Lattice-based public-key data encryption method, lattice-based public-key data decryption method and key encapsulation method based on vector decoding
Through vector decoding and NTT number theory transformation optimization grid public key encryption methods, the problems of large size and low computing efficiency of public key and ciphertext are solved, and efficient and secure data encryption and decryption are achieved, which is suitable for resisting quantum computing attacks.
Patent Information
- Application Number
- PCT/CN2023/077521
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-02-21
- Publication Date
- 2025-07-03
AI Technical Summary
The existing grid-based public key encryption methods have problems such as large public key and ciphertext sizes, low computational efficiency of encryption and decryption operations, and high decryption failure rate, which are difficult to meet practical application requirements.
The grid public key data encryption and decryption method based on vector decoding is adopted. By encoding plain text data to the most significant bit and encoding multiple times, combined with NTT number theory transformation operation, the ring parameters are optimized, the public key and ciphertext size are reduced, and the encryption and decryption speed is improved.
It effectively reduces the size of public key and ciphertext, reduces storage and communication overhead, improves the computing efficiency of encryption and decryption operations, reduces the decryption failure rate, and can resist quantum computing attacks.
Smart Images

Figure CN2023077521_03072025_PF_FP_ABST
Abstract
Description
Lattice public key data encryption and decryption method and key encapsulation method based on vector decoding Technical Field
[0001] The present invention belongs to the field of public key encryption in cryptography, and relates to data encryption and decryption and related technologies in lattice cryptography. Specifically, it is a lattice public key data encryption and decryption method and a key encapsulation method based on vector decoding. Background Art
[0002] Public-key cryptography has been widely deployed in many practical applications, including e-government and online banking. However, the increase in large-scale computing power and advances in cryptanalysis, especially the rapid development of quantum computing theory and quantum computers, have posed significant threats and challenges to the security of many public-key cryptography methods based on RSA or elliptic curves. Consequently, there is an urgent need to design public-key cryptography methods that are secure against quantum computing attacks.
[0003] Lattice-based public-key encryption methods have been widely recognized by scholars both domestically and internationally for their efficiency and security, and are currently considered one of the most promising candidate methods. However, these technologies and methods still suffer from the large size of public keys and ciphertexts, which in turn increases storage and communication overhead, as well as low computational efficiency of encryption and decryption operations and high decryption failure rates, which hinder their ability to meet practical application requirements.
[0004] Summary of the Invention
[0005] The embodiments of the present invention provide a lattice public key data encryption and decryption method and a key encapsulation method based on vector decoding to solve the problems existing in related technologies or methods, such as large public key and ciphertext size, low computational efficiency of encryption and decryption operations, and high decryption failure rate.
[0006] According to one aspect of an embodiment of the present invention, a lattice public key data encryption method based on vector decoding is provided, comprising: determining predetermined plaintext data M a , wherein the predetermined plaintext data described Indicates the message space, the predetermined plaintext data Indicates that the predetermined plaintext data is plaintext data of 1 bit length; adopts the first predetermined encryption method PKE.Enc(h, M), according to the predetermined plaintext data, the first target public key h1, and the predetermined interference term, obtains the first target ciphertext data c1; sends the first target ciphertext data c1 to the first terminal, wherein adopting the first predetermined encryption method PKE.Enc(h, M), according to the predetermined plaintext data, the first target public key h1, and the predetermined interference term, obtains the first target ciphertext data c1 includes: encoding the predetermined plaintext data M according to the predetermined encoding method a, obtain the target coding polynomial m, wherein the number of terms of the target coding polynomial m is based on the predetermined plaintext data M a The predetermined bit length is determined, and the coefficients of each term of the target coding polynomial m are determined according to the plaintext data on the corresponding bit data bits in the predetermined plaintext data; according to the first target public key h1, the predetermined interference term and the target coding polynomial m, the first target ciphertext data c1 is obtained.
[0007] Optionally, according to the first target public key h1, the predetermined interference term and the target coding polynomial m, the first target ciphertext data c1 is obtained, including: when the predetermined coding mode is Msg2poly(M), the target coding polynomial m=M0+M1x+…+M i x i +…+M l-1 x l-1 The predetermined interference term includes a random number r, a predetermined noise value e, and an inverse ring element v of the ring element v. -1 , based on the first target public key h1, the random number r, the predetermined noise value e, the inverse ring element v -1 and the target encoding polynomial m to obtain the first target ciphertext data c1, where M i Indicates M a The data on the i-th bit length in M i = {0, 1}, the ring element v = (1-x n / k ), v∈R q , reverse ring elements m∈R q , It is R q The set of all reversible elements in , is a predetermined ring structure, representing a polynomial ring of degree n-1, The n is a power of 2, the q is a prime number, the k is the largest integer that satisfies k|n and n / k≥1, and the represents a set of integers, the Represents the set of positive integers.
[0008] Optionally, according to the first target public key h1, the predetermined interference term and the target coding polynomial m, the first target ciphertext data c1 is obtained, including: when the predetermined coding method is Msg2noise(M,η), the target coding polynomial m=m0+m1x+…+m n-1 x n-1, the predetermined interference term includes a random number r; according to the first target public key h1, the random number r and the target encoding polynomial m, the first target ciphertext data c1 is obtained, wherein η represents the parameter value of the central binomial distribution, the target encoding polynomial m is a polynomial whose coefficients conform to the central binomial distribution with the parameter value η, and the target encoding polynomial m is determined to be m0+m1x+…+m n-1 x n-1 Includes: Determine So that for all i∈[2kη-1] there is s i ∈{0, 1} n / k , and determine According to the s and the s 2kη-1 , for all i∈[k] and j∈[n / k], determine According to the m in / k+j , determine the target coding polynomial m=m0+m1x+…+m n-1 x n-1 .
[0009] Optionally, before obtaining the first target ciphertext data c1 using the first predetermined encryption method PKE.Enc(h, M), according to the predetermined plaintext data, the first target public key h1, and the predetermined interference term, the method further includes: when the predetermined encoding method is Msg2poly(M), obtaining the initial private key f′, the predetermined private key g, and the ring element v, wherein the ring element v=(1-x n / w); determine the first target private key f1 based on the initial private key f′ and the ring element v; and obtain the first target public key h1 based on the first target private key f1 and the predetermined private key g.
[0010] Optionally, before obtaining the first target ciphertext data c1 using the first predetermined encryption method PKE.Enc(h, M), according to the predetermined plaintext data, the first target public key h1, and the predetermined interference term, the method further includes: when the predetermined encoding method is Msg2noise(M, η), obtaining the initial private key f′, the predetermined private key g and the inverse ring element v -1 , wherein the reverse ring element According to the initial private key f′ and the reverse ring element v -1 , determine the first target private key f1; and obtain the first target public key h1 based on the first target private key f1 and the predetermined private key g.
[0011] According to one aspect of an embodiment of the present invention, a lattice public key data decryption method based on vector decoding is provided, comprising: receiving first target ciphertext data c1 sent by a second terminal, wherein the first target ciphertext data c1 is obtained by using a first predetermined encryption method PKE.Enc(h, M) based on a first target public key h1, a predetermined interference term and a target encoding polynomial m, and the target encoding polynomial m encodes the predetermined plaintext data M according to the predetermined encoding method a The number of terms of the target coding polynomial m is obtained according to the predetermined plaintext data M a The predetermined bit length is determined by the target coding polynomial m, and the coefficients of each item of the target coding polynomial m are determined according to the predetermined plaintext data M a The plaintext data corresponding to the bit data position is determined, and the predetermined plaintext data described Indicates the message space, the predetermined plaintext data Indicates that the target plaintext data is plaintext data of 1 bit length; using the predetermined decryption method PKE.Dec(f, c), according to the first target ciphertext data c1 and the first target private key f1, the target plaintext data M is obtained b , wherein the first target private key f1 is determined according to the predetermined encoding method, wherein the predetermined decryption method PKE.Dec(f, c) is used to obtain the target plaintext data M according to the first target ciphertext data c1 and the first target private key f1 b The method includes: determining a target decoding polynomial w according to the first target ciphertext data c1 and the first target private key f1; decoding the target decoding polynomial w according to a predetermined decoding method to obtain the target plaintext data M b , wherein the predetermined decoding method corresponds to the predetermined encoding method.
[0012] Optionally, a predetermined decryption method PKE.Dec(f, c) is used to obtain the target plaintext data M according to the first target ciphertext data c1 and the first target private key f1. b Before, it also includes: when the predetermined encoding method is Msg2poly(M), determining the first target private key f1 based on the initial private key f′ and the ring element v; and / or, when the predetermined encoding method is Msg2noise(M,η), determining the first target private key f1 based on the initial private key f′ and the inverse ring element v -1 , determine the first target private key f1, wherein the ring element v=(1-x n / k ), v∈R q , the reverse ring element described It is R q The set of all reversible elements in , is the predetermined ring structure, representing a polynomial ring of degree n-1, The n is a power of 2, the q is a prime number, the k is the largest integer that satisfies k|n and n / k≥1, and the represents a set of integers, the represents a set of positive integers, and η represents the parameter value of the central binomial distribution.
[0013] Optionally, when the predetermined encoding mode includes at least one of the following: Msg2poly(M), Msg2noise(M, η), the predetermined decoding mode is Poly2msg(w), and the target decoding polynomial w is decoded according to the predetermined decoding mode to obtain the target plaintext data M b , including: inputting the target decoding polynomial w into the Poly2msg(w), where w=w0+w1x+…+w n-1 x n-1 , the w∈R q ; Based on all i∈[n], determine Based on all j∈[l], determine in accordance with Get the target plaintext data M b .
