Skip to main content
QUICK REVIEW

[论文解读] Improved Cryptanalysis of Rank Metric Schemes Based on Gabidulin Codes

Ayoub Otmani, Hervé Talé Kalachi|arXiv (Cornell University)|Feb 27, 2016
Coding theory and cryptography参考文献 12被引用 5
一句话总结

本文表明,基于Gabidulin码的秩度量密码系统——特别是那些使用扩展域上右列混淆器以抵抗Overbeck攻击的系统——仍然存在漏洞。通过将Frobenius算子应用于公钥,攻击者可以恢复出一个长度更低但纠错能力仍足以解密所有密文的Gabidulin码,因此尽管先前声称具有抗性,此类变体仍不安全。

ABSTRACT

We prove that any variant of the GPT cryptosystem which uses a right column scrambler over the extension field as advocated by the works of Gabidulin et al. with the goal to resist to Overbeck's structural attack are actually still vulnerable to that attack. We show that by applying the Frobenius operator appropriately on the public key, it is possible to build a Gabidulin code having the same dimension as the original secret Gabidulin code but with a lower length. In particular, the code obtained by this way correct less errors than the secret one but its error correction capabilities are beyond the number of errors added by a sender, and consequently an attacker is able to decrypt any ciphertext with this degraded Gabidulin code. We also considered the case where an isometric transformation is applied in conjunction with a right column scrambler which has its entries in the extension field. We proved that this protection is useless both in terms of performance and security. Consequently, our results show that all the existing techniques aiming to hide the inherent algebraic structure of Gabidulin codes have failed.

研究动机与目标

  • 研究使用扩展域上右列混淆器以抵抗Overbeck结构攻击的Gabidulin码基秩度量密码系统的安全性。
  • 分析此类混淆器相较于基域混淆器是否真正提升了安全性。
  • 确定Frobenius算子是否仍可被利用,从公钥中恢复出一个弱化但功能完整的Gabidulin码。
  • 证明即使在使用扩展域混淆器的情况下,所导出码的纠错能力仍超过加密过程中添加的错误数,从而实现完整解密。
  • 证明所有先前尝试隐藏Gabidulin码代数结构的努力,在此攻击向量下均告失败。

提出的方法

  • 对公钥生成矩阵 G_pub 多次应用Frobenius算子 Λi,以揭示底层码的结构特性。
  • 利用重复应用Frobenius算子会使码的维度每次增加一这一事实,作为Gabidulin码的显著特征。
  • 从公钥构造一个长度更低但纠错能力仍超过加密时添加错误数的退化Gabidulin码。
  • 证明Frobenius变换码的对偶维度为1,使攻击者能够识别出在 F_q 上的有效替代列混淆器矩阵 T。
  • 通过涉及 T 和Frobenius像的变换,从公钥推导出新的生成矩阵 G*,其生成一个有效的Gabidulin码。
  • 表明所得到的码 G* 可用于解密任意密文,即使它并非原始秘密码。

实验结果

研究问题

  • RQ1Frobenius算子能否用于从使用扩展域列混淆器的公钥中恢复出一个功能完整的Gabidulin码?
  • RQ2如先前所声称,使用 F_q^m 上的右列混淆器是否真能防止Overbeck攻击?
  • RQ3所导出码的纠错能力是否足以解密所有密文,即使它并非原始秘密码?
  • RQ4能否从Frobenius变换码的对偶中构造出一个有效的替代列混淆器 T?
  • RQ5当混淆器定义在扩展域上时,扭曲矩阵的秩与攻击成功之间的关系是什么?

主要发现

  • 对公钥应用Frobenius算子 Λi(其中 i < n−k−1)可产生一个纠错能力 t* 严格小于原始秘密码 t 但仍大于加密过程中添加的错误数 t_pub 的Gabidulin码。
  • 攻击者可恢复出满足 t* > t_pub 的码,从而解密所有密文,因此即使使用扩展域混淆器,该方案仍被攻破。
  • Frobenius变换码 Λ_{n−k−1}(C_pub) 的对偶维度为1,使攻击者能够识别出在 F_q 上的有效替代列混淆器矩阵 T。
  • 矩阵 T 满足 G_pub = S(Z | G*)T,证明 T 作为有效替代列混淆器,揭示了秘密码的结构。
  • 即使列混淆器定义在扩展域 F_q^m 上,基于Frobenius的攻击仍有效,从而推翻了先前的安全性声明。
  • 所有使用扩展域右列混淆器的GPT密码系统变体均不安全,因为它们无法阻止通过Frobenius运算实现的结构恢复。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。