WO2019030799A1 - 乱数生成システム、乱数生成方法および乱数生成プログラム - Google Patents

乱数生成システム、乱数生成方法および乱数生成プログラム Download PDF

Info

Publication number
WO2019030799A1
WO2019030799A1 PCT/JP2017/028584 JP2017028584W WO2019030799A1 WO 2019030799 A1 WO2019030799 A1 WO 2019030799A1 JP 2017028584 W JP2017028584 W JP 2017028584W WO 2019030799 A1 WO2019030799 A1 WO 2019030799A1
Authority
WO
WIPO (PCT)
Prior art keywords
random number
probability
discrete
number generation
gaussian distribution
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2017/028584
Other languages
English (en)
French (fr)
Inventor
裕貴 太中
一彦 峯松
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
NEC Corp
Original Assignee
NEC Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by NEC Corp filed Critical NEC Corp
Priority to PCT/JP2017/028584 priority Critical patent/WO2019030799A1/ja
Priority to US16/635,262 priority patent/US11327719B2/en
Priority to JP2019535457A priority patent/JP6870738B2/ja
Publication of WO2019030799A1 publication Critical patent/WO2019030799A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F7/00—Methods or arrangements for processing data by operating upon the order or content of the data handled
    • G06F7/58—Random or pseudo-random number generators

