A method for secure analysis of NTRU private keys under arbitrary Hamming weights
By constructing a specific set of equations and constraints to filter the solution space, the problem of recovering NTRU private keys under arbitrary Hamming weights was solved, achieving efficient and widely applicable private key recovery and security analysis.
Patent Information
- Application Number
- CN202610222025.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-02-25
- Publication Date
- 2026-04-21
- Estimated Expiration
- 2046-02-25
AI Technical Summary
Existing technologies cannot effectively recover NTRU private keys when the Hamming weight of the private key is unknown, resulting in the coefficient matrix not being of full rank, making it impossible to find a unique solution, and thus making it impossible to recover the private key.
By constructing a specific system of equations in matrix form, calculating the rank, solving the homogeneous solution space, selecting the unique true solution based on constraints, and recovering the private key using the Gentry-Szydlo algorithm.
When the Hamming weight of the private key is unknown, it can efficiently recover the private key, reduce the number of calls to the Gentry-Szydlo algorithm, achieve fast recovery, and is applicable to different parameterization schemes, thereby improving the coverage and completeness of security analysis.
Smart Images

Figure CN121727742B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication security technology, specifically a security analysis method for NTRU private keys under arbitrary Hamming weights. Background Technology
[0002] The private key of the post-quantum cryptography algorithm NTRU consists of two small-coefficient polynomials, and the public key of the NTRU algorithm is closely related to the product of these two polynomials. In some applications, it is necessary to recover the private key. To achieve this, current technology can fix one polynomial in the private key and continuously change the other polynomial, thus obtaining a series of different public keys. Utilizing the algebraic relationship between the public and private keys, combined with delinearization techniques, a system of modular linear equations with a full-rank coefficient matrix can be constructed. By solving this system of equations, a solution related to the private key can be uniquely determined. Then, the Gentry-Szydlo algorithm can be used to recover the complete private key from this solution, thereby achieving private key recovery.
[0003] To recover a private key, current techniques rely on the premise that the Hamming weight of the fixed polynomial in the private key must be public, i.e., known. This is because only when the Hamming weight is known can the constructed system of equations satisfy the requirement of a full-rank coefficient matrix, thus ensuring a unique solution. If the Hamming weight is unknown, the coefficient matrix will not be full-rank, a unique solution cannot be obtained, and therefore, private key recovery is impossible. Therefore, a method is needed that can effectively recover a private key even when its Hamming weight is unknown. Summary of the Invention
[0004] To address the shortcomings of existing technologies, the purpose of this invention is to provide a secure analysis method for NTRU private keys under arbitrary Hamming weights, which can solve the problems described in the background art.
[0005] The technical solution to achieve the purpose of this invention is: a secure analysis method for NTRU private keys under arbitrary Hamming weights, comprising the following steps:
[0006] Obtain the same first private key And different second private keys are generated Different public keys Based on the relationship between the public and private keys, a specific system of equations in matrix form is constructed. The rank of this system of equations is calculated. Based on the calculated rank, a particular solution satisfying the system of equations is found. Furthermore, based on the parity of the number of coefficients of 1 in each second private key, the homogeneous solution space of the system of equations is obtained. Constraints are constructed for filtering within the homogeneous solution space. According to these constraints, a unique true solution is selected from the homogeneous solution space, and the first private key is recovered from this unique true solution. This allows us to solve for each second private key, thus obtaining the result from the first private key. The private key pair consisting of the second private key is used for security analysis based on the solved private key.
[0007] Furthermore, the private key of the post-quantum cryptography algorithm NTRU includes the first private key. Each second private key forms a corresponding private key pair, where the first private key... and the A second private key Construct a private key pair , Let be a ternary polynomial, in which the number of coefficients 1 and the number of coefficients -1 are equal. Public Key Satisfying the public key relation: , , It is a power of 2. This represents the modulo operation, and it is performed on each coefficient of the polynomial. (First private key) Both the second private key and the business ring are in the business ring. On; targeting Each public key ,use A linear equation with the following formula is constructed: (1);
[0008] In the formula, Indicates the first A second private key The number of elements with a coefficient of 1, the coefficient By the Public Key Calculations show that For unknown quantities; the first Public Key Expressed as a polynomial as follows: Through this polynomial, let
[0009] ,
[0010] ;
[0011] In the formula, For the coefficient term, according to the above formula, It is a true solution that satisfies formula (1), where, for conjugate, Representing a polynomial and In the business environment The product of the above, express Chinese on monomials The coefficient of the term, ;for public key under All of them can be used to construct equations as shown in formula (1). Therefore, A public key can be used to construct Such equations, combined with these Equations, thus in the model This forms a system of linear equations. and , No. A second private key The number of coefficients that are 1 or -1 and the number of the first A second private key The number of coefficients that are 1 or -1 is equal, therefore the number of coefficients that are 1 or -1 for each second private key is denoted as . The system of equations can be represented in matrix form as follows:
[0012] (2);
[0013] In the formula, The coefficient matrix, , , that is It is the vector of variables to be solved. Let be a vector whose components are all 1. Indicates behavior Listed as A matrix, and all elements of the matrix are in The interval, the system of equations formed by the above formula (2) is the specific system of equations.
