Reconfigurable module-lattice post-quantum cryptography processor for key encapsulation mechanism
A reconfigurable module-lattice quantum-resistant cryptographic processor with memory-based NTT and INTT operations addresses high complexity in ML-KEM encryption by enabling efficient key generation, encapsulation, and decapsulation across multiple security levels with reduced resource usage.
Patent Information
- Application Number
- PCT/KR2024/015286
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-30
- Filing Date
- 2024-10-08
- Publication Date
- 2025-11-06
AI Technical Summary
Existing ML-KEM quantum-resistant encryption systems face high computational complexity and resource consumption due to large private and public keys, making them difficult to implement in practical cryptographic systems, especially as security levels increase.
A reconfigurable module-lattice quantum-resistant cryptographic processor using memory-based NTT and INTT operations, with a flexible hardware architecture that supports multiple security levels (1, 3, and 5) and includes modules for key generation, encapsulation, and decapsulation, utilizing high-speed modular reduction methods for efficient operations.
The system achieves low complexity and high-speed processing of key generation, encapsulation, and decapsulation operations using fewer resources, supporting multiple security levels and reducing computational overhead.
Smart Images

Figure KR2024015286_06112025_PF_FP_ABST
Abstract
Description
A reconfigurable module-lattice quantum-resistant cryptographic processor for key encapsulation mechanisms.
[0001] The present invention relates to a reconfigurable module-lattice quantum-resistant cryptographic processor for a key encapsulation mechanism.
[0002] Various cutting-edge technologies, such as the Internet of Things (IoT), artificial intelligence (AI), next-generation communications, and autonomous driving, have brought about changes to our daily lives. As the use of connected devices becomes more prevalent in daily life and corporate environments, sensitive personal and corporate information is often exchanged through online communication. Therefore, ensuring the secure transmission of data is crucial to protecting personal information and preventing unauthorized access.
[0003] Public-key cryptosystems like RSA (Rivest, Sharmir, and Adleman) and ECC (Elliptic Curve Cryptosystem) are currently used to transmit encryption keys for communication. However, these systems are based on mathematically challenging problems like Prime Factorization (PF) and the Discrete Logarithm Problem (DLP). As quantum computers become commercially available, they can be decrypted in polynomial time by quantum algorithms like Shor's Algorithm, necessitating a new cryptosystem.
[0004] As the threat to existing cryptographic systems increases, the need for new encryption algorithms resistant to quantum computer attacks, namely post-quantum cryptography (PQC), is growing. Accordingly, the National Institute of Standards and Technology (NIST) in the United States held a competition on post-quantum cryptography to protect against quantum computer attacks. ML-KEM, a lattice-based post-quantum cryptography, was ultimately selected for the key exchange / encryption field for secret-key cryptography, and standardization is underway.
[0005] ML-KEM is a public-key cryptographic algorithm that generates a secret shared key. It utilizes the Module-LWE (Learning With Error) technique. It consists of a matrix A containing random elements within a polynomial ring, a secret vector value s, and an error value e. By varying the parameter k, it provides various security levels (levels 1, 3, and 5).
[0006] ML-KEM requires a significant amount of computation due to the large private and public keys used. Furthermore, as security levels increase, the amount of computation and resources consumed increases, making implementation difficult. Furthermore, data encryption / decryption requires significant time, making it difficult to use in practical cryptographic systems.
[0007] The technical problem to be achieved by the present invention is to provide an encryption / decryption method and system for ML-KEM quantum-resistant encryption that supports three security levels (levels 1, 3, and 5), has low complexity, and is configurable. In particular, the main controller is used to operate the hardware architecture variably, thereby providing key generation, encapsulation, and decapsulation for various security levels (levels 1, 3, and 5). In addition, in order to use a small amount of resources, the present invention is configured as a reconfigurable memory-based NTT that supports both NTT (Number Theoretic Transform) operations and INTT (Inverse NTT) operations, and applies two high-speed modular reduction methods for repetitive operations and multiplications and additions, thereby aiming to process key generation, encapsulation, and decapsulation operations at high speed.
