{"id":219,"date":"2025-07-07T19:11:00","date_gmt":"2025-07-07T11:11:00","guid":{"rendered":"http:\/\/www.triode.cc\/?p=219"},"modified":"2025-09-30T23:56:46","modified_gmt":"2025-09-30T15:56:46","slug":"lwe","status":"publish","type":"post","link":"https:\/\/www.triode.cc\/index.php\/2025\/07\/07\/lwe\/","title":{"rendered":"LWE"},"content":{"rendered":"\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u53c2\u8003\u8d44\u6599\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><a href=\"https:\/\/eprint.iacr.org\/2025\/304\">Lattice-based Cryptography: A survey on the security of the lattice-based NIST finalists<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/link.springer.com\/chapter\/10.1007\/978-3-319-89500-0_47\">An Experimental Study of Kannan\u2019s Embedding Technique for the Search LWE Problem | SpringerLink<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/link.springer.com\/article\/10.1007\/s11432-020-2958-9\">A detailed analysis of primal attack and its variants | Science China Information Sciences<\/a><\/li>\n<\/ol>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">LWE\u4ee5\u53caRLWE<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">LWE<\/h3>\n\n\n\n<p>\u8bbe\\(n,m\\)\u4ee5\u53ca\\(q\\)\u4e3a\u6b63\u6574\u6570\uff08\u5176\u4e2d\\(q\\)\u4e00\u822c\u4e3a\u8d28\u6570\uff09\uff0c\\(\\chi\\)\u4e3a\u4e00\u4e2a\\(\\mathbb{Z}^{m}\\)\u4e0a\u7684\u6982\u7387\u5206\u5e03\uff0c\u5e76\u8bbe\\(\\pmb{s}\\in(\\mathbb{Z}\/q\\mathbb{Z})^n\\)\u662f\u4e00\u6761\u201c\u79d8\u5bc6\u5411\u91cf\u201d\uff0c\u5728\\((\\mathbb{Z}\/q\\mathbb{Z})^{m\\times n}\\)\u4e0a\u5747\u5300\u968f\u673a\u9009\u53d6\u77e9\u9635\\(\\pmb{A}\\)\uff0c\u5e76\u5728\\(\\mathbb{Z}^m\\)\u4e0a\u9009\u53d6\u4e00\u4e2a\u5206\u5e03\u670d\u4ece\\(\\chi\\)\u7684\u5c0f\u5411\u91cf\\(\\pmb{e}\\)\u4f5c\u4e3a\u566a\u58f0\uff0c\u8ba1\u7b97\uff1a<\/p>\n\n\n\n<p>$$<br>\\pmb{b}\\equiv \\pmb{A}\\pmb{s}+\\pmb{e}\\pmod{q}<br>$$<\/p>\n\n\n\n<p>\u5e76\u7ed9\u51fa\\((\\pmb{A},\\pmb{b})\\)\uff0c\u90a3\u4e48\u4e00\u822c\u7684LWE\u95ee\u9898\uff08\u4e00\u822c\u79f0\u4e3a\u641c\u7d22LWE\uff0cSearch-LWE\uff09\u5373\u4e3a\u7ed9\u5b9a\\((\\pmb{A},\\pmb{b})\\)\uff0c\u8fd8\u539f\u51fa\\(\\pmb{s}\\).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u73afLWE\uff08Ring-LWE\uff0cRLWE\uff09<\/h3>\n\n\n\n<p>\u8bbe\\(n\\)\u4e3a\u4e00\u4e2a\u5927\u4e8e\u7b49\u4e8e\\(1\\)\u7684\u6574\u6570\uff0c\\(q\\)\u4e3a\u4e00\u8d28\u6570\uff0c\u5f97\u5230\u5546\u73af\uff1a<\/p>\n\n\n\n<p>$$<br>R=\\frac{\\mathbb{Z}[x]}{(x^n+1)},R_q=\\frac{(\\mathbb{Z}\/q\\mathbb{Z})[x]}{(x^n+1)}<br>$$<\/p>\n\n\n\n<p>\u800c\\(\\chi\\)\u4e3a\\(R\\)\u4e0a\u7684\u4e00\u4e2a\u6982\u7387\u5206\u5e03\uff0c\u9009\u53d6\u968f\u673a\u79d8\u5bc6\u591a\u9879\u5f0f\\(s(x)\\in R_q\\)\u4ee5\u53ca\u968f\u673a\u591a\u9879\u5f0f\\(A(x)\\in R_q\\)\uff0c\u5e76\u5728\\(R_q\\)\u4e0a\u9009\u53d6\u4e00\u4e2a\u5206\u5e03\u670d\u4ece\\(\\chi\\)\u7684\u591a\u9879\u5f0f\\(e\\)\u4f5c\u4e3a\u566a\u58f0\uff0c\u8ba1\u7b97\uff1a<\/p>\n\n\n\n<p>$$<br>b(x)=A(x)s(x)+e(x)<br>$$<\/p>\n\n\n\n<p>\u641c\u7d22RLWE\u95ee\u9898\u5373\u4e3a\u7ed9\u51fa\u82e5\u5e72\u7ec4\\((A_i(x),b_i(x))\\)\uff0c\u5e76\u4ece\u4e2d\u6062\u590d\u51fa\\(s(x)\\).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u901a\u8fc7\u683c\u65b9\u6cd5\u6c42\u89e3LWE\u53ca\u5176\u53d8\u79cd<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">LWE<\/h3>\n\n\n\n<p>\u89c2\u5bdfLWE\u7684\u95ee\u9898\u5f62\u5f0f\uff1a<\/p>\n\n\n\n<p>$$<br>\\pmb{b}\\equiv \\pmb{A}\\pmb{s}+\\pmb{e}\\pmod{q}<br>$$<\/p>\n\n\n\n<p>\u4f5c\u4e3a\u653b\u51fb\u8005\uff0c\u6211\u4eec\u8981\u901a\u8fc7\u5df2\u77e5\u7684\\(\\pmb{A},\\pmb{b}\\)\u6765\u6062\u590d\\(\\pmb{s}\\)\uff0c\u4e14\\(\\pmb{e}\\)\u662f\u4e00\u4e2a\u672a\u77e5\u7684\u5c0f\u5411\u91cf\uff0c\u663e\u7136\u8fd9\u662f\u4e00\u4e2aCVP\u95ee\u9898\uff0c\u9996\u5148\u5c06\u539f\u95ee\u9898\u8f6c\u6362\u4e3a\uff1a<\/p>\n\n\n\n<p>$$<br>\\pmb{b}+q\\pmb{k}=\\pmb{A}\\pmb{s}+\\pmb{e}<br>$$<\/p>\n\n\n\n<p>\u5373\uff1a<\/p>\n\n\n\n<p>$$<br>q\\pmb{k}-\\pmb{A}\\pmb{s}+\\pmb{b}=\\pmb{e}<br>$$<\/p>\n\n\n\n<p>\u663e\u7136\u53ef\u4ee5\u6784\u9020\u51fa\u5982\u4e0b\u683c\u57fa\uff1a<\/p>\n\n\n\n<p>$$<br>\\pmb{B} = \\left(\\begin{matrix}<br>q\\pmb{I}_m&amp;0&amp;0\\\\<br>-\\pmb{A}^T&amp;\\pmb{I}_n&amp;0\\\\<br>\\pmb{b}&amp;0&amp;1<br>\\end{matrix}\\right)<br>$$<\/p>\n\n\n\n<p>\uff08\u5b9e\u9645\u4e0a\u662f\u5229\u7528Kannan\u5d4c\u5165\u6cd5\u6765\u5c06CVP\u8f6c\u6362\u4e3aSVP\u6c42\u89e3\uff09\u3002\u5bf9\u4e0a\u8ff0\u683c\u57fa\u6709\u5982\u4e0b\u5173\u7cfb\uff1a<\/p>\n\n\n\n<p>$$<br>(\\pmb{k}^{T},\\pmb{s}^{T},1)\\pmb{B}=(\\pmb{e}^{T},\\pmb{s}^{T},1)<br>$$<\/p>\n\n\n\n<p>\u901a\u8fc7\u683c\u57fa\u89c4\u7ea6\u7b97\u6cd5\uff08\u5982LLL\uff0cBKZ\u7b49\uff09\u5373\u53ef\u5f97\u5230\u77ed\u5411\u91cf\\((\\pmb{e}^{T},\\pmb{s}^{T},1)\\)\uff0csage\u5b9e\u73b0\u5982\u4e0b\uff1a<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#2e3440ff\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" style=\"color:#d8dee9ff;display:none\" aria-label=\"\u590d\u5236\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>q = ...\n\nL = block_matrix(ZZ, 3, 3, [&#91;q, 0, 0&#93;, &#91;-A.transpose(), 1, 0&#93;, &#91;matrix(b), 0, 1&#93;])\nres = L.LLL()\n\nv = res&#91;0&#93;<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki nord\" style=\"background-color: #2e3440ff\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #D8DEE9FF\">q <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> ...