[0014] Furthermore, calculating the rank of this particular system of equations includes the following steps: when When the coefficient matrix is odd, The rank theory maximum value is ;when When the coefficients are even, the coefficient matrix The maximum value of the rank theory is And the number of public keys collected. .
[0015] Furthermore, based on the parity of the number of coefficients equal to 1 in each second private key, the homogeneous solution space of this specific system of equations is obtained, including the following steps: obtaining a particular solution. Satisfying formula (2), that is, we have And then according to The parity of the equation characterizes the homogeneous solution space of formula (2), that is, to find the solution space of the homogeneous solution space of formula (2). All bases.
[0016] Furthermore, when When the integer part is odd, the homogeneous solution space is one-dimensional, consisting of vectors all equal to 1. Composition, the set of all homogeneous solutions The following relationship must be satisfied: , It is an integer; when When it is even, let , It is an integer. Let be odd number. , If the integers are integers, then the homogeneous solution space is two-dimensional, consisting of a vector of all 1s. sum vector composition, At this point, the set of all homogeneous solutions is... The following relationship must be satisfied:
[0017] , and All are integers.
[0018] Furthermore, the constraints are as follows: I) Quadratic constraints: The result value is a value located in the interval The perfect square of an odd number within a given range; II) Parity constraints: It is a positive odd number; III) Size constraint: for all All satisfy .
[0019] Furthermore, any solution that satisfies the specific system of equations Both can be represented as follows: When When it is an odd number, ,in ;when When it is even, ,in , .
[0020] Furthermore, based on the constraints, a unique true solution is selected from the homogeneous solution space, which includes the following steps: when When it is an odd number, Each integer in Each solution is constructed. If the solution satisfies the above constraints, it is retained; otherwise, it is discarded. Finally, a unique integer is obtained. The constraints are satisfied; when When the number is even, the range is respectively in and Each integer pair Each solution can be constructed if it satisfies the above constraints and also satisfies... If the answer is yes, keep it; otherwise, discard the solution. This will ultimately yield a unique pair of integers. The constraints are met.
[0021] Furthermore, based on the unique true solution, we can find... The coefficients of each term, that is, to find , .
[0022] Furthermore, the solution will be obtained The input is fed into the Gentry-Szydlo algorithm to recover the first private key. And based on the first private key Recover each second private key.
[0023] Compared with existing technologies, the beneficial effects of this invention are: 1. This invention can recover the private key even when the Hamming weight of the private key is unknown (i.e., the Hamming weight is not fixed). It fundamentally solves the key recovery problem in this scenario without relying on prior knowledge of the Hamming weight. Furthermore, it has stronger practical application feasibility and can be better applied to the security analysis of cryptographic security systems. For example, the security analysis of a cryptographic system can be performed using the solved private key.
[0024] 2. This invention offers more efficient private key recovery, requiring less time. By accurately characterizing the homogeneous solution space and designing efficient mathematical constraints as a filter, the number of calls to the Gentry-Szydlo algorithm is reduced from a theoretical exponential level to a linear or even constant level, with a success rate approaching 100%. Experiments show that on ordinary computing platforms, the process of recovering solutions related to the private key can be completed within seconds to minutes, demonstrating its feasibility and efficiency in practical cryptanalysis scenarios.
