Safety design device, safety design method, and safety design program
The use of a discrete Gaussian distribution in the Reused-A-LWE problem addresses the limitations of continuous Gaussian distributions, enabling secure and efficient cryptographic parameter derivation for threshold cryptography.
Patent Information
- Application Number
- JP2024082645
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-21
- Publication Date
- 2025-12-04
AI Technical Summary
Existing cryptographic methods based on the LWE problem are limited by the use of continuous Gaussian distributions, which do not align with computer implementations requiring discrete error distributions, and rounding errors complicate security parameter derivation.
A security design device and method that utilize a discrete Gaussian distribution as the error distribution to solve the Reused-A-LWE problem, deriving security parameters through a calculation process that ensures a predetermined level of security.
Enables the derivation of secure security parameters suitable for cryptographic designs, particularly in threshold cryptography, using a discrete Gaussian distribution, enhancing the security and efficiency of cryptographic schemes.
Smart Images

Figure 2025176467000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a technology for designing security in high-performance cryptography (such as threshold cryptography) based on the LWE (Learning with Errors) problem. [Background technology]
[0002] In Non-Patent Document 1, the LWE problem was proposed as a computationally difficult problem in lattice theory, and subsequently, many cryptographic methods based on this LWE problem have been proposed. Furthermore, in Non-Patent Document 2, the Reused-A-LWE problem, a variant of the LWE problem, is proposed, and it is shown that when the error distributions χ1 and χ2 are continuous Gaussian distributions, LWE≦Reused-A-LWE (the LWE problem reduces to the Reused-A-LWE problem), that is, the Reused-A-LWE problem is more difficult to compute than the LWE problem. Then, a threshold public key cryptosystem with a security design based on this reduction is proposed. [Prior art documents] [Non-patent literature]
[0003] [Non-Patent Document 1] O. Regev. "On Lattices, Learning with Errors, Random Linear Codes, and Cryptography". J. ACM 56.6 (2009). Preliminary version appeared in STOC '05. [Non-patent document 2] D. Micciancio and A. Suhl. "Simulation-Secure Threshold PKE from LWE with Polynomial Modulus". ePrint 2023 / 1728. 2023. [Non-patent document 3] D. Micciancio and C. Peikert. "Hardness of SIS and LWE with Small Parameters". CRYPTO 2013. 2013, pp. 21-39. [Non-patent document 4] L. Ducas, S. Galbraith, T. Prest, and Y. Yu. "Integral Matrix Gram Root and Lattice Gaussian Sampling without Floats". EUROCRYPT 2020. 2020, pp. 608-637. [Non-patent document 5] MR Albrecht, BR Curtis, A. Deo, A. Davidson, R. Player, EW Postlethwaite, F. Virdia, and T. Wunderer. "Estimate All the {LWE, NTRU} Schemes!" SCN 2018. 2018, pp. 351-367. [Non-patent document 6] V. Lyubashevsky, C. Peikert, and O. Regev. "On Ideal Lattices and Learning with Errors over Rings". EUROCRYPT 2010. 2010, pp. 1-23. Summary of the Invention [Problem to be solved by the invention]
[0004] However, the reduction LWE≦Reused-A-LWE shown in Non-Patent Document 2 was limited to the case where the error distributions χ1 and χ2 were continuous Gaussian distributions. On the other hand, in computer implementation, the error distributions must be discrete values. Furthermore, when real numbers in the continuous Gaussian distribution were substituted with floating-point numbers, the impact of rounding errors had to be separately discussed.
[0005] The present invention aims to provide a security design device, a security design method, and a security design program that can derive security parameters with guaranteed security in cipher design based on the Reused-A-LWE problem, which uses a discrete Gaussian distribution as the error distribution. [Means for solving the problem]
[0006] The safety design device according to the present invention solves the Reused-A-LWE problem using a discrete Gaussian distribution as the error distribution. S (n,m,q,D Z,s1 ,D Z,s2 ) parameters n, m, q, s1, s2 (where s2 = Cs1 for a constant C∈N (a natural number)) and an input part that accepts input of the LWE problem d-LWE with a discrete Gaussian distribution as the error distribution from the parameter s1 and the constant C. S (n,m,q,D Z,sb ) parameter s b of,
number
[0007] The Reused-A-LWE problem may be a Reused-A-Ring-LWE problem, and the LWE problem may be a Ring-LWE problem.