Definitions

  • the present invention relates to a random number generation system, a random number generation method, and a random number generation program, and more particularly, to a random number generation system, a random number generation method, and a random number generation program that are used for lattice encryption and signature and generate a random number according to a discrete Gaussian distribution whose center is not the origin.
  • the random numbers generated in accordance with the above discrete Gaussian distribution are used for encryption using a lattice (hereinafter referred to as lattice encryption) as described in Non-Patent Document 1.
  • Lattice cryptosystems are expected to be used as quantum tolerant cryptosystems.
  • lattice cryptography is a cryptographic system that has been studied as a computationally efficient and highly functional cryptographic scheme.
  • the discrete Gaussian distribution is a probability distribution that can output all integer values.
  • generation of random variables is often streamlined by limiting the range of integer values output by the discrete Gaussian distribution.
  • the range of the output integer is ⁇ k ⁇ Z
  • the integer value u ⁇ Z is a probability ⁇ s (u) It refers to the probability distribution output by.
  • a discrete Gaussian distribution whose center is c and whose variance is s is a probability distribution that outputs an integer value u with a probability s s (u-c).
  • the above content is a definition for discrete Gaussian distribution on a one-dimensional lattice.
  • a definition for discrete Gaussian distribution on an n-dimensional lattice is given.
  • a matrix in which vectors ⁇ b 1 ⁇ ,..., B n ⁇ ⁇ ⁇ R n are arranged horizontally is described as B 1.
  • An n-dimensional lattice ⁇ (B) in which the matrix B is used is defined as follows.
  • a Gaussian function on R n whose center is c ⁇ is defined as follows using the parameter s:
  • the discrete Gaussian distribution on the n-dimensional lattice ⁇ ⁇ is defined as follows.
  • the discrete Gaussian distribution on the n-dimensional lattice is a probability distribution in which the random variable obeys equation (4).
  • the discrete Gaussian distribution on a one-dimensional lattice and the discrete Gaussian distribution on an n-dimensional lattice are also referred to as a one-dimensional discrete Gaussian distribution and an n-dimensional discrete Gaussian distribution, respectively, for the sake of simplicity.
  • the above contents are the definition of one-dimensional discrete Gaussian distribution and the definition of multi-dimensional (n-dimensional) discrete Gaussian distribution. Next, a sampling method for generating random numbers according to each discrete Gaussian distribution will be described.
  • sampling methods which are random number generation methods according to a one-dimensional discrete Gaussian distribution, an accumulation method and a rejection sampling method. It is assumed that a function for determining a one-dimensional discrete Gaussian distribution is ⁇ (x), and an output range of the one-dimensional discrete Gaussian distribution is ⁇ k ⁇ Z
  • FIG. 9 is a block diagram showing a configuration example of a general random number generation system which generates random numbers in accordance with a one-dimensional discrete Gaussian distribution.
  • the random number generation system 910 for generating a random number according to a one-dimensional discrete Gaussian distribution whose center is the origin is configured of a storage unit 911, a searcher 912 and a uniform random number generator 913. .
  • a general random number generation system 910 that generates a random number according to a one-dimensional discrete Gaussian distribution whose origin is at the center with a component as shown in FIG. 9 operates as follows. First, each value of ⁇ (0) / 2, ⁇ (1), ⁇ (2),..., ⁇ (t ⁇ s) is calculated in advance and stored in the storage unit 911. Each vertical line in the storage unit 911 shown in FIG. 9 represents each stored value such as ⁇ (0) / 2, ⁇ (1) and the like.
  • the uniform random number generator 913 outputs a real value x ⁇ [0, 1].
  • the output x ⁇ R is input to the searcher 912.
  • the searcher 912 to which x is input, performs binary search of z ⁇ Z among the values stored in the storage unit 911 satisfying ⁇ (z ⁇ 1) ⁇ x ⁇ (z).
  • the above contents are a method of generating random numbers according to a one-dimensional discrete Gaussian distribution whose center is the origin by the accumulation method.
  • the method of generating random numbers according to the one-dimensional discrete Gaussian distribution whose center is not the origin, for example, the center is a1 uses ⁇ (x) in the method of generating random numbers according to the one-dimensional discrete Gaussian distribution whose center is the origin. May be replaced by ⁇ (x-a).
  • the number of data stored in the storage device is proportional to t ⁇ s.
  • the data stored in the storage device may be ⁇ (0) / 2, ⁇ (1), ⁇ (2),..., ⁇ (t) when a one-dimensional discrete Gaussian distribution whose center is the origin is used. S). Also, when a one-dimensional discrete Gaussian distribution whose center is not the origin but is a is used, ⁇ (0-a) / 2, ⁇ (1-a), ⁇ (2-a),. S -a).
  • the accumulation method has a problem that, when a discrete Gaussian distribution having a large dispersion value s 2 is used, the amount of memory required to store the value of the function increases.
  • the dispersion value s takes a relatively large value in the existing lattice cipher.
  • FIG. 10 is an explanatory drawing showing an example of the amount of memory consumed when the accumulation method is used. As shown in FIG. 10, as the variance value increases, the amount of memory consumed also increases.
  • 2-type / 1 signature means that only 2 types of centers are prepared for one signature generation.
  • Useage shown in FIG. 10 represents an application in which a Gaussian distribution is used in each method.
  • Gaussian distribution is used for "key generation” applications.
  • Gaussian distribution is used for the purpose of "signature generation”. If a Gaussian distribution is used for "signature generation” applications, the Gaussian distribution is used many times.
  • Lattice ciphers such as RSA generally require less computational effort. Therefore, lattice cryptography is expected to be used in devices with small computational resources and storage capacity such as sensor devices and mobile phones.
  • the rejection sampling method is not limited to discrete Gaussian distribution, and is a method used when random numbers according to any discrete probability distribution are generated.
  • Step 1 Generate random number Y according to probability distribution function r (x).
  • Step 2 Generate uniform random numbers U in the interval [0, 1] independently of Y.
  • Non-Patent Document 3 is a method in which the above-mentioned rejection sampling method is applied to the case where the function t (x) is identically 1.
  • FIG. 11 is a block diagram showing another configuration example of a general random number generation system which generates random numbers in accordance with a one-dimensional discrete Gaussian distribution.
  • the random number generation system 920 for generating random numbers according to a one-dimensional discrete Gaussian distribution whose center is the origin is composed of a rejection determination unit 921, a uniform random number generator 922 and an output device 923. There is.
  • a general random number generation system 920 that generates random numbers according to a one-dimensional discrete Gaussian distribution whose origin is at the center with a component as shown in FIG. 11 operates as follows. First, the uniform random number generator 922 generates uniform random numbers u 1 ⁇ Z in the range of ⁇ k ⁇ Z
  • the uniform random number generator 922 generates a real-valued random number u 2 ⁇ R in the range of [0, ⁇ (0)].
  • the uniform random number generator 922 inputs the generated u 1 ⁇ Z and u 2 ⁇ R into the rejection determination unit 921.
  • the rejection determination unit 921 compares ⁇ (u 1 ) with u 2 ⁇ R. If u 2 ⁇ ⁇ (u 1 ) as a result of comparison, the rejection determination unit 921 inputs u 1 ⁇ Z to the output device 923.
  • the output device 923 outputs u 1 ⁇ Z as a random number in accordance with a one-dimensional discrete Gaussian distribution whose center is the origin.
  • the random number generation system 920 returns to the first step and executes the same operation again.
  • the above contents are the generation method of the random number according to the one-dimensional discrete Gaussian distribution whose center is the origin by the rejection sampling method.
  • the generation method of random numbers according to the one-dimensional discrete Gaussian distribution whose center is not the origin, for example, the center a, according to the rejection sampling method is the random number generation method according to the one-dimensional discrete Gaussian distribution whose center is the origin. ) May be replaced by ⁇ (x-a).
  • the rejection sampling method when the condition in the process corresponding to the above (Step 3) is not satisfied, the same process is repeatedly executed again. That is, since the rejection sampling method is required to recalculate the function that determines the discrete Gaussian distribution every time the generated uniform random number is rejected, there is a problem that the calculation efficiency is lowered.
  • the merit of the accumulation method is that the calculation cost is small.
  • the disadvantage of the accumulation method is that the memory cost is large.
  • the merit of the rejection sampling method is that the memory cost is small.
  • the disadvantage of the rejection sampling method is that the computational cost is large.
  • Vector a 1 ⁇ , ⁇ each Gram-Schmidt orthogonalization vectors a 1 ⁇ for a n ⁇ ⁇ , ⁇ , and a vector of a n ⁇ ⁇ , is calculated as follows.
  • FIG. 12 is an explanatory view showing an example of a random number generation algorithm according to the discrete Gaussian distribution on the multidimensional lattice.
  • a random number z i is generated in one process, and c i ⁇ 1 is updated based on the generated z i .
  • the discrete Gaussian distribution is updated based on the updated c i-1 and then the random number z i-1 is generated. That is, random numbers z n ,..., Z 1 are sequentially generated.
  • D Z, c ′ i , ⁇ i in the process of the seventh line of the algorithm shown in FIG. 12 represent a one-dimensional discrete Gaussian distribution whose center is c ′ i and whose dispersion value is ⁇ i . Since c i-1 is updated in each process constituting a loop, generation of random numbers in accordance with one-dimensional discrete Gaussian distribution with different centers is also obtained each time.
  • random numbers according to one-dimensional discrete Gaussian distribution are generated by the number of dimensions of the grid to be output.
  • it is required to store a new numerical value in a storage device each time the center of the one-dimensional discrete Gaussian distribution used for generating random numbers is different.
  • the problem in generating random numbers according to discrete Gaussian distribution on a multidimensional lattice using the rejection sampling method is that the generation speed of random numbers according to one-dimensional discrete Gaussian distribution is slow. The reason is that every time the generated uniform random number is rejected, calculation of a function that determines a discrete Gaussian distribution is required, so that the overall calculation efficiency is reduced.
  • the present invention provides a random number generation system, a random number generation method, and a random number generation program capable of further reducing the memory cost and calculation cost required to generate random numbers according to discrete Gaussian distribution on a multidimensional lattice, which solves the problems described above.
  • the purpose is
  • the random number generation system is a random number generation system that generates a random number according to a first discrete distribution that is a discrete Gaussian distribution on a one-dimensional grid whose center is a positive value, and the random variable is positive in the first discrete distribution.
  • the random number generation method is a random number generation method executed by a random number generation system for generating a random number according to a first discrete distribution which is a discrete Gaussian distribution on a one-dimensional lattice whose center is a positive value.
  • a random number generation program is a computer-implemented random number generation program for generating a random number according to a first discrete distribution which is a discrete Gaussian distribution on a one-dimensional lattice whose center is a positive value.
  • FIG. 1 is an explanatory view showing a one-dimensional discrete Gaussian distribution whose center is the origin and a one-dimensional discrete Gaussian distribution whose center is not the origin. Note that only the positive range of the output range of the one-dimensional discrete Gaussian distribution is shown in FIG. 1 to simplify the description. As shown in FIG. 1, since the one-dimensional discrete Gaussian distribution is a line-symmetrical distribution, it is only necessary to consider only the positive range of the output range.
  • the probability ⁇ (1) in the first section shown in FIG. 1 occupies most of the probability ⁇ (1-a).
  • the probability ⁇ (2) in the second section occupies most of the probability ⁇ (2-a).
  • similar features can be seen in all sections.
  • the random numbers in the first section following the one-dimensional discrete Gaussian distribution whose center is not the origin are considered to be random numbers following the one-dimensional discrete Gaussian distribution whose center is the origin with the probability of ⁇ (1) / ⁇ (1-a) .
  • the above features are used.
  • FIG. 2 is an explanatory view showing an area to which the accumulation method is applied and an area to which the rejection sampling method is applied.
  • the probability P 1 shown in FIG. 2 is the sum of the probability ⁇ (1 ⁇ a),..., The probability ⁇ (t ⁇ s ⁇ a). That is, the probability P 1 is the probability that a random number is output according to a one-dimensional discrete Gaussian distribution whose center is not the origin.
  • the probability p ⁇ 1-dim ⁇ is the sum of the probability ⁇ (1),..., The probability ⁇ (t ⁇ s). That is, the probability p ⁇ 1-dim ⁇ is the probability that a random number is output according to a one-dimensional discrete Gaussian distribution whose center is the origin.
  • the function ⁇ (which determines the one-dimensional discrete Gaussian distribution whose center is the origin This is a cumulative method in which the value of x) is used to generate a random number that follows a one-dimensional discrete Gaussian distribution whose center is not the origin.
  • the probability p ⁇ r j c ⁇ is the probability ⁇ (1-a) - ⁇ (1) ⁇ ,...,
  • the probability ⁇ (t s ⁇ a) ⁇ (t ⁇ s) is the sum of. That is, the probability p ⁇ r j c ⁇ is the probability P that the random number is output according to the one-dimensional discrete Gaussian distribution whose center is not the origin and the probability p ⁇ 1-dim ⁇ that the random number is output according the one-dimensional discrete Gaussian distribution whose center is the origin And the difference.
  • the probability p ⁇ 1-dim ⁇ is sufficiently larger than the probability p ⁇ rjc ⁇ , the probability of random numbers being generated by the rejection sampling method is low. That is, since the chance of random numbers being generated by the rejection sampling method is reduced, the overall computational cost for generating random numbers is reduced.
  • the value of the function .phi. (X) which always determines the one-dimensional discrete Gaussian distribution whose center is the origin is used, so that the value of the function .phi. (X) may be stored in the storage device. That is, the overall memory cost for generating random numbers is also reduced.
  • random numbers according to the one-dimensional discrete Gaussian distribution with the center shifted to the right from the origin are also generated by the same method Be done.
  • the random number generation system of the present embodiment efficiently generates random numbers according to the discrete Gaussian distribution on the multidimensional lattice by virtually converting the center of the discrete Gaussian distribution on the one-dimensional lattice.
  • FIG. 3 is a block diagram showing a configuration example of a first embodiment of a random number generation system according to the present invention.