<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">L <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">block_matrix<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">ZZ<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">3<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">3<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">[&#91;<\/span><span style=\"color: #D8DEE9FF\">q<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">&#93;,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #D8DEE9FF\">A<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #88C0D0\">transpose<\/span><span style=\"color: #ECEFF4\">(),<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">1<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">&#93;,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #88C0D0\">matrix<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">b<\/span><span style=\"color: #ECEFF4\">),<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">1<\/span><span style=\"color: #ECEFF4\">&#93;])<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">res <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> L<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #88C0D0\">LLL<\/span><span style=\"color: #ECEFF4\">()<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">v <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> res<\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">&#93;<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p>\u6d4b\u8bd5\u53d1\u73b0\uff0c\\(m\\)\u8d8a\u5927\u8fd9\u79cd\u65b9\u6cd5\u5c31\u8d8a\u5bb9\u6613\u89c4\u7ea6\u51fa\u76ee\u6807\u5411\u91cf\uff0c\u4f46\u662f\u8fd9\u79cd\u7b97\u6cd5\u5b9e\u9645\u6548\u679c\u5e76\u4e0d\u597d\uff0c\u5728\u53c2\u8003\u8d44\u65992\u4e2d\u63d0\u53ca\u4e86\u53e6\u5916\u4e00\u79cd\u901a\u8fc7Kannan\u5d4c\u5165\u6cd5\u6c42\u89e3LWE\u7684\u65b9\u6cd5\uff0c\u8bba\u6587\u4e2d\u63d0\u53ca\u7b97\u6cd5\u5982\u4e0b\uff1a<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a href=\"http:\/\/www.triode.cc\/wp-content\/uploads\/2025\/09\/image-66.png\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.triode.cc\/wp-content\/uploads\/2025\/09\/image-66.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"870\" height=\"454\" data-original=\"http:\/\/www.triode.cc\/wp-content\/uploads\/2025\/09\/image-66.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-220\"  sizes=\"auto, (max-width: 870px) 100vw, 870px\" \/><\/div><\/a><\/figure>\n<\/div>\n\n\n<p>\u5176\u4e2dHNF\u662fHermite Normal Form\uff08\u57c3\u5c14\u7c73\u7279\u6807\u51c6\u578b\uff09\u7684\u7f29\u5199\uff0c\u5728\u4e4b\u524d\u7684\u8ba8\u8bba\u4e2d\u6211\u4eec\u6784\u9020\u51fa\u7684\u683c\u57fa\u5927\u5c0f\u4e3a\\((n+m+1)\\times(n+m+1)\\)\uff0c\u5f53\\(n,m\\)\u90fd\u6bd4\u8f83\u5927\u7684\u65f6\u5019\u5982\u679c\u60f3\u8981\u89c4\u7ea6\u51fa\u76ee\u6807\u5411\u91cf\u662f\u6bd4\u8f83\u56f0\u96be\u7684\uff0c\u5373\u4f7f\u53ef\u4ee5\u89c4\u7ea6\u51fa\u76ee\u6807\u5411\u91cf\u4e5f\u9700\u8981\u6bd4\u8f83\u957f\u65f6\u95f4\uff0c\u5982\u679c\u5229\u7528\u8fd9\u79cd\u7b97\u6cd5\u90a3\u4e48\u5f97\u5230\u7684\u683c\u57fa\u5927\u5c0f\u5c06\u662f\\((m+1)\\times(m+1)\\)\uff0c\u4f1a\u76f8\u5bf9\u8f83\u5bb9\u6613\u89c4\u7ea6\u51fa\u76ee\u6807\u5411\u91cf\uff0c\u8be5\u76ee\u6807\u5411\u91cf\u4f1a\u5305\u542b\u8bef\u5dee\u5411\u91cf\\(\\pmb{e}\\)\uff0c\u8be5\u7b97\u6cd5\u7684sage\u5b9e\u73b0\u5982\u4e0b\uff1a<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#2e3440ff\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" style=\"color:#d8dee9ff;display:none\" aria-label=\"\u590d\u5236\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>m = len(b&#91;0&#93;)\nB = block_matrix(ZZ, 2, 1, [&#91;A.transpose()&#93;, &#91;q&#93;])\nB_HNF = B.hermite_form(include_zero_rows=False)\n\nL = block_matrix(ZZ, 2, 2, [&#91;B_HNF, 0&#93;, &#91;matrix(b), 1&#93;])\n\nres = L.LLL()&#91;0&#93;\n\nif res&#91;-1&#93; == -1:\n    e = -vector(res&#91;:-1&#93;)\nelse:\n    e = vector(res&#91;:-1&#93;)\n\ncvp = vector(b) - e\n\nAA = matrix(Zmod(q), A)\ncvp = vector(Zmod(q), cvp)\n\ns = AA.solve_right(cvp)<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki nord\" style=\"background-color: #2e3440ff\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #D8DEE9FF\">m <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">len<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">b<\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">&#93;)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">B <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">block_matrix<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">ZZ<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">2<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">1<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">[&#91;<\/span><span style=\"color: #D8DEE9FF\">A<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #88C0D0\">transpose<\/span><span style=\"color: #ECEFF4\">()&#93;,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #D8DEE9FF\">q<\/span><span style=\"color: #ECEFF4\">&#93;])<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">B_HNF <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> B<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #88C0D0\">hermite_form<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9\">include_zero_rows<\/span><span style=\"color: #81A1C1\">=False<\/span><span