Skip to main content
QUICK REVIEW

[论文解读] Distinguisher-Based Attacks on Public-Key Cryptosystems Using Reed-Solomon Codes

Alain Couvreur, Philippe Gaborit|arXiv (Cornell University)|Jul 24, 2013
Coding theory and cryptography参考文献 21被引用 7
一句话总结

本文提出了针对基于广义 Reed-Solomon (GRS) 码的多个公钥密码系统的多项式时间密钥恢复攻击,利用基于码的分量乘积的区分器。通过分析平方子码和删减码的维数,该攻击高效地恢复了 Wieschebrink、Bogdanov-Lee 和 Baldi 等人所用 GRS 码的密钥结构,表明尽管这些系统被设计用于抵御先前的攻击,但其安全性仍被破坏。

ABSTRACT

Because of their interesting algebraic properties, several authors promote the use of generalized Reed-Solomon codes in cryptography. Niederreiter was the first to suggest an instantiation of his cryptosystem with them but Sidelnikov and Shestakov showed that this choice is insecure. Wieschebrink proposed a variant of the McEliece cryptosystem which consists in concatenating a few random columns to a generator matrix of a secretly chosen generalized Reed-Solomon code. More recently, new schemes appeared which are the homomorphic encryption scheme proposed by Bogdanov and Lee, and a variation of the McEliece cryptosystem proposed by Baldi et extit{al.} which hides the generalized Reed-Solomon code by means of matrices of very low rank. In this work, we show how to mount key-recovery attacks against these public-key encryption schemes. We use the concept of distinguisher which aims at detecting a behavior different from the one that one would expect from a random code. All the distinguishers we have built are based on the notion of component-wise product of codes. It results in a powerful tool that is able to recover the secret structure of codes when they are derived from generalized Reed-Solomon codes. Lastly, we give an alternative to Sidelnikov and Shestakov attack by building a filtration which enables to completely recover the support and the non-zero scalars defining the secret generalized Reed-Solomon code.

研究动机与目标

  • 证明尽管对系统进行了修改以抵御先前攻击,基于广义 Reed-Solomon (GRS) 码的公钥密码系统仍易受密钥恢复攻击。
  • 开发一种基于码的分量乘积的区分器,以检测从 GRS 码导出的公钥码中的结构异常。
  • 表明从 GRS 码导出的子码的平方具有异常低的维数,从而实现高效的密钥恢复。
  • 通过滤波方法恢复秘密 GRS 码的支撑集和非零标量,提供一种替代 Sidelnikov-Shestakov 攻击的方案。
  • 将基于区分器的攻击方法扩展至使用低秩扰动的 GRS 码的同态加密和 McEliece 类型方案。

提出的方法

  • 利用码的分量乘积构造一个区分器,当应用于从广义 Reed-Solomon 码导出的码时,可揭示其与随机码的结构偏差。
  • 计算公钥码中各类子码的平方维数,以检测 Wieschebrink 方案中添加的随机列的位置。
  • 在关键位置对公钥码进行删减,并分析删减后码的平方维数,以在 Bogdanov-Lee 的同态加密方案中分离出 GRS 成分。
  • 识别一个同时位于公钥码和 GRS 码中的子码,以在 Baldi 等人的方案中恢复秘密 GRS 结构。
  • 利用基于连续缩短和维数分析的滤波过程,重建 Niederreiter 类型系统中的完整 GRS 码结构。
  • 利用 PGL(2,𝔽q) 的 3-传递性,通过有理映射将商向量转换为位置向量,以归一化并恢复 GRS 码的求值点。

实验结果

研究问题

  • RQ1基于码的分量乘积的区分器能否高效检测从广义 Reed-Solomon 码导出的公钥码中与随机性的偏差?
  • RQ2公钥码的子码平方在多大程度上能揭示底层秘密 GRS 码的结构信息?
  • RQ3基于分量乘积的滤波方法是否能完全重构 McEliece 类型系统中隐藏的 GRS 码的支撑集和标量?
  • RQ4该基于区分器的方法对近期使用低秩扰动隐藏 GRS 结构的 McEliece 密码系统变体的攻击效果如何?
  • RQ5该区分器是否提供了一种多项式时间替代方案,以替代 Sidelnikov-Shestakov 攻击来恢复秘密 GRS 码?

主要发现

  • 码的分量乘积可构造一个区分器,即使在任意码率下,也能检测从广义 Reed-Solomon 码导出的公钥码中的非随机行为。
  • 在 Wieschebrink 的方案中,计算子码平方的维数可揭示添加到 GRS 生成矩阵中的随机列的位置。
  • 在 Bogdanov-Lee 的同态加密方案中,删减后公钥码的平方维数分析可实现对底层 GRS 结构的恢复。
  • 在 Baldi 等人的方案中,可识别出同时属于公钥码和 GRS 码的子码,从而实现秘密码的重构。
  • 基于连续缩短和维数分析的滤波方法可恢复 Niederreiter 类型系统中的完整秘密 GRS 码结构,从而有效攻破该方案。
  • 该攻击在多项式时间内运行且效率高,仅依赖于从公钥导出的矩阵的秩计算,无需穷举搜索或量子资源。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。