[0008] In one aspect, the reconfigurable ML-KEM quantum-resistant encryption system using memory-based NTT proposed in the present invention variably selects one security strength from among a plurality of security strengths to reconfigure a plurality of internal sub-modules, reconfigures the execution of the plurality of internal sub-modules to change through a main controller, and variably processes data according to the selected security strength to perform key generation, encapsulation, and decapsulation operations through the reconfigured plurality of internal sub-modules, wherein the plurality of internal sub-modules include: a hash sampler module that generates a pseudo-random number using a public seed input from an arbitrary input or a key decoder and outputs the pseudo-random number through a squeeze function; a binomial sampler module that processes different bits depending on the security level using a sampling method using the principle of binomial distribution, and generates an error using the pseudo-random number input using a subtraction operation; A rejection sampler module that inputs the pseudo-random number using a sampling method utilizing the principle of probability distribution and generates a polynomial matrix and a transpose matrix for public key generation and encryption using an extraction and rejection method for the sampling; a key encoder that performs encoding with a public key and a private key; a key decoder that performs decoding for the public key and the private key; a message encoder that converts an element of a polynomial ring of the received polynomial matrix into a message in units of bytes; a message decoder that converts a mask of a message in units of bytes obtained as a result of the operation into an element of a polynomial ring; a compress module that outputs the input ciphertext in a form for transmission through compression according to a security level;A decompressor for receiving compressed ciphertext, reducing an error rate, and decompressing data according to a security strength suitable for an element of a polynomial ring; an integrated NTT&INTT module for receiving outputs of the binomial sampler and the decompressor and performing NTT and INTT operations; and a point-wise multiplier and adder for performing a bow-tie multiplication operation and an addition for polynomial values using a plurality of multipliers and a plurality of adders.
[0009] The above hash sampler module uses the padding module, F-permutation, and squeeze of the Keccak algorithm, and controls the operation and number of operations according to the state of the rejection sampler module and the binomial sampler module.
[0010] The above rejection sampler module receives the output of the hash sampler module in predetermined bit units and passes two random integers smaller than the modulus value, which is the maximum value of the polynomial coefficient, through it, and the binomial sampler module receives the output of the hash sampler module in predetermined bit units and converts bit masking according to each security strength, generates a secret vector value and an error value using a subtraction operation, and generates a coefficient value according to a central binomial distribution.
[0011] The above integrated NTT & INTT module performs multiple stage processing through multiple PEs (Processing Elements), and the multiple PEs sequentially perform reduction operations after multiplication operations to output the results.
[0012] The above point-wise multiplier and adder are composed of a bow-tie multiplier and adder, and RAM, and perform a variable accumulation operation depending on the matrix size of data according to the security strength.
[0013] The above compressor performs shift, addition, and division operations on the operation results within the encryption process according to the security strength, and compresses and encodes the size of the ciphertext through serialization in predetermined bit units, and the above decompress performs multiplication, addition, and shift operations on the operation results within the decryption process according to the security strength, and decompresses and decodes the data so that it can be operated by changing it into an element of a ring.
[0014] In another aspect, the reconfigurable ML-KEM quantum-resistant encryption method using memory-based NTT proposed in the present invention includes the steps of: variably selecting one security strength among a plurality of security strengths to reconfigure a plurality of internal sub-modules; reconfiguring the execution of the plurality of internal sub-modules to be changed through a main controller; and variably processing data according to the selected security strength to perform key generation, encapsulation, and decapsulation operations through the reconfigured plurality of internal sub-modules.
[0015] According to embodiments of the present invention, the encryption / decryption method and system of ML-KEM quantum-resistant encryption supports three security strengths (levels 1, 3, and 5), has low complexity, and is configurable. In particular, by allowing the hardware architecture to operate variably using the main controller, key generation, encapsulation, and decapsulation for various security levels (levels 1, 3, and 5) are provided, and it is composed of a reconfigurable memory-based NTT that supports both NTT (Number Theoretic Transform) operations and INTT (Inverse NTT) operations, and by applying two modular reduction high-speed operation methods for repetitive operations and multiplications and additions, key generation, encapsulation, and decapsulation operations can be processed at high speed. Additionally, it has the effect of performing variable operations (key generation, encapsulation, and decapsulation) for three security levels using fewer resources. In this case, the use of memory-based reconfigurable NTT&INTT has the advantage of using fewer resources than pipeline-based NTT.
[0016] FIG. 1 is a diagram for explaining the configuration of an ML-KEM quantum-resistant encryption system using a memory-based NTT according to one embodiment of the present invention.
[0017] FIG. 2 is a diagram for explaining a key generation process of an ML-KEM quantum-resistant encryption system using a memory-based NTT according to one embodiment of the present invention.
[0018] FIG. 3 is a diagram for explaining the encapsulation process of an ML-KEM quantum-resistant encryption system using a memory-based NTT according to one embodiment of the present invention.