style=\"color: #ECEFF4\">)<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">L <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">block_matrix<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">ZZ<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">2<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">2<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">[&#91;<\/span><span style=\"color: #D8DEE9FF\">B_HNF<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">&#93;,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #88C0D0\">matrix<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">b<\/span><span style=\"color: #ECEFF4\">),<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">1<\/span><span style=\"color: #ECEFF4\">&#93;])<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">res <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> L<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #88C0D0\">LLL<\/span><span style=\"color: #ECEFF4\">()&#91;<\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">&#93;<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #81A1C1\">if<\/span><span style=\"color: #D8DEE9FF\"> res<\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #B48EAD\">1<\/span><span style=\"color: #ECEFF4\">&#93;<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">==<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #B48EAD\">1<\/span><span style=\"color: #ECEFF4\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">    e <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #88C0D0\">vector<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">res<\/span><span style=\"color: #ECEFF4\">&#91;:<\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #B48EAD\">1<\/span><span style=\"color: #ECEFF4\">&#93;)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #81A1C1\">else<\/span><span style=\"color: #ECEFF4\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">    e <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">vector<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">res<\/span><span style=\"color: #ECEFF4\">&#91;:<\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #B48EAD\">1<\/span><span style=\"color: #ECEFF4\">&#93;)<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">cvp <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">vector<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">b<\/span><span style=\"color: #ECEFF4\">)<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #D8DEE9FF\"> e<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">AA <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">matrix<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #88C0D0\">Zmod<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">q<\/span><span style=\"color: #ECEFF4\">),<\/span><span style=\"color: #D8DEE9FF\"> A<\/span><span style=\"color: #ECEFF4\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">cvp <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">vector<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #88C0D0\">Zmod<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">q<\/span><span style=\"color: #ECEFF4\">),<\/span><span style=\"color: #D8DEE9FF\"> cvp<\/span><span style=\"color: #ECEFF4\">)<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">s <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> AA<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #88C0D0\">solve_right<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">cvp<\/span><span style=\"color: #ECEFF4\">)<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p>\u6c42\u89e3\u51fa\u7684<code>s<\/code>\u5373\u4e3a\u6211\u4eec\u6240\u9700\u8981\u7684\u3002\u7ecf\u6d4b\u8bd5\u53d1\u73b0\uff0c\u76f8\u8f83\u4e8e\u4e4b\u524d\u8ba8\u8bba\u5f97\u5230\u7684\u7b97\u6cd5\u8fd9\u79cd\u7b97\u6cd5\u6c42\u89e3LWE\u7684\u6548\u679c\u66f4\u597d.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">RLWE<\/h3>\n\n\n\n<p>\u5728\u901a\u8fc7\u683c\u6765\u6c42\u89e3RLWE\u4e4b\u524d\uff0c\u9700\u8981\u4e86\u89e3\u5546\u73af\u4e2d\u591a\u9879\u5f0f\u4e58\u6cd5\u7684\u77e9\u9635\u8868\u793a\uff08\u4e8b\u5b9e\u4e0a\u5546\u73af\u4e2d\u591a\u9879\u5f0f\u4e58\u6cd5\u7684\u77e9\u9635\u8868\u793a\u5728<a href=\"https:\/\/triodelzx.github.io\/2025\/04\/09\/NTRU\/\">NTRU | Triode Field<\/a>\u4e2d\u6709\u7b80\u5355\u63d0\u53ca\uff0c\u5728\u8fd9\u91cc\u4f5c\u8be6\u7ec6\u8bf4\u660e\uff09\uff1a<\/p>\n\n\n\n<p>\u8bbe\u4e00\u5546\u73af\\(R=\\mathbb{Z}[x]\/f(x)\\)\uff08\u5176\u4e2d\\(f(x)\\)\u4e3a\\(\\mathbb{Z}\\)\u4e2d\u7684\u4e00\u4e2a\u9996\u4e00\\(n\\)\u6b21\u591a\u9879\u5f0f\uff09\uff0c\u8bbe\\(f(x)\\)\u7684\u7cfb\u6570\u5206\u522b\u4e3a\uff1a\\((a_0,a_1,\\cdots,a_{n-1},1)\\)\uff0c\u90a3\u4e48\u5f88\u663e\u7136\u53ef\u4ee5\u77e5\u9053\u5728\u8be5\u5546\u73af\u4e2d\u6709\uff1a<\/p>\n\n\n\n<p>$$<br>x^{n}=-(a_0+a_1x+\\cdots+a_{n-1}x^{n-1})<br>$$<\/p>\n\n\n\n<p>\u90a3\u4e48\u5bf9\u4e8e\u8be5\u5546\u73af\u4e2d\u4efb\u610f\u4e24\u591a\u9879\u5f0f\uff1a<\/p>\n\n\n\n<p>$$<br>\\begin{aligned}<br>g(x)=b_0+b_1x+b_2x^2+\\cdots+b_{n-1}x^{n-1}\\\\<br>h(x)=c_0+c_1x+c_2x^2+\\cdots+c_{n-1}x^{n-1}<br>\\end{aligned}<br>$$<\/p>\n\n\n\n<p>\u8bbe\u5bf9\\(\\mathbb{Z}[x]\\)\u4e2d\u6709\\(g(x)\\cdot