  • the random number generation system 100 of the present embodiment includes a generation method selection device 110, a rejection sampling device 120, and an accumulation method sampling device 130.
  • FIG. 4 is a block diagram showing an example of the configuration of the generation method selection apparatus 110 according to the first embodiment.
  • the generation method selection apparatus 110 of the present embodiment has a section uniform random number generation unit 111 and a generation method selection unit 112.
  • the section uniform random number generation means 111 has a function of generating a uniform random number r 2 of the section [0, P].
  • the generation method selection unit 112 has a function of selecting the generation method of the random number after comparing the generated uniform random number r 1 with the probability p ⁇ 1-dim ⁇ .
  • the generation method selection unit 112 selects the accumulation method as the generation method of the random number when the uniform random number r is less than or equal to the probability p ⁇ 1-dim ⁇ . After the selection, the generation method selection means 112 instructs the cumulative sampling device 130 to generate a random number.
  • the generation method selection unit 112 selects the rejection sampling method as the random number generation method. After the selection, the generation method selection means 112 instructs the rejection sampling device 120 to generate a random number.
  • FIG. 5 is a block diagram showing an example of the configuration of the rejection sampling device 120 according to the first embodiment.
  • the rejection sampling device 120 of the present embodiment includes uniform random number generation means 121 and rejection determination means 122.
  • the function of the uniform random number generation unit 121 is the same as the function of the uniform random number generator 922. That is, the uniform random number generation means 121 generates uniform random numbers u 1 ⁇ Z in the range of ⁇ k ⁇ Z
  • the uniform random number generation unit 121 generates a real-valued random number u 2 ⁇ R in the range of [0, ⁇ ( ⁇ a)].
  • the uniform random number generation means 121 inputs the generated u 1 ⁇ Z and u 2 ⁇ R into the rejection determination means 122.
  • the function possessed by the rejection determination means 122 is the same as the function possessed by the rejection decision unit 921 and the function possessed by the output device 923. That is, the rejection determination means 122 compares ⁇ (u 1 -a) with u 2 ⁇ R. If u 2 ⁇ ⁇ (u 1 ⁇ a) as a result of comparison, the rejection determination means 122 outputs u 1 ⁇ Z as a random number conforming to a one-dimensional discrete Gaussian distribution whose center is not the origin.
  • the rejection determination means 122 returns to the first step and executes the same operation again.
  • FIG. 6 is a block diagram showing a configuration example of the cumulative sampling system 130 according to the first embodiment.
  • the cumulative method sampling device 130 according to the present embodiment includes uniform random number generation means 131, search means 132, storage means 133, and output means 134.
  • the function of the uniform random number generation unit 131 is the same as the function of the uniform random number generator 913. That is, the uniform random number generation means 131 outputs the real value x ⁇ [0, 1].
  • the function possessed by the search means 132 is the same as the function possessed by the searcher 912. That is, the search means 132 performs binary search for z ⁇ Z satisfying ⁇ (z ⁇ a ⁇ 1) ⁇ x ⁇ (z ⁇ a) from among the values stored in the storage means 133.
  • the function of the storage unit 133 is the same as the function of the storage device 911. That is, the storage means 133 stores the values of ⁇ (0-a) / 2, ⁇ (1-a), ⁇ (2-a),..., ⁇ (t ⁇ s-a).
  • the output unit 134 has a function of outputting the random number searched by the search unit 132 as a random number conforming to a one-dimensional discrete Gaussian distribution whose center is not the origin.
  • the random number generation system 100 has a memory cost for generating random numbers in accordance with a one-dimensional discrete Gaussian distribution by the accumulation method, and a calculation cost close to the calculation cost when each sampling process is performed by the accumulation method. It can generate random numbers according to discrete Gaussian distribution on multidimensional lattice.
  • FIG. 7 is a flowchart showing the operation of random number generation processing by the random number generation system 100 of the first embodiment.
  • the section uniform random number generation unit 111 generates a uniform random number r 1 of the section [0, P] (step S101).
  • the section uniform random number generation unit 111 inputs the generated uniform random number r 1 to the generation method selection unit 112.
  • the generation method selection unit 112 determines whether the input uniform random number r 1 is larger than the probability p ⁇ 1-dim ⁇ (step S102).
  • the generation method selection unit 112 selects a rejection sampling method as a method of sampling processing of random numbers (step S103). Next, the generation method selection means 112 instructs the rejection sampling device 120 to generate a random number.
  • the rejection sampling device 120 instructed to generate random numbers generates a random number according to the one-dimensional discrete Gaussian distribution whose center is not the origin by the rejection sampling method (step S104). After the generation, the rejection sampling device 120 outputs the generated random number (step S105). After the output, the random number generation system 100 ends the random number generation process.
  • the generation method selection means 112 selects the accumulation method as the method of sampling processing of random numbers (step S106). Next, the generation method selection means 112 instructs the cumulative sampling device 130 to generate a random number.
  • the accumulation method sampling device 130 instructed to generate the random numbers generates the random numbers according to the one-dimensional discrete Gaussian distribution whose center is not the origin in the accumulation method (step S107).
  • the cumulative sampling device 130 generates random numbers by a cumulative method in which the value of a function that defines a one-dimensional discrete Gaussian distribution whose center is the origin is used.
  • the accumulation method sampling device 130 outputs the generated random number (step S108). After the output, the random number generation system 100 ends the random number generation process.
  • the random number generation system 100 executes the random number generation process shown in FIG. 7 n times.
  • the generation method selection means 112 Since the value of the probability p ⁇ 1-dim ⁇ is sufficiently large compared to the value of the probability p ⁇ rjc ⁇ , the generation method selection means 112 almost always has the value of the function that determines the one-dimensional discrete Gaussian distribution whose center is the origin.
  • the accumulation method to be used is selected as the random number generation method. That is, when the random number generation system 100 of the present embodiment is used, the sampling process executed each time when the random number according to the discrete Gaussian distribution on the multidimensional lattice is generated is the sampling process by the accumulation method with almost probability. Become.
  • the memory cost required for the whole random number generation process by the random number generation system 100 is reduced to the same value as the memory cost required for generating the random number according to the one-dimensional discrete Gaussian distribution whose center is the origin by the accumulation method. .
  • the calculation cost required for the whole random number generation process by the random number generation system 100 is reduced to a value close to the calculation cost required for the sampling process performed each time by the accumulation method.
  • the random number generation system 100 may be, for example, a processor such as a central processing unit (CPU (Central Processing Unit)) that executes processing according to a program stored in a non-temporary storage medium, or a data processing apparatus It may be realized by That is, the section uniform random number generation unit 111, the generation method selection unit 112, the uniform random number generation unit 121, the rejection determination unit 122, the uniform random number generation unit 131, the search unit 132, and the output unit 134 It may be realized by a CPU that executes processing.
  • CPU Central Processing Unit
  • the storage unit 133 may be realized by, for example, a random access memory (RAM).
  • RAM random access memory
  • each unit in the random number generation system 100 of the present embodiment may be realized by a hardware circuit.
  • the section uniform random number generation unit 111, the generation method selection unit 112, the uniform random number generation unit 121, the rejection determination unit 122, the uniform random number generation unit 131, the search unit 132, the storage unit 133, and the output unit 134 Each is realized by LSI (Large Scale Integration). Also, they may be realized by one LSI.
  • FIG. 8 is a block diagram showing an outline of a random number generation system according to the present invention.
  • the random number generation system 10 according to the present invention is a random number generation system that generates a random number according to a first discrete distribution which is a discrete Gaussian distribution on a one-dimensional lattice whose center is a positive value, and random variables are random in the first discrete distribution.
  • Generation means 11 for generating uniform random numbers between the first probability, which is the probability of becoming a value in a predetermined section in the positive range, and 0, and the center is the origin
  • the second discrete distribution that is a discrete Gaussian distribution on a one-dimensional grid
  • Selection means 12 for example, generation method selection means which selects the cumulative sampling method in which the value of the function that determines the distribution is used and selects the rejection sampling method as the random number generation method when uniform random numbers larger than the second probability are generated 112) Including the.
  • the random number generation system can further reduce the memory cost and calculation cost for generating random numbers following discrete Gaussian distribution on a multidimensional lattice.
  • the random number generation system 10 is an accumulation method in which the value of the function that determines the second discrete distribution is used to generate accumulation method generation means (for example, the accumulation method sampling device 130) that generates random numbers according to the discrete Gaussian distribution on a one-dimensional grid.
  • the selection unit 12 may instruct the accumulation method generation unit to generate a random number after the accumulation method is selected, and the accumulation method generation unit may generate a random number in response to the instruction.
  • the accumulation method generation means may have a storage means (for example, storage means 133) in which the value of the function that determines the second discrete distribution is stored.
  • the random number generation system can generate random numbers according to a discrete Gaussian distribution on a one-dimensional lattice whose center is not the origin in the accumulation method.
  • the random number generation system 10 includes a rejection sampling method generation means (for example, rejection sampling device 120) for generating random numbers according to discrete Gaussian distribution on a one-dimensional lattice by a rejection sampling method, and the selection means 12 is a rejection sampling method After being selected, the rejection sampling method generation means may be instructed to generate a random number, and the rejection sampling method generation means may generate a random number in response to the instruction.
  • rejection sampling method generation means for example, rejection sampling device 120 for generating random numbers according to discrete Gaussian distribution on a one-dimensional lattice by a rejection sampling method
  • the selection means 12 is a rejection sampling method After being selected, the rejection sampling method generation means may be instructed to generate a random number, and the rejection sampling method generation means may generate a random number in response to the instruction.
  • the random number generation system can generate random numbers according to the discrete Gaussian distribution on the one-dimensional lattice whose center is not the origin by the rejection sampling method.
  • a random number generation system for generating a random number according to a third discrete distribution which is a discrete Gaussian distribution on a one-dimensional lattice whose center is a negative value, wherein the random variable is in the negative range in the third discrete distribution.
  • a random number generation system including selection means for selecting and selecting a rejection sampling method as the random number generation method when uniform random numbers larger than the fourth probability are selected and selected.
  • Cumulative method in which the value of a function that determines the fourth discrete distribution is used includes cumulative method generation means for generating random numbers according to discrete Gaussian distribution on a one-dimensional grid, and the selection means is selected after the cumulative method is selected
  • the random number generation system according to appendix 1 wherein the accumulation method generation means instructs the generation of a random number, and the accumulation method generation means receives the instruction and generates a random number.
  • the rejection sampling method includes a rejection sampling method generation means for generating random numbers according to discrete Gaussian distribution on a one-dimensional lattice by the rejection sampling method, and the selection means selects random numbers for the rejection sampling method generation means after the rejection sampling method is selected.
  • the random number generation system according to any one of appendices 1 to 3, which instructs generation, and the reject sampling method generation means generates an random number upon reception of the instruction.
  • a random number generation method performed by a random number generation system for generating a random number according to a third discrete distribution that is a discrete Gaussian distribution on a one-dimensional lattice whose center is a negative value, in the third discrete distribution A discrete Gaussian distribution on the one-dimensional lattice, generating a uniform random number between a third probability, which is a probability that the random variable will be a value in a predetermined range in a negative range, and 0, and having a center at the origin
  • the value of the function that determines the fourth discrete distribution is used as the random number generation method
  • a random sampling method is selected, and when a uniform random number larger than the fourth probability is generated, a rejection sampling method is selected as the random number generation method.
  • a random number generation program executed by a computer that generates a random number according to a third discrete distribution that is a discrete Gaussian distribution on a one-dimensional lattice whose center is a negative value, wherein the third discrete Generation processing for generating uniform random numbers between a third probability and 0, which is a probability that the random variable is a value within a predetermined range in a negative range in the distribution, discrete Gaussian on the one-dimensional lattice whose center is the origin
  • a function that determines the fourth discrete distribution in the random number generation method when a uniform random number equal to or less than the fourth probability is generated in the fourth discrete distribution that is a probability that the random variable is a value within the predetermined section
  • a third selection process to select the accumulation method in which the value of the second is used, and a fourth selection process to select the rejection sampling method as the random number generation method when a uniform random number larger than the fourth probability is generated. Because of the random number generator program.