[0019] FIG. 4 is a diagram for explaining the decapsulation process of an ML-KEM quantum-resistant encryption system using a memory-based NTT according to one embodiment of the present invention.
[0020] FIG. 5 is a diagram for explaining the data flow of a key generation process of a quantum-resistant encryption system using a memory-based NTT according to one embodiment of the present invention.
[0021] FIG. 6 is a diagram for explaining the data flow of the encapsulation process of a quantum-resistant encryption system using a memory-based NTT according to one embodiment of the present invention.
[0022] FIG. 7 is a diagram for explaining the data flow of a decapsulation process of a quantum-resistant encryption system using a memory-based NTT according to one embodiment of the present invention.
[0023] FIG. 8 is a diagram showing the structure of a memory-based integrated NTT & INTT module according to one embodiment of the present invention.
[0024] FIG. 9 is a diagram for explaining the NTT operation and INTT operation of a memory-based NTT processor device according to one embodiment of the present invention.
[0025] FIG. 10 is a diagram showing the structure of a KECCAK device, which is an internal operation module according to one embodiment of the present invention.
[0026] FIG. 11 is a diagram for explaining an ML-KEM quantum-resistant encryption method using a memory-based NTT according to one embodiment of the present invention.
[0027] Hereinafter, embodiments of the present invention will be described in detail with reference to the attached drawings.
[0028] The ML-KEM quantum-resistant encryption system proposed in the present invention is a lattice-based PKE / KEM public-key encryption method. The lattice-based encryption algorithm is an NP-hard encryption algorithm that is difficult to find a specific vector on a lattice existing in an n-dimensional space, and uses the Ring-LWE method. LWE (Learning With Error) is a public-key encryption technique based on the SVP problem in polynomials. It injects small-sized errors during the encryption process, so that even if the same key is repeatedly used, different encrypted values are obtained, and the ciphertext has higher security than the existing one. However, Ring-LWE has high time complexity because it uses a large key and performs a convolution operation, which is a polynomial multiplication.
[0029] (Formula 1-1)
[0030] Ring LWE is a polynomial ring encryption It is performed within. The denominator f(x) is f(x)=x N It has the form of +1, and q is the modulus value, which means the maximum value of the polynomial coefficient, as in (Equation 1-1). The parameter N value is N=2. m It can be expressed in the form of a power of 2, as shown in the following. Ring-LWE, a public key encryption method, consists of a public key used for encryption and a private key used for decryption. Ring-LWE is as in (Equation 1-2) and generates a public key and a private key using a public matrix a, which is a random value, a secret key s, and an error value e with a Gaussian distribution.
[0031] (Formula 1-2)
[0032] Encryption is performed using the generated public and private keys as in (Equation 1-3), and the message m is encrypted using the public key (a, b) to output the ciphertext (c1, c2). At this time, since additional error values e1, e2, and e3 are used during encryption, different values are obtained even if the same public key (a, b), thus ensuring high security.
[0033] , (Formula 1-3)
[0034] Decryption outputs the message m from the ciphertext (c1, c2) using the private key s associated with the public key (a, b) used for encryption. Decryption is as in (Equation 1-4).
[0035] (Formula 1-4)
[0036] In this way, the core operations of Ring-LWE are polynomial multiplication and addition, and polynomial multiplication has high time complexity because it performs convolution operation. To solve this, the NTT algorithm, which applies FFT (Fast Fourier Transform) to the finite ring field for convolution operation, is used. Module-LWE, which is a type of Ring-LWE, is a polynomial ring based on Ring-LWE. is defined as . Therefore, in order to increase the security level, the length N of the polynomial or the size of the modulus q must be changed. This change in the ring of the polynomial requires a change in the configuration of the internal calculation unit, such as the NTT algorithm that performs polynomial multiplication operation or the modular reduction for modulus operation. Consequently, Ring-LWE does not have flexibility for security levels because it requires a change in the internal calculation structure according to the security level. To solve this, Module-LWE is configured as in (Equation 1-5).
[0037] (Formula 1-5)
[0038] Unlike Ring-LWE, Module-LWE consists of k vectors of public keys (a, b), private keys s, and error values e. This method can satisfy various security levels using the same internal operator by adjusting the parameter k, which represents the number of polynomials and the sizes of matrices and vectors, without changing the polynomial ring.