h(x)=k_0+k_1x+k_2x^2+\\cdots+k_{2n-2}x^{2n-2}\\)\uff0c\u5219\u6709\u5982\u4e0b\u5173\u7cfb\uff1a<\/p>\n\n\n\n<p>$$<br>k_{i}=\\sum_{s+t=i}b_sc_t<br>$$<\/p>\n\n\n\n<p>\u90a3\u4e48\u53ef\u4ee5\u5f97\u5230\u4e0a\u8ff0\u591a\u9879\u5f0f\u4e58\u6cd5\u7684\u77e9\u9635\u8868\u793a\uff1a<\/p>\n\n\n\n<p>$$<br>(b_0,b_1,b_2,\\cdots,b_{n-1})<br>\\left(\\begin{matrix}<br>c_0&amp;c_1&amp;c_2&amp;\\cdots&amp;c_{n-1}\\\\<br>&amp;c_0&amp;c_1&amp;\\cdots&amp;c_{n-2}&amp;c_{n-1}\\\\<br>&amp;&amp;c_0&amp;\\cdots&amp;c_{n-3}&amp;c_{n-2}&amp;c_{n-1}\\\\<br>&amp;&amp;&amp;\\ddots&amp;\\vdots&amp;\\vdots&amp;\\vdots&amp;\\ddots\\\\<br>&amp;&amp;&amp;&amp;c_{0}&amp;c_1&amp;c_2&amp;\\cdots&amp;c_{n-1}<br>\\end{matrix}\\right)=(k_0,k_1,k_2,\\cdots,k_{2n-2})<br>$$<\/p>\n\n\n\n<p>\u4f46\u662f\u8fd9\u53ea\u662f\u5bf9\u4e00\u822c\u7684\u591a\u9879\u5f0f\u4e58\u6cd5\u751f\u6548\u7684\uff0c\u5bf9\u4e8e\u5546\u73af\\(R\\)\u4e2d\u7684\u591a\u9879\u5f0f\uff0c\u5219\u8fd8\u9700\u8981\u5bf9\\((k_0,k_1,\\cdots,k_{2n-2})\\)\u8fdb\u884c\u8fdb\u4e00\u6b65\u5904\u7406\uff0c\u5df2\u77e5\u5728\\(R\\)\u4e2d\u6709\uff1a<\/p>\n\n\n\n<p>$$<br>x^{n}=-(a_0+a_1x+\\cdots+a_{n-1}x^{n-1})<br>$$<\/p>\n\n\n\n<p>\u6240\u4ee5\u5bf9\\(x^{n+1}\\)\uff0c\u6709\uff1a<\/p>\n\n\n\n<p>$$<br>\\begin{aligned}<br>x^{n+1}&amp;=-(a_0x+a_1x^2+\\cdots+a_{n-2}x^{n-1}+a_{n-1}x^{n})\\\\<br>&amp;=-[a_0x+a_1x^2+\\cdots+a_{n-2}x^{n-1}-a_{n-1}(a_0+a_1x+\\cdots+a_{n-1}x^{n-1})]<br>\\end{aligned}<br>$$<\/p>\n\n\n\n<p>\u5c55\u5f00\u5c31\u53ef\u4ee5\u8ba1\u7b97\u51fa\u5404\u9879\u7cfb\u6570\uff0c\u540c\u7406\uff0c\u6709\uff1a<\/p>\n\n\n\n<p>$$<br>\\begin{aligned}<br>x^{n+2}&amp;=-(a_0x^2+a_1x^3+\\cdots+a_{n-2}x^{n}+a_{n-1}x^{n+1})\\<br>\\end{aligned}<br>$$<\/p>\n\n\n\n<p>\u5c06\u5148\u524d\u6c42\u51fa\u7684\\(x^{n+1}\\)\u4e0e\\(x^n\\)\u4ee3\u8fdb\u53bb\u5373\u53ef\u6c42\u51fa\\(x^{n+2}\\)\uff0c\u4ee5\u6b64\u7c7b\u63a8\u53ef\u4ee5\u6c42\u51fa\\(x^{n+3},x^{n+4},\\cdots,x^{2n-2}\\)\u5728\\(R\\)\u4e2d\u7684\u8868\u793a\uff0c\u8bbe\u5728\\(R\\)\u4e2d\\(g(x)\\cdot h(x)=s_0+s_1x+s_2x^2+\\cdots+s_{n-1}x^{n-1}\\)\uff0c\u6709\u5982\u4e0b\u5173\u7cfb\uff1a<\/p>\n\n\n\n<p>$$<br>(k_0,k_1,k_2,\\cdots,k_{2n-2})<br>\\left(\\begin{matrix}<br>1&amp;&amp;&amp;\\\\<br>&amp;1&amp;&amp;\\\\<br>&amp;&amp;\\ddots\\\\<br>&amp;&amp;&amp;1\\\\<br>t_{n,0}&amp;t_{n,1}&amp;\\cdots&amp;t_{n,n-1}\\\\<br>t_{n+1,0}&amp;t_{n+1,1}&amp;\\cdots&amp;t_{n+1,n-1}\\\\<br>\\vdots&amp;\\vdots&amp;&amp;\\vdots\\\\<br>t_{2n-2,0}&amp;t_{2n-2,1}&amp;\\cdots&amp;t_{2n-2,n-1}<br>\\end{matrix}\\right)=(s_0,s_1,\\cdots,s_{n-1})<br>$$<\/p>\n\n\n\n<p>\u5176\u4e2d\\(t_{n,0}\\)\u5230\\(t_{2n-2,n-1}\\)\u9700\u8981\u901a\u8fc7\u524d\u9762\u6240\u8bf4\u6b65\u9aa4\u8fdb\u884c\u8ba1\u7b97\uff0c\u5177\u4f53\u4ee3\u7801\u5982\u4e0b\uff08\u53c2\u8003\u4e86<a href=\"https:\/\/tangcuxiaojikuai.xyz\/post\/7a9f0ad2.html\">2024-NSSCTF-Round-18-Basic-wp-crypto | \u7cd6\u918b\u5c0f\u9e21\u5757\u7684blog<\/a>\u4e2dNew Year Ring 3\u7684\u4ee3\u7801\uff09\uff1a<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#2e3440ff\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" style=\"color:#d8dee9ff;display:none\" aria-label=\"\u590d\u5236\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>MR = Matrix(ZZ, 2*n-1, n)  \nfor i in range(n):  \n    MR&#91;i, i&#93; = 1\n\nfor i in range(n, 2*n-1):  \n    for j in range(i-n, n):  \n        MR&#91;i, j&#93; = -a&#91;j-(i-n)&#93;  \n\n    tmp = vector(ZZ, n*&#91;0&#93;)  \n    for j in range(i-n):  \n        tmp2 = -a&#91;n-1-j&#93; * vector(ZZ, MR&#91;i-j-1&#93;)  \n        tmp += tmp2  \n    for j in range(n):  \n        MR&#91;i, j&#93; += tmp&#91;j&#93;<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki nord\" style=\"background-color: #2e3440ff\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #D8DEE9FF\">MR <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">Matrix<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">ZZ<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">2<\/span><span style=\"color: #81A1C1\">*<\/span><span style=\"color: #D8DEE9FF\">n<\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #B48EAD\">1<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> n<\/span><span style=\"color: #ECEFF4\">)<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #81A1C1\">for<\/span><span style=\"color: #D8DEE9FF\"> i <\/span><span style=\"color: #81A1C1\">in<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">range<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">n<\/span><span style=\"color: #ECEFF4\">):<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">    MR<\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #D8DEE9FF\">i<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> i<\/span><span style=\"color: #ECEFF4\">&#93;<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">1<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #81A1C1\">for<\/span><span style=\"color: #D8DEE9FF\"> i <\/span><span style=\"color: #81A1C1\">in<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">range<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">n<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">2<\/span><span style=\"color: #81A1C1\">*<\/span><span style=\"color: #D8DEE9FF\">n<\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #B48EAD\">1<\/span><span style=\"color: #ECEFF4\">):<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">    <\/span><span style=\"color: #81A1C1\">for<\/span><span style=\"color: #D8DEE9FF\"> j <\/span><span style=\"color: #81A1C1\">in<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">range<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">i<\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #D8DEE9FF\">n<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> n<\/span><span