Landscapes

  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computational Mathematics (AREA)
  • Mathematical Analysis (AREA)
  • Mathematical Optimization (AREA)
  • Pure & Applied Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • Complex Calculations (AREA)

Abstract

乱数生成システム10は、中心が正の値である1次元格子上の離散ガウス分布である第1離散分布に従う乱数を生成する乱数生成システムであって、第1離散分布において確率変数が正の範囲における所定の区間内の値になる確率である第1確率と0の間の一様乱数を生成する生成手段11と、中心が原点である1次元格子上の離散ガウス分布である第2離散分布において確率変数が所定の区間内の値になる確率である第2確率以下の一様乱数が生成されると乱数の生成方法に第2離散分布を定める函数の値が用いられる累積法を選択し、第2確率よりも大きい一様乱数が生成されると乱数の生成方法に棄却サンプリング法を選択する選択手段12とを含む。

Description

乱数生成システム、乱数生成方法および乱数生成プログラム
 本発明は、乱数生成システム、乱数生成方法および乱数生成プログラムに関し、特に格子暗号および署名に用いられ中心が原点でない離散ガウス分布に従う乱数を生成する乱数生成システム、乱数生成方法および乱数生成プログラムに関する。
 最初に、離散ガウス分布を定義する。実数s ∈R (R は実数全体の集合を表す記号)で定まる函数を、以下のように定義する。
Figure JPOXMLDOC01-appb-M000001
 整数値u ∈Z (Z は整数全体の集合を表す記号)が確率φs(u)/ Σ∞ j=-∞ φs(j)で出力された分布を、分散値がs である離散ガウス分布と呼ぶ。上記の離散ガウス分布に従って生成された乱数は、非特許文献1に記載されているように、格子が用いられた暗号(以下、格子暗号という。)に使用される。格子暗号は、耐量子暗号として使用されることが期待されている。さらに、格子暗号は、計算効率が良く、機能性の高い暗号スキームとして研究されている暗号システムである。
 離散ガウス分布は、全ての整数値を出力し得る確率分布である。しかし、離散ガウス分布に従って生成された乱数が格子暗号に用いられる場合、離散ガウス分布が出力する整数値の範囲が制限されることによって、確率変数の生成が効率化される場合が多い。
 例えば、以下のように離散ガウス分布が出力する整数値の範囲がセキュリティパラメータn ∈N (N は自然数全体の集合を表す記号)に依存する形で制限されることによって、確率変数の生成が効率化される。
 すなわち、t = ω(logn)1/2として、{k∈Z|- t・s ≦k ≦ t・s}が離散ガウス分布の出力範囲とされることによって、確率変数の生成が効率化される。なお、ωは、ランダウの記号である。離散ガウス分布が出力する整数の範囲が上記のように制限されても、格子暗号の安全性に影響が及ばないことが一般的に知られている。
 正規化定数W をW = Σ t・s i= - t・s φs(i)のように定義するとき、出力する整数の範囲が上記のように制限された離散ガウス分布をΨs(x) = φs(x)/Wとおく。Ψs(x)が用いられる場合、整数値u ∈Z が確率Ψs(u)で出力される。
 以下、本明細書における「離散ガウス分布」は、出力する整数の範囲が{k∈Z|- t・s ≦k ≦ t・s}であり、整数値u ∈Z を確率Ψs(u)で出力する確率分布を指す。また、函数Ψs(x) = φs(x)/Wを、離散ガウス分布を定める函数と呼ぶ。
 次に、離散ガウス分布の中心を説明する。中心がc 、分散値がs である離散ガウス分布は、整数値u を確率Ψs(u-c)で出力する確率分布である。
 上記の内容は、1次元格子上の離散ガウス分布に対する定義である。次に、n次元格子上の離散ガウス分布に対する定義を与える。
 ベクトル{b1 →, ・・・,bn →} ∈Rnが横に並べられた行列をB と記載する。行列B が用いられたn次元の格子Λ(B) を、以下のように定める。
Figure JPOXMLDOC01-appb-M000002
 また、中心がc→であるRn上のガウス函数を、パラメータs を用いて以下のように定義する。
Figure JPOXMLDOC01-appb-M000003
 上記の式(3)で表現されるガウス函数を用いて、n次元格子Λ上の離散ガウス分布を以下のように定義する。
Figure JPOXMLDOC01-appb-M000004
 すなわち、n次元格子上の離散ガウス分布は、確率変数が式(4)に従う確率分布である。以下、1次元格子上の離散ガウス分布、n次元格子上の離散ガウス分布を、簡単のためそれぞれ1次元離散ガウス分布、n次元離散ガウス分布とも呼ぶ。
 以上の内容が、1次元離散ガウス分布の定義、および多次元(n次元)離散ガウス分布の定義である。次に、それぞれの離散ガウス分布に従う乱数を生成するためのサンプリング法を説明する。
 一般的に、1次元離散ガウス分布に従う乱数の生成方法であるサンプリング法には、累積法と棄却サンプリング法の2つの方法がある。なお、1次元離散ガウス分布を定める函数をφ(x) 、1次元離散ガウス分布の出力範囲を{k∈Z|- t・s ≦k ≦ t・s}とする。
 上記の2つのサンプリング法をそれぞれ、1次元離散ガウス分布の中心が原点である場合と1次元離散ガウス分布の中心が原点でない場合とに分けて説明する。
 最初に、中心が原点である1次元離散ガウス分布に従う乱数を累積法で生成する処理を、非特許文献2に記載されている内容に基づいて説明する。図9は、1次元離散ガウス分布に従う乱数を生成する一般的な乱数生成システムの構成例を示すブロック図である。
 図9に示すように、中心が原点である1次元離散ガウス分布に従う乱数を生成する乱数生成システム910は、記憶装置911と、探索器912と、一様乱数生成器913とで構成されている。
 図9に示すような構成要素を有する中心が原点である1次元離散ガウス分布に従う乱数を生成する一般的な乱数生成システム910は、以下のように動作する。最初に、φ(0)/2,φ(1),φ(2),・・・ ,φ(t・s)の各値が事前に計算され、記憶装置911に記憶される。図9に示す記憶装置911内の各縦線が、φ(0)/2,φ(1) 等の記憶された各値を表す。
 次いで、一様乱数生成器913が、実数値x ∈[0,1] を出力する。出力されたx ∈R は、探索器912に入力される。x が入力された探索器912は、記憶装置911に記憶されている各値の中からφ(z-1)≦x <φ(z) を満たすz ∈Z を二分探索する。
 次いで、探索器912は、符号sign= ±を一様に選ぶ。次いで、探索器912は、sign・z ∈Z を1次元離散ガウス分布に従う乱数として出力する。以上の内容が、累積法による中心が原点である1次元離散ガウス分布に従う乱数の生成方法である。
 なお、中心が原点でない、例えば中心がa である1次元離散ガウス分布に従う乱数の累積法による生成方法は、上記の中心が原点である1次元離散ガウス分布に従う乱数の生成方法においてφ(x) をφ(x-a)に置き換えればよい。
 累積法の場合、記憶装置に記憶されるデータの数が t・s に比例する。なお、記憶装置に記憶されるデータは、中心が原点である1次元離散ガウス分布が用いられる場合はφ(0)/2,φ(1),φ(2),・・・ ,φ(t・s)である。また、中心が原点でなくa である1次元離散ガウス分布が用いられる場合はφ(0-a)/2, φ(1-a), φ(2-a), ・・・ ,φ(t・s -a)である。
 すなわち、累積法には、分散値s が大きい離散ガウス分布が使用される場合、函数の値の記憶に要するメモリ量が多くなるという問題がある。既存の格子暗号において分散値s は、比較的大きな値をとる。
 函数の値の記憶に要する具体的なメモリ量として、例えば、図10に示す値が非特許文献4に記載されている。図10は、累積法が使用される時に消費されるメモリ量の例を示す説明図である。図10に示すように、分散値が大きくなるほど消費されるメモリ量も多くなる。
 なお、図10に示す中心の「q-種類/1署名」は、1回の署名生成につき、q=2Kの中心が用意されることを意味する。同様に、「2-種類/1署名」は、1回の署名生成につき、2種類の中心しか用意されないことを意味する。
 また、図10に示すUseageは、各方式でガウス分布が使用される用途を表す。例えば、方式「LWE-plane 」では、「鍵生成」の用途でガウス分布が使用される。また、方式「GPV 」等では、「署名生成」の用途でガウス分布が使用される。「署名生成」の用途でガウス分布が使用される場合、ガウス分布は何度も使用される。
 RSA 等の格子暗号では、一般的に求められる計算量が少ない。よって、格子暗号は、センサ機器や携帯電話のような計算資源や記憶容量が小さいデバイスでの利用が期待されている。
 しかし、格子暗号のサブルーチンである離散ガウス分布に従う乱数の生成に累積法が用いられると、累積法で使用されるデータの保存のために多くの記憶容量が使用される。すなわち、記憶容量の小さいデバイスでの格子暗号の利用が困難になるという問題がある。
 次に、棄却サンプリング法を説明する。棄却サンプリング法は、離散ガウス分布に限られず、任意の離散型確率分布に従う乱数が生成される際に使用される方法である。
 最初に、一般の確率変数X に対する離散型確率分布に従う乱数を生成する棄却サンプリング法を、非特許文献5に記載されている内容に基づいて説明する。その後に、1次元離散ガウス分布に従う乱数を生成する棄却サンプリング法を説明する。
 離散型確率分布p(X=xi) に従う乱数を棄却サンプリング法を利用して生成するために、最初に全てのxiに対してt(xi) ≧p(xi) を満足する函数t(x)のうち、効率的に計算可能なt(x)を準備する。