[0014] According to one aspect of an embodiment of the present invention, a lattice key encapsulation method based on vector decoding is provided, comprising: determining target random data M c , wherein the described Represents the message space, the Indicates that the target random data is 1-bit data; Determine the term value H1(h) for the second cryptographic hash function H2 based on the second target public key h2 and the first cryptographic hash function H1, wherein the first cryptographic hash function H1: {0, 1} * →{0, 1} κ , used to convert data of any bit length into data of κ bit length, the second cryptographic hash function H2: {0, 1} l+κ →{0, 1} κ ×{0, 1} κ , used to convert data of a specific bit length into two data of κ bit lengths, wherein the specific bit length is determined according to the data of 1 bit length and the data of κ bit length; according to the item value H1(h) and the target random data M c , using the second cryptographic hash function H2, determine the first unknown number And the first offset ρ; According to the second target public key h2, the target random data M c With the first offset ρ, a second predetermined encryption method PKE.Enc (h, M; ρ) is used to obtain the second target ciphertext data c2; according to the first unknown number The second target ciphertext data c2 is used to determine the encapsulation key K through a third cryptographic hash function H3, wherein the third cryptographic hash function H3: {0, 1} * →{0, 1} κ , used to convert data of any bit length into data of κ bit length.
[0015] Optionally, according to the first unknown number After the second target ciphertext data c2 is determined by the third cryptographic hash function H3, the method further includes: according to the second target ciphertext data c2 and the second target private key f2, a predetermined decryption method PKE.Dec(f, c) is used to obtain the target decrypted data M d ; According to the item value H1(h) and the target decrypted data M d , using the second cryptographic hash function H2, determine the second unknown number And the second offset ρ '; According to the second target public key h2, the target decrypted data M d and the second offset ρ′, using the second predetermined encryption method PKE.Enc(h, M; ρ) to obtain the third target ciphertext data c3; when the second target ciphertext data c2 is the same as the third target ciphertext data c3, outputting the encapsulation key K to the third terminal.
[0016] According to one aspect of an embodiment of the present invention, a lattice public key data encryption device based on vector decoding is provided, comprising: a first determining module configured to determine a predetermined plaintext data M a , wherein the predetermined plaintext data described Indicates the message space, the predetermined plaintext data Indicates that the predetermined plaintext data is plaintext data of 1 bit length; a first encryption module, configured to adopt a first predetermined encryption method PKE.Enc(h, M), and obtain a first target ciphertext data c1 based on the predetermined plaintext data, the first target public key h1, and a predetermined interference term; a sending module, configured to send the first target ciphertext data c1 to the first terminal, wherein the first encryption module includes: an encoding module, configured to encode the predetermined plaintext data M according to a predetermined encoding method a , obtain the target coding polynomial m, wherein the number of terms of the target coding polynomial m is based on the predetermined plaintext data Ma The predetermined bit length is determined, and the coefficients of each term of the target coding polynomial m are determined according to the plaintext data on the corresponding bit data bits in the predetermined plaintext data; the encryption submodule is configured to obtain the first target ciphertext data c1 based on the first target public key h1, the predetermined interference term and the target coding polynomial m.
[0017] According to one aspect of an embodiment of the present invention, a lattice public key data decryption device based on vector decoding is provided, comprising: a receiving module, configured to obtain the first target ciphertext data c1 based on the first target public key h1, a predetermined interference term and a target encoding polynomial m, using a first predetermined encryption method PKE.Enc(h, M), and the target encoding polynomial m encodes the predetermined plaintext data M according to the predetermined encoding method a The number of terms of the target coding polynomial m is obtained according to the predetermined plaintext data M a The predetermined bit length is determined by the target coding polynomial m, and the coefficients of each item of the target coding polynomial m are determined according to the predetermined plaintext data M a The plaintext data corresponding to the bit data position is determined, and the predetermined plaintext data described Indicates the message space, the predetermined plaintext data Indicates that the target plaintext data is plaintext data of 1 bit length; a decryption module is configured to use a predetermined decryption method PKE.Dec(f, c) to obtain the target plaintext data M according to the first target ciphertext data c1 and the first target private key f1. b , wherein the first target private key f1 is determined according to the predetermined encoding method, wherein the decryption module includes: a second determination module, configured to determine a target decoding polynomial w according to the first target ciphertext data c1 and the first target private key f1; a decoding module, configured to decode the target decoding polynomial w according to the predetermined decoding method to obtain the target plaintext data M b , wherein the predetermined decoding method corresponds to the predetermined encoding method.
[0018] According to one aspect of an embodiment of the present invention, a lattice key encapsulation device based on vector decoding is provided, comprising: a third determination module configured to determine the target random data M c , wherein the described Represents the message space, the Indicates that the target random data is 1-bit data; a fourth determination module is configured to determine a term value H1(h) for the second cryptographic hash function H2 based on the second target public key h2 and the first cryptographic hash function H1, wherein the first cryptographic hash function H1: {0, 1}* →{0, 1} κ , used to convert data of any bit length into data of κ bit length, the second cryptographic hash function H2: {0, 1} l+κ →{0, 1} κ ×{0, 1} κ , used to convert data of a specific bit length into two data of κ bit lengths, wherein the specific bit length is determined based on the data of 1 bit length and the data of κ bit length; a fifth determining module is configured to determine the data of the specific bit length based on the item value H1(h) and the target random data M c , using the second cryptographic hash function H2, determine the first unknown number And a first offset ρ; a second encryption module, configured to be based on the second target public key h2, the target random data M c and the first offset ρ, using the second predetermined encryption method PKE.Enc (h, M; ρ) to obtain the second target ciphertext data c2; the sixth determination module is set to be based on the first unknown number The second target ciphertext data c2 is used to determine the encapsulation key K through a third cryptographic hash function H3, wherein the third cryptographic hash function H3: {0, 1} * →{0, 1} κ , used to convert data of any bit length into data of κ bit length.
[0019] According to one aspect of an embodiment of the present invention, an electronic device is provided, comprising: a processor; a memory configured to store instructions executable by the processor; wherein the processor is configured to execute the instructions to implement any one of the above-mentioned lattice public key data encryption methods based on vector decoding, any one of the above-mentioned lattice public key data decryption methods based on vector decoding, and any one of the above-mentioned lattice key encapsulation methods based on vector decoding.
[0020] According to one aspect of an embodiment of the present invention, a computer-readable storage medium is provided. When the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the lattice public key data encryption method based on vector decoding as described in any one of the above, the lattice public key data decryption method based on vector decoding as described in any one of the above, and the lattice key encapsulation method based on vector decoding as described in any one of the above.
[0021] In the embodiment of the present invention, the predetermined plaintext data M of 1 bit length is determined. a, using the first predetermined encryption method PKE.Enc(h, M), based on the predetermined plaintext data, the first target public key h1, and the predetermined interference term, to obtain the first target ciphertext data c1, thereby achieving the purpose of encrypting the predetermined plaintext data. The first predetermined encryption method is as follows: Encode the predetermined plaintext data M according to the predetermined encoding method a , obtaining the target encoding polynomial m, thereby encoding the predetermined plaintext data. Then, based on the first target public key h1, the predetermined interference term, and the target encoding polynomial m, the first target ciphertext data c1 is obtained, thereby encrypting the encoded predetermined plaintext data, strengthening the protection of the predetermined plaintext data and enhancing security during the process. Finally, the first target ciphertext data c1 can be sent to the first terminal. Since the first target ciphertext data is encrypted after encoding the predetermined plaintext data, data leakage can be prevented during transmission to the first terminal. Moreover, unlike other schemes that only encode plaintext data to the least significant bit, the predetermined encoding method of the present invention can encode each plaintext data to the most significant bit, and encode the plaintext data multiple times, thereby greatly reducing the decryption failure rate; at the same time, the encoding and decoding methods proposed in the present invention support smaller ring parameters q, thereby greatly reducing the size of the public key and ciphertext, and reducing storage and communication overhead; in addition, the ring structure used in the present invention has the property of supporting NTT number theory transformation operations, thereby greatly reducing the number of operations such as polynomial multiplication and inverse calculation, so the encryption and decryption speed of the present invention is also greatly improved, thereby solving the problems existing in related technologies and methods such as large public key and ciphertext size, low encryption and decryption operation efficiency, and high decryption failure rate. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0023] 1 is a flowchart of a lattice public key data encryption method based on vector decoding according to an embodiment of the present invention;
[0024] 2 is a flow chart of a method for decrypting lattice public key data based on vector decoding according to an embodiment of the present invention;
[0025] 3 is a flow chart of a lattice key encapsulation method based on vector decoding according to an embodiment of the present invention;
[0026] 4 is a structural block diagram of a lattice public key data encryption device based on vector decoding according to an embodiment of the present invention;
[0027] 5 is a structural block diagram of a lattice public key data decryption device based on vector decoding according to an embodiment of the present invention;
[0028] FIG6 is a structural block diagram of a lattice key encapsulation device based on vector decoding according to an embodiment of the present invention. DETAILED DESCRIPTION
[0029] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0030] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0031] First, some nouns or terms that appear in the description of the embodiments of the present application are subject to the following interpretations:
[0032] 1) represents a set of integers, i.e. represents the set of residue classes modulo q, that is, Where q is a positive integer; for any positive integer n, Indicates n The direct product of
[0033] 2) represents a set of positive integers, that is
[0034] 3) Let n, are positive integers, R, R2 and R q They are defined in and The polynomial ring of degree n-1 on as well as For any positive integer represents k R q The direct product of For any positive integer Indicated by R q The set of k×k matrices composed of the elements in ;
[0035] 4) For distribution D, Indicates that element x is randomly selected according to distribution D; for a finite set S, Indicates uniformly random selection of element x from the set S;
[0036] 5) Symbol: = indicates assignment, that is, for any two values a and b, a: = b means that b is assigned the value of a;
[0037] 6) For any positive integer B η represents the binomial distribution with η as parameter; χ represents the probability distribution over the polynomial ring R;
[0038] 7) For a positive even number α and any integer r, define the operation r′=r mod ± α output satisfies r′=r mod α; for a positive odd number α and any integer r, define the operation r′=r mod ± α output For any positive integer α and integer r, define the operation r′=r mod α. + α output r′∈[0,α) satisfies r′=r mod α. When the exact modular reduction operation is not important, it is abbreviated as r mod α;
[0039] 8) Central binomial distribution B with a positive integer η as parameter η The definition is as follows:
[0040] where (a1, ..., a η ,b1,...,b η )←{0,1} 2η Represents the set {0, 1} 2η uniformly randomly select bits a1,...,a η ,b1,...,b η From B η Sampling a polynomial f∈R q Or polynomial vector means from B η The coefficients of each polynomial are sampled in . It is easy to prove that the binomial distribution with η as parameter is is a sub-Gaussian distribution with a standard deviation;
[0041] 9) Ternary distribution with positive real number σ∈(0,1 / 2) as parameter It means sampling element x from the ternary set {-1, 0, 1} with the following probability:
[0042] Pr[x=1]=Pr[x=-1]=σ and Pr[x=0]=1-2σ,
[0043] Easy to prove, is a uniform distribution on the set {-1, 0, 1}, is a central binomial distribution with parameter η = 1;
[0044] 10) RSA algorithm: A public key encryption algorithm proposed by Rivest, Shamir, and Adleman. Public key encryption algorithms use different encryption keys and decryption keys to encrypt and decrypt data.