style=\"color: #ECEFF4\">):<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">        MR<\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #D8DEE9FF\">i<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> j<\/span><span style=\"color: #ECEFF4\">&#93;<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #D8DEE9FF\">a<\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #D8DEE9FF\">j<\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">i<\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #D8DEE9FF\">n<\/span><span style=\"color: #ECEFF4\">)&#93;<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">    tmp <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">vector<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">ZZ<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> n<\/span><span style=\"color: #81A1C1\">*<\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">&#93;)<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">    <\/span><span style=\"color: #81A1C1\">for<\/span><span style=\"color: #D8DEE9FF\"> j <\/span><span style=\"color: #81A1C1\">in<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">range<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">i<\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #D8DEE9FF\">n<\/span><span style=\"color: #ECEFF4\">):<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">        tmp2 <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #D8DEE9FF\">a<\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #D8DEE9FF\">n<\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #B48EAD\">1<\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #D8DEE9FF\">j<\/span><span style=\"color: #ECEFF4\">&#93;<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">*<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">vector<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">ZZ<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> MR<\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #D8DEE9FF\">i<\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #D8DEE9FF\">j<\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #B48EAD\">1<\/span><span style=\"color: #ECEFF4\">&#93;)<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">        tmp <\/span><span style=\"color: #81A1C1\">+=<\/span><span style=\"color: #D8DEE9FF\"> tmp2  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">    <\/span><span style=\"color: #81A1C1\">for<\/span><span style=\"color: #D8DEE9FF\"> j <\/span><span style=\"color: #81A1C1\">in<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">range<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">n<\/span><span style=\"color: #ECEFF4\">):<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">        MR<\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #D8DEE9FF\">i<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> j<\/span><span style=\"color: #ECEFF4\">&#93;<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">+=<\/span><span style=\"color: #D8DEE9FF\"> tmp<\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #D8DEE9FF\">j<\/span><span style=\"color: #ECEFF4\">&#93;<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p>\u83b7\u5f97\u4e24\u77e9\u9635\u4e4b\u540e\u53ea\u9700\u8981\u901a\u8fc7\u5982\u4e0b\u8ba1\u7b97\u5c31\u53ef\u4ee5\u5f97\u5230\u5546\u73af\\(R\\)\u4e2d\u591a\u9879\u5f0f\\(g(x)\\cdot h(x)\\)\u7684\u77e9\u9635\u8868\u793a\uff1a<\/p>\n\n\n\n<p>$$<br>(b_0,b_1,b_2,\\cdots,b_{n-1})\\pmb{M}_L\\pmb{M}_R=(s_0,s_1,\\cdots,s_{n-1})<br>$$<\/p>\n\n\n\n<p>\u5176\u4e2d\uff1a<\/p>\n\n\n\n<p>$$<br>\\begin{aligned}<br>&amp;\\pmb{M}_L=\\left(\\begin{matrix} c_0&amp;c_1&amp;c_2&amp;\\cdots&amp;c_{n-1}\\\\<br>&amp;c_0&amp;c_1&amp;\\cdots&amp;c_{n-2}&amp;c_{n-1}\\\\<br>&amp;&amp;c_0&amp;\\cdots&amp;c_{n-3}&amp;c_{n-2}&amp;c_{n-1}\\\\<br>&amp;&amp;&amp;\\ddots&amp;\\vdots&amp;\\vdots&amp;\\vdots&amp;\\ddots\\\\<br>&amp;&amp;&amp;&amp;c_{0}&amp;c_1&amp;c_2&amp;\\cdots&amp;c_{n-1}<br>\\end{matrix}\\right)\\\\<br>&amp;\\pmb{M}_R=\\left(\\begin{matrix} 1&amp;&amp;&amp;\\\\ <br>&amp;1&amp;&amp;\\\\ <br>&amp;&amp;\\ddots\\\\ <br>&amp;&amp;&amp;1\\\\ <br>t_{n,0}&amp;t_{n,1}&amp;\\cdots&amp;t_{n,n-1}\\\\<br>t_{n+1,0}&amp;t_{n+1,1}&amp;\\cdots&amp;t_{n+1,n-1}\\\\<br>\\vdots&amp;\\vdots&amp;&amp;\\vdots\\\\<br>t_{2n-2,0}&amp;t_{2n-2,1}&amp;\\cdots&amp;t_{2n-2,n-1}<br>\\end{matrix}\\right)<br>\\end{aligned}<br>$$<\/p>\n\n\n\n<p>\u4e8b\u5b9e\u4e0a\u5728sage\u4e2d\u53ef\u4ee5\u901a\u8fc7\u5546\u73af\u591a\u9879\u5f0f\u7684<code>matrix()<\/code>\u65b9\u6cd5\u6765\u83b7\u5f97\u591a\u9879\u5f0f\\(g(x)\\)\u7684\u4e58\u6cd5\u77e9\u9635\\(\\pmb{M}=\\pmb{M}_L\\pmb{M}_R\\)\uff0c\u5728\u83b7\u5f97\u8fd9\u4e2a\u77e9\u9635\u4e4b\u540e\uff0cRLWE\u95ee\u9898\u5c31\u53ef\u4ee5\u8f6c\u6362\u4e3a\u4e00\u822c\u7684LWE\u95ee\u9898\u4e86\uff1a<\/p>\n\n\n\n<p>$$<br>b(x)=A(x)s(x)+e(x)\\Leftrightarrow\\pmb{b}=\\pmb{s}\\pmb{M}+\\pmb{e}<br>$$<\/p>\n\n\n\n<p>\u5176\u4e2d\\(\\pmb{b},\\pmb{s},\\pmb{e}\\)\u5206\u522b\u4e3a\\(b(x),s(x),e(x)\\)\u7684\u7cfb\u6570\uff08\u884c\uff09\u5411\u91cf.