 次いで、t(x)が正規化された函数r(x)を、r(x)=t(x)/Σt(xi) とする。次いで、以下の手順を実行することによって、確率変数X に対する離散型確率分布p(X=xi) (確率分布函数)に従う乱数を、棄却サンプリング法を利用して生成する。
 (Step 1) 確率分布函数r(x)に従う乱数Y を生成する。
 (Step 2) Y と独立に区間[0,1] 内の一様乱数U を発生させる。
 (Step 3)  U ≦p(Y)/t(Y) が満たされる場合、乱数X をX=Y とする。U ≦p(Y)/t(Y) が満たされない場合、再度(Step 1)の処理を行う。
 なお、非特許文献5に記載されているAlgorithm A1における1/ε、g 、f がそれぞれ上記の手順では1 、t 、p に変換されている。
 次に、1次元離散ガウス分布に従う乱数を生成する棄却サンプリング法を、非特許文献3に記載されている内容に基づいて説明する。なお、非特許文献3に記載されている方法は、上述した棄却サンプリング法が、函数t(x)が恒等的に1である場合に対して適応された方法である。
 非特許文献3に記載されている方法を実現するための装置の構成例を図11に示す。図11は、1次元離散ガウス分布に従う乱数を生成する一般的な乱数生成システムの他の構成例を示すブロック図である。
 図11に示すように、中心が原点である1次元離散ガウス分布に従う乱数を生成する乱数生成システム920は、棄却判定器921と、一様乱数生成器922と、出力装置923とで構成されている。
 図11に示すような構成要素を有する中心が原点である1次元離散ガウス分布に従う乱数を生成する一般的な乱数生成システム920は、以下のように動作する。最初に、一様乱数生成器922は、{k∈Z|- t・s ≦k ≦ t・s}の範囲で一様乱数u1∈Z を生成する。
 次いで、一様乱数生成器922は、[0, φ(0)]の範囲で実数値の乱数u2∈R を生成する。一様乱数生成器922は、生成されたu1∈Z とu2∈R を棄却判定器921に入力する。
 次いで、棄却判定器921は、φ(u1)とu2∈R を比較する。比較した結果u2≦φ(u1)であれば、棄却判定器921は、u1∈Z を出力装置923に入力する。出力装置923は、中心が原点である1次元離散ガウス分布に従う乱数としてu1∈Z を出力する。
 比較した結果u2>φ(u1)であれば、乱数生成システム920は、最初のステップに戻り、同じ操作を再度実行する。以上の内容が、棄却サンプリング法による中心が原点である1次元離散ガウス分布に従う乱数の生成方法である。
 なお、中心が原点でない、例えば中心がa である1次元離散ガウス分布に従う乱数の棄却サンプリング法による生成方法は、上記の中心が原点である1次元離散ガウス分布に従う乱数の生成方法においてφ(x) をφ(x-a)に置き換えればよい。
 棄却サンプリング法では、上記の(Step 3)に相当する処理における条件が満たされない場合、再度同様の処理が繰り返し実行される。すなわち、棄却サンプリング法には、生成された一様乱数が棄却される度に離散ガウス分布を定める函数を再度計算することが求められるため、計算効率が低下するという問題がある。
 以上の内容をまとめると、累積法の長所は、計算コストが小さいことである。一方、累積法の短所は、メモリコストが大きいことである。また、棄却サンプリング法の長所は、メモリコストが小さいことである。一方、棄却サンプリング法の短所は、計算コストが大きいことである。
 次に、多次元格子上の離散ガウス分布に従う乱数の生成方法を、非特許文献3に記載されている内容に基づいて説明する。説明の前に、いくつかの事項を用意する。
 ベクトルa1 →,・・・,an →に対する各Gram-Schmidt直交化ベクトルa1 ~→, ・・・ ,an ~→を、以下のように計算されるベクトルとする。
Figure JPOXMLDOC01-appb-M000005
 なお、本明細書においてテキスト中で使用する記号である「-」「→」「~」等は、本来直前の文字の真上に記載されるべきであるが、テキスト記法の制限により上記のように当該文字の直後に記載する。式中および図面においてはこれらの記号は本来の位置に記載される。
 図12は、多次元格子上の離散ガウス分布に従う乱数の生成アルゴリズムの例を示す説明図である。図12に示すアルゴリズムの4行目~9行目のループでは、1回の処理で乱数ziが生成され、生成されたziを基にci-1 が更新される。また、次の処理では更新されたci-1 を基に離散ガウス分布が更新された上で乱数zi-1 が生成される。すなわち、乱数zn, ・・・ ,z1が、それぞれ逐次的に生成される。
 図12に示すアルゴリズムの7行目の処理におけるDZ,c’i,σi は、中心がc’i 、分散値がσi である1次元離散ガウス分布を表す。ループを構成する各処理でci-1 が更新されるため、中心が異なる1次元離散ガウス分布に従う乱数の生成も毎回求められる。
Regev, "On lattices, learning with errors, random linear codes, and cryptography," STOC 2005, ACM, 2005, pages 84-93. Chris Peikert, "An efficient and parallel Gaussian Sampler for lattices," CRYPTO, 2010, pages 80-97. Craig Gentry, Chris Peikert, and Vinod Vaikuntanathan, "How to Use a Short Basis: Trapdoors for Hard Lattices and New Cryptographic Constructions," STOC, 2008, pages 197-206. DWARAKANATH, N. C, GALBRAITH, S. D, "Sampling From Discrete Gaussians for Lattice-Based Cryptography on a Constrained Device," Appl. Algebra Engrg. Comm. Comput. 25, 2014, pages 159-180. George Casella, Christian P. Robert, and Martin T. Wells, "Generalized Accept-Reject sampling schemes," A Festschrift for Herman Rubin Institute of Mathematical Statistics Lecture Notes - Monograph Series Vol. 45, 2004, pages 342-347.
 多次元(n次元)格子上の離散ガウス分布に従う乱数を生成する場合、中心が原点であるとは限られない1次元格子上の離散ガウス分布に従う乱数をn回生成することが求められる。中心が原点であるとは限られない1次元格子上の離散ガウス分布に従う乱数の生成方法に、上記の累積法および棄却サンプリング法が使用される。
 累積法を用いて多次元格子上の離散ガウス分布に従う乱数を生成する時の課題と、棄却サンプリング法を用いて多次元格子上の離散ガウス分布に従う乱数を生成する時の課題をそれぞれ順に述べる。
 累積法が用いられて多次元格子上の離散ガウス分布に従う乱数が生成される場合、出力対象の格子の次元の数だけ1次元離散ガウス分布に従う乱数が生成される。また、累積法では、乱数の生成に用いられる1次元離散ガウス分布の中心が異なる度に新しい数値を記憶装置に保存することが求められる。
 よって、乱数の生成に用いられる複数の1次元離散ガウス分布の中心が殆ど異なるような場合、多くのメモリ量が消費される。すなわち、多次元格子上の離散ガウス分布に従う乱数の生成に使用される累積法は、メモリ量の観点において効率的なサンプリング法ではない。
 棄却サンプリング法を用いて多次元格子上の離散ガウス分布に従う乱数を生成する時の課題は、1次元離散ガウス分布に従う乱数の生成速度が遅い点である。その理由は、生成された一様乱数が棄却される度に離散ガウス分布を定める函数の計算が求められるので、全体的な計算効率が低下するためである。
[発明の目的]
 そこで、本発明は、上述した課題を解決する、多次元格子上の離散ガウス分布に従う乱数の生成に掛かるメモリコストと計算コストをより低減できる乱数生成システム、乱数生成方法および乱数生成プログラムを提供することを目的とする。
 本発明による乱数生成システムは、中心が正の値である1次元格子上の離散ガウス分布である第1離散分布に従う乱数を生成する乱数生成システムであって、第1離散分布において確率変数が正の範囲における所定の区間内の値になる確率である第1確率と0の間の一様乱数を生成する生成手段と、中心が原点である1次元格子上の離散ガウス分布である第2離散分布において確率変数が所定の区間内の値になる確率である第2確率以下の一様乱数が生成されると乱数の生成方法に第2離散分布を定める函数の値が用いられる累積法を選択し、第2確率よりも大きい一様乱数が生成されると乱数の生成方法に棄却サンプリング法を選択する選択手段とを含むことを特徴とする。
 本発明による乱数生成方法は、中心が正の値である1次元格子上の離散ガウス分布である第1離散分布に従う乱数を生成する乱数生成システムで実行される乱数生成方法であって、第1離散分布において確率変数が正の範囲における所定の区間内の値になる確率である第1確率と0の間の一様乱数を生成し、中心が原点である1次元格子上の離散ガウス分布である第2離散分布において確率変数が所定の区間内の値になる確率である第2確率以下の一様乱数が生成されると乱数の生成方法に第2離散分布を定める函数の値が用いられる累積法を選択し、第2確率よりも大きい一様乱数が生成されると乱数の生成方法に棄却サンプリング法を選択することを特徴とする。
