponding certificate holder in the form of a digital certificate extension. Specifically, the CA appends a signature of the digital certificate using its own private key to the data content of the digital certificate. The CA then distributes the signed digital certificate to the certificate holder and simultaneously places the signed digital certificate in a digital certificate repository for access by dependent parties.

[0137] As another implementation, the OCSP server transmits pre-computed information to the requester in the form of a digital certificate status request response extension. Specifically, the OCSP server encapsulates the latest status of the specified digital certificate and the corresponding pre-computed information into an OCSP response, where the pre-computed information is an extension of the OCSP response. The server then signs the OCSP response before transmitting it to the requester. In this implementation, when the OCSP server transmits the corresponding pre-computed information as an extension of the OCSP response message to the requester, the requester receives an OCSP response message that includes the pre-computed information as an extension and is signed by the OCSP server. The requester then parses the signed OCSP response message and verifies it using the OCSP server's public key.

[0138] The following details the process of distributing and verifying pre-computed information using the CA-issued digital certificate process (see [link]). Figure 4 The specific steps are as follows:

[0139] S1. Obtaining Pre-computation Information. Specifically, the certificate holder submits certificate application materials to the CA, including various identity verification materials and the public key that the certificate holder wishes to bind to the digital certificate. The CA reviews the application materials accordingly, and upon approval, obtains the certificate holder's public key and uses the obtained public key to generate pre-computation information.

[0140] S2, Store pre-calculated information.

[0141] Specifically, pre-computed information can be stored in the digital certificate as a two-dimensional array, serving as an extension of the digital certificate.

[0142] S3, Distribute pre-computed information.

[0143] Specifically, the CA signs a digital certificate containing pre-computed information: the CA assembles all the data required for the certificate according to the standard format of the digital certificate, with the pre-computed information serving as an extension of the digital certificate. Then, the CA signs this data content using its private key and appends the signature to the data content.

[0144] The CA distributes digital certificates with pre-computed information to the certificate holder. After issuing the digital certificate, the CA publicly releases it for use by all dependent parties and distributes the obtained digital certificate to the certificate holder. At the same time, the CA also puts the digital certificate into the digital certificate database for dependent parties to access. The pre-computed information is distributed as an extension of the digital certificate.

[0145] S4. Verify the pre-calculated information.

[0146] Specifically, the overall information of the digital certificate is verified, and the pre-computed information within the digital certificate is simultaneously verified during the verification process. First, a digital certificate with pre-computed information is obtained. The dependent party can obtain the certificate from the CA's digital certificate repository, or the certificate holder can send it to the dependent party through other means; in this case, there is no need to worry about the security of the transmission channel. Then, the CA's public key is used to verify the signature on the digital certificate. After successful verification, the pre-computed information in the certificate extension can be used for public-key cryptographic calculations.

[0147] It should be noted that the above Figure 4 In this context, the certificate principal user is the user who applies for the certificate. The dependent party is different from the certificate principal user. Each user can obtain their own digital certificate, as well as digital certificates from other users. The user who verifies the digital certificate after obtaining it is called the dependent party.

[0148] The following details the process of pre-computed information distribution and verification using the OCSP query procedure. The specific steps are as follows:

[0149] The first step is to generate pre-computation information. The CA server calculates the pre-computation information for the corresponding public key. This step is an independent process for the CA server, which calculates the pre-computation information for all public keys on its own.

[0150] The second step is to store pre-computed information. This pre-computed information comes from the CA database; the CA stores pre-computed information on the response public key when issuing the certificate; the OCSP server establishes a connection with the CA database to obtain the pre-computed information. Specifically:

[0151] 1) The OCSP server establishes a connection with the CA database.

[0152] 2) The requester queries the OCSP server for the status of the specified certificate and requests pre-computed information: The requester encapsulates the OCSP request, in which the request for pre-computed information is used as an extension of the OCSP request; the requester establishes a connection with the OCSP server, and then sends the encapsulated OCSP request through the connection.

[0153] The requester can select the content to be pre-computed in the OCSP request: a) specify the type of pre-computed information required; b) select the table size of the pre-computed table for different types of pre-computed information (assuming it is a pre-computed table).

[0154] 3) The OCSP server parses the request and processes the pre-computed information extension request for the OCSP query.

[0155] 4) OCSP directly queries the CA database to obtain the latest status and pre-calculated information of the specified certificate and temporarily stores it.

[0156] The third step is to send the pre-calculated information.

[0157] The OCSP server encapsulates the latest certificate status and pre-computed information into an OCSP response, with the pre-computed information serving as an extension of the OCSP response. The OCSP server then signs the OCSP response, returns the pre-computed information to the requester through the connection, and closes the connection.

[0158] The fourth step is to verify the pre-calculated information.

[0159] The OCSP response message itself requires signature by the OCSP server and verification by the requester. Pre-computed information is also included in the OCSP response message and is signed and verified along with other message content. First, the requester parses the response and verifies the signature; then, upon successful verification, obtains the digital certificate status and pre-computed information; finally, the requester can use the pre-computed information to perform public-key cryptography related calculations.

[0160] It should be noted that, in the two methods mentioned above, the method of including the pre-computed information in the certificate extension can be chosen by the CA according to its own policy; or, users applying for digital certificates can inform the CA how to include the pre-computed information in the certificate extension based on the possible application scope of their certificates.