[0039]
[0040] FIG. 1 is a diagram for explaining the configuration of an ML-KEM quantum-resistant encryption system using a memory-based NTT according to one embodiment of the present invention.
[0041] The ML-KEM quantum-resistant encryption system using memory-based NTT according to the present invention performs key generation process, encapsulation process, and decapsulation process using an internal computation module, and also provides different security strengths according to data processing volume.
[0042] A module-LWE processor according to an embodiment of the present invention includes a hash sampler module (110), a binomial sampler module (121), a rejection sampler module (122), a message decoder (131), a message encoder (132), a key decoder (141), a key encoder (142), a decompressor (151), a compressor (152), an integrated NTT&INTT module (160), a point-wise multiplier and adder (170), and an internal operation module (180).
[0043] The hash sampler module (110) according to an embodiment of the present invention is implemented using the f-permutation function of the Keccak algorithm, and generates a pseudo-random number using a public seed received from an arbitrary input or key decoder and outputs it through the squeeze function.
[0044] The rejection sampler (122), which is one of the sampler modules according to an embodiment of the present invention, receives a pseudo-random number as an input through a sampling method using the principle of probability distribution, and uses an extraction and rejection method for the corresponding sampling to generate a polynomial matrix and a transpose matrix for public key generation and encryption.
[0045] The binomial sampler (121), which is one of the sampler modules according to an embodiment of the present invention, is a sampling method that utilizes the principle of binomial distribution, and the bits processed are different depending on the security level, and a pseudo-random number input using a subtraction operation is used to generate an error.
[0046] An encoder (132) according to an embodiment of the present invention converts an element of a received polynomial ring into a message in byte units.
[0047] A decoder (131) according to an embodiment of the present invention converts a mask of a message in byte units obtained as a result of the operation into an element of a polynomial ring.
[0048] The compressor (152) according to an embodiment of the present invention outputs the input ciphertext in a form that is easy to transmit through compression according to the security level.
[0049] The decompressor (151) according to an embodiment of the present invention receives a compressed ciphertext, reduces the error rate, and decompresses the data according to the security strength suitable for the elements of the ring.
[0050] The integrated NTT&INTT module (160) according to an embodiment of the present invention receives the output of the binomial sampler (121) and decompressor (151) and performs NTT and INTT operations.
[0051] A point-wise multiplier and adder (170) according to an embodiment of the present invention performs Bow-tie multiplication operations and additions for polynomial values using five multipliers and four adders.
[0052]
[0053] FIG. 2 is a diagram for explaining a key generation process of an ML-KEM quantum-resistant encryption system using a memory-based NTT according to one embodiment of the present invention.
[0054] According to one embodiment of the present invention, a seed is first input and a random value (ρ, σ) is generated through a hash sampler module. Then, a binomial sampler and a rejection sampler are used to generate a public matrix. And generates a secret vector value s and an error value e. Since a matrix must be generated according to the security level, an iterative operation is performed according to the N value for the security level. s and e generated from the binomial sampler are converted to values in the NTT domain by performing NTT operations in the integrated NTT&INTT module. and and stored in RAM for use in performing the Ring-LWE process later. In the rejection sampler, a public value is generated and the generated value is After storing it in RAM, later and Used together. After and After first performing the multiplication of polynomials for Performs polynomial addition with . When the values required for polynomial multiplication are stored in RAM, the point-wise multiplier module reads the RAM values and performs polynomial multiplication. Afterwards, in the adder module, The result of the operation and the value stored in RAM Used to construct encapsulation key values using values Calculate the value. After that, the random value ρ and The value is encoded to create an encryption key, which is an intermediate key value, and the value is encoded to create a decryption key, which is an intermediate key value. After that, the encapsulation key uses the encryption key and outputs a value that is the sum of the decapsulation decryption encryption key, the encryption key that re-executes the hash sampler module, and the seed value that was initially input.
[0055]
[0056] FIG. 3 is a diagram for explaining the encapsulation process of an ML-KEM quantum-resistant encryption system using a memory-based NTT according to one embodiment of the present invention.