[0045] 11) NTRU lattice public key encryption: This is an important branch of lattice cryptography. Its security is based on the difficulty of the NTRU problem proposed by Hoffstein, Pipher, and Silverman in 1996.
[0046] 12) RLWE: Ring Learning with Errors Problem (RLWE);
[0047] 13) sspRLWE: Subset-Sum Parity RLWE (sspRLWE), a variant of the RLWE problem.
[0048] Example 1
[0049] According to an embodiment of the present invention, an embodiment of a lattice public key data encryption method based on vector decoding is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0050] FIG1 is a flow chart of a lattice public key data encryption method based on vector decoding according to an embodiment of the present invention. As shown in FIG1 , the method includes the following steps:
[0051] Step S102: Determine the predetermined plaintext data M a , where the predetermined plaintext data Indicates message space, reserved plaintext data Indicates that the predetermined plaintext data is plaintext data of 1 bit length;
[0052] After step S102, the first predetermined encryption method PKE.Enc(h, M) is used to obtain the first target ciphertext data c1 according to the predetermined plaintext data, the first target public key h1, and the predetermined interference term, including:
[0053] Step S104: Encode the predetermined plaintext data M according to the predetermined encoding method. a , get the target coding polynomial m, where the number of terms in the target coding polynomial m is based on the predetermined plaintext data M a The predetermined bit length of the target coding polynomial m is determined, and the coefficients of each term of the target coding polynomial m are determined according to the plaintext data corresponding to the bit data position in the predetermined plaintext data;
[0054] Step S106, obtaining first target ciphertext data c1 according to the first target public key h1, the predetermined interference term and the target encoding polynomial m;
[0055] Step S108: Send the first target ciphertext data c1 to the first terminal.
[0056] Through the above steps, the predetermined plaintext data M of l bit length is determined a , using the first predetermined encryption method PKE.Enc(h, M), based on the predetermined plaintext data, the first target public key h1, and the predetermined interference term, to obtain the first target ciphertext data c1, thereby achieving the purpose of encrypting the predetermined plaintext data. The first predetermined encryption method is as follows: Encode the predetermined plaintext data M according to the predetermined encoding method a, obtaining the target encoding polynomial m, thereby encoding the predetermined plaintext data. Then, based on the first target public key h1, the predetermined interference term, and the target encoding polynomial m, the first target ciphertext data c1 is obtained, thereby encrypting the encoded predetermined plaintext data, strengthening the protection of the predetermined plaintext data and enhancing security during the process. Finally, the first target ciphertext data c1 can be sent to the first terminal. Since the first target ciphertext data is encrypted after encoding the predetermined plaintext data, data leakage can also be protected during transmission to the first terminal. Furthermore, unlike other schemes that only encode plaintext data to the least significant bit, the predetermined encoding method of the present invention encodes each plaintext data to the most significant bit and encodes the plaintext data multiple times, significantly reducing the decryption failure rate. Furthermore, the encoding and decoding methods proposed in the present invention support a smaller ring parameter q, significantly reducing the size of the public key and ciphertext, and reducing storage and communication overhead. Furthermore, the ring structure used in the present invention supports NTT number theory transformation operations, significantly reducing the number of operations required for polynomial multiplication and inversion, thereby greatly improving the encryption and decryption speed of the present invention. This solves the problems in related technologies or methods, such as large public key and ciphertext sizes, low computational efficiency of encryption and decryption operations, and high decryption failure rate.
[0057] As an optional embodiment, according to the first target public key h1, the predetermined interference term and the target coding polynomial m, the first target ciphertext data c1 is obtained, including: when the predetermined coding method is Msg2poly(M), the target coding polynomial m=M0+M1x+…+M i x i +…+M l-1 x l-1 The predetermined interference items include a random number r, a predetermined noise value e, and the inverse ring element v of the ring element v. -1 , based on the first target public key h1, random number r, predetermined noise value e, inverse ring element v +1 and the target coding polynomial m, the first target ciphertext data c1 is obtained, where M i Indicates M q The data on the i-th bit length in M i = {0, 1}, ring element v = (1-x n / k ), v∈R q , reverse ring elements m∈R q , It is R q The set of all reversible elements in , is a predetermined ring structure, representing a polynomial ring of degree n-1, n is a power of 2, q is a prime number, k is the largest integer that satisfies k|n and n / k ≥ l, represents a set of integers, Represents the set of positive integers.
[0058] In this embodiment, an encryption method is described in which the predetermined encoding method is Msg2poly(M). In this case, M in the target polynomial is i Indicates M a The plaintext data M of the i-th bit length q It has a length of 1 bit. Unlike other schemes that only encode plaintext data to the least significant bit, the encoding polynomial v of the present invention is -1 Each plaintext data is encoded to the most significant bit, and the plaintext data is encoded multiple times, thereby greatly reducing the decryption failure rate; at the same time, the encoding and decoding method proposed in the present invention supports a smaller ring parameter q, thereby significantly reducing the size of the public key and ciphertext, reducing storage and communication overhead; in addition, the ring parameter used in the present invention is The invention supports NTT number theory transform operations, significantly reducing the number of calculations required. This greatly improves encryption and decryption speeds, resolving issues in related technologies and methods such as large public key and ciphertext sizes, low encryption and decryption computational efficiency, and high decryption failure rates.
[0059] It should be noted that the polynomial rings R, R mentioned in the present invention are q and the ring element v, There are many options for parameters such as , which are not limited to the specific examples given in the present invention. For example, the ring of NTT operation is also supported. Wherein d is an even number, etc. For those skilled in the art, without departing from the principle and method of the present invention, several improvements or variations can be made, and these improvements and variations are also considered to be within the scope of protection of the present invention.
[0060] As an optional embodiment, according to the first target public key h1, the predetermined interference term and the target coding polynomial m, the first target ciphertext data c1 is obtained, including: when the predetermined coding method is Msg2noise(M,η), the target coding polynomial m=m0+m1x+…+m n-1 x n-1 The predetermined interference term includes a random number r; based on the first target public key h1, the random number r and the target coding polynomial m, the first target ciphertext data c1 is obtained, wherein η represents the parameter value of the central binomial distribution, the target coding polynomial m is a polynomial whose coefficients conform to the central binomial distribution with the parameter value η, and the target coding polynomial m is determined to be m0+m1x+…+m n-1 x n-1 Includes: Determine So that for all i∈[2kη-1] there is s i ∈{0, 1} n / k , and determine According to s and s 2kη-1 , for all i∈[k] and j∈[n / k], determine According to m in / k+j , determine the target coding polynomial m=m0+m1x+…+m n-1 x n-1 .
[0061] This embodiment describes an encryption method using the Msg2noise(M, η) encoding scheme. In this case, while maintaining the same storage overhead for the ciphertext and public key, encoding the plaintext data within the noise reduces the overall noise carried by the ciphertext, further reducing the impact of noise on the decryption failure rate and achieving a lower decryption failure rate.
[0062] As an optional embodiment, the first predetermined encryption method PKE.Enc(h, M) is used, and before obtaining the first target ciphertext data c1 based on the predetermined plaintext data, the first target public key h1, and the predetermined interference term, the method further includes: when the predetermined encoding method is Msg2poly(M), obtaining the initial private key f′, the predetermined private key g, and the ring element v, wherein the ring element According to the initial private key f′ and the ring element v, a first target private key f1 is determined; according to the first target private key f1 and the predetermined private key g, a first target public key h1 is obtained.
[0063] In this embodiment, the key generation process is described when the predetermined encoding mode is Msg2poly(M). In this case, it is necessary to generate a first target private key and a first target public key based on ring elements.
[0064] As an optional embodiment, the first predetermined encryption method PKE.Enc(h, M) is used, and before obtaining the first target ciphertext data c1 according to the predetermined plaintext data, the first target public key h1, and the predetermined interference term, the following further comprises: when the predetermined encoding method is Msg2noise(M, η), obtaining the initial private key f′, the predetermined private key g and the inverse ring element v -1 , where the reverse ring element According to the initial private key f′ and the inverse ring element v -1 , determine the first target private key f1; and obtain the first target public key h1 based on the first target private key f1 and the predetermined private key g.
[0065] In this embodiment, the key generation process is described when the predetermined encoding method is Msg2noise(M,η). In this case, it is necessary to generate the first target private key and the first target public key based on the inverse ring element.
