Skip to main content
QUICK REVIEW

[论文解读] LDPC codes in the McEliece cryptosystem: attacks and countermeasures

Marco Baldi|ArXiv.org|Sep 30, 2007
Coding theory and cryptography被引用 4
一句话总结

本文提出一种基于准循环低密度奇偶校验(QC-LDPC)码的改进McEliece密码系统,以减小密钥尺寸并提高传输速率,同时保持安全性。该工作针对近期利用公钥变换中结构缺陷的攻击提出对策,证明对构成矩阵进行微小修改可在不增加复杂度的前提下维持安全性,从而实现可扩展、高性能的后量子加密。

ABSTRACT

The McEliece cryptosystem is a public-key cryptosystem based on coding theory that has successfully resisted cryptanalysis for thirty years. The original version, based on Goppa codes, is able to guarantee a high level of security, and is faster than competing solutions, like RSA. Despite this, it has been rarely considered in practical applications, due to two major drawbacks: i) large size of the public key and ii) low transmission rate. Low-Density Parity-Check (LDPC) codes are state-of-art forward error correcting codes that permit to approach the Shannon limit while ensuring limited complexity. Quasi-Cyclic (QC) LDPC codes are a particular class of LDPC codes, able to join low complexity encoding of QC codes with high-performing and low-complexity decoding of LDPC codes. In a previous work it has been proposed to adopt a particular family of QC-LDPC codes in the McEliece cryptosystem to reduce the key size and increase the transmission rate. Recently, however, new attacks have been found that are able to exploit a flaw in the transformation from the private key to the public one. Such attacks can be effectively countered by changing the form of some constituent matrices, without altering the system parameters. This work gives an overview of the QC-LDPC codes-based McEliece cryptosystem and its cryptanalysis. Two recent versions are considered, and their ability to counter all the currently known attacks is discussed. A third version able to reach a higher security level is also proposed. Finally, it is shown that the new QC-LDPC codes-based cryptosystem scales favorably with the key length.

研究动机与目标

  • 解决原始McEliece密码系统的两大缺陷:公钥尺寸过大和传输速率过低。
  • 评估基于LDPC的McEliece变体在经典攻击与新近开发攻击下的安全性,特别是针对稀疏变换矩阵的攻击。
  • 提出一种安全、高效且可扩展的McEliece密码系统变体,采用QC-LDPC码,同时保持较低的计算复杂度。
  • 证明对公钥变换矩阵的微小修改可有效抵御近期密码分析攻击,且不损害系统性能。
  • 展示QC-LDPC-based系统在密钥尺寸增大时具有有利的可扩展性,其增长呈线性,相较原始系统呈二次增长。

提出的方法

  • 系统采用具有稀疏奇偶校验矩阵的准循环LDPC码,以减小密钥尺寸并提高传输速率,同时保留高效编码与解码所需的结构。
  • 应用稠密变换矩阵以隐藏私钥码的结构,防止针对先前基于LDPC变体中稀疏变换的攻击。
  • 通过使用稠密矩阵与置换对私钥进行变换生成公钥,确保生成的生成矩阵呈现随机性,从而隐藏底层码结构。
  • 系统利用高效的置信传播算法(SPA)解码LDPC码,最小化解密复杂度并实现高吞吐量。
  • 所提出的对策涉及对公钥变换中构成矩阵形式的修改,可破坏攻击向量,且不改变系统参数或增加计算成本。
  • 安全性通过已知攻击(包括信息集解码、Stern型算法及针对稀疏结构的攻击)进行评估,性能通过复杂度估算与密钥尺寸扩展进行分析。

实验结果

研究问题

  • RQ1QC-LDPC码能否被安全地集成到McEliece密码系统中,以减小密钥尺寸并提高传输速率,同时不损害安全性?
  • RQ2近期针对稀疏变换矩阵的攻击如何破坏基于LDPC的McEliece变体?何种结构修改可有效中和这些攻击?
  • RQ3QC-LDPC-based McEliece系统在提升安全级别时,其可扩展性如何?能否在保持高效性与低复杂度的前提下实现?
  • RQ4与RSA及原始McEliece系统相比,QC-LDPC变体的加密与解密计算成本如何?
  • RQ5该系统能否在实现与RSA相当或更优性能的同时,抵御所有已知攻击(包括抗量子攻击)?

主要发现

  • 首个基于QC-LDPC的McEliece变体将密钥尺寸减小至6144字节,较原始McEliece系统(67072字节)缩小逾10倍,且比Niederreiter变体小逾5倍。
  • 系统实现传输速率0.75(3/4),显著高于原始McEliece系统的0.51,提升了实际通信效率。
  • 第二个变体保持与第一个相同的密钥尺寸,但通过将速率降低至2/3,将安全级别提高约2^10倍,展示了性能与安全性的权衡。
  • 第三个变体通过将密钥尺寸加倍至12288字节,实现2^106.5的安全级别,仍比原始系统小逾5倍,表明其与码长呈有利的线性增长关系。
  • 加密与解密的计算成本保持较低水平:对于首个变体,每信息位加密成本为658次操作,解密为4678次,远低于RSA的每比特738112次操作。
  • 通过修改公钥变换中构成矩阵的形式,系统可有效抵御所有已知攻击,包括改进的Stern型算法及针对稀疏变换的结构攻击,且不改变系统参数或增加复杂度。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。