[0025] 3. This invention has broad applicability and versatility. It is not only applicable to ternary coefficient polynomial private keys, but also, through adaptive filtering conditions, effectively applicable to attack methods... The private key. This covers mainstream variants of the post-quantum cryptography algorithm NTRU, such as NTRU-HPS, demonstrating the powerful versatility of this invention in handling different parameterization schemes and improving the coverage and completeness of security analysis in this field. Attached Figure Description
[0026] Figure 1 This is a flowchart illustrating a preferred embodiment of the present invention. Detailed Implementation
[0027] The present invention will be further described below with reference to the accompanying drawings and specific embodiments:
[0028] like Figure 1 As shown, a method for secure analysis of NTRU private keys under arbitrary Hamming weights includes the following steps:
[0029] Step 1: Obtain the same first private key as the post-quantum cryptography algorithm NTRU from the public channel. And different second private keys are generated Different public keys The private key of the post-quantum cryptography algorithm NTRU includes the first private key. Each second private key forms a corresponding private key pair, where the first private key... and the A second private key Construct a private key pair First private key This is the target private key, which is the private key that needs to be recovered. Among them, the first... Public Key satisfy , , Let be a ternary polynomial, in which the number of coefficients 1 is equal to the number of coefficients -1. It is a power of 2, and is a constant. The modulo operation is performed on each coefficient of the polynomial, that is... The resulting value is then modulo q. It should be noted that... and Since both are polynomials, the result of dividing them is also a polynomial.
[0030] It is understandable that the above result is a polynomial, and here we assume that one of the coefficients of this polynomial takes the value of . And assume , ,but That is, the result of the modulo operation (i.e., the remainder) is 1.
[0031] Understandably, the private key is derived from the first private key. The polynomial consists of a first polynomial constructed from the first private key and a second polynomial constructed from the second private key, with the coefficients of both polynomials taken from the set. That is, the coefficients of the two polynomials are either 1, 0, or -1, and their degrees are less than N, where N is an odd number. Therefore, these two polynomials are ternary polynomials. (This is based on the same first private key.) generated Different public keys That is, by maintaining the first private key in the private key pair. The same principle applies; by continuously changing the second private key, different public keys can be achieved. This is achieved by fixing a polynomial in the private key (the first private key). By continuously changing another polynomial (the second private key), different public keys can be obtained.
[0032] First private key Both the second private key and the business ring are in the business ring. The above is carried out. Among them, The number of 1s and -1s in the second private key coefficient is equal, that is... and , No. A second private key The number of coefficients that are 1 or -1 and the number of the first A second private key The number of coefficients that are 1 or -1 is equal, therefore the number of coefficients that are 1 or -1 for each second private key is denoted as . .
[0033] against Each public key ,use A linear equation with the following formula is constructed: (1);
[0034] In the formula, Indicates the first In the second private key The number of coefficients equal to 1, coefficient By the Public Key Calculations show that This is an unknown quantity. It should be noted that... This indicates rounding down to the nearest integer, for example, The value is 1.
[0035] No. Public Key Expressed as a polynomial as follows: Through this polynomial, let
[0036] ,
[0037] ;
[0038] In the formula, For the coefficient term, that is The calculated result, according to the above formula, is easily known. All of them are true solutions that satisfy formula (1), and there are a total of true solutions. +1 element. Among them, , that is for . conjugate. Representing a polynomial and In the business environment The product of the above, express Chinese on monomials The coefficient of the term, .
[0039] for public key under All of them can be used to construct equations as shown in formula (1). Therefore, A public key can be used to construct Such equations, combined with these Equations, thus in the model This forms a system of linear equations. This system of equations can be represented in matrix form as follows: (2); where, The coefficient matrix, , , that is It is the vector of variables to be solved. Let be a vector whose components are all 1. Indicates behavior Listed as A matrix, and all elements of the matrix are in Interval. The system of equations formed by the above formula (2) is the specific system of equations.
[0040] Step 2: Determine the coefficient matrix in the specific system of equations The rank. Specifically, when When the coefficient matrix is odd, The maximum value of the rank theory is .when When the coefficients are even, the coefficient matrix The maximum value of the rank theory is And when the number of public keys collected... When, coefficient matrix The rank of can reach the above theoretical maximum value with an overwhelming probability (extreme probability).
[0041] Step 3: Solve for a particular solution that satisfies the specific system of equations, and then solve for the homogeneous solution space that satisfies formula (2) based on the particular solution.
[0042] Specifically, firstly, a particular solution is obtained. Satisfying formula (2), that is, we have Then according to The parity of the equation characterizes the homogeneous solution space of formula (2), that is, to find the solution space of the homogeneous solution space of formula (2). All bases.