[0057] According to one embodiment of the present invention, first, a random coin value and an encapsulation key are input, and a shared secret key and a random value r required for encryption are obtained through a hash sampler module. The shared secret key is output as is and transmitted to the user, and an encryption operation is performed using the coin value and the r value encapsulation key. Using the encapsulation key, a random value ρ and a key decoder are used to obtain a vector value. After that, the random value ρ and the internal counters i, j are passed through the hash sampler module and the rejection sampler module to obtain the public matrix You get the value. You get it like this is stored in RAM and used for Ring-LWE operation. Then, the r value and e1, e2 values are obtained through the hash sampler module and the binomial sampler with the random value r and the internal counter N. The generated r value is then used to perform the NTT operation of the integrated NTT&INTT module, which is a value in the NTT domain. It is used to get the value of and the value stored in RAM. The point-wise multiplier module performs polynomial multiplication. The result value performed in the point-wise multiplier module is converted to the original domain through the INTT operation in the integrated NTT / INTT module. Afterwards, the modular addition module performs an addition operation with the converted value and the error value e1 to obtain the result value μ of Ring-LWE. The obtained μ value is used as c1 to configure the ciphertext c value through compression and encoding in the compressor module. In order to obtain the remaining value c2 that constitutes the ciphertext c, the input coin goes through a decoding process and decompression process in the message decoding module to obtain the μ value. Afterwards, the point-wise multiplier module performs polynomial multiplication with the initially input value and μ value, and then converts it to the original domain value through the INTT operation in the integrated NTT&INTT module. Afterwards, the modular addition module performs an addition operation with the converted value and the values e2 and μ to obtain the v value. At this time, RAM within the ML-KEM architecture is used to manage input / output data during computation. The obtained v value is used in c2 after undergoing compression and encoding processes in the compression module. The compression module combines c1 and c2 to output the ciphertext c. While the Coins value used is the same, the size of the key used and the size of the output ciphertext vary depending on the security level.
[0058]
[0059] FIG. 4 is a diagram for explaining the decapsulation process of an ML-KEM quantum-resistant encryption system using a memory-based NTT according to one embodiment of the present invention.
[0060] According to one embodiment of the present invention, the input ciphertext c undergoes a decoding process and a decompression process in a decompress module to obtain the u and v values, and the input decapsulation key is decoded through a key decoder module. The u value is obtained by performing the NTT operation in the integrated NTT&INTT module and then in the point-wise multiplication module. Perform a multiplication operation between the value and the polynomial. The generated value and the value v are added (subtracted) by the polynomial in the modular addition module to obtain the value w. The value w thus obtained can then be compressed and encoded in the message encoder module to obtain the coin value, which is the initial message value.
[0061] Using the coin value obtained during the encryption process, a shared secret key and a random value r are obtained from the hash sampler module. The r value and the shared secret key obtained at this time are the same as those obtained during the intermediate encapsulation process. Now, in order to verify that the input ciphertext is correct, the obtained coin value is used as a random message value, a part of the decapsulation key value is used as the ciphertext key value, and the r value is used as the seed value to perform an encryption process. The encryption process is performed in the same manner as described in the encapsulation process, and it is determined whether the ciphertext c' value output during the encryption process is the same as the input c value. If the values are the same, it means that there is no error in the ciphertext modification or the ML-KEM architecture. The size of the decapsulation key used at this time varies depending on the security level.
[0062]
[0063] FIG. 5 is a diagram for explaining the data flow of a key generation process of a quantum-resistant encryption system using a memory-based NTT according to one embodiment of the present invention.
[0064] Referring to Fig. 5, the Hash Sampler module receives a random seed value and generates an intermediate random value, and using the value, the Rejection Sampler generates a transpose matrix A, and the Binomial Sampler generates error values s and e. The error values s and e are converted to the NTT domain through the integrated NTT&INTT module, and then polynomial addition and multiplication are performed using a point-wise multiplier and an adder together with the transpose matrix A. At this time, the operation result value is stored in RAM to perform polynomial multiplication. Thereafter, the generated values are used to generate a byte-unit encapsulation key and a decapsulation key. At this time, the number of times the transpose matrix A and the error values s and e are repeatedly generated is controlled to provide a security level.
[0065]
[0066] FIG. 6 is a diagram for explaining the data flow of the encapsulation process of a quantum-resistant encryption system using a memory-based NTT according to one embodiment of the present invention.
[0067] Referring to Figure 6, this is the process of generating a shared secret key and ciphertext by receiving the coin value and encapsulation key of the message that the user wants to encrypt. The hash sampler module uses the coin value and the encapsulation key generated during the key generation process to generate an intermediate random value r required to generate the shared secret key and ciphertext. Then, encryption is performed using the coin value, the intermediate random value r, and the encapsulation key. The encryption uses the rejection sampler to generate the transpose matrix A, and the binomial sampler to obtain the error values r, e1, and e2. The generated error value R is then converted to the NTT domain through the integrated NTT&INTT module, and this is used to perform polynomial addition and multiplication using a point-wise multiplier and adder. The intermediate operation values generated during this process are stored in RAM to facilitate the polynomial multiplication. The generated ciphertext value and the shared secret key are then output. At this time, the security level is provided by controlling the number of repeated generation of the transpose matrix A and the error values s and e.
