GGH-crypto
GGH-crypto is a Python package implementing the Goldreich-Goldwasser-Halevi (GGH) public key cryptosystem and its optimization, GGH-HNF by Micciancio. This package is designed for educational and research purposes, offering insights into lattice-based cryptography. This project was developed as part of a 3-year degree program at the Università degli Studi di Milano (University of Milan). It explores the resilience of lattice-based cryptography against quantum threats and introduces an hybrid variant.
Features
- Implementation of the original GGH cryptosystem (1997)
- Implementation of the GGH-HNF optimization (2002)
- Utility functions for lattice-based cryptography
- Algorithms for solving the Closest Vector Problem (CVP)
- Lattice reduction algorithms
Usage and details
For detailed installation, usage, examples and documentation, please visit the GitHub repository.
Note
Both the original GGH cryptosystem and its GGH-HNF optimization have known security vulnerabilities. This implementation is not intended for production use.
Changelog
1.1.0
Performance
Utils.babai_roundingnow solves the linear systemx · basis = pointinstead of computingpoint * basis.inv(), removing a full exact-rational matrix inversion (and an extra matrix multiply) from everydecrypt()call in bothGGHCryptosystemandGGHHNFCryptosystem. On large dimensions this is the dominant cost of decryption — roughly an order-of-magnitude speedup at n ≈ 200, with bit-identical output.GGHCryptosystem.decryptapplies the same change to the finalCVP * public_basis.inv()step.GGHHNFCryptosystem.generate_keys_from_RandGGHCryptosystem.generate_keys_from_Rno longer compute an unusedR.inv(), avoiding an O(n³) inversion when a private basis is supplied.
Bug fixes
- Constructing
GGHCryptosystemwith a suppliedprivate_basiswas broken:__init__called the non-existentgenerate_keys_from_basis()(renamed togenerate_keys_from_R). Fixed the call site. GGHCryptosystem.generate_sigmawas inverting the basis twice on the keys-from-R path, sosigmawas derived fromRinstead ofR⁻¹and disagreed with normal key generation. It now receives the basis, like every other call site.GGHHNFCryptosystem.generate_keys_from_RcomputedR_rhoonly whendebug=True, so building from a private basis withdebug=Falseleft itNoneand brokegenerate_error(). The computation is now unconditional.
Breaking changes
GGHHNFCryptosystem.private_keyis now the private basis matrix (fmpz_mat), not a(R_inv, R)tuple, matching the other key-generation path andGGHCryptosystem.private_key. Replaceprivate_key[1]withprivate_key.
1.0.5
- Added
nguyen_fixparameter toGGHCryptosystem(defaultFalse). When enabled, implements the Mandangan et al. (2020) countermeasure against Nguyen's attack: error entries are drawn from {σ-2, σ-1, σ, σ+1} instead of {-σ, +σ}, preserving ||e|| = σ√n while breaking the elimination stage of the attack. - Key generation with
nguyen_fix=Trueautomatically retries until a basis yielding σ > 2 is found (required by the countermeasure). RaisesValueErrorafter 100 failed attempts with a suggestion to increase the dimension.
1.0.4
- Initial stable release.
Release files for GGH-crypto 1.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ggh_crypto-1.1.0.tar.gz | 13.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ggh_crypto-1.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 29.5 kB
Release files / ggh_crypto-1.1.0.tar.gz
| Download URL | ggh_crypto-1.1.0.tar.gz |
|---|---|
| Size | 13.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
55a1ab463eabe39da1153ffd058aaa7821e55768a9c15f2ae4c3ae12474b285a
|
|
BLAKE2b-256 checksum How to use checksums |
f62b6810784a3cf6ec90fbd30a1cba1167e235980a441b407965eafd923738c0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.14.7
|
Release files / ggh_crypto-1.1.0-py3-none-any.whl
| Download URL | ggh_crypto-1.1.0-py3-none-any.whl |
|---|---|
| Size | 15.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
32f8dbe602d6d0993ae9f757c49d2b51df48bd0b27cf38f28449a4cf906ae273
|
|
BLAKE2b-256 checksum How to use checksums |
ceb47a04f8b9bcc8185bbe418d15f12abeb2606e3f5e73cdd675248d3ec40f1f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.14.7
|