[0043] when When the integer part is odd, the homogeneous solution space is one-dimensional, consisting of vectors all equal to 1. The set of all homogeneous solutions (i.e., the homogeneous solution space). The following relationship must be satisfied: , It is an integer.
[0044] when When it is even, let ( It is an integer. (If it is an odd number), let , If the integers are integers, then the homogeneous solution space is two-dimensional, consisting of a vector of all 1s. sum vector composition, At this point, the set of all homogeneous solutions is... The following relationship must be satisfied: , and All are integers.
[0045] Step 4: Based on the constraints, extract the homogeneous solution set The unique true solution is selected from the given conditions, which are as follows: I) Quadratic constraint: The result value is a value located in the interval The perfect square of an odd number within a given range; II) Parity constraints: It is a positive odd number; III) Size constraint: for all All satisfy .
[0046] It is understandable that, according to step 3, any solution satisfying formula (2) Both can be represented as follows: When When it is an odd number, ,in ;when When it is even, ,in , .
[0047] More specifically, the screening process is as follows: When When it is an odd number, Each integer in A solution can be constructed for each of these conditions. If the solution satisfies the above constraints (meaning it satisfies all three of the constraints simultaneously), then the solution is retained; otherwise, the solution is discarded.
[0048] Experimental results show that only one unique integer will ultimately be obtained. The constraints are satisfied, therefore, when When the number is odd, a unique true solution can be selected.
[0049] when When the number is even, the range is respectively in and Each integer pair Each of these can construct a solution if it satisfies the above constraints and also satisfies the advanced version of the third constraint. If the solution is correct, retain it; otherwise, discard it.
[0050] Experimental results show that ultimately only one pair exists. The requirements are met, thus identifying the unique true solution.
[0051] For the NTRU cryptographic algorithm, the first private key It can be a ternary polynomial of arbitrary Hamming weight, or it can be in the following form: , It is a constant, usually taking the value 3. is a ternary polynomial of arbitrary Hamming weight.
[0052] It should be noted that the above constraints apply to the first private key. For a ternary polynomial of arbitrary Hamming weight, for If the constraints are modified, the logic of this embodiment can also be implemented.
[0053] Step 5: Based on the unique true solution, find The coefficients of each term, that is, to find , .
[0054] Then, The input is fed into the Gentry-Szydlo algorithm (also known as the GS algorithm) to recover the first private key. Recover the first private key. Afterwards, naturally, The second private key All can be recovered, meaning the second private key can be recovered, thus allowing the recovery of the private key (including the first private key). (and the second private key), thus obtaining the first private key The private key pair consisting of the second private key is used for security analysis based on the solved private key.
[0055] It should be noted that the second private key is recovered first. Then by different The corresponding second private key The final second private key is not directly recovered.
[0056] The embodiments disclosed in this specification are merely illustrative of one aspect of the invention, and the scope of protection of the invention is not limited to these embodiments. Any other functionally equivalent embodiments fall within the scope of protection of the invention. Those skilled in the art can make various other corresponding changes and modifications based on the technical solutions and concepts described above, and all such changes and modifications should fall within the scope of protection of the claims of this invention.
Claims
1. A method for secure analysis of NTRU private keys under arbitrary Hamming weights, characterized in that, Includes the following steps: Obtain the same first private key And different second private keys are generated Different public keys Based on the relationship between the public and private keys, a specific system of equations in matrix form is constructed. The rank of this system of equations is calculated. Based on the calculated rank, a particular solution satisfying the system of equations is found. Furthermore, based on the parity of the number of coefficients of 1 in each second private key, the homogeneous solution space of the system of equations is obtained. Constraints are constructed for filtering within the homogeneous solution space. According to these constraints, a unique true solution is selected from the homogeneous solution space, and the first private key is recovered from this unique true solution. This allows us to solve for each second private key, thus obtaining the result from the first private key. The private key pair formed by the second private key is used for security analysis based on the solved private key. The private key of the post-quantum cryptography algorithm NTRU includes the first private key. Each second private key forms a corresponding private key pair, where the first private key... and the A second private key Construct a private key pair , It is a ternary polynomial, in which the number of coefficients 1 and the number of coefficients -1 are equal; Calculating the rank of this particular system of equations includes the following steps: when When the coefficient matrix is odd, The maximum value of the rank theory is ;when When the coefficients are even, the coefficient matrix The rank theory maximum value is And the number of public keys collected. ; The constraints are as follows: I) Quadratic constraint: The result value is a value located in the interval The perfect square of an odd number within a given range; II) Parity constraints: It is a positive odd number; III) Size constraint: for all All satisfy .