[0068]
[0069] FIG. 7 is a diagram for explaining the data flow of a decapsulation process of a quantum-resistant encryption system using a memory-based NTT according to one embodiment of the present invention.
[0070] Referring to Fig. 7, the decompress module receives the ciphertext and the decapsulation key and generates the u and v values. In addition, the decapsulation key value generates the s' value using the Key Decoder module, and then obtains the w value through multiplication and addition operations using the integrated NTT&INTT module and the point-wise multiplier adder module. After that, the w value obtains a random value m through the Message Encoder. The generated m value is used to generate a shared secret key value and a random value r using the Hash Sampler module. After that, the encapsulation process is repeated using the encapsulation key value extracted from the decapsulation key to confirm that the input ciphertext value and the generated shared secret key value are normal. At this time, the integrity of the decapsulation is proven by confirming that the generated ciphertext value and the input ciphertext value are the same.
[0071]
[0072] FIG. 8 is a diagram showing the structure of a memory-based integrated NTT & INTT module according to one embodiment of the present invention.
[0073] Referring to FIG. 7, an operation is performed using a pipeline structure of a 2-parallel structure according to one embodiment of the present invention, and an NTT operation is performed by decomposing a general polynomial ring into two rings of even and odd degrees. The structure is composed of a main controller part that controls memory and stages, a processing element part that performs repetitive operations on stages, a memory read / write part that reads data and writes data to perform repetitive operations, and an output part that processes the final stage and output.
[0074]
[0075] FIG. 9 is a diagram for explaining the NTT operation and INTT operation of a memory-based NTT processor device according to one embodiment of the present invention.
[0076] According to one embodiment of the present invention, the logic used in NTT operation and the logic used in INTT operation are different.
[0077]
[0078] FIG. 10 is a diagram showing the structure of a KECCAK device, which is an internal operation module according to one embodiment of the present invention.
[0079] According to one embodiment of the present invention, a hash sampler module receives a seed value, pads the seed value to 1600 bits in a padding module, and then outputs a hash value through a permutation and squeeze process.
[0080]
[0081] FIG. 11 is a diagram for explaining an ML-KEM quantum-resistant encryption method using a memory-based NTT according to one embodiment of the present invention.
[0082] The ML-KEM quantum-resistant encryption method using memory-based NTT according to an embodiment of the present invention includes a step (1111) of reconfiguring a plurality of internal sub-modules by variably selecting one security strength among a plurality of security strengths, a step (1112) of reconfiguring the execution of the plurality of internal sub-modules to be changed through a main controller, and a step (1120, 1130, and 1140) of variably processing data according to the selected security strength (steps 1, 3, and 5) to perform key generation, encapsulation, and decapsulation operations through the reconfigured plurality of internal sub-modules.
[0083] By determining the security level and operation through the received security strength value (k) and mode value, one of the plurality of security strengths is variably selected to reconfigure the plurality of internal sub-modules (1111). Thereafter, the execution of the plurality of internal sub-modules is changed through the main controller (1112).
[0084] According to an embodiment of the present invention, as the value (k) of the parameter that controls the size of the data matrix increases, the key size used increases, the data processing amount increases, and the security strength increases, and a plurality of security strengths are variably selected by controlling the value of the parameter (k).
[0085] The process of variably processing data (1120, 1130 and 1140) according to the selected security strength (steps 1, 3 and 5) to perform key generation, encapsulation and decapsulation operations through multiple reconfigured internal sub-modules is described in more detail.
[0086] In the security strength (step 1) according to an embodiment of the present invention, an input seed is received (1121), and error and public matrix values are generated through a hash sampler module, a binomial sampler module, and a rejection sampler module (1122). The error value is converted to the NTT domain in the NTT domain (1123), and point-wise multiplication and addition are performed with the error value in the NTT domain and the public matrix (1124). The public key and private key are output using a key encoder (1125).