<\/p>\n\n\n\n<p>\u4ee5<a href=\"https:\/\/www.nssctf.cn\/problem\/5112\">NSSRound#18 Basic-New Year Ring2 | NSSCTF<\/a>\u4e3a\u4f8b\uff1a<\/p>\n\n\n\n<p>\u52a0\u5bc6\u4ee3\u7801\u5982\u4e0b\uff1a<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#2e3440ff\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" style=\"color:#d8dee9ff;display:none\" aria-label=\"\u590d\u5236\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>from Crypto.Util.number import *  \nfrom random import *  \nfrom secret import flag  \n\np = getPrime(128)  \nn = 64  \nassert len(flag) &lt; n  \n\nPRp.&lt;x> = PolynomialRing(Zmod(p))  \nf = x^n+2*x^3+0*x^2+2*x+4  #welcome to 2024!  \nPR = PRp.quo(f)  \nassert f.is_irreducible()  \n\nA = &#91;randint(0, p) for i in range(n)&#93;  \nE = &#91;randint(-4, 4) for i in range(n)&#93;  \nS = [ord(flag&#91;i&#93;) for i in range(len(flag))]  \n\nB = PR(A)*PR(S)+PR(E)  \nprint(A)  \nprint(B.list())  \nprint(p)  \n\n#&#91;...&#93;  \n#&#91;...&#93;  \n#p = 171384865635734387982308861436753436427<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki nord\" style=\"background-color: #2e3440ff\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #81A1C1\">from<\/span><span style=\"color: #D8DEE9FF\"> Crypto<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #D8DEE9FF\">Util<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #D8DEE9FF\">number <\/span><span style=\"color: #81A1C1\">import<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">*<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #81A1C1\">from<\/span><span style=\"color: #D8DEE9FF\"> random <\/span><span style=\"color: #81A1C1\">import<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">*<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #81A1C1\">from<\/span><span style=\"color: #D8DEE9FF\"> secret <\/span><span style=\"color: #81A1C1\">import<\/span><span style=\"color: #D8DEE9FF\"> flag  <\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">p <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">getPrime<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #B48EAD\">128<\/span><span style=\"color: #ECEFF4\">)<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">n <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">64<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #81A1C1\">assert<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">len<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">flag<\/span><span style=\"color: #ECEFF4\">)<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">&lt;<\/span><span style=\"color: #D8DEE9FF\"> n  <\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">PRp<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #81A1C1\">&lt;<\/span><span style=\"color: #D8DEE9FF\">x<\/span><span style=\"color: #81A1C1\">&gt;<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">PolynomialRing<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #88C0D0\">Zmod<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">p<\/span><span style=\"color: #ECEFF4\">))<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">f <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> x<\/span><span style=\"color: #81A1C1\">^<\/span><span style=\"color: #D8DEE9FF\">n<\/span><span style=\"color: #81A1C1\">+<\/span><span style=\"color: #B48EAD\">2<\/span><span style=\"color: #81A1C1\">*<\/span><span style=\"color: #D8DEE9FF\">x<\/span><span style=\"color: #81A1C1\">^<\/span><span style=\"color: #B48EAD\">3<\/span><span style=\"color: #81A1C1\">+<\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #81A1C1\">*<\/span><span style=\"color: #D8DEE9FF\">x<\/span><span style=\"color: #81A1C1\">^<\/span><span style=\"color: #B48EAD\">2<\/span><span style=\"color: #81A1C1\">+<\/span><span style=\"color: #B48EAD\">2<\/span><span style=\"color: #81A1C1\">*<\/span><span style=\"color: #D8DEE9FF\">x<\/span><span style=\"color: #81A1C1\">+<\/span><span style=\"color: #B48EAD\">4<\/span><span style=\"color: #D8DEE9FF\">  <\/span><span style=\"color: #616E88\">#welcome to 2024!  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">PR <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> PRp<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #88C0D0\">quo<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">f<\/span><span style=\"color: #ECEFF4\">)<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #81A1C1\">assert<\/span><span style=\"color: #D8DEE9FF\"> f<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #88C0D0\">is_irreducible<\/span><span style=\"color: #ECEFF4\">()<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">A <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #88C0D0\">randint<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> p<\/span><span style=\"color: #ECEFF4\">)<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">for<\/span><span style=\"color: #D8DEE9FF\"> i <\/span><span style=\"color: #81A1C1\">in<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">range<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">n<\/span><span style=\"color: #ECEFF4\">)&#93;<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">E <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #88C0D0\">randint<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #81A1C1\">-<\/span><span style=\"color: #B48EAD\">4<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">4<\/span><span style=\"color: #ECEFF4\">)<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">for<\/span><span style=\"color: #D8DEE9FF\"> i <\/span><span style=\"color: #81A1C1\">in<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">range<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">n<\/span><span