[Paper Review] Analyzing the Length-Based Attack on Polycyclic Groups
This paper analyzes the resistance of polycyclic groups to the length-based attack in the context of the Anshel-Anshel-Goldfeld (AAG) key-exchange protocol. It demonstrates that with sufficiently high Hirsch length, polycyclic groups provide strong resistance to this attack, making them a viable and secure platform for non-commutative cryptographic protocols such as non-commutative Diffie-Hellman, ElGamal, and Cramer-Shoup.
After the Anshel-Anshel-Goldfeld (AAG) key-exchange protocol was introduced in 1999, it was implemented and studied with braid groups and with the Thompson group as its underlying platforms. The length-based attack, introduced by Hughes and Tannenbaum, has been used to extensively study AAG with the braid group as the underlying platform. Meanwhile, a new platform, using polycyclic groups, was proposed by Eick and Kahrobaei. In this paper, we show that with a high enough Hirsch length, the polycyclic group as an underlying platform for AAG is resistant to the length-based attack. In particular, polycyclic groups could provide a secure platform for any cryptosystem based on conjugacy search problem such as non-commutative Diffie-Hellman, ElGamal and Cramer-Shoup key exchange protocols.
Motivation & Objective
- To evaluate the security of polycyclic groups as platforms for the AAG key-exchange protocol under the length-based attack.
- To determine the threshold Hirsch length at which polycyclic groups become resistant to length-based cryptanalysis.
- To establish the suitability of polycyclic groups for broader non-commutative cryptographic protocols based on the conjugacy search problem.
Proposed method
- The authors analyze the behavior of the length-based attack on polycyclic groups by simulating the attack under varying Hirsch lengths.
- They examine the distribution of group element lengths during the attack process to assess feasibility and success rate.
- The study uses computational experiments to measure the convergence and success probability of the length-based attack on polycyclic groups.
- Theoretical analysis is combined with empirical results to evaluate resistance as a function of Hirsch length.
- The approach compares the attack's performance on polycyclic groups to its known success on braid groups.
Experimental results
Research questions
- RQ1Does the length-based attack succeed in breaking the AAG protocol when using polycyclic groups as the underlying platform?
- RQ2At what Hirsch length does the length-based attack become computationally infeasible against polycyclic groups?
- RQ3How does the resistance of polycyclic groups to the length-based attack compare to that of braid groups?
- RQ4Can polycyclic groups serve as a secure foundation for other conjugacy search problem-based cryptosystems?
Key findings
- Polycyclic groups with sufficiently high Hirsch length exhibit strong resistance to the length-based attack.
- The success rate of the length-based attack diminishes significantly as the Hirsch length increases.
- Polycyclic groups outperform braid groups in resisting this attack when the Hirsch length is large.
- The results suggest that polycyclic groups are suitable platforms for secure non-commutative key exchange protocols.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.