[0087] In the security strength (step 3) according to an embodiment of the present invention, encoding and decoding are performed after receiving a message and an encryption key (1131). A shared secret key, error, and public matrix values are generated through a hash sampler module, a binomial sampler module, and a rejection sampler module (1132). The error value is converted to the NTT domain in the NTT domain (1133), and point-wise multiplication and addition are performed on the error value and the public matrix in the NTT domain (1134). An INTT operation and addition are performed, and a ciphertext is output using a compressor (1135).
[0088] In the security strength (step 5) according to an embodiment of the present invention, a ciphertext and a decryption key are received and decoding and decompressing are performed (1141). An NTT domain change and point-wise multiplication using NTT are performed (1142), an INTT operation and subtraction are performed, and the message is restored through compression and encoding (1143). A shared secret key, error, and public matrix values are generated through a hash sampler module, a binomial sampler module, and a rejection sampler module (1144). After encryption is performed using the error and public matrix generation values, the ciphertext is compared and the shared secret key is output (1145).
[0089]
[0090] The devices described above may be implemented as hardware components, software components, and / or a combination of hardware components and software components. For example, the devices and components described in the embodiments may be implemented using one or more general-purpose computers or special-purpose computers, such as, for example, a processor, a controller, an arithmetic logic unit (ALU), a digital signal processor, a microcomputer, a field programmable gate array (FPGA), a programmable logic unit (PLU), a microprocessor, or any other device capable of executing instructions and responding to them. The processing device may execute an operating system (OS) and one or more software applications running on the operating system. The processing device may also access, store, manipulate, process, and generate data in response to the execution of the software. For ease of understanding, the processing device is sometimes described as being used alone; however, one of ordinary skill in the art will recognize that the processing device may include multiple processing elements and / or multiple types of processing elements. For example, a processing unit may include multiple processors, or a processor and a controller. Other processing configurations, such as parallel processors, are also possible.
[0091] Software may include a computer program, code, instructions, or a combination of one or more of these, which may configure a processing device to perform a desired operation or may independently or collectively command the processing device. The software and / or data may be embodied in any type of machine, component, physical device, virtual equipment, computer storage medium, or device for interpretation by the processing device or for providing instructions or data to the processing device. The software may also be distributed over networked computer systems and stored or executed in a distributed manner. The software and data may be stored on one or more computer-readable recording media.
[0092] The method according to the embodiment may be implemented in the form of program commands that can be executed through various computer means and recorded on a computer-readable medium. The computer-readable medium may include program commands, data files, data structures, etc., alone or in combination. The program commands recorded on the medium may be those specially designed and configured for the embodiment or may be those known and available to those skilled in the art of computer software. Examples of the computer-readable recording medium include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specially configured to store and execute program commands such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc.
[0093] Although the embodiments described above have been described by way of limited examples and drawings, those skilled in the art will appreciate that various modifications and variations can be made based on the above teachings. For example, appropriate results can still be achieved even if the described techniques are performed in a different order than described, and / or components of the described systems, structures, devices, circuits, etc. are combined or combined in a different manner than described, or are replaced or substituted with other components or equivalents.
[0094] Therefore, other implementations, other embodiments, and equivalents to the claims also fall within the scope of the claims described below.
Claims
1. In a quantum-resistant encryption system including multiple internal sub-modules, The above quantum-resistant encryption system is, A plurality of internal sub-modules are reconfigured by variably selecting one security strength among a plurality of security strengths, and the execution of the plurality of internal sub-modules is changed through a main controller, and data is variably processed according to the selected security strength to perform key generation, encapsulation, and decapsulation operations through the reconfigured plurality of internal sub-modules. The above multiple internal sub-modules are: A hash sampler module that generates a pseudo-random number using a public seed received from a random input or key decoder and outputs it through a squeeze function; A binomial sampler module that processes different bits depending on the security level using a sampling method that utilizes the principle of binomial distribution and generates an error using the pseudo-random number input using a subtraction operation; A rejection sampler module that inputs the pseudo-random number using a sampling method utilizing the principle of probability distribution and generates a polynomial matrix and a transpose matrix for public key generation and encryption using an extraction and rejection method for the sampling; A key encoder that performs encoding with public and private keys; A key decoder that performs decoding on public and private keys; A message encoder that converts elements of a polynomial ring of the received polynomial matrix into a message in byte units; A message decoder that converts the mask of a message in bytes obtained as a result of the operation into an element of a polynomial ring; Compress, which outputs the input ciphertext in a form for transmission through compression according to the security level; Decompressing the data by receiving compressed ciphertext, reducing the error rate, and decompressing the data according to the security strength to fit the elements of the polynomial ring; An integrated NTT&INTT module that receives the output of the above binomial sampler and the above decompressor and performs NTT and INTT operations; and A point-wise multiplier and adder that performs bow-tie multiplication operations and additions on polynomial values using multiple multipliers and multiple adders. A quantum-resistant encryption system comprising:
2. In paragraph 1, The above hash sampler module, It uses the padding module, F-permutation, and squeeze of the Keccak algorithm, and controls the operation and the number of operations according to the state of the rejection sampler module and the binomial sampler module. Quantum-resistant encryption system.
