[论文解读] Improving GGH Public Key Scheme Using Low Density Lattice Codes
本文提出了一种基于格的公钥密码系统,通过利用低密度格码(LDLCs)改进GGH方案,以减小公钥尺寸并降低解密复杂度。通过将LDLC生成矩阵的赫米特标准形(HNF)作为公钥,并利用LDLC的线性复杂度解码特性,该方案实现了更短的密钥和更快的解密速度,同时通过引入方差受Poltyrev极限约束的扰动向量,增强了对已知攻击的抵抗能力。
Goldreich-Goldwasser-Halevi (GGH) public key cryptosystem is an instance of lattice-based cryptosystems whose security is based on the hardness of lattice problems. In fact, GGH cryptosystem is the lattice version of the first code-based cryptosystem, proposed by McEliece. However, it has a number of drawbacks such as; large public key length and low security level. On the other hand, Low Density Lattice Codes (LDLCs) are the practical classes of lattice codes which can achieve capacity on the additive white Gaussian noise (AWGN) channel with low complexity decoding algorithm. This paper introduces a public key cryptosystem based on LDLCs to withdraw the drawbacks of GGH cryptosystem. To reduce the key length, we employ the generator matrix of the used LDLC in Hermite normal form (HNF) as the public key. Also, by exploiting the linear decoding complexity of the used LDLC, the decryption complexity is decreased compared with GGH cryptosystem. These increased efficiencies allow us to use the bigger values of security parameters. Moreover, we exploit the special Gaussian vector whose variance is upper bounded by the Poltyrev limit as the perturbation vector. These techniques can resist the proposed scheme against the most efficient attacks to the GGH-like cryptosystems.
研究动机与目标
- 解决原始GGH公钥密码系统的公钥尺寸过大和安全级别过低的问题。
- 通过利用LDLCs中的高效解码算法,降低GGH中解密的计算复杂度。
- 通过引入方差受Poltyrev极限约束的扰动向量,提升安全性。
- 通过提高密钥尺寸和解密效率,支持使用更大的安全参数。
- 证明LDLCs可作为安全且高效的格基密码学的实用基础。
提出的方法
- 公钥通过LDLC生成矩阵的赫米特标准形(HNF)构建,显著缩短密钥长度。
- 解密利用LDLC固有的线性复杂度解码算法,相比GGH降低了计算成本。
- 选择方差受Poltyrev极限约束的扰动向量,以抵抗对GGH类方案的已知攻击。
- 该方案保留了GGH的格基安全基础,但通过结构化码设计提升了效率。
- LDLCs在AWGN信道上实现逼近容量的性能,支持实际部署。
- 通过确保扰动向量的统计特性与格安全的理论极限一致,进一步增强安全性。
实验结果
研究问题
- RQ1低密度格码(LDLCs)能否有效用于减小GGH密码系统中的公钥尺寸?
- RQ2与原始GGH方案相比,使用LDLCs如何影响解密复杂度?
- RQ3方差受Poltyrev极限约束的扰动向量能否增强对GGH类系统已知攻击的抵抗能力?
- RQ4由于效率提升,该方案在多大程度上可支持使用更大的安全参数?
- RQ5基于HNF的公钥与LDLC解码相结合,是否可行用于构建安全且高效的格基密码系统?
主要发现
- 使用LDLC生成矩阵的赫米特标准形(HNF)显著减小了公钥尺寸,相比原始GGH方案有明显优势。
- 由于采用的LDLC具有线性复杂度解码算法,解密复杂度降低,性能得到提升。
- 方差受Poltyrev极限约束的扰动向量能有效抵抗针对GGH类密码系统的最高效已知攻击。
- 效率的提升使得可使用更大的安全参数,从而增强整体安全性。
- 通过利用LDLC的结构特性,该方案在安全性、密钥尺寸和计算效率之间实现了良好平衡。
- 将LDLCs整合到GGH框架中,可构建出资源需求更低、实用且安全的格基密码系统。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。