[0066] FIG2 is a flow chart of a method for decrypting lattice public key data based on vector decoding according to Embodiment 1 of the present invention. As shown in FIG2 , the method includes the following steps:
[0067] Step S202: Receive the first target ciphertext data c1 sent by the second terminal, wherein the first target ciphertext data c1 is obtained by using the first predetermined encryption method PKE.Enc(h, M) based on the first target public key h1, the predetermined interference term and the target encoding polynomial m, and the target encoding polynomial m encodes the predetermined plaintext data M according to the predetermined encoding method. a The number of terms in the target coding polynomial m is determined by the predetermined plaintext data M. a The coefficients of each item of the target coding polynomial m are determined by the predetermined plaintext data M a In the case of a bit, the plaintext data corresponding to the bit data position is determined, and the predetermined plaintext data Indicates message space, reserved plaintext data Indicates that the target plaintext data is m∈R q bit length of plaintext data;
[0068] After step S202, the predetermined decryption method PKE.Dec(f, c) is used to obtain the target plaintext data M according to the first target ciphertext data c1 and the first target private key f1. b ,include:
[0069] Step S204: determining a target decoding polynomial w based on the first target ciphertext data c1 and the first target private key f1, wherein the first target private key f1 is determined based on a predetermined encoding method;
[0070] Step S206: Decode the target decoding polynomial w according to a predetermined decoding method to obtain the target plaintext data M b , wherein the predetermined decoding method corresponds to the predetermined encoding method.
[0071] Through the above steps, the first target ciphertext data sent by the second terminal is received, a target decoding polynomial is determined based on the first target ciphertext data and the first target private key, and finally the target polynomial is decoded according to a predetermined decoding method to obtain the target plaintext data. Because the first target ciphertext data is based on the first target public key h1, the predetermined interference term, and the target encoding polynomial m, the encryption operation performed is the encoded predetermined plaintext data, which strengthens the protection of the predetermined plaintext data and enhances the security of the process. Because the first target ciphertext data is encrypted after encoding the predetermined plaintext data, the process of transmitting the first target ciphertext data can also protect data from leakage. Moreover, unlike other schemes that encode plaintext data only to the least significant bit, the predetermined encoding method of the present invention can encode each plaintext data to the most significant bit and encode the plaintext data multiple times, thereby significantly reducing the decryption failure rate. At the same time, the encoding and decoding method proposed by the present invention supports a smaller ring parameter q, which significantly reduces the size of the public key and ciphertext, reducing storage and communication overhead. In addition, the ring structure used in the present invention has the property of supporting NTT number theory transformation operations, which greatly reduces the number of calculations such as polynomial multiplication and inversion. Therefore, the encryption and decryption speed of the present invention is also greatly improved. This solves the problems of large public key and ciphertext size, low encryption and decryption operation efficiency, and high decryption failure rate in related technologies or methods.
[0072] As an optional embodiment, a predetermined decryption method PKE.Dec(f, c) is used to obtain the target plaintext data M according to the first target ciphertext data c1 and the first target private key f1. b Before, it also includes: when the predetermined encoding method is Msg2poly(M), determining the first target private key f1 based on the initial private key f′ and the ring element v; and / or when the predetermined encoding method is Msg2noise(M,η), determining the first target private key f1 based on the initial private key f′ and the inverse ring element v -1 , determine the first target private key f1, where the ring element v=(1-x n / k ), v∈R q , reverse ring elements It is R q The set of all reversible elements in , is a predetermined ring structure, representing a polynomial ring of degree n-1, n is a power of 2, q is a prime number, k is the largest integer that satisfies k|n and n / k ≥ l, represents a set of integers, represents the set of positive integers, and η represents the parameter value of the central binomial distribution.
[0073] In this embodiment, the operation of obtaining the first target private key before determining the target decoding polynomial w based on the first target ciphertext data and the first target private key is explained. When the predetermined encoding used in the encoding process is different, the process of determining the first target private key is also different, and can be customized according to actual applications and scenarios.
[0074] As an optional embodiment, when the predetermined encoding mode includes at least one of the following: Msg2poly(M), Msg2noise(M, η), the predetermined decoding mode is Poly2msg(w), and the target decoding polynomial w is decoded according to the predetermined decoding mode to obtain the target plaintext data M b , including: inputting the target decoding polynomial w into Poly2msg(w), where w=w0+w1x+…+w n-1 x n-1 , w∈R q ; Based on all i∈[n], determine Based on all j∈[l], determine in accordance with Get the target plaintext data M b .
[0075] In this embodiment, a predetermined decoding method is described when the predetermined encoding method is Msg2poly(M) or Msg2noise(M, η), and a process of decoding to obtain target plaintext data according to the predetermined decoding method is described. In this process, due to the precise modularization operation, the noise and other data are appropriately processed, so that the obtained target plaintext data can be the same as the original predetermined plaintext data with a high probability, thereby achieving the purpose of restoring the data and realizing the entire process of data decryption.
[0076] FIG3 is a flow chart of a lattice key encapsulation method based on vector decoding according to Embodiment 1 of the present invention. As shown in FIG3 , the method includes the following steps:
[0077] S302, determine the target random data M c ,in, Represents the message space, Indicates that the target random data is 1 bit long;
[0078] Step S304: Determine the term value H1(h) for the second cryptographic hash function H2 based on the second target public key h2 and the first cryptographic hash function H1, wherein the first cryptographic hash function H1: {0, 1} * →{0, 1} κ , used to convert data of any bit length into data of κ bit length, the second cryptographic hash function H2: {0, 1} l+κ→{0, 1} κ ×{0, 1} κ , used to convert data of a specific bit length into two data of κ bits, where the specific bit length is determined based on the data of 1 bit length and the data of κ bits length;
[0079] Step S306, according to the item value H1(h) and the target random data M c , through the second cryptographic hash function H2, determine the first unknown number and a first offset ρ;
[0080] Step S308: Based on the second target public key h2, the target random data M c and the first offset ρ, using the second predetermined encryption method PKE.Enc(h, M; ρ) to obtain the second target ciphertext data c2;
[0081] It should be noted that the second predetermined encryption method is similar to the first predetermined encryption method, except that the first offset in the second encryption method is equivalent to the predetermined interference term in the first predetermined encryption method, that is, the predetermined interference term in the second encryption method is calculated.
[0082] That is equivalent to using the first predetermined encryption method PKE.Enc (h, M) according to the predetermined plaintext data M a In the process of obtaining the first target ciphertext data c1, the first target public key h1 and the predetermined interference term are obtained based on the first offset, and the calculation process is the same as that of encoding the predetermined plaintext data M according to the predetermined encoding method. a , obtain the target coding polynomial m, according to the first target public key h1, the predetermined interference term is similar to the target coding polynomial m, and the first target ciphertext data c1 is obtained.
[0083] Step S310, based on the first unknown number The second target ciphertext data c2 is used to determine the encapsulation key K through the third cryptographic hash function H3, where the third cryptographic hash function H3 is: {0, 1} * →{0, 1} κ , used to convert data of any bit length into data of κ bit length.
[0084] It should be noted that the encapsulation key K is applicable to a symmetric encryption algorithm.
[0085] Through the above steps, the target random data is determined, and based on the second target public key and the first cryptographic hash function, the second cryptographic hash function is used to determine the term value for the second cryptographic hash function. Based on the term value and the target random data, the second cryptographic hash function is used to determine the first unknown number and the first offset. Then, based on the second target public key, the target random data, and the first offset, the second predetermined encryption method is used to obtain the second ciphertext data. Based on the first unknown number and the second ciphertext data, the final encapsulation key is determined through the third cryptographic hash function to verify the security of the data transmission process. Since the second predetermined encryption method is used in determining the second target ciphertext data, the encryption operation of the encoded target random data is implemented, thereby strengthening the protection of the target random data and enhancing the security of the data transmission process. Furthermore, because the present invention utilizes a second predetermined encryption method and a predetermined encoding scheme, unlike other schemes that encode plaintext data only to the least significant bit, the present invention can encode each plaintext data to the most significant bit and encode the plaintext data multiple times, thereby significantly reducing the decryption failure rate. Furthermore, the encoding and decoding method proposed in the present invention supports a smaller ring parameter q, thereby significantly reducing the size of the public key and ciphertext, and reducing storage and communication overhead. Furthermore, the ring structure used in the present invention has the property of supporting NTT number theory transformation operations, thereby significantly reducing the number of operations required for calculations such as polynomial multiplication and inversion. Therefore, the encryption and decryption speed of the present invention is also greatly improved. This solves the problems of large public key and ciphertext sizes, low encryption and decryption operation efficiency, and high decryption failure rates in related technologies or methods.
[0086] As an optional embodiment, according to the first unknown number After determining the encapsulation key K through the third cryptographic hash function H3, the method further includes: obtaining the target decrypted data M using a predetermined decryption method PKE.Dec(f, c) based on the second target ciphertext data c2 and the second target private key f2. d ; Based on the item value H1(h) and the target decrypted data M d , through the second cryptographic hash function H2, determine the second unknown number And the second offset ρ '; According to the second target public key h2, the target decrypted data M d With the second offset ρ′, the second predetermined encryption method PKE.Enc(h, M; ρ) is used to obtain the third target ciphertext data c3; when the second target ciphertext data c2 is the same as the third target ciphertext data c3, the encapsulation key K is output to the third terminal.
[0087] This embodiment describes the process of verifying the encapsulation key. Specifically, when the encrypted second target ciphertext data matches the third target ciphertext data, the encapsulation key can be obtained for data encryption and decryption. This process utilizes a second predetermined encryption method having a predetermined ring structure, ring elements, and inverse ring elements, thus achieving the aforementioned beneficial effects.
[0088] It should be noted that the above predetermined decryption method is the same as the method in steps S204-S206, and will not be described in detail here.