[0008] The security design method according to the present invention is a method for designing a security algorithm in which a computer, via an input unit, solves a Reused-A-LWE problem using a discrete Gaussian distribution as an error distribution. S (n,m,q,D Z,s1 ,D Z,s2) parameters n, m, q, s1, s2 (where s2 = Cs1 for a constant C∈N (a natural number)) are input, and the calculation unit calculates the LWE problem d-LWE using the parameter s1 and the constant C as the error distribution. S (n,m,q,D Z,sb ) parameter s b of,
number
[0009] A safety design program according to the present invention is for causing a computer to function as the safety design device. [Effects of the Invention]
[0010] According to the present invention, it is possible to derive security parameters with guaranteed security in a cipher design based on the Reused-A-LWE problem with a discrete Gaussian distribution as the error distribution. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 2 is a diagram illustrating a functional configuration of a safety design device according to an embodiment. [Figure 2] FIG. 2 is a diagram showing an algorithm of a safety design program executed by a safety design device in an embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0012] An example of an embodiment of the present invention will be described below. The security design device of this embodiment outputs security parameters based on reduction from the LWE problem when designing parameters for a cipher based on the Reused-A-LWE problem in which the error distribution is a discrete Gaussian distribution. First, various definitions and lemmas will be presented, followed by the theorems on which this embodiment is based and their proofs.
[0013] [Definition 1 (Statistical distance)] The statistical distance between distributions χ1 and χ2 is defined as follows:
number
[0014] [Definition 2 (statistically indistinguishable)] χ1 and χ2 are
number
number
[0015] [Definition 3 (LWE distribution)] n,m,q∈N(natural number),X q to Z q (integer) or R q (real number), and χ is X q The distribution above has a mean of 0.
number
number
[0016] [Definition 4 (Decision-LWE problem)] d-LWE(n,m,q,χ) is the LWE s (n,m,q,χ) and uniform distribution U(Z m×n q ×X m q ) and Algorithm A:Z m×n q ×Z m q →We define the dominance of {0,1} over d-LWE as follows:
number
[0017] [Definition 5 (Search-LWE problem)] s-LWE(n,m,q,χ) is the LWE of sample (A,b) s This problem is called the problem of finding s from (n, m, q, χ). It is also called difficult when the probability of successful decryption of any PPT algorithm for this problem is negl(n).
[0018] [Definition 6 (Reused-A-LWE distribution)] n,m,q∈N(natural number),X q to Z q (integer) or R q (real number), and let χ1 and χ2 be X q The distribution is as above.
number
number
[0019] [Definition 7 (Decision-Reused-A-LWE problem)] d-Reused-A-LWE(n,m,q,χ1,χ2) is the Reused-A-LWE distribution. s The problem is to distinguish between (n,m,q,χ1,χ2) and the following uniform random distribution V:
number
number
[0020] [Definition 8 (Search-Reused-A-LWE problem)] s-Reused-A-LWE(n,m,q,χ1,χ2) is the Reused-A-LWE sample (A,b1,b2) ← Reused-A-LWE s The problem is to take (n,m,q,χ1,χ2) as input and output s.
[0021] Here, the lattice L is a set of linearly independent vectors b1,…,b n ∈R m is the set of linear sums of integer coefficients of
number
number
[0022] A continuous Gaussian distribution with mean 0 and standard deviation σ>0 is N σ It is written as follows. A column-full-rank matrix S∈R n×m In contrast, R n Above, the covariance matrix Σ=SS T ∈R n×n The Gaussian function of
number
number
[0023] [Definition 9 (Discrete Gaussian distribution on a lattice L)] For a full column rank matrix S, the covariance matrix Σ:=SS T A discrete Gaussian distribution on a lattice L is a distribution with the following probability function:
number
[0024] [Fact 10]
number
number
number
[0025] [Definition 11 (Smoothing Parameter)] For a lattice L and a sufficiently small ε>0, the smoothing parameter of L is
number
[0026] [Fact 12] For any ε>0,
number
number
[0027] [Lemma 13 (a special case of Theorem 3.3 in Non-Patent Document 3)] e∈Z m satisfies gcd(e)=1, and for i=1,…,m,
number
number
number
number
number
[0028] [Lemma 14 (Lemma 3 in Non-Patent Document 4)] ε=negl(λ),s≧η + ε (Z n ) for any regular matrix T∈Z n×n For , the following holds:
number
[0029] In the security design method of this embodiment, the security parameter λ of the Reused-A-LWE problem, in which the error distribution is a discrete Gaussian distribution, is derived based on the security derivation from the LWE problem. Note that the security parameter λ is determined by the advantage (ε=2 -λ ), i.e., the exponent that represents the computational effort required for decryption. This security consequence is shown by Theorem 15 and is proved as follows.
