[论文解读] Distinguisher-Based Attacks on Public-Key Cryptosystems Using Reed-Solomon Codes
本文提出了针对基于广义 Reed-Solomon (GRS) 码的多个公钥密码系统的多项式时间密钥恢复攻击,利用基于码的分量乘积的区分器。通过分析平方子码和删减码的维数,该攻击高效地恢复了 Wieschebrink、Bogdanov-Lee 和 Baldi 等人所用 GRS 码的密钥结构,表明尽管这些系统被设计用于抵御先前的攻击,但其安全性仍被破坏。
Because of their interesting algebraic properties, several authors promote the use of generalized Reed-Solomon codes in cryptography. Niederreiter was the first to suggest an instantiation of his cryptosystem with them but Sidelnikov and Shestakov showed that this choice is insecure. Wieschebrink proposed a variant of the McEliece cryptosystem which consists in concatenating a few random columns to a generator matrix of a secretly chosen generalized Reed-Solomon code. More recently, new schemes appeared which are the homomorphic encryption scheme proposed by Bogdanov and Lee, and a variation of the McEliece cryptosystem proposed by Baldi et extit{al.} which hides the generalized Reed-Solomon code by means of matrices of very low rank. In this work, we show how to mount key-recovery attacks against these public-key encryption schemes. We use the concept of distinguisher which aims at detecting a behavior different from the one that one would expect from a random code. All the distinguishers we have built are based on the notion of component-wise product of codes. It results in a powerful tool that is able to recover the secret structure of codes when they are derived from generalized Reed-Solomon codes. Lastly, we give an alternative to Sidelnikov and Shestakov attack by building a filtration which enables to completely recover the support and the non-zero scalars defining the secret generalized Reed-Solomon code.
研究动机与目标
- 证明尽管对系统进行了修改以抵御先前攻击,基于广义 Reed-Solomon (GRS) 码的公钥密码系统仍易受密钥恢复攻击。
- 开发一种基于码的分量乘积的区分器,以检测从 GRS 码导出的公钥码中的结构异常。
- 表明从 GRS 码导出的子码的平方具有异常低的维数,从而实现高效的密钥恢复。
- 通过滤波方法恢复秘密 GRS 码的支撑集和非零标量,提供一种替代 Sidelnikov-Shestakov 攻击的方案。
- 将基于区分器的攻击方法扩展至使用低秩扰动的 GRS 码的同态加密和 McEliece 类型方案。
提出的方法
- 利用码的分量乘积构造一个区分器,当应用于从广义 Reed-Solomon 码导出的码时,可揭示其与随机码的结构偏差。
- 计算公钥码中各类子码的平方维数,以检测 Wieschebrink 方案中添加的随机列的位置。
- 在关键位置对公钥码进行删减,并分析删减后码的平方维数,以在 Bogdanov-Lee 的同态加密方案中分离出 GRS 成分。
- 识别一个同时位于公钥码和 GRS 码中的子码,以在 Baldi 等人的方案中恢复秘密 GRS 结构。
- 利用基于连续缩短和维数分析的滤波过程,重建 Niederreiter 类型系统中的完整 GRS 码结构。
- 利用 PGL(2,𝔽q) 的 3-传递性,通过有理映射将商向量转换为位置向量,以归一化并恢复 GRS 码的求值点。
实验结果
研究问题
- RQ1基于码的分量乘积的区分器能否高效检测从广义 Reed-Solomon 码导出的公钥码中与随机性的偏差?
- RQ2公钥码的子码平方在多大程度上能揭示底层秘密 GRS 码的结构信息?
- RQ3基于分量乘积的滤波方法是否能完全重构 McEliece 类型系统中隐藏的 GRS 码的支撑集和标量?
- RQ4该基于区分器的方法对近期使用低秩扰动隐藏 GRS 结构的 McEliece 密码系统变体的攻击效果如何?
- RQ5该区分器是否提供了一种多项式时间替代方案,以替代 Sidelnikov-Shestakov 攻击来恢复秘密 GRS 码?
主要发现
- 码的分量乘积可构造一个区分器,即使在任意码率下,也能检测从广义 Reed-Solomon 码导出的公钥码中的非随机行为。
- 在 Wieschebrink 的方案中,计算子码平方的维数可揭示添加到 GRS 生成矩阵中的随机列的位置。
- 在 Bogdanov-Lee 的同态加密方案中,删减后公钥码的平方维数分析可实现对底层 GRS 结构的恢复。
- 在 Baldi 等人的方案中,可识别出同时属于公钥码和 GRS 码的子码,从而实现秘密码的重构。
- 基于连续缩短和维数分析的滤波方法可恢复 Niederreiter 类型系统中的完整秘密 GRS 码结构,从而有效攻破该方案。
- 该攻击在多项式时间内运行且效率高,仅依赖于从公钥导出的矩阵的秩计算,无需穷举搜索或量子资源。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。