[0089] It should also be noted that the above-mentioned lattice public key data encryption method based on vector decoding, the lattice public key data decryption method based on vector decoding, and the lattice public key data encryption device based on vector decoding, wherein the common parameter expression has the same meaning, such as the ring element v = (1-x n / k ), v∈R q , reverse ring elements It is R q The set of all reversible elements in , is a predetermined ring structure, representing a polynomial ring of degree n-1, n is a power of 2, q is a prime number, k is the largest integer that satisfies k|n and n / k ≥ l, represents a set of integers, Represents a set of positive integers, and η represents the parameter value of the central binomial distribution, which is not described in detail above.
[0090] Based on the above embodiment and optional embodiment, an optional implementation manner is provided, which is described in detail below.
[0091] In the related art, existing NTRU-based lattice public key encryption methods, decryption methods, and key encapsulation methods have problems such as large public key and ciphertext sizes, low computational efficiency of encryption and decryption operations, and high decryption failure rate.
[0092] In view of this, an optional embodiment of the present invention provides a lattice public key data encryption and decryption method based on vector decoding, as well as a lattice key encapsulation and decapsulation method based on vector decoding. The public key and ciphertext are small in size, thereby reducing storage and communication overhead. At the same time, the NTT number theory transformation operation is used to reduce the number of operations in polynomial multiplication and inverse element calculation, thereby improving the computational efficiency of encryption and decryption operations. This solves the problems of large public key and ciphertext sizes, low encryption and decryption operation computational efficiency, and high decryption failure rate in the NTRU-based lattice public key encryption method, decryption method, and key encapsulation method in the related art. The optional embodiment of the present invention is described in detail below:
[0093] Optional implementations of the present invention include the following aspects:
[0094] (1) Design a lattice public key encryption method based on NTRU based on the vector encoding and decoding method.
[0095] (2) Define the variant problem subset of the ring learning with errors (RLWE) problem and the parity RLWE problem (Subset-Sum Parity RLWE, sspRLWE), and design an improved lattice public key encryption method based on vector decoding based on the sspRLWE problem.
[0096] (3) Design an efficient key encapsulation mechanism using the public key encryption method.
[0097] The following are introductions to the above three aspects:
[0098] (1) A lattice public key encryption method based on vector decoding:
[0099] (1) Define mathematically difficult problems:
[0100] Let n, Be a positive integer, where n is a power of 2 and q is a prime number, let is a polynomial ring, It is R q The set of all reversible elements on f , χ g For the ring Probability distribution over . Computational NTRU problem The goal is to Given a sample h = g / f∈R q , solve the secret vector f′. Deterministic NTRU problem The goal is to distinguish and R q Uniform random tuples on
[0101] (2) Define message vector encoding and decoding methods:
[0102] For a positive integer n, Where n is a power of 2, q is a prime number, let and is a polynomial ring, It is R q The set of all reversible elements in ;
[0103] make For message space, is the largest integer that satisfies k|n and n / k≥l, so that the ring element Then its inverse element (the same as the inverse ring element above) is in and denote the set of integers and positive integers respectively, R q It is defined in For a polynomial ring of degree n-1, when n=1, we have
[0104] 1) Define the predetermined encoding method:
[0105] Msg2poly(M): Given a message, the predetermined plaintext data M a As input, returns the target encoding polynomial m = M0 + M1x + ... + M i x i +…+M l-1 x l-1 ∈R q , where the predetermined plaintext data m∈R q , here M i ∈{0, 1} is the i-th bit of M, denoted by m=Msg2poly(M);
[0106] 2) Define the predetermined decoding method:
[0107] Poly2msg(w): Given the target decoding polynomial w = w0 + w1x + ... + w n-1 x n-1 ∈R q As input, first calculate for all i∈[n] Then for all j∈[l] we calculate Final settings Finally, the target plaintext data M can be output b .
[0108] (3) Implement encryption and decryption:
[0109] Based on the above predetermined encoding method and predetermined decoding method, a lattice public key encryption method based on vector decoding is proposed, in which the plaintext is encrypted with the public key to obtain the ciphertext, and the ciphertext is decrypted with the private key to obtain the plaintext.
[0110] For example: The lattice public key encryption method based on vector decoding consists of four positive integer parameters n, q, k, 1 ring element and 4 R's q The probability distribution χ on f , χ g , χ r , χ e To instantiate, including: key generation method PKE.KeyGen(1 κ) Generates a public key pk (also expressed as h) and a private key sk according to the security parameter κ; the encryption method PKE.Enc(h, M) encrypts the plaintext M according to the public key h and outputs the ciphertext c; the decryption method PKE.Dec(sk, c) decrypts the ciphertext c according to the private key sk and outputs the plaintext M.
[0111] 1) Key generation method PKE.KeyGen(1 κ ):
[0112] S1, random selection satisfy in (As described above, when the predetermined encoding method is Msg2poly(M), the first target private key f1 is determined based on the initial private key f′ and the ring element v);
[0113] S2, random selection Calculate h1 = g / f1 (same as above, based on the first target private key f1 and the predetermined private key g, to obtain the first target public key h1);
[0114] S3, output the public-private key pair (pk, sk) = (h, f)∈R q ×R q .
[0115] 2) Encryption method PKE.Enc(pk, M):
[0116] S1, obtain the predetermined plaintext data M a , where the predetermined plaintext data
[0117] S2, when the predetermined encoding mode is Msg2poly(M), m=Msg2poly(M a ), and obtain the target coding polynomial m=M0+M1x+…+M i x i +…+M l-1 x l-1 ;
[0118] S3, determine c1=h1r+e+v -1 m, where the number of random selections and (Same as above based on the first target public key h1, random number r, predetermined noise value e, inverse ring element v -1 and the target encoding polynomial m to obtain the first target ciphertext data c1);
[0119] S4, output the target decrypted data c1.
[0120] 3) Decryption method PKE.Dec(sk, c):
[0121] S1, obtain the target decrypted data c1∈R q .
[0122] S2, calculate w=f1c1 (same as above, based on the first target ciphertext data c1 and the first target private key f1, determine the target decoding polynomial w);
[0123] S3, calculate M b =Poly2msg(w) (decode the target decoding polynomial w according to the predetermined decoding method as above to obtain the target plaintext data M b );
[0124] S4, output target plaintext data M b .
[0125] (2) Define the variant problem subset of the ring learning with errors (RLWE) problem and the parity RLWE problem (Subset-Sum Parity RLWE, sspRLWE), and design an improved lattice public key encryption method based on vector decoding based on the sspRLWE problem.
[0126] (1) Define the mathematical difficulty of sspRLWE:
[0127] Define the mathematically difficult problem sspRLWE: For a positive integer n, (where n is a power of 2 and q is a prime number), defined in and Polynomial ring of degree n-1 and (When n=1, there is ), computational The mathematical difficulty problem is that given a sample (a, b = ar + e) ∈ R q , solve ve mod 2∈R2, where and are all randomly selected values, v∈R q is a fixed ring element, and represent integers and positive integer sets respectively, χ r , χ e R q The probability distribution on .
[0128] (2) Define message encoding and decoding methods:
[0129] For a positive integer n, (where n is a power of 2 and q is a prime number), let and They are defined in and The polynomial ring of degree n-1 (when n=1, there is and ), It is R q The set of all reversible elements in ;
[0130] make For message space, And satisfy k|n, so that the ring element Then its inverse is make is a positive integer, B η is a central binomial distribution with a positive integer η as parameter.
[0131] 1) Define the predetermined encoding method:
[0132] Msg2noise(M, η; ρ): given a message and integer η as input, randomly selected Set s=(s0,...,s 2kη-2 ) is parsed into (2kη-1) blocks of n / k bits (i.e., for all i∈[2kη-1] there are s i ∈{0, 1} n / k ); then let Calculate and return m=m0+m1x+…+m n-1 x n-1 ∈R q , where for all i∈[k] and j∈[n / k]
[0133] 2) Define the predetermined decoding method:
[0134] Noise2msg(w): Given a ring element w = w0 + w1x + ... + w n-1 x n-1 ∈R q As input, the message M=Poly2msg(w) is calculated and returned.
[0135] (3) Implement encryption and decryption:
[0136] In the above manner, based on the above predetermined encoding method and predetermined decoding method, an improved lattice public key encryption method based on vector decoding is proposed, in which the plaintext is encrypted with the public key to obtain the ciphertext, and the ciphertext is decrypted with the private key to obtain the plaintext.
[0137] For example, the improved lattice public key encryption method based on vector decoding consists of four positive integer parameters n, q, k, 3 Rs qThe probability distribution χ on f , χ g , χ r and 1 ring element To instantiate, including: key generation method PKE.KeyGen(1 κ ), generates a public key pk and a private key sk according to the security parameter κ; the encryption method PKE.Enc(pk, M) encrypts the plaintext M according to the public key pk and outputs the ciphertext c; the decryption method PKE.Dec(sk, c) decrypts the ciphertext c according to the private key sk and outputs the plaintext M.
[0138] 1) Key generation method PKE.KeyGen(1 κ ):
[0139] S1, random selection satisfy in (As above, when the predetermined encoding method is Msg2noise(M, η), according to the initial private key f′ and the inverse ring element v -1 , determine the first target private key f1);
[0140] S2, random selection Calculate h1 = g / f1 (same as above, based on the first target private key f1 and the predetermined private key g, to obtain the first target public key h1);
[0141] S3, output the public-private key pair (pk, sk) = (h1, f1), where (h1, f1)∈R q ×R q .
[0142] 2) Encryption method PKE.Enc(pk, M):
[0143] S1, obtain the predetermined plaintext data M b , where the predetermined plaintext data
[0144] S2, when the predetermined encoding mode is Msg2noise(M,η), m=Msg2noise(M b ,η), and obtain the target coding polynomial m=m0+m1x+…+m n-1 x n-1 ∈R q ;
[0145] S3, determine c1 = h1r + m, randomly select a number (Similar to the above, based on the first target public key h1, random number r and target encoding polynomial m, the first target ciphertext data c1 is obtained);
[0146] S4, output the target decrypted data c1.