style=\"color: #ECEFF4\">)&#93;<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">S <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">[<\/span><span style=\"color: #88C0D0\">ord<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">flag<\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #D8DEE9FF\">i<\/span><span style=\"color: #ECEFF4\">&#93;)<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">for<\/span><span style=\"color: #D8DEE9FF\"> i <\/span><span style=\"color: #81A1C1\">in<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">range<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #88C0D0\">len<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">flag<\/span><span style=\"color: #ECEFF4\">))]<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">B <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">PR<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">A<\/span><span style=\"color: #ECEFF4\">)<\/span><span style=\"color: #81A1C1\">*<\/span><span style=\"color: #88C0D0\">PR<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">S<\/span><span style=\"color: #ECEFF4\">)<\/span><span style=\"color: #81A1C1\">+<\/span><span style=\"color: #88C0D0\">PR<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">E<\/span><span style=\"color: #ECEFF4\">)<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #88C0D0\">print<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">A<\/span><span style=\"color: #ECEFF4\">)<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #88C0D0\">print<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">B<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #88C0D0\">list<\/span><span style=\"color: #ECEFF4\">())<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #88C0D0\">print<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">p<\/span><span style=\"color: #ECEFF4\">)<\/span><span style=\"color: #D8DEE9FF\">  <\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #616E88\">#&#91;...&#93;  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #616E88\">#&#91;...&#93;  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #616E88\">#p = 171384865635734387982308861436753436427<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p>\u53ef\u4ee5\u770b\u5230\u8fd9\u5f88\u663e\u7136\u662fRLWE\u95ee\u9898\uff0c\u8fd9\u91cc\u7684\u73af\u662f\uff1a<\/p>\n\n\n\n<p>$$<br>R=\\frac{\\mathbb{Z}_p[x]}{x^{64}+2x^3+2x+4}<br>$$<\/p>\n\n\n\n<p>\u53ef\u4ee5\u901a\u8fc7\u5982\u4e0b\u4ee3\u7801\u6784\u9020\u683c\u5e76\u8fdb\u884c\u89c4\u7ea6\u83b7\u5f97\u76ee\u6807\u5411\u91cf\u5e76\u83b7\u5f97flag\uff1a<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#2e3440ff\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" style=\"color:#d8dee9ff;display:none\" aria-label=\"\u590d\u5236\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>A = &#91;...&#93;\nb = &#91;...&#93;\np = 171384865635734387982308861436753436427\nn = 64\n\nPR.&lt;x> = ZZ[]\nf = x^n + 2*x^3 + 2*x + 4\nR = PR.quotient(f)\n\ng = R(A)\nM = g.matrix()\n\nL = block_matrix(ZZ, 3, 3, [&#91;p, 0, 0&#93;, &#91;M, 1, 0&#93;, &#91;matrix(b), 0, 1&#93;])\nres = L.LLL()\n\nflag = \"\"\nfor i in range(n, 2*n):\n    if res&#91;i, i&#93; != 0:\n        flag += chr(abs(res&#91;0, i&#93;))\n\nprint(flag)<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki nord\" style=\"background-color: #2e3440ff\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #D8DEE9FF\">A <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #D8DEE9FF\">...<\/span><span style=\"color: #ECEFF4\">&#93;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">b <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #D8DEE9FF\">...<\/span><span style=\"color: #ECEFF4\">&#93;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">p <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">171384865635734387982308861436753436427<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">n <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">64<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">PR<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #81A1C1\">&lt;<\/span><span style=\"color: #D8DEE9FF\">x<\/span><span style=\"color: #81A1C1\">&gt;<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> ZZ<\/span><span style=\"color: #ECEFF4\">[]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">f <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> x<\/span><span style=\"color: #81A1C1\">^<\/span><span style=\"color: #D8DEE9FF\">n <\/span><span style=\"color: #81A1C1\">+<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">2<\/span><span style=\"color: #81A1C1\">*<\/span><span style=\"color: #D8DEE9FF\">x<\/span><span style=\"color: #81A1C1\">^<\/span><span style=\"color: #B48EAD\">3<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">+<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">2<\/span><span style=\"color: #81A1C1\">*<\/span><span style=\"color: #D8DEE9FF\">x <\/span><span style=\"color: #81A1C1\">+<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">4<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">R <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> PR<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #88C0D0\">quotient<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">f<\/span><span style=\"color: #ECEFF4\">)<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">g <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">R<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">A<\/span><span style=\"color: #ECEFF4\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">M <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> g<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #88C0D0\">matrix<\/span><span style=\"color: #ECEFF4\">()<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">L <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">block_matrix<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">ZZ<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">3<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">3<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">[&#91;<\/span><span style=\"color: #D8DEE9FF\">p<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">&#93;,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #D8DEE9FF\">M<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">1<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">&#93;,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #88C0D0\">matrix<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">b<\/span><span style=\"color: #ECEFF4\">),<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">1<\/span><span style=\"color: #ECEFF4\">&#93;])<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">res <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> L<\/span><span style=\"color: #ECEFF4\">.<\/span><span style=\"color: #88C0D0\">LLL<\/span><span style=\"color: #ECEFF4\">()<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">flag <\/span><span style=\"color: #81A1C1\">=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #ECEFF4\">&quot;&quot;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #81A1C1\">for<\/span><span style=\"color: #D8DEE9FF\"> i <\/span><span style=\"color: #81A1C1\">in<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">range<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">n<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">2<\/span><span style=\"color: #81A1C1\">*<\/span><span style=\"color: #D8DEE9FF\">n<\/span><span style=\"color: #ECEFF4\">):<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">    <\/span><span style=\"color: #81A1C1\">if<\/span><span style=\"color: #D8DEE9FF\"> res<\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #D8DEE9FF\">i<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> i<\/span><span style=\"color: #ECEFF4\">&#93;<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #81A1C1\">!=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D8DEE9FF\">        flag <\/span><span style=\"color: #81A1C1\">+=<\/span><span style=\"color: #D8DEE9FF\"> <\/span><span style=\"color: #88C0D0\">chr<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #88C0D0\">abs<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">res<\/span><span style=\"color: #ECEFF4\">&#91;<\/span><span style=\"color: #B48EAD\">0<\/span><span style=\"color: #ECEFF4\">,<\/span><span style=\"color: #D8DEE9FF\"> i<\/span><span style=\"color: #ECEFF4\">&#93;))<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #88C0D0\">print<\/span><span style=\"color: #ECEFF4\">(<\/span><span style=\"color: #D8DEE9FF\">flag<\/span><span style=\"color: #ECEFF4\">)<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p>\u6d4b\u8bd5\u53d1\u73b0\u5bf9\u4e8e\u4efb\u610f\u4e00\u4e2a\u65b9\u9635\\(\\pmb{M}&#8217;\\)\uff0c\\(\\left(\\begin{matrix}\\pmb{M}&#8217;\\\\q\\pmb{I}\\end{matrix}\\right)\\)\u7684HNF\uff08\u53bb\u9664\u6240\u67090\u5411\u91cf\uff09\u90fd\u662f\u5355\u4f4d\u77e9\u9635\uff0c\u6240\u4ee5\u5bf9\u4e8e\u4e0a\u8ff0\u77e9\u9635\\(\\pmb{M}\\)\uff0c\u6211\u4eec\u5e76\u4e0d\u80fd\u901a\u8fc7\u6c42\u77e9\u9635\\(\\left(\\begin{matrix}\\pmb{M}\\\\q\\pmb{I}\\end{matrix}\\right)\\)\u7684HNF\u6765\u51cf\u5c0f\u683c\u7684\u89c4\u6a21\uff0c\u6240\u4ee5\u8981\u4f18\u5316\u6c42\u89e3\u6548\u7387\u7684\u8bdd\u53ea\u80fd\u501f\u52a9\u6548\u7387\u66f4\u9ad8\u7684\u89c4\u7ea6\u7b97\u6cd5\uff08\u4f8b\u5982<a href=\"https:\/\/github.com\/keeganryan\/flatter\">flatter<\/a>\uff09\u4e86\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5173\u4e8eLWE\uff0cRLWE\u4ee5\u53ca\u76f8\u5173\u653b\u51fb<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[7,10],"class_list":["post-219","post","type-post","status-publish","format-standard","hentry","category-3","tag-crypto","tag-10"],"_links":{"self":[{"href":"https:\/\/www.triode.cc\/index.php\/wp-json\/wp\/v2\/posts\/219","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.triode.cc\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.triode.cc\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.triode.cc\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.triode.cc\/index.php\/wp-json\/wp\/v2\/comments?post=219"}],"version-history":[{"count":6,"href":"https:\/\/www.triode.cc\/index.php\/wp-json\/wp\/v2\/posts\/219\/revisions"}],"predecessor-version":[{"id":226,"href":"https:\/\/www.triode.cc\/index.php\/wp-json\/wp\/v2\/posts\/219\/revisions\/226"}],"wp:attachment":[{"href":"https:\/\/www.triode.cc\/index.php\/wp-json\/wp\/v2\/media?parent=219"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.triode.cc\/index.php\/wp-json\/wp\/v2\/categories?post=219"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.triode.cc\/index.php\/wp-json\/wp\/v2\/tags?post=219"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}