 本発明による乱数生成プログラムは、中心が正の値である1次元格子上の離散ガウス分布である第1離散分布に従う乱数を生成するコンピュータで実行される乱数生成プログラムであって、コンピュータに、第1離散分布において確率変数が正の範囲における所定の区間内の値になる確率である第1確率と0の間の一様乱数を生成する生成処理、中心が原点である1次元格子上の離散ガウス分布である第2離散分布において確率変数が所定の区間内の値になる確率である第2確率以下の一様乱数が生成されると乱数の生成方法に第2離散分布を定める函数の値が用いられる累積法を選択する第1選択処理、および第2確率よりも大きい一様乱数が生成されると乱数の生成方法に棄却サンプリング法を選択する第2選択処理を実行させることを特徴とする。
 本発明によれば、多次元格子上の離散ガウス分布に従う乱数の生成に掛かるメモリコストと計算コストをより低減できる。
中心が原点である1次元離散ガウス分布と中心が原点でない1次元離散ガウス分布とを示す説明図である。 累積法が適用される領域と棄却サンプリング法が適用される領域とを示す説明図である。 本発明による乱数生成システムの第1の実施形態の構成例を示すブロック図である。 第1の実施形態の生成方法選択装置110の構成例を示すブロック図である。 第1の実施形態の棄却サンプリング装置120の構成例を示すブロック図である。 第1の実施形態の累積法サンプリング装置130の構成例を示すブロック図である。 第1の実施形態の乱数生成システム100による乱数生成処理の動作を示すフローチャートである。 本発明による乱数生成システムの概要を示すブロック図である。 1次元離散ガウス分布に従う乱数を生成する一般的な乱数生成システムの構成例を示すブロック図である。 累積法が使用される時に消費されるメモリ量の例を示す説明図である。 1次元離散ガウス分布に従う乱数を生成する一般的な乱数生成システムの他の構成例を示すブロック図である。 多次元格子上の離散ガウス分布に従う乱数の生成アルゴリズムの例を示す説明図である。
[第1の実施形態]
 以下、本発明の実施形態を、図面を参照して説明する。本実施形態では、中心が原点である1次元離散ガウス分布を、以下に示す方法で中心が原点でない1次元離散ガウス分布に仮想的に変換することを考える。
 図1は、中心が原点である1次元離散ガウス分布と中心が原点でない1次元離散ガウス分布とを示す説明図である。なお、説明の簡略化のために、図1には1次元離散ガウス分布の出力範囲のうち正の範囲のみが示されている。図1に示すように、1次元離散ガウス分布は線対称な分布であるため、出力範囲のうち正の範囲のみが考慮されればよい。
 図1を参照すると、中心が原点でなくa である1次元離散ガウス分布の大部分は、中心が原点である1次元離散ガウス分布に含まれていることが分かる。例えば、図1に示す第1区間(便宜上、横軸の長さを1とする。)における確率φ(1) は、確率φ(1-a)の大部分を占めている。
 同様に、図1に示す第2区間(便宜上、横軸の長さを1とする。)における確率φ(2) は、確率φ(2-a)の大部分を占めている。以下、全ての区間において同様の特徴が見受けられる。
 すなわち、中心が原点でない1次元離散ガウス分布に従う第1区間における乱数は、φ(1)/φ(1-a)の確率で中心が原点である1次元離散ガウス分布に従う乱数であると考えられる。本実施形態では、上記の特徴が用いられている。
 図2は、累積法が適用される領域と棄却サンプリング法が適用される領域とを示す説明図である。図2に示す確率P は、確率φ(1-a)、・・・、確率φ(t・s -a)の総和である。すなわち、確率P は、中心が原点でない1次元離散ガウス分布に従って乱数が出力される確率である。
 また、図2に示すように、確率p{1-dim}は、確率φ(1) 、・・・、確率φ(t・s)の総和である。すなわち、確率p{1-dim}は、中心が原点である1次元離散ガウス分布に従って乱数が出力される確率である。
 本実施形態の乱数生成システムは、区間[0, P]で取られた一様乱数r がp{1-dim}以下である場合、中心が原点である1次元離散ガウス分布を定める函数φ(x) の値が用いられる累積法で、中心が原点でない1次元離散ガウス分布に従う乱数を生成する。
 また、図2に示すように、確率p{rjc}は、確率 {φ(1-a)-φ(1)}、・・・、確率 {φ(t・s -a)-φ(t・s)} の総和である。すなわち、確率p{rjc}は、中心が原点でない1次元離散ガウス分布に従って乱数が出力される確率P と中心が原点である1次元離散ガウス分布に従って乱数が出力される確率p{1-dim}との差である。
 本実施形態の乱数生成システムは、区間[0, P]で取られた一様乱数r がp{1-dim}より大きい場合、棄却サンプリング法で中心が原点でない1次元離散ガウス分布に従う乱数を生成する。
 確率p{1-dim}の方が確率p{rjc}よりも十分に大きいため、棄却サンプリング法で乱数が生成される確率は低い。すなわち、棄却サンプリング法で乱数が生成される機会が減るため、乱数の生成に掛かる全体の計算コストが低減される。
 また、累積法では常に中心が原点である1次元離散ガウス分布を定める函数φ(x) の値が用いられるので、記憶装置には函数φ(x) の値さえ記憶されていればよい。すなわち、乱数の生成に掛かる全体のメモリコストも低減される。
 なお、上記では中心が原点から右にずれている1次元離散ガウス分布に従う乱数の生成方法を説明したが、中心が原点から左にずれている1次元離散ガウス分布に従う乱数も同様の方法で生成される。本実施形態の乱数生成システムは、1次元格子上の離散ガウス分布の中心を仮想的に変換することによって、多次元格子上の離散ガウス分布に従う乱数を効率的に生成する。
[構成の説明]
 図3は、本発明による乱数生成システムの第1の実施形態の構成例を示すブロック図である。図3に示すように、本実施形態の乱数生成システム100は、生成方法選択装置110と、棄却サンプリング装置120と、累積法サンプリング装置130とを含む。
 図4は、第1の実施形態の生成方法選択装置110の構成例を示すブロック図である。図4に示すように、本実施形態の生成方法選択装置110は、区間一様乱数生成手段111と、生成方法選択手段112とを有する。
 区間一様乱数生成手段111は、区間[0, P]の一様乱数r を生成する機能を有する。また、生成方法選択手段112は、生成された一様乱数r と確率p{1-dim}とを比較した上で乱数の生成方法を選択する機能を有する。
 生成方法選択手段112は、一様乱数r が確率p{1-dim}以下である場合、乱数の生成方法として累積法を選択する。選択した後、生成方法選択手段112は、累積法サンプリング装置130に乱数を生成するように指示する。
 また、生成方法選択手段112は、一様乱数r が確率p{1-dim}より大きい場合、乱数の生成方法として棄却サンプリング法を選択する。選択した後、生成方法選択手段112は、棄却サンプリング装置120に乱数を生成するように指示する。
 図5は、第1の実施形態の棄却サンプリング装置120の構成例を示すブロック図である。図5に示すように、本実施形態の棄却サンプリング装置120は、一様乱数生成手段121と、棄却判定手段122とを有する。
 一様乱数生成手段121が有する機能は、一様乱数生成器922が有する機能と同様である。すなわち、一様乱数生成手段121は、{k∈Z|-(t・s -a)≦k ≦(t・s -a)} の範囲で一様乱数u1∈Z を生成する。
 次いで、一様乱数生成手段121は、[0, φ (-a)] の範囲で実数値の乱数u2∈R を生成する。一様乱数生成手段121は、生成されたu1∈Z とu2∈R を棄却判定手段122に入力する。
 また、棄却判定手段122が有する機能は、棄却判定器921が有する機能、および出力装置923が有する機能と同様である。すなわち、棄却判定手段122は、φ (u1-a)とu2∈R を比較する。比較した結果u2≦φ (u1-a)であれば、棄却判定手段122は、中心が原点でない1次元離散ガウス分布に従う乱数としてu1∈Z を出力する。
 また、比較した結果u2>φ (u1-a)であれば、棄却判定手段122は、最初のステップに戻り、同じ操作を再度実行する。
 図6は、第1の実施形態の累積法サンプリング装置130の構成例を示すブロック図である。図6に示すように、本実施形態の累積法サンプリング装置130は、一様乱数生成手段131と、探索手段132と、記憶手段133と、出力手段134とを有する。
 一様乱数生成手段131が有する機能は、一様乱数生成器913が有する機能と同様である。すなわち、一様乱数生成手段131は、実数値x ∈[0,1] を出力する。
 また、探索手段132が有する機能は、探索器912が有する機能と同様である。すなわち、探索手段132は、記憶手段133に記憶されている各値の中からφ(z-a -1)≦x <φ(z-a)を満たすz ∈Z を二分探索する。
 また、記憶手段133が有する機能は、記憶装置911が有する機能と同様である。すなわち、記憶手段133は、φ(0-a)/2, φ(1-a), φ(2-a), ・・・ ,φ(t・s -a)の各値を記憶する。
 出力手段134は、探索手段132が探索した乱数を中心が原点でない1次元離散ガウス分布に従う乱数として出力する機能を有する。
 本実施形態の乱数生成システム100は、累積法による1次元離散ガウス分布に従う乱数の生成に掛かるメモリコストで、また毎回のサンプリング処理が累積法で実行されたときの計算コストに近い計算コストで、多次元格子上の離散ガウス分布に従う乱数を生成できる。
[動作の説明]
 以下、本実施形態の乱数生成システム100が中心が原点でない1次元離散ガウス分布に従う乱数を生成する動作を図7を参照して説明する。図7は、第1の実施形態の乱数生成システム100による乱数生成処理の動作を示すフローチャートである。
 最初に、区間一様乱数生成手段111は、区間[0, P]の一様乱数r を生成する(ステップS101)。区間一様乱数生成手段111は、生成された一様乱数r を生成方法選択手段112に入力する。