[0030] [Theorem 15 (main theorem)] Let ε=negl(λ) and C∈N be a constant (for example, C=1, C=2, etc.).
number
number
[0031] (Proof)
number
number
number
number
number
[0032] [Lemma 16] Let ε = negl(λ) and C∈N be a constant (C=1, C=2, etc.).
number
number
number
number
[0033] Lemma 16 can be understood as replacing the continuous distribution in Non-Patent Document 2 (Theorem 1) with a discrete Gaussian distribution. However, this configuration is not trivial because it is necessary to satisfy the conditions for the smoothing parameter and the conditions for applying Lemma 17 described later.
[0034] (Proof)
number
number
number
number
number
number
[0035] [Lemma 17 (special case of Lemma 13)] C∈N is a constant,
number
number
[0036] In this embodiment, the safety design device 1 is configured based on the above-mentioned Theorem 15. FIG. 1 is a diagram showing the functional configuration of a safety design device 1 in this embodiment. The safety design device 1 is an information processing device (computer) that includes a control unit 10, a storage unit 20, and various input / output interfaces.
[0037] The control unit 10 is a part that controls the entire safety design device 1, and realizes each function in this embodiment by appropriately reading and executing various programs stored in the storage unit 20. The control unit 10 may be a CPU.
[0038] The storage unit 20 is a storage area for various programs for causing the hardware group to function as the safety design device 1, various data, etc., and may be a ROM, RAM, flash memory, hard disk drive (HDD), or the like.
[0039] The control unit 10 includes an input unit 11, a calculation unit 12, an acquisition unit 13, and an output unit 14, and these functional units output security parameters for the Reused-A-LWE problem, in which the error distribution is the discrete Gaussian distribution adopted by the cryptographic scheme being designed.
[0040] The input unit 11 receives a discrete Gaussian distribution D Z,s1 and D Z,s2 Reused-A-LWE problem with error distribution S (n,m,q,D Z,s1 ,D Z,s2 ) parameters n, m, q, s1, and s2 are input. However, for a constant C∈N (a natural number), the standard deviations s1 and s2 have the relationship s2=Cs1.
[0041] The calculation unit 12 calculates a discrete Gaussian distribution D from the input parameter s1 and constant C. Z,sb LWE problem d-LWE with error distribution S (n,m,q,D Z,sb ) the standard deviation s bof,
number
[0042] The acquisition unit 13 acquires the parameter s calculated by the calculation unit 12. b In addition, the LWE problem d-LWE is constructed with the same parameters n, m, and q as the Reused-A-LWE problem. S (n,m,q,D Z,sb ) a security parameter λ for ensuring the required level of security is obtained using a predetermined formula. This security parameter λ can be obtained by a known method such as that shown in Non-Patent Document 5. The calculated value may be stored in a database in association with the parameter.
[0043] The output unit 14 outputs the security parameter λ acquired by the acquisition unit 13 as the security parameter for the Reused-A-LWE problem.
[0044] FIG. 2 is a diagram showing the algorithm of the safety design program executed by the safety design device 1 in this embodiment. This algorithm solves the Reused-A-LWE problem where the error distribution is a discrete Gaussian distribution. S (n,m,q,D Z,s1 ,D Z,s2 ) parameters n, m, q, s1, and s2 as input and output a security bit λ.
[0045] In step 1, the safety design device 1 calculates the LWE problem d-LWE, which is the source of the safety reduction to the Reused-A-LWE problem. S (n,m,q,D Z,sb ) parameter s b Calculate. In step 2, the safety design device 1 calculates the parameter s b Using the LWE problem d-LWE S (n,m,q,DZ,sb ) security parameter λ is obtained and output by a predetermined method.