3. In paragraph 1, The above rejection sampler module, The output of the above hash sampler module is input in predetermined bit units and two random integers smaller than the modulus value, which is the maximum value of the polynomial coefficient, are passed through it. The above binomial sampler module, The output of the above hash sampler module is input in predetermined bit units, bit masking is converted according to each security strength, a secret vector value and an error value are generated using a subtraction operation, and a coefficient value is generated according to the central binomial distribution. Quantum-resistant encryption system.
4. In paragraph 1, The above integrated NTT & INTT module, It performs multiple stage processing through multiple PEs (Processing Elements), and the multiple PEs sequentially perform reduction operations after multiplication operations to output. Quantum-resistant encryption system.
5. In paragraph 1, The above point-wise multiplier and adder are, It consists of a bow-tie multiplier, an adder, and RAM. Performs variable accumulation operations depending on the size of the data matrix according to the security strength. Quantum-resistant encryption system.
6. In paragraph 1, The above compressor, The operation results within the encryption process are subjected to shift, addition, and division operations according to the security strength, and the size of the ciphertext is compressed and encoded through serialization into predetermined bit units. The above decompress, Decompress and decode the data so that it can be operated by performing multiplication, addition, and shift operations on the results of operations within the decryption process and changing them into elements of a ring. Quantum-resistant encryption system.
7. A quantum-resistant encryption method of a quantum-resistant encryption system including multiple internal sub-modules, A step of reconfiguring a plurality of internal sub-modules by variably selecting one security strength among a plurality of security strengths; A step of reconfiguring the execution of the plurality of internal sub-modules to be changed through the Main Controller; and A step of variably processing data according to the selected security strength to perform key generation, encapsulation, and decapsulation operations through multiple reconfigured internal sub-modules. A quantum-resistant encryption method comprising:
8. In paragraph 7, The step of reconfiguring multiple internal sub-modules by variably selecting one security strength among the multiple security strengths is as follows: As the value of the parameter (k) that controls the size of the data matrix increases, the key size used increases, the data processing volume increases, and the security strength increases. By adjusting the value of the parameter (k), multiple security strengths can be variably selected. Quantum-resistant encryption method.
9. In paragraph 7, The step of reconfiguring the execution of the plurality of internal sub-modules through the main controller is as follows: Generate a pseudo-random number using a random input or a public seed received from the key decoder through the hash sampler module and output it through the squeeze function; The bits processed are different depending on the security level through a sampling method using the principle of binomial distribution through the Binomial Sampler module, and an error is generated using the pseudo-random number input using a subtraction operation; The pseudo-random number is inputted using a sampling method utilizing the principle of probability distribution through a rejection sampler module, and a polynomial matrix and a transpose matrix for public key generation and encryption are generated using an extraction and rejection method for the sampling; Encoding is performed with public and private keys through a key encoder; Decode the public and private keys using a key decoder; Converting the elements of the polynomial ring of the polynomial matrix received through the message encoder into a message in byte units; Convert the byte-unit message mask obtained as a result of the operation through the Message Decoder into an element of a polynomial ring; The ciphertext received through Compress is output in a form for transmission through compression according to the security level; Receive compressed ciphertext through decompression, reduce error rate, and decompress data according to security strength to fit the elements of a polynomial ring; The output of the above binomial sampler and the above decompressor is input through the integrated NTT&INTT module, and NTT and INTT operations are performed; Point-wise multipliers and adders perform bow-tie multiplication operations and additions on polynomial values using multiple multipliers and multiple adders. Quantum-resistant encryption method.
Citation Information
Patent Citations
Beverage water-proof cup holder
KR1020230042172A
Module-LWE based Crypto-Processor System and Method for Post-Quantum Cryptography
KR102462395B1
Cathode active material for lithium secondary battery and lithium secondary battery including the same
KR102536950B1
KR20220134159A