2. The method for secure analysis of NTRU private keys under arbitrary Hamming weights according to claim 1, characterized in that, No. Public Key Satisfying the public key relation: , , It is a power of 2. This represents the modulo operation, and it is performed on each coefficient of the polynomial. (First private key) Both the second private key and the business ring are in the business ring. On; targeting Each public key ,use A linear equation with the following formula is constructed: (1); In the formula, Indicates the first A second private key The number of elements with a coefficient of 1, the coefficient By the Public Key Calculations show that For unknown quantities; the first Public Key Expressed as a polynomial as follows: Through this polynomial, let , ; In the formula, For the coefficient term, according to the above formula, It is a true solution that satisfies formula (1), where, for conjugate, Representing a polynomial and In the business environment The product of the above, express Regarding monomials The coefficient of the term, ;for public key under All of them can be used to construct equations as shown in formula (1). Therefore, A public key can be used to construct... Such equations, combined with these Equations, thus in the model This forms a system of linear equations. and , No. A second private key The number of coefficients that are 1 or -1 and the number of the first A second private key The number of coefficients that are 1 or -1 is equal, therefore the number of coefficients that are 1 or -1 for each second private key is denoted as . The system of equations can be represented in matrix form as follows: (2); In the formula, The coefficient matrix, , , that is It is the vector of variables to be solved. Let be a vector whose components are all 1. Indicates behavior Listed as A matrix, and all elements of the matrix are in The interval, the system of equations formed by the above formula (2) is the specific system of equations.
3. The method for secure analysis of NTRU private keys under arbitrary Hamming weights according to claim 2, characterized in that, The homogeneous solution space of this particular system of equations is obtained by determining the parity of the number of coefficients equal to 1 in each second private key, including the following steps: Solving for a particular solution. Satisfying formula (2), that is, we have And then according to The parity of the equation characterizes the homogeneous solution space of formula (2), that is, to find the solution space of the homogeneous solution space of formula (2). All bases.
4. The method for secure analysis of NTRU private keys under arbitrary Hamming weights according to claim 3, characterized in that, when When the integer part is odd, the homogeneous solution space is one-dimensional, consisting of vectors all equal to 1. Composition, the set of all homogeneous solutions The following relationship must be satisfied: , It is an integer; when When it is even, let , It is an integer. Let be an odd number. , If the integers are integers, then the homogeneous solution space is two-dimensional, consisting of a vector of all 1s. sum vector composition, At this point, the set of all homogeneous solutions is... The following relationship must be satisfied: , and All are integers.
5. A method for secure analysis of NTRU private keys under arbitrary Hamming weights according to claim 4, characterized in that, Any solution that satisfies the specific system of equations Both can be represented as follows: When When it is an odd number, ,in ;when When it is even, ,in , .
6. A method for secure analysis of an NTRU private key under arbitrary Hamming weights according to claim 5, characterized in that, Based on the constraints, a unique true solution is selected from the homogeneous solution space, which includes the following steps: When When it is an odd number, Each integer in Each solution is constructed. If the solution satisfies the above constraints, it is retained; otherwise, it is discarded. Finally, a unique integer is obtained. The constraints are satisfied; when When the number is even, the range is respectively in and Each integer pair Each solution can be constructed if it satisfies the above constraints and also satisfies... If the answer is yes, keep it; otherwise, discard the solution. This will ultimately yield a unique pair of integers. The constraints are met.
7. A method for secure analysis of an NTRU private key under arbitrary Hamming weights according to claim 6, characterized in that, Based on the unique true solution, find The coefficients of each term, that is, to find , .
8. A method for secure analysis of an NTRU private key under arbitrary Hamming weights according to claim 7, characterized in that, The solution The input is fed into the Gentry-Szydlo algorithm to recover the first private key. And based on the first private key Recover each second private key.
Citation Information
Patent Citations
NTRU-based efficient and compact key packaging, encryption and decryption method
CN120342618A
Security analysis method for post-quantum NTRU cryptographic algorithm
CN120825286A