[0046] According to this embodiment, the safety design device 1 can derive security parameters for the Reused-A-LWE problem using a discrete Gaussian distribution as the error distribution based on reduction from the LWE problem using the same discrete Gaussian distribution as the error distribution. In other words, the security design device 1 can output parameters that can be proven secure for the Reused-A-LWE problem using a discrete Gaussian distribution that is suitable for implementation on a computer, making it possible to construct a practical encryption method.
[0047] Furthermore, this embodiment can also be applied to the relationship between the Ring-LWE problem (Non-Patent Document 6) and the Reused-A-Ring-LWE problem, and it is clear that security can be proven. Therefore, by replacing LWE with Ring-LWE in the algorithm of Fig. 2, the security design device 1 can derive security parameters for the Reused-A-Ring-LWE problem, which uses a discrete Gaussian distribution as the error distribution, based on reduction from the Ring-LWE problem.
[0048] This embodiment can be applied to threshold fully homomorphic encryption schemes or the threshold public key encryption schemes that form the basis of their configurations, for example, when performing advanced statistical analysis such as AI using secure computation, and can efficiently realize secure computation services with guaranteed security.
[0049] The above-described embodiment makes it possible to design, for example, a secure and efficient cryptographic method, which can contribute to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), which is to "Develop resilient infrastructure, promote sustainable industrialization and foster innovation."
[0050] Although the embodiments of the present invention have been described above, the present invention is not limited to the above-described embodiments. Furthermore, the effects described in the above-described embodiments are merely a list of the most preferable effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments.
[0051] The safety design method using the safety design device 1 is realized by software. When realized by software, the programs that make up this software are installed in an information processing device (computer). These programs may be recorded on removable media such as CD-ROMs and distributed to users, or may be distributed by being downloaded to the user's computer via a network. Furthermore, these programs may be provided to the user's computer as a web service via a network without being downloaded. [Explanation of symbols]
[0052] 1 Safety design device 10 Control Unit 11 Input section 12 Calculation section 13 Acquisition Department 14 Output section 20 Memory section
Claims
1. Reused-A-LWE problem with discrete Gaussian distribution as the error distribution S (n, m, q, D Z,s1 , D Z,s2 ) parameters n, m, q, s 1 , s 2 (However, for a constant C∈N (natural number), s 2 = Cs 1 an input unit for accepting input of Parameter s 1 From the constant C, the LWE problem d-LWE with the discrete Gaussian distribution as the error distribution is S (n, m, q, D Z,sb ) parameter s b of, [Equation 1] A calculation unit that calculates: The LWE problem d-LWE S (n, m, q, D Z,sb an acquisition unit that acquires a security parameter λ of the above-mentioned key pair by a calculation formula that ensures a predetermined level of security; an output unit that outputs the security parameter λ acquired by the acquisition unit as a security parameter for the Reused-A-LWE problem.
2. 2. The safety design device according to claim 1, wherein the Reused-A-LWE problem is a Reused-A-Ring-LWE problem, and the LWE problem is a Ring-LWE problem.
3. The computer The input part is used to solve the Reused-A-LWE problem where the discrete Gaussian distribution is used as the error distribution. S (n, m, q, D Z,s1 , D Z,s2 ) parameters n, m, q, s 1 , s 2 (However, for a constant C∈N (natural number), s 2 = Cs 1 ) input, The calculation unit calculates the parameter s 1 From the constant C, the LWE problem d-LWE with the discrete Gaussian distribution as the error distribution is S (n, m, q, D Z,sb ) parameter s b of, [Equation 2] and calculates, The acquisition unit acquires the LWE problem d-LWE S (n, m, q, D Z,sb ) security parameter λ is obtained using a formula that ensures a predetermined level of security, an output unit that outputs the security parameter λ acquired by the acquisition unit as a security parameter for the Reused-A-LWE problem;
4. A safety design program for causing a computer to function as the safety design device according to claim 1.
Citation Information
Cited By
Anti-quantum threshold encryption method and system
CN121814321A
A quantum threshold resistant encryption method and system
CN121814321B