 次いで、生成方法選択手段112は、入力された一様乱数r が確率p{1-dim}より大きいか否かを判定する(ステップS102)。
 一様乱数r が確率p{1-dim}より大きい場合(ステップS102におけるTrue)、生成方法選択手段112は、乱数のサンプリング処理の方法として棄却サンプリング法を選択する(ステップS103)。次いで、生成方法選択手段112は、棄却サンプリング装置120に乱数の生成を指示する。
 乱数の生成を指示された棄却サンプリング装置120は、棄却サンプリング法で中心が原点でない1次元離散ガウス分布に従う乱数を生成する(ステップS104)。生成した後、棄却サンプリング装置120は、生成された乱数を出力する(ステップS105)。出力した後、乱数生成システム100は、乱数生成処理を終了する。
 一様乱数r が確率p{1-dim}以下である場合(ステップS102におけるFalse )、生成方法選択手段112は、乱数のサンプリング処理の方法として累積法を選択する(ステップS106)。次いで、生成方法選択手段112は、累積法サンプリング装置130に乱数の生成を指示する。
 乱数の生成を指示された累積法サンプリング装置130は、累積法で中心が原点でない1次元離散ガウス分布に従う乱数を生成する(ステップS107)。累積法サンプリング装置130は、中心が原点である1次元離散ガウス分布を定める函数の値が用いられる累積法で乱数を生成する。
 生成した後、累積法サンプリング装置130は、生成された乱数を出力する(ステップS108)。出力した後、乱数生成システム100は、乱数生成処理を終了する。n次元格子上の離散ガウス分布に従う乱数が生成される場合、乱数生成システム100は、図7に示す乱数生成処理をn回実行する。
[効果の説明]
 確率p{rjc}の値に比べて確率p{1-dim}の値が十分大きいため、生成方法選択手段112は、殆どの場合中心が原点である1次元離散ガウス分布を定める函数の値が用いられる累積法を乱数の生成方法として選択する。すなわち、本実施形態の乱数生成システム100が使用されると、多次元格子上の離散ガウス分布に従う乱数が生成される際に毎回実行されるサンプリング処理が、殆どの確率で累積法によるサンプリング処理になる。
 よって、乱数生成システム100による乱数生成処理全体に要するメモリコストは、中心が原点である1次元離散ガウス分布に従う乱数が累積法で生成される際に要するメモリコストと同程度の値まで削減される。
 また、乱数生成システム100による乱数生成処理全体に要する計算コストは、毎回実行されるサンプリング処理が累積法によるサンプリング処理である場合に要する計算コストに近い値まで削減される。
 なお、本実施形態の乱数生成システム100は、例えば、非一時的な記憶媒体に格納されているプログラムに従って処理を実行する中央処理装置(CPU(Central Processing Unit))等のプロセッサ、またはデータ処理装置によって実現されてもよい。すなわち、区間一様乱数生成手段111、生成方法選択手段112、一様乱数生成手段121、棄却判定手段122、一様乱数生成手段131、探索手段132、および出力手段134は、例えば、プログラム制御に従って処理を実行するCPU によって実現されてもよい。
 また、記憶手段133は、例えばRAM(Random Access Memory) で実現されてもよい。
 また、本実施形態の乱数生成システム100における各部は、ハードウェア回路によって実現されてもよい。一例として、区間一様乱数生成手段111、生成方法選択手段112、一様乱数生成手段121、棄却判定手段122、一様乱数生成手段131、探索手段132、記憶手段133、および出力手段134が、それぞれLSI(Large Scale Integration)で実現される。また、それらが1つのLSI で実現されていてもよい。
 次に、本発明の概要を説明する。図8は、本発明による乱数生成システムの概要を示すブロック図である。本発明による乱数生成システム10は、中心が正の値である1次元格子上の離散ガウス分布である第1離散分布に従う乱数を生成する乱数生成システムであって、第1離散分布において確率変数が正の範囲における所定の区間内の値になる確率である第1確率と0の間の一様乱数を生成する生成手段11(例えば、区間一様乱数生成手段111)と、中心が原点である1次元格子上の離散ガウス分布である第2離散分布において確率変数が所定の区間内の値になる確率である第2確率以下の一様乱数が生成されると乱数の生成方法に第2離散分布を定める函数の値が用いられる累積法を選択し、第2確率よりも大きい一様乱数が生成されると乱数の生成方法に棄却サンプリング法を選択する選択手段12(例えば、生成方法選択手段112)とを含む。
 そのような構成により、乱数生成システムは、多次元格子上の離散ガウス分布に従う乱数の生成に掛かるメモリコストと計算コストをより低減できる。
 また、乱数生成システム10は、第2離散分布を定める函数の値が用いられる累積法で1次元格子上の離散ガウス分布に従う乱数を生成する累積法生成手段(例えば、累積法サンプリング装置130)を含み、選択手段12は、累積法が選択された後に累積法生成手段に乱数の生成を指示し、累積法生成手段は、指示を受けて乱数を生成してもよい。また、累積法生成手段は、第2離散分布を定める函数の値が記憶されている記憶手段(例えば、記憶手段133)を有してもよい。
 そのような構成により、乱数生成システムは、累積法で中心が原点でない1次元格子上の離散ガウス分布に従う乱数を生成できる。
 また、乱数生成システム10は、棄却サンプリング法で1次元格子上の離散ガウス分布に従う乱数を生成する棄却サンプリング法生成手段(例えば、棄却サンプリング装置120)を含み、選択手段12は、棄却サンプリング法が選択された後に棄却サンプリング法生成手段に乱数の生成を指示し、棄却サンプリング法生成手段は、指示を受けて乱数を生成してもよい。
 そのような構成により、乱数生成システムは、棄却サンプリング法で中心が原点でない1次元格子上の離散ガウス分布に従う乱数を生成できる。
 以上、実施形態および実施例を参照して本願発明を説明したが、本願発明は上記実施形態および実施例に限定されるものではない。本願発明の構成や詳細には、本願発明のスコープ内で当業者が理解し得る様々な変更をすることができる。
 また、上記の実施形態の一部又は全部は、以下の付記のようにも記載されうるが、以下に限られない。
 (付記1)中心が負の値である1次元格子上の離散ガウス分布である第3離散分布に従う乱数を生成する乱数生成システムであって、前記第3離散分布において確率変数が負の範囲における所定の区間内の値になる確率である第3確率と0の間の一様乱数を生成する生成手段と、中心が原点である前記1次元格子上の離散ガウス分布である第4離散分布において確率変数が前記所定の区間内の値になる確率である第4確率以下の一様乱数が生成されると前記乱数の生成方法に前記第4離散分布を定める函数の値が用いられる累積法を選択し、前記第4確率よりも大きい一様乱数が生成されると前記乱数の生成方法に棄却サンプリング法を選択する選択手段とを含むことを特徴とする乱数生成システム。
 (付記2)第4離散分布を定める函数の値が用いられる累積法で1次元格子上の離散ガウス分布に従う乱数を生成する累積法生成手段を含み、選択手段は、累積法が選択された後に前記累積法生成手段に乱数の生成を指示し、前記累積法生成手段は、指示を受けて乱数を生成する付記1記載の乱数生成システム。
 (付記3)累積法生成手段は、第4離散分布を定める函数の値が記憶されている記憶手段を有する付記2記載の乱数生成システム。
 (付記4)棄却サンプリング法で1次元格子上の離散ガウス分布に従う乱数を生成する棄却サンプリング法生成手段を含み、選択手段は、棄却サンプリング法が選択された後に前記棄却サンプリング法生成手段に乱数の生成を指示し、前記棄却サンプリング法生成手段は、指示を受けて乱数を生成する付記1から付記3のうちのいずれか1項に記載の乱数生成システム。
 (付記5)中心が負の値である1次元格子上の離散ガウス分布である第3離散分布に従う乱数を生成する乱数生成システムで実行される乱数生成方法であって、前記第3離散分布において確率変数が負の範囲における所定の区間内の値になる確率である第3確率と0の間の一様乱数を生成し、中心が原点である前記1次元格子上の離散ガウス分布である第4離散分布において確率変数が前記所定の区間内の値になる確率である第4確率以下の一様乱数が生成されると前記乱数の生成方法に前記第4離散分布を定める函数の値が用いられる累積法を選択し、前記第4確率よりも大きい一様乱数が生成されると前記乱数の生成方法に棄却サンプリング法を選択することを特徴とする乱数生成方法。
 (付記6)中心が負の値である1次元格子上の離散ガウス分布である第3離散分布に従う乱数を生成するコンピュータで実行される乱数生成プログラムであって、前記コンピュータに、前記第3離散分布において確率変数が負の範囲における所定の区間内の値になる確率である第3確率と0の間の一様乱数を生成する生成処理、中心が原点である前記1次元格子上の離散ガウス分布である第4離散分布において確率変数が前記所定の区間内の値になる確率である第4確率以下の一様乱数が生成されると前記乱数の生成方法に前記第4離散分布を定める函数の値が用いられる累積法を選択する第3選択処理、および前記第4確率よりも大きい一様乱数が生成されると前記乱数の生成方法に棄却サンプリング法を選択する第4選択処理を実行させるための乱数生成プログラム。
10、100、910、920 乱数生成システム
11 生成手段
12 選択手段
110 生成方法選択装置
111 区間一様乱数生成手段
112 生成方法選択手段
120 棄却サンプリング装置
121、131 一様乱数生成手段
122 棄却判定手段
130 累積法サンプリング装置
132 探索手段
133 記憶手段
134 出力手段
911 記憶装置
912 探索器
913、922 一様乱数生成器
921 棄却判定器
923 出力装置

