[Paper Review] Iterated LD-Problem in non-associative key establishment
This paper introduces iterated versions of non-associative key establishment protocols based on left self-distributive (LD), multi-LD, and mutual LD-systems, leveraging variations of the iterated LD-problem for security. The protocols are instantiated in braid groups, symmetric groups, and matrix groups using generalized shifted conjugacy and f-symmetric conjugacy, with parameter suggestions for cryptographic efficiency and resistance to known attacks.
We construct new non-associative key establishment protocols for all left self-distributive (LD), multi-LD-, and mutual LD-systems. The hardness of these protocols relies on variations of the (simultaneous) iterated LD-problem and its generalizations. We discuss instantiations of these protocols using generalized shifted conjugacy in braid groups and their quotients, LD-conjugacy and $f$-symmetric conjugacy in groups. We suggest parameter choices for instantiations in braid groups, symmetric groups and several matrix groups.
Motivation & Objective
- To develop improved key establishment protocols (KEPs) for non-associative algebraic structures, particularly LD-systems and their generalizations.
- To strengthen security by basing protocols on the hardness of the iterated LD-problem and its variants, including simultaneous and subgroup conjugacy coset problems.
- To provide concrete, efficient instantiations of these protocols in braid groups, symmetric groups, and matrix groups over finite and rational function fields.
- To suggest secure parameter choices for practical deployment, focusing on large centralizers of generator differences to resist algebraic attacks.
- To extend non-commutative cryptography beyond associative structures by formalizing protocols for partial and mutual LD-systems.
Proposed method
- Proposes an iterated version of the KEP from [KT13] for LD-systems, using planar rooted binary trees to generate shared key components via iterated left self-distributive operations.
- Employs the generalized shifted conjugacy operation in braid groups as a platform for constructing LD-systems, with parameters chosen to maximize security and computational efficiency.
- Introduces f-symmetric conjugacy in groups as a new operation for LD-systems, using evaluation endomorphisms f on matrix groups over rings like F_q[X]/(X^N - 1).
- Uses tree-based generation of group elements (a0, b1, ..., bk) to compute shared keys through iterated applications of the LD operation, ensuring key agreement across parties.
- Applies the conjugacy coset problem as a base hard problem, particularly in braid groups, and suggests that solving it is computationally difficult.
- Implements all protocols in MAGMA, with code and instantiations detailed in [KT13a], supporting both infinite and finite matrix groups.
Experimental results
Research questions
- RQ1Can iterated versions of non-associative key exchange protocols be constructed that are more secure than prior AAG-like schemes?
- RQ2What are the hardness assumptions underlying the iterated LD-problem and its generalizations in non-associative systems?
- RQ3How can efficient and secure instantiations of these protocols be realized in braid groups and matrix groups?
- RQ4What parameter choices maximize resistance to algebraic attacks, particularly by ensuring large centralizers of generator differences?
- RQ5Can f-symmetric conjugacy in matrix groups provide a viable platform for non-associative KEPs with practical efficiency?
Key findings
- The iterated LD-problem and its variants, including the simultaneous and conjugacy coset problems, are shown to be hard computational problems suitable for cryptographic use in non-associative systems.
- Concrete parameter sets are proposed for braid groups (e.g., d=4, m=n=6, kA=kB=5, l=5) and matrix groups (e.g., d=4, p=17, m=n=8, kA=kB=10) to ensure security and efficiency.
- The use of evaluation endomorphisms f on matrix groups over F_q[X]/(X^N - 1) enables efficient computation while preserving hardness of the f-symmetric conjugacy problem.
- Large centralizers of generator differences (e.g., f(si sj^{-1})) are critical for security, and can be achieved via cabling or reducible braid structures in the Gassner representation.
- The conjugacy coset problem in braid groups is identified as a novel and relevant hard problem, potentially more resistant than standard conjugacy problems.
- Implementation in MAGMA confirms feasibility, with full code and instantiations available in [KT13a], supporting both infinite and finite platforms.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.