[0161] In addition, this application embodiment also provides another pre-computation information transmission system, which includes: a pre-computation information generation subsystem, a pre-computation information distribution subsystem, and a pre-computation information verification subsystem.

[0162] The pre-computed information generation subsystem, located within the CA, binds the pre-computed information to the certificate using certificate extensions; alternatively, it may reside within the CA or the OCSP server, binding the pre-computed information to the OCSP response message using OCSP response message extensions. Furthermore, the OCSP response message can be transmitted using the OCSP protocol or the OCSP Stapling protocol. Alternatively, it may reside in the CT Log Server, transmitting the pre-computed information to the user using SCT extensions.

[0163] The pre-computed information distribution subsystem is located in the CA and is used to distribute pre-computed information to the appropriate certificate subject and the requester.

[0164] The pre-computed information verification subsystem is located on the user side and is used to verify the pre-computed information; the certificate subject user and the requester belong to different user categories.

[0165] This application also provides an electronic device, such as... Figure 5As shown, the electronic device may include: a processor 51, a memory 52, and a communication interface 53. The memory 52 stores executable code, which, when executed by the processor 51, enables the processor 51 to implement the encrypted communication method as described in the preceding embodiments.

[0166] In addition, embodiments of this application provide a non-transitory machine-readable storage medium storing executable code, which, when executed by a processor of an electronic device, enables the processor to at least implement the encrypted communication method provided in the foregoing embodiments.

[0167] This application provides a computer program product, which includes a computer program that, when executed by a processor of an electronic device, causes the processor to execute the encrypted communication method provided in the foregoing embodiments.

[0168] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0169] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0170] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0171] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0172] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0173] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0174] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0175] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0176] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A method for obtaining a polynomial matrix, characterized in that, include: Obtain an input seed for generating a polynomial matrix, which is used in the execution of the target task based on a post-quantum cryptography algorithm; Based on the input seed, a sampling operation is performed on multiple polynomial coefficients of the polynomial matrix using an extensible output function and pre-computation information to obtain the polynomial matrix. The pre-computation information is a data table pre-computed and distributed to the user by a trusted party. The pre-computation information contains multiple intermediate checkpoints, each of which represents an internal state of the extensible output function during the sampling operation. The internal state contains all the information required to continue generating all subsequent random bytes. The sampling operation on multiple polynomial coefficients of the polynomial matrix using an extensible output function and pre-computed information includes: Identify multiple target threads, each target thread corresponding to an intermediate checkpoint; Based on the scalable output function, sampling operations are performed on multiple polynomial coefficients of the polynomial matrix in parallel by the multiple target threads.

2. The method according to claim 1, characterized in that, After obtaining the input seed for generating the polynomial matrix, the method further includes: Obtain pre-calculated information.

3. The method according to claim 2, characterized in that, The acquisition of pre-calculated information includes: Identify multiple intermediate checkpoints that meet the set checkpoint filtering criteria; The multiple intermediate checkpoints are stored to form pre-calculated information.

4. The method according to claim 3, characterized in that, The determination of multiple intermediate checkpoints that meet the set checkpoint filtering conditions includes: Determine the number of polynomial coefficients in the target polynomial; If it is determined that the sampled target polynomial coefficients satisfy a multiple relationship with the target threshold, then an intermediate checkpoint is determined to correspond to the target polynomial coefficients. The target threshold is determined based on the number of polynomial coefficients and the number of multiple target threads, and the target polynomial coefficients are one of the multiple polynomial coefficients.

5. The method according to any one of claims 1-4, characterized in that, The post-quantum cryptography algorithm is a lattice-based digital signature algorithm or a key encapsulation algorithm.

6. A polynomial matrix acquisition device, characterized in that, include: The acquisition module is used to acquire the input seed for generating the polynomial matrix, which is used in the process of executing the target task based on the post-quantum cryptography algorithm; A sampling module is used to perform sampling operations on multiple polynomial coefficients of a polynomial matrix based on the input seed, using an extensible output function and pre-computation information to obtain the polynomial matrix. The pre-computation information is a data table pre-computed and distributed to the user by a trusted party. The pre-computation information includes multiple intermediate checkpoints, each representing an internal state of the extensible output function during the sampling operation. This internal state contains all the information needed to continue generating all subsequent random bytes. The sampling operation on the multiple polynomial coefficients of the polynomial matrix using the extensible output function and pre-computation information includes: determining multiple target threads, each corresponding to an intermediate checkpoint; and performing the sampling operation on the multiple polynomial coefficients of the polynomial matrix in parallel using the multiple target threads based on the extensible output function.

7. An electronic device, characterized in that, include: The system includes a memory, a processor, and a communication interface; wherein the memory stores executable code, and when the executable code is executed by the processor, the processor performs the polynomial matrix acquisition method as described in any one of claims 1 to 5.

8. A non-transitory machine-readable storage medium, characterized in that, The non-transitory machine-readable storage medium stores executable code that, when executed by a processor of an electronic device, causes the processor to perform the polynomial matrix acquisition method as described in any one of claims 1 to 5.

9. A computer program product, characterized in that, include: A computer program, when executed by a processor of an electronic device, causes the processor to perform the polynomial matrix acquisition method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Parallel generation of random matrices

    CN115427928A

  • Efficient storage architecture based on anti-quantum encryption algorithm

    CN118798376A