[0147] 3) Decryption method PKE.Dec(sk, c):
[0148] S1, obtain the target decrypted data c1∈R q .
[0149] S2, calculate u = f1c1 (same as above, based on the first target ciphertext data c1 and the first target private key f1, determine the target decoding polynomial w);
[0150] S3, calculate M b =Noise2msg(u) (decode the target decoding polynomial w according to the predetermined decoding method as above, use the predetermined decryption method PKE.Dec(sk, c) to obtain the target plaintext data M b );
[0151] S4, output target plaintext data M b .
[0152] (3) Design an efficient key encapsulation mechanism using the public key encryption method.
[0153] The above public key encryption method can be extended to a key encapsulation mechanism based on vector decoding, where the first cryptographic hash function H1 is: {0, 1} * →{0, 1} κ , the second cryptographic hash function H2: {0, 1} l+κ →{0, 1} κ ×{0, 1} κ and the third cryptographic hash function H3: {0, 1} * →{0, 1} κ , the key encapsulation mechanism includes the following sub-methods:
[0154] 1) Key generation method KEM.KeyGen(1 κ ): Input security parameter κ, output public key pk and private key sk;
[0155] 2) Encapsulation method KEM.Encaps(pk) encapsulates a key K with the public key pk and outputs a ciphertext c;
[0156] 3) The decapsulation method KEM.Decaps(sk, c) decapsulates the ciphertext c and obtains the key K according to the private key sk = (sk′, pk, H1(pk), s).
[0157] The following are the three sub-methods:
[0158] 1) Key generation method KEM.kevGen(1 κ ):
[0159] S1, random selection
[0160] S2, execute (h, f): = PKE.KeyGen (1 κ );
[0161] S3, output the public key h = h2 and the private key f = (f, h2H1(h2), s);
[0162] 2) Encapsulation method KEM.Encaps(pk):
[0163] S1, determine the target random data M c ,in, M∈{0,1} l Represents the message space, Indicates that the target random data is 1 bit long;
[0164] S2, determine H1(h2), (similar to the above, determine the term value H1(h) for the second cryptographic hash function H2 based on the second target public key h2 and the first cryptographic hash function H1);
[0165] S3, calculation (Same as above based on item value H1(h) and target random data M c , through the second cryptographic hash function H2, determine the first unknown number and a first offset ρ);
[0166] S4, calculate c2: =PKE.Enc(h2, M c ; ρ), (same as above based on the second target public key h2, target random data M c With the first offset ρ, the second predetermined encryption method PKE.Enc(h2, M c ; ρ), obtain the second target ciphertext data c2);
[0167] S5, calculation (Same as above based on the first unknown and the second target ciphertext data c2, using a third cryptographic hash function H3 to determine the encapsulation key K);
[0168] S6, output the second target ciphertext data c2 and the encapsulated key K.
[0169] 3) Decapsulation method KEM.Decaps(sk, c):
[0170] S1, calculate M d=PKE.Dec(f2, c2), (same as above, based on the second target ciphertext data c2 and the second target private key f2, the predetermined decryption method PKE.Dec(f, c) is used to obtain the target decrypted data M d );
[0171] S2, calculation (Same as above based on item value H1(h) and target decrypted data M d , through the second cryptographic hash function H2, determine the second unknown number and a second offset ρ′);
[0172] S3, calculate c3: =PKE.Enc(h2, M d ; ρ '), (same as above based on the second target public key h2, target decrypted data M d and the second offset ρ′, using the second predetermined encryption method PKE.Enc(h, M; ρ) to obtain a third target ciphertext c3);
[0173] S4, if c3=c2, then output Otherwise, output K:=H3(s, c) (same as above, when the second target ciphertext data c2 is the same as the third target ciphertext data c3, output the encapsulation key K).
[0174] Therefore, it can be seen that key encapsulation and decapsulation can be achieved through (3). The public key encryption method with selected plaintext security and the key encapsulation mechanism with selected ciphertext security proposed in this invention can both be converted into a public key encryption method with selected ciphertext security. In addition, using known general conversion methods, the public key encryption method and key encapsulation mechanism proposed in this invention can both be converted into a key exchange protocol or a key exchange protocol with authentication.
[0175] It should be noted that
[0176] For the above (1), this optional implementation method can select a positive integer n that is a power of 2, a prime number q that satisfies q=1 mod 2n, and a polynomial ring To support NTT operation. You can also choose a ring that supports NTT operation when the positive integer d is an even number. Note that the polynomial rings R, R supported by the above optional implementations q and the ring element v, There are many options for parameters such as , and they are not limited to those given in this specific example.
[0177] In the above lattice public key encryption method based on vector decoding, the present invention provides Gaussian distribution as the noise distribution χ f , χ g , χ r , χ eTo facilitate system implementation, the present invention will use binomial distribution or ternary distribution as the noise distribution in the NTRU problem. Note that the noise distribution χ f , χ g , χ r , χ e The selection is not limited to discrete Gaussian distribution, binomial distribution or ternary distribution, etc. Table 1 is a list of two sets of parameters provided by the present invention. The optional embodiment of the present invention provides the following two sets of parameter selections shown in Table 1 for reference, but is not limited to these two sets of parameter selections.
[0178] [Corrected 30.04.2025 in accordance with Article 91]
[0179] For the above (2), the optional implementation method can also select the positive integer n to be a power of 2, the prime number q satisfies q = 1 mod 2n, and the polynomial ring To support NTT operation. You can also choose a ring that supports NTT operation when the positive integer d is an even number. Note that the polynomial rings R, R supported by the above optional implementations q and the ring element v, There are many options for parameters such as , which are not limited to the ones given in this specific example. Table 2 is a list of two sets of parameters provided by the present invention. The optional embodiment of the present invention provides the two sets of parameter selections shown in Table 2 below for reference, but is not limited to these two sets of parameter selections.
[0180] Table 2
[0181] Table 3 shows the experimental data of the present invention when using the two parameter sets in Table 2. As shown in Table 3, Table 3 provides some experimental data of optional embodiments of the present invention. The experimental platform is a 64-bit CentOS Linux 7.6 system equipped with an Intel Core-i7 4790 chip with a 3.6GHz CPU and 4GB of memory, and the programming language is C.
[0182] [Corrected 30.04.2025 in accordance with Article 91]
[0183] For (3) above, Table 4 shows the experimental data of an optional embodiment of the present invention when using the two parameter sets in Table 1. The experimental platform is a 64-bit CentOS Linux 7.6 system equipped with an Intel Core-i7 4790 chip with a 3.6GHz CPU and 4GB of memory, and the programming language is C.
[0184] Table 4
[0185] Therefore, it can be seen that through the above optional implementation, at least the following beneficial effects can be achieved:
[0186] 1) High security: The present invention is provably secure against chosen ciphertext attacks and can resist attacks from future quantum computers;
[0187] 2) Short public key and ciphertext length: Compared with similar schemes on the lattice, it has shorter public key and ciphertext length;
[0188] 3) High computational efficiency: Provides very fast computational speed for key generation, encryption and decryption, encapsulation and decapsulation sub-methods;
[0189] 4) Low decryption failure rate: The proposed encoding and decoding methods enable the present invention to have a lower decryption failure rate;
[0190] 5) Flexible parameter selection: Supports more flexible and fine-grained parameter selection, making it easier to achieve a balance between security and performance;
[0191] 6) Resistance to multi-target attacks: prevents attackers from recovering the private keys of multiple users at the cost of recovering the private key of one user;
[0192] It should be noted that for the aforementioned method embodiments, for simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should be aware that the present invention is not limited by the order of the actions described, because according to the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present invention.
[0193] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods of various embodiments of the present invention.
[0194] Example 2
[0195] According to an embodiment of the present invention, a device for implementing the above-mentioned lattice public key data encryption method based on vector decoding is also provided. Figure 4 is a structural block diagram of the lattice public key data encryption device based on vector decoding according to an embodiment of the present invention. As shown in Figure 4, the device includes: a first determination module 402, a first encryption module 404 and a sending module 406. The device is described in detail below.
[0196] The first determining module 402 is configured to determine the predetermined plaintext data M a , where the predetermined plaintext data Indicates message space, reserved plaintext data Indicates that the predetermined plaintext data is plaintext data of 1 bit length; a first encryption module 404, connected to the first determination module 402, is configured to adopt a first predetermined encryption method PKE.Enc(h, M), and obtain a first target ciphertext data c1 based on the predetermined plaintext data, the first target public key h1, and the predetermined interference term; a sending module 406, connected to the first encryption module 404, is configured to send the first target ciphertext data c1 to the first terminal,
[0197] The first encryption module 404 includes:
[0198] The encoding module is configured to encode the predetermined plaintext data M according to a predetermined encoding method. a , get the target coding polynomial m, where the number of terms in the target coding polynomial m is based on the predetermined plaintext data M a The predetermined bit length is determined, and the coefficients of each term of the target coding polynomial m are determined according to the plaintext data on the corresponding bit data bits in the predetermined plaintext data; the encryption submodule is connected to the encoding module and is configured to obtain the first target ciphertext data c1 based on the first target public key h1, the predetermined interference term and the target coding polynomial m.
[0199] It should be noted here that the above-mentioned first determination module 402, first encryption module 404 and sending module 406 correspond to steps S102 to S108 in implementing the lattice public key data encryption method based on vector decoding. The instances and application scenarios implemented by multiple modules and corresponding steps are the same, but are not limited to the contents disclosed in the above-mentioned embodiment 1.
[0200] Example 3
[0201] According to an embodiment of the present invention, a device for implementing the above-mentioned lattice public key data decryption method based on vector decoding is also provided. Figure 5 is a structural block diagram of the lattice public key data encryption device based on vector decoding according to an embodiment of the present invention. As shown in Figure 5, the device includes: a receiving module 502 and a decryption module 504. The device is described in detail below.