Claims (6)

  1.  中心が正の値である1次元格子上の離散ガウス分布である第1離散分布に従う乱数を生成する乱数生成システムであって、
     前記第1離散分布において確率変数が正の範囲における所定の区間内の値になる確率である第1確率と0の間の一様乱数を生成する生成手段と、
     中心が原点である前記1次元格子上の離散ガウス分布である第2離散分布において確率変数が前記所定の区間内の値になる確率である第2確率以下の一様乱数が生成されると前記乱数の生成方法に前記第2離散分布を定める函数の値が用いられる累積法を選択し、前記第2確率よりも大きい一様乱数が生成されると前記乱数の生成方法に棄却サンプリング法を選択する選択手段とを含む
     ことを特徴とする乱数生成システム。
  2.  第2離散分布を定める函数の値が用いられる累積法で1次元格子上の離散ガウス分布に従う乱数を生成する累積法生成手段を含み、
     選択手段は、累積法が選択された後に前記累積法生成手段に乱数の生成を指示し、
     前記累積法生成手段は、指示を受けて乱数を生成する
     請求項1記載の乱数生成システム。
  3.  累積法生成手段は、第2離散分布を定める函数の値が記憶されている記憶手段を有する
     請求項2記載の乱数生成システム。
  4.  棄却サンプリング法で1次元格子上の離散ガウス分布に従う乱数を生成する棄却サンプリング法生成手段を含み、
     選択手段は、棄却サンプリング法が選択された後に前記棄却サンプリング法生成手段に乱数の生成を指示し、
     前記棄却サンプリング法生成手段は、指示を受けて乱数を生成する
     請求項1から請求項3のうちのいずれか1項に記載の乱数生成システム。
  5.  中心が正の値である1次元格子上の離散ガウス分布である第1離散分布に従う乱数を生成する乱数生成システムで実行される乱数生成方法であって、
     前記第1離散分布において確率変数が正の範囲における所定の区間内の値になる確率である第1確率と0の間の一様乱数を生成し、
     中心が原点である前記1次元格子上の離散ガウス分布である第2離散分布において確率変数が前記所定の区間内の値になる確率である第2確率以下の一様乱数が生成されると前記乱数の生成方法に前記第2離散分布を定める函数の値が用いられる累積法を選択し、
     前記第2確率よりも大きい一様乱数が生成されると前記乱数の生成方法に棄却サンプリング法を選択する
     ことを特徴とする乱数生成方法。
  6.  中心が正の値である1次元格子上の離散ガウス分布である第1離散分布に従う乱数を生成するコンピュータで実行される乱数生成プログラムであって、
     前記コンピュータに、
     前記第1離散分布において確率変数が正の範囲における所定の区間内の値になる確率である第1確率と0の間の一様乱数を生成する生成処理、
     中心が原点である前記1次元格子上の離散ガウス分布である第2離散分布において確率変数が前記所定の区間内の値になる確率である第2確率以下の一様乱数が生成されると前記乱数の生成方法に前記第2離散分布を定める函数の値が用いられる累積法を選択する第1選択処理、および
     前記第2確率よりも大きい一様乱数が生成されると前記乱数の生成方法に棄却サンプリング法を選択する第2選択処理
     を実行させるための乱数生成プログラム。
PCT/JP2017/028584 2017-08-07 2017-08-07 乱数生成システム、乱数生成方法および乱数生成プログラム Ceased WO2019030799A1 (ja)

Priority Applications (3)

Application Number Priority Date Filing Date Title
PCT/JP2017/028584 WO2019030799A1 (ja) 2017-08-07 2017-08-07 乱数生成システム、乱数生成方法および乱数生成プログラム
US16/635,262 US11327719B2 (en) 2017-08-07 2017-08-07 Random number generation method selecting system, random number generation method selecting method, and random number generation method selecting program
JP2019535457A JP6870738B2 (ja) 2017-08-07 2017-08-07 乱数生成システム、乱数生成方法および乱数生成プログラム

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2017/028584 WO2019030799A1 (ja) 2017-08-07 2017-08-07 乱数生成システム、乱数生成方法および乱数生成プログラム

Publications (1)

Publication Number Publication Date
WO2019030799A1 true WO2019030799A1 (ja) 2019-02-14

Family

ID=65271211

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2017/028584 Ceased WO2019030799A1 (ja) 2017-08-07 2017-08-07 乱数生成システム、乱数生成方法および乱数生成プログラム

Country Status (3)

Country Link
US (1) US11327719B2 (ja)
JP (1) JP6870738B2 (ja)
WO (1) WO2019030799A1 (ja)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2020190277A1 (en) 2019-03-18 2020-09-24 Hewlett-Packard Development Company, L.P. Three-dimensional printing with epoxy and amine compounds

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2019157503A1 (en) 2018-02-12 2019-08-15 Massachusetts Institute Of Technology Systems and methods for providing secure communications using a protocol engine
EP3903300A4 (en) * 2019-02-19 2022-09-07 Massachusetts Institute Of Technology CONFIGURABLE GRID CRYPTOGRAPHY PROCESSOR FOR THE QUANTUM SECURE INTERNET OF THINGS AND ASSOCIATED PROCEDURES
CN116192357A (zh) * 2022-12-06 2023-05-30 电子科技大学长三角研究院(湖州) 一种logistic分布随机数的生成方法、系统及设备

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2014216005A (ja) * 2013-04-29 2014-11-17 韓國電子通信研究院Electronics and Telecommunications ResearchInstitute 2進乱数列を整数乱数に変換する装置および方法

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6324558B1 (en) * 1995-02-14 2001-11-27 Scott A. Wilber Random number generator and generation method
US6539410B1 (en) * 1999-03-17 2003-03-25 Michael Jay Klass Random number generator
JP2000276459A (ja) * 1999-03-26 2000-10-06 Fujitsu Ltd 学習による変換関数を用いた乱数発生装置,乱数発生方法および乱数発生システム
US8352384B2 (en) * 2008-03-04 2013-01-08 Massachusetts Institute Of Technology Combinational stochastic logic
US20170220322A1 (en) * 2016-01-28 2017-08-03 International Business Machines Corporation Generating gaussian random numbers using inverse sampling and recurrence relationship

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2014216005A (ja) * 2013-04-29 2014-11-17 韓國電子通信研究院Electronics and Telecommunications ResearchInstitute 2進乱数列を整数乱数に変換する装置および方法

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
YUKI TANAKA ET AL.: "Efficient Discrete Gaussian Sampling on Constrained Devices", IEICE TECHNICAL REPORT, vol. 116, no. 132, 7 July 2016 (2016-07-07), pages 169 - 175 *

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2020190277A1 (en) 2019-03-18 2020-09-24 Hewlett-Packard Development Company, L.P. Three-dimensional printing with epoxy and amine compounds

Also Published As

Publication number Publication date
US11327719B2 (en) 2022-05-10
JPWO2019030799A1 (ja) 2020-07-02
JP6870738B2 (ja) 2021-05-12
US20200371751A1 (en) 2020-11-26

Similar Documents

Publication Publication Date Title
Teh et al. Parallel chaotic hash function based on the shuffle-exchange network
El Bansarkhani et al. Improvement and efficient implementation of a lattice-based signature scheme
US20150262074A1 (en) Solving digital logic constraint problems via adiabatic quantum computation
JP6870738B2 (ja) 乱数生成システム、乱数生成方法および乱数生成プログラム
JP6477461B2 (ja) 順序保存暗号化システム、装置、方法およびプログラム
Ablayev et al. On the concept of cryptographic quantum hashing
Potii et al. Post quantum hash based digital signatures comparative analysis. Features of their implementation and using in public key infrastructure
US8677135B2 (en) Digital signatures with error polynomials
WO2019092804A1 (ja) 乱数生成システム、乱数生成方法および乱数生成プログラム
KR20210130044A (ko) 데이터 분석 장치 및 방법
Iavich et al. Improved Post-quantum Merkle Algorithm Based on Threads
Cohen et al. A unified scheme for generalizing cardinality estimators to sum aggregation
US20240039693A1 (en) Encryption processing device, encryption processing method, and encryption processing program
US11216533B2 (en) Inverse-image sampling device, inverse-image sampling method, and inverse-image sampling program
Eden et al. Embeddings and labeling schemes for A
Zeng et al. Detecting affine equivalence of Boolean functions and circuit transformation
Gorbenko et al. Methods of building general parameters and keys for NTRU Prime Ukraine of 5 th–7 th levels of stability. Product form
Holzer et al. Recovering short generators of principal fractional ideals in cyclotomic fields of conductor p α q β
US20240267200A1 (en) Method and System for Modifying Document Without Changing Hash Value
WO2019069403A1 (ja) 乱数生成システム、乱数生成方法および乱数生成プログラム
Zhang et al. Chaos of exponential logistic map
Zhao Markov chain mirror descent on data federation
Hayasaka et al. A construction of 3-dimensional lattice sieve for number field sieve over F_ {p^ n}
Jo Hash functions based on Ramanujan graphs
Khajavi et al. The goodness of covariance selection problem from AUC bounds

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17921359

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2019535457

Country of ref document: JP

Kind code of ref document: A

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17921359

Country of ref document: EP

Kind code of ref document: A1