Skip to main content

GGH-crypto

GGH-crypto is a Python package implementing the Goldreich-Goldwasser-Halevi (GGH) public key cryptosystem and its optimization, GGH-HNF by Micciancio. This package is designed for educational and research purposes, offering insights into lattice-based cryptography. This project was developed as part of a 3-year degree program at the Università degli Studi di Milano (University of Milan). It explores the resilience of lattice-based cryptography against quantum threats and introduces an hybrid variant.

Features

  • Implementation of the original GGH cryptosystem (1997)
  • Implementation of the GGH-HNF optimization (2002)
  • Utility functions for lattice-based cryptography
  • Algorithms for solving the Closest Vector Problem (CVP)
  • Lattice reduction algorithms

Usage and details

For detailed installation, usage, examples and documentation, please visit the GitHub repository.

Note

Both the original GGH cryptosystem and its GGH-HNF optimization have known security vulnerabilities. This implementation is not intended for production use.

Changelog

1.1.0

Performance

  • Utils.babai_rounding now solves the linear system x · basis = point instead of computing point * basis.inv(), removing a full exact-rational matrix inversion (and an extra matrix multiply) from every decrypt() call in both GGHCryptosystem and GGHHNFCryptosystem. On large dimensions this is the dominant cost of decryption — roughly an order-of-magnitude speedup at n ≈ 200, with bit-identical output.
  • GGHCryptosystem.decrypt applies the same change to the final CVP * public_basis.inv() step.
  • GGHHNFCryptosystem.generate_keys_from_R and GGHCryptosystem.generate_keys_from_R no longer compute an unused R.inv(), avoiding an O(n³) inversion when a private basis is supplied.

Bug fixes

  • Constructing GGHCryptosystem with a supplied private_basis was broken: __init__ called the non-existent generate_keys_from_basis() (renamed to generate_keys_from_R). Fixed the call site.
  • GGHCryptosystem.generate_sigma was inverting the basis twice on the keys-from-R path, so sigma was derived from R instead of R⁻¹ and disagreed with normal key generation. It now receives the basis, like every other call site.
  • GGHHNFCryptosystem.generate_keys_from_R computed R_rho only when debug=True, so building from a private basis with debug=False left it None and broke generate_error(). The computation is now unconditional.

Breaking changes

  • GGHHNFCryptosystem.private_key is now the private basis matrix (fmpz_mat), not a (R_inv, R) tuple, matching the other key-generation path and GGHCryptosystem.private_key. Replace private_key[1] with private_key.

1.0.5

  • Added nguyen_fix parameter to GGHCryptosystem (default False). When enabled, implements the Mandangan et al. (2020) countermeasure against Nguyen's attack: error entries are drawn from {σ-2, σ-1, σ, σ+1} instead of {-σ, +σ}, preserving ||e|| = σ√n while breaking the elimination stage of the attack.
  • Key generation with nguyen_fix=True automatically retries until a basis yielding σ > 2 is found (required by the countermeasure). Raises ValueError after 100 failed attempts with a suggestion to increase the dimension.

1.0.4

  • Initial stable release.

Release files for GGH-crypto 1.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for GGH-crypto 1.1.0
File Size Uploaded
ggh_crypto-1.1.0.tar.gz 13.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for GGH-crypto 1.1.0
File Interpreter ABI Platform
ggh_crypto-1.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 29.5 kB

Release files / ggh_crypto-1.1.0.tar.gz

Download URL ggh_crypto-1.1.0.tar.gz
Size 13.6 kB
Tags Source
SHA-256 checksum
How to use checksums
55a1ab463eabe39da1153ffd058aaa7821e55768a9c15f2ae4c3ae12474b285a
BLAKE2b-256 checksum
How to use checksums
f62b6810784a3cf6ec90fbd30a1cba1167e235980a441b407965eafd923738c0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.7

Release files / ggh_crypto-1.1.0-py3-none-any.whl

Download URL ggh_crypto-1.1.0-py3-none-any.whl
Size 15.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
32f8dbe602d6d0993ae9f757c49d2b51df48bd0b27cf38f28449a4cf906ae273
BLAKE2b-256 checksum
How to use checksums
ceb47a04f8b9bcc8185bbe418d15f12abeb2606e3f5e73cdd675248d3ec40f1f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.7

Release history Release notifications | RSS feed

This release

1.1.0 This release

2 release files

1.0.5

2 release files

1.0.4

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page