[0202] The receiving module 502 is configured to receive the first target ciphertext data c1 sent by the second terminal, wherein the first target ciphertext data c1 is obtained by using a first predetermined encryption method PKE.Enc(h, M) based on the first target public key h1, a predetermined interference term and a target encoding polynomial m, wherein the first predetermined encryption method PKE.Enc(h, M) is determined based on a predetermined ring structure, and the target encoding polynomial m encodes the predetermined plaintext data M based on a predetermined encoding method. a The number of terms in the target coding polynomial m is determined by the predetermined plaintext data M. a The coefficients of each item of the target coding polynomial m are determined by the predetermined plaintext data M a In the case of a bit, the plaintext data corresponding to the bit data position is determined, and the predetermined plaintext data Indicates message space, reserved plaintext data Indicates that the target plaintext data is m∈R q bit length of plaintext data;
[0203] The decryption module 504 is connected to the receiving module 502 and is configured to use a predetermined decryption method PKE.Dec(f, c) to obtain the target plaintext data M according to the first target ciphertext data c1 and the first target private key f1. b , wherein the first target private key f1 is determined according to a predetermined encoding method,
[0204] The decryption module 504 includes:
[0205] The second determination module is configured to determine the target decoding polynomial w based on the first target ciphertext data c1 and the first target private key f1; the decoding module is connected to the second determination module and is configured to decode the target decoding polynomial w according to a predetermined decoding method to obtain the target plaintext data M b , wherein the predetermined decoding method corresponds to the predetermined encoding method.
[0206] It should be noted here that the above-mentioned receiving module 502 and decryption module 504 correspond to steps S202 to S206 in implementing the lattice public key data encryption method based on vector decoding. The instances and application scenarios implemented by multiple modules and corresponding steps are the same, but are not limited to the contents disclosed in the above-mentioned embodiment 1.
[0207] Example 4
[0208] According to an embodiment of the present invention, a device for implementing the above-mentioned lattice public key and secret key encapsulation method based on vector decoding is also provided. Figure 6 is a structural block diagram of a lattice public key data encryption device based on vector decoding according to an embodiment of the present invention. As shown in Figure 6, the device includes: a third determination module 602, a fourth determination module 604, a fifth determination module 606, a second encryption module 608 and a sixth determination module 610. The device is described in detail below.
[0209] The third determining module 602 is configured to determine the target random data M c ,in, Represents the message space, Indicates that the target random data is 1 bit long; a fourth determination module 604, connected to the third determination module 602, is configured to determine the term value H1(h) for the second cryptographic hash function H2 based on the second target public key h2 and the first cryptographic hash function H1, wherein the first cryptographic hash function H1: {0, 1} * →{0, 1} κ , used to convert data of any bit length into data of κ bit length, the second cryptographic hash function H2: {0, 1} l+κ →{0, 1} κ ×{0, 1} κ , used to convert data of a specific bit length into two data of κ bit lengths, where the specific bit length is determined based on the data of 1 bit length and the data of κ bit length; a fifth determining module 606, connected to the fourth determining module 604, is configured to determine the data based on the item value H1(h) and the target random data M c , through the second cryptographic hash function H2, determine the first unknown number And the first offset ρ; the second encryption module 608, connected to the fifth determination module 606, is set according to the second target public key h2, the target random data M c and the first offset ρ, and adopt the second predetermined encryption method PKE.Enc(h, M; ρ) to obtain the second target ciphertext data c2; the sixth determination module 610 is connected to the second encryption module 608 and is set to be based on the first unknown number The second target ciphertext data c2 is used to determine the encapsulation key K through the third cryptographic hash function H3, where the third cryptographic hash function H3 is: {0, 1} * →{0, 1} κ , used to convert data of any bit length into data of κ bit length.
[0210] It should be noted here that the above-mentioned third determination module 602, fourth determination module 604, fifth determination module 606, second encryption module 608 and sixth determination module 610 correspond to steps S302 to S310 in implementing the lattice public key data encryption method based on vector decoding. The instances and application scenarios implemented by multiple modules and corresponding steps are the same, but are not limited to the contents disclosed in the above-mentioned embodiment 1.
[0211] Example 5
[0212] According to another aspect of an embodiment of the present invention, an electronic device is also provided, including: a processor; a memory configured to store processor-executable instructions, wherein the processor is configured to execute instructions to implement any of the above-mentioned lattice public key data encryption methods based on vector decoding, any of the above-mentioned lattice public key data decryption methods based on vector decoding, and any of the above-mentioned lattice key encapsulation methods based on vector decoding.
[0213] Example 6
[0214] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is also provided. When the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute any one of the above-mentioned lattice public key data encryption methods based on vector decoding, any one of the above-mentioned lattice public key data decryption methods based on vector decoding, and any one of the above-mentioned lattice key encapsulation methods based on vector decoding.
[0215] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.
[0216] In the above embodiments of the present invention, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0217] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units can be a logical functional division. In actual implementation, there may be other division methods, such as combining or integrating multiple units or components into another system, or ignoring or not implementing some features. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interface, or the indirect coupling or communication connection of units or modules may be electrical or other forms.
[0218] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0219] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0220] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, etc. Various media that can store program codes.
[0221] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention. Industrial Applicability
[0222] The solution provided in the embodiment of the present application can be applied to the field of public key encryption in cryptography. In the embodiment of the present application, according to predetermined plaintext data, a first predetermined encryption method, a first target public key, and a predetermined interference term, a first target ciphertext data is obtained, and lattice public key data encryption can be achieved. According to the first target ciphertext data, a first target private key and a predetermined decryption method, target plaintext data is obtained, and lattice public key data decryption can be achieved. At the same time, the present invention also proposes a variant problem of the ring learning with errors (RLWE), namely the subset-sum parity RLWE problem (Subset-Sum Parity RLWE, sspRLWE), and based on this variant problem, further optimizes the lattice public key data encryption method based on vector decoding in the present invention. The public key encryption method and key encapsulation method designed by the present invention have the characteristics and advantages of provable security, resistance to quantum computer attacks, short public key and ciphertext length, high computational efficiency, low decryption failure rate, and flexible parameter selection.
Claims
1. A lattice public key data encryption method based on vector decoding, comprising: Determine the predetermined plaintext data M a , wherein the predetermined plaintext data The Represents the message space, the predetermined plaintext data Representing the predetermined plaintext data as plaintext data of l-bit length; Using the first predetermined encryption method PKE.Enc(h, M), based on the predetermined plaintext data M a , the first target public key h1, and a predetermined interference term, to obtain the first target ciphertext data c1; Sending the first target ciphertext data c1 to a first terminal, Among them, the first predetermined encryption method PKE.Enc(h, M) is used, and according to the predetermined plaintext data M a , the first target public key h1, and the predetermined interference term, the obtained first target ciphertext data c1 includes: Encode the predetermined plaintext data M according to a predetermined encoding method a , to obtain a target encoding polynomial m, wherein the number of terms of the target encoding polynomial m is determined according to the predetermined bit length of the predetermined plaintext data M a ; and the coefficients of each term of the target encoding polynomial m are determined according to the plaintext data on the corresponding bit data bits in the predetermined plaintext data Obtaining the first target ciphertext data c1 according to the first target public key h1, the predetermined interference term and the target encoding polynomial m.
2. The method according to claim 1, wherein Obtaining the first target ciphertext data c1 according to the first target public key h1, the predetermined interference term and the target encoding polynomial m, comprising: When the predetermined coding method is Msg2poly(M), the target coding polynomial m = M0 + M1x + … + M i x i + … + M l-1 x l-1 , the predetermined interference term includes a random number r, a predetermined noise value e, and the inverse ring element v -1 ; Based on the first target public key h1, the random number r, the predetermined noise value e, and the inverse ring element v -1 and the target encoding polynomial m, the first target ciphertext data c1 is obtained, where M i represents the data of the i-th bit in M a and M i ∈ {0, 1}, the ring element v = (1 - x n / k ), v ∈ R q , and the inverse ring element The is R q the set of all invertible elements on is a predetermined ring structure, representing a polynomial ring of degree n - 1, where n is a power of 2, q is a prime number, k is the largest integer satisfying k|n and n / k≥l, the Denote the set of integers, the Representing the set of positive integers.
3. The method according to claim 1, wherein, Obtaining the first target ciphertext data c1 according to the first target public key h1, the predetermined interference term and the target encoding polynomial m, comprising: When the predetermined coding method is Msg2noise(M, η), the target coding polynomial m = m0 + m1x + … + m n-1 x n-1 , and the predetermined interference term includes a random number r; Obtaining the first target ciphertext data c1 according to the first target public key h1, the random number r and the target encoding polynomial m, wherein η represents the parameter value of the central binomial distribution, and the target encoding polynomial m is a polynomial whose coefficients conform to the central binomial distribution with the parameter value of η; Determine the target encoded polynomial \(m = m_0 + m_1x+\cdots+m\) n-1 x n-1 including: Determine such that for all \(i\in[2k\eta - 1]\), \(s\) i \(\in\{0, 1\}\) n / k , and determine Based on the said s and the said s 2kη-1 , for all i ∈ [k] and j ∈ [n / k], determine According to the said m in / k+j , determine the target encoding polynomial m = m0 + m1x + … + m n-1 x n-1 .
4. The method according to claim 1, wherein Using the first predetermined encryption method PKE.Enc(h, M), based on the predetermined plaintext data M a , before obtaining the first target ciphertext data c1 according to the first target public key h1 and the predetermined interference term, further comprising: When the predetermined coding method is Msg2poly(M), an initial private key f′, a predetermined private key g, and a ring element v are obtained, where the ring element v = (1 - x n / k ); Determining a first target private key f1 according to the initial private key f′ and the ring element v; Obtaining the first target public key h1 according to the first target private key f1 and the predetermined private key g.
5. The method according to claim 1, wherein, Using the first predetermined encryption method PKE.Enc(h, M), based on the predetermined plaintext data M a , before obtaining the first target ciphertext data c1 using the first target public key h1 and a predetermined interference term, further comprising: When the predetermined encoding method is Msg2noise(M, η), obtaining the initial private key f′, predetermined Private key g and inverse ring element v -1 , where the inverse ring element Based on the initial private key f' and the inverse ring element v -1 , determine the first target private key f1; Obtaining the first target public key h1 according to the first target private key f1 and the predetermined private key g.
6. A lattice public key data decryption method based on vector decoding, comprising: Receive the first target ciphertext data c1 sent by the second terminal, where the first target ciphertext data c1 is obtained by using the first predetermined encryption method PKE.Enc(h, M) according to the first target public key h1, the predetermined interference term, and the target encoding polynomial m, and the target encoding polynomial m encodes the predetermined plaintext data M according to the predetermined encoding method a obtained, and the number of terms of the target encoding polynomial m is determined according to the predetermined plaintext data M a The coefficients on each term of the target encoding polynomial m are determined according to the plaintext data on the corresponding bit data bits in the predetermined plaintext data M a In M, the predetermined plaintext data The said Represents the message space, the predetermined plaintext data Representing the target plaintext data as plaintext data of l-bit length; Using the predetermined decryption method PKE.Dec(f, c), based on the first target ciphertext data c1 and the first target private key f1, the target plaintext data M is obtained b , where the first target private key f1 is determined according to the predetermined encoding method; Among them, by using the predetermined decryption method PKE.Dec(f, c), based on the first target ciphertext data c1 and the first target private key f1, the target plaintext data M is obtained b including: Determining a target decoding polynomial w according to the first target ciphertext data c1 and the first target private key f1; Decode the target decoding polynomial w according to a predetermined decoding method to obtain the target plaintext data M b , where the predetermined decoding method corresponds to the predetermined encoding method.
7. The method according to claim 6, wherein, Using the predetermined decryption method PKE.Dec(f, c), based on the first target ciphertext data c1 and the first target private key f1, the target plaintext data M is obtained b Before that, it also includes: When the predetermined encoding method is Msg2poly(M), determining the first target private key f1 according to the initial private key f′ and the ring element v; and / or, When the predetermined encoding method is Msg2noise(M, η), according to the initial private key f′ and the inverse ring Element v -1 , determine the first target private key f1 wherein, the ring element v = (1 - x n / k ), v ∈ R q , and the inverse ring element The above-mentioned is R q the set of all invertible elements on, is a predetermined ring structure, representing a polynomial ring of degree n - 1, where n is a power of 2, q is a prime number, k is the largest integer satisfying k|n and n / k≥l, and the represents a set of integers, the Representing the set of positive integers, and η represents the parameter value of the central binomial distribution.
8. The method according to claim 6, wherein When the predetermined encoding method includes at least one of the following: Msg2poly(M), Msg2noise(M, η), the predetermined decoding method is Poly2msg(w), and the target decoding polynomial w is decoded according to the predetermined decoding method to obtain the target plaintext data M b , including: Input the target decoding polynomial w into the Poly2msg(w), where w = w0 + w1x + … + w n-1 x n-1 , and w ∈ R q ; Determine for all i ∈ [n] Determine, for all j ∈ [l], According to Obtain the target plaintext data M b .
9. A lattice key encapsulation method based on vector decoding, comprising: Determine the target random data M c , wherein the The said Represents the message space, the Representing the target random data as data of l-bit length; Determine the item value H1(h) for the second cryptographic hash function H2 based on the second target public key h2 and the first cryptographic hash function H1, where the first cryptographic hash function H1: {0, 1} * →{0, 1} κ , and is used to convert data of any bit length into data of κ bit length. The second cryptographic hash function H2: {0, 1} l+κ →{0, 1} κ ×{0, 1} κ , and is used to convert data of a specific bit length into two data of κ bit length, where the specific bit length is determined based on data of l bit length and data of κ bit length; Based on the item value H1(h) and the target random data M c , through the second cryptographic hash function H2, determine the first unknown And a first offset ρ; Based on the second target public key h2, the target random data M c and the first offset ρ, use the second predetermined encryption method PKE.Enc(h, M; ρ) to obtain the second target ciphertext data c2; Based on the first unknown and the second target ciphertext data c2, determine the encapsulation key K through a third cryptographic hash function H3, where the third cryptographic hash function H3: {0, 1} * →{0, 1} κ , and is used to convert data of any bit length into data of κ bit length.
10. The method according to claim 9, wherein, Based on the first unknown After determining the encapsulation key K through the third cryptographic hash function H3 according to the second target ciphertext data c2, it further includes: Based on the second target ciphertext data c2 and the second target private key f2, using the predetermined decryption method PKE.Dec(f, c), the target decrypted data M is obtained d ; Based on the item value H1(h) and the target decryption data M d , determine the second unknown through the second cryptographic hash function H2 And a second offset ρ′; Based on the second target public key h2, the target decrypted data M d and the second offset ρ′, using the second predetermined encryption method PKE.Enc(h, M; ρ), obtain the third target ciphertext data c3; When the second target ciphertext data c2 is the same as the third target ciphertext data c3, outputting the encapsulated key K to a third terminal.
11. A lattice public key data encryption device based on vector decoding, characterized in that, Comprising: The first determination module is configured to determine a predetermined plaintext data M a , wherein the predetermined plaintext data The said Represents the message space, the predetermined plaintext data Representing the predetermined plaintext data as plaintext data of l-bit length; A first encryption module, configured to use a first predetermined encryption method PKE.Enc(h, M) to obtain the first target ciphertext data c1 according to the predetermined plaintext data, the first target public key h1, and the predetermined interference term; A sending module, configured to send the first target ciphertext data c1 to a first terminal; Wherein, the first encryption module comprises: Encoding module, configured to encode the predetermined plaintext data M according to a predetermined encoding method a , to obtain a target encoding polynomial m, wherein the number of terms of the target encoding polynomial m depends on the predetermined plaintext data M a of Determining the predetermined bit length, and determining the coefficients on each item of the target encoding polynomial m according to the plaintext data on the corresponding bit data bits in the predetermined plaintext data; An encryption sub-module, configured to obtain the first target ciphertext data c1 based on the first target public key h1, the predetermined interference term, and the target encoding polynomial m.
12. A lattice public key data decryption device based on vector decoding, characterized in that, Comprising: A receiving module, configured to receive first target ciphertext data c1 sent by a second terminal, where the first target ciphertext data c1 is obtained by using a first predetermined encryption method PKE.Enc(h, M) according to a first target public key h1, a predetermined interference term, and a target encoding polynomial m, and the target encoding polynomial m encodes the predetermined plaintext data M according to the predetermined encoding method a obtained, the number of terms of the target encoding polynomial m is determined according to the predetermined plaintext data M a of the predetermined bit length, and the coefficients of each term of the target encoding polynomial m are determined according to the plaintext data on the corresponding bit data bits in the predetermined plaintext data M a Among them, the predetermined plaintext data The Denote the message space, the predetermined plaintext data Indicating that the target plaintext data is plaintext data with a length of l bits; Decryption module, configured to use a predetermined decryption method PKE.Dec(f, c) to obtain target plaintext data M based on the first target ciphertext data c1 and the first target private key f1 b , where the first target private key f1 is determined according to the predetermined encoding method Wherein, the decryption module comprises: A second determination module, configured to determine a target decoding polynomial w based on the first target ciphertext data c1 and the first target private key f1; A decoding module, configured to decode the target decoding polynomial w according to a predetermined decoding method to obtain the target plaintext data M b , where the predetermined decoding method corresponds to the predetermined encoding method.
13. A lattice key encapsulation device based on vector decoding, characterized in that, Comprising: The third determination module is configured to determine the target random data M c , wherein the The Represents the message space, the Indicating that the target random data is data with a length of l bits; A fourth determination module, configured to determine an item value H1(h) for a second cryptographic hash function H2 based on a second target public key h2 and a first cryptographic hash function H1, where the first cryptographic hash function H1: {0, 1} * →{0, 1} κ , and configured to convert data of any bit length into data of κ bit length The second cryptographic hash function H2: {0, 1} l+κ →{0, 1} κ ×{0, 1} κ , which is used to convert data of a specific bit length into two data of length κ, and the specific bit length is determined according to the data of length l bits and the data of length κ bits; A fifth determination module, configured to determine a first unknown number according to the item value H1(h) and the target random data M c , through the second cryptographic hash function H2 And a first offset ρ; The second encryption module is configured to, based on the second target public key h2 and the target random data M c and the first offset ρ, use the second predetermined encryption method PKE.Enc(h, M; ρ) to obtain the second target ciphertext data c2; The sixth determination module is configured to be based on the first unknown and the second target ciphertext data c2, determine the encapsulation key K through a third cryptographic hash function H3, where the third cryptographic hash function H3: {0, 1} * →{0, 1} κ , and is used to convert data of any bit length into data of κ bit length.
14. An electronic device, characterized in that, Comprising: A processor; A memory configured to store executable instructions for the processor; Wherein, the processor is configured to execute the instructions to implement the lattice public key data encryption method based on vector decoding according to any one of claims 1 to 5, the lattice public key data decryption method based on vector decoding according to any one of claims 6 to 8, and the lattice key encapsulation method based on vector decoding according to any one of claims 9 to 10.
15. A computer-readable storage medium, characterized in that, When the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the lattice public key data encryption method based on vector decoding according to any one of claims 1 to 5, the lattice public key data decryption method based on vector decoding according to any one of claims 6 to 8, and the lattice key encapsulation method based on vector decoding according to any one of claims 9 to 10.