[论文解读] On the Security of Some Compact Keys for McEliece Scheme
本文提出了一种针对基于准循环交替码的紧凑McEliece方案的新代数密钥恢复攻击,通过引入在置换群下的不变码操作。该方法表明原始码的安全性可归约为一个更小的不变码的安全性,该不变码同样为交替码,从而建立了一个统一且简化的攻击框架,适用于射影线性群自同构,且提出了高效的线性代数重构算法以恢复原始码结构。
In this paper we study the security of the key of compact McEliece schemes based on alternant/Goppa codes with a non-trivial permutation group, in particular quasi-cyclic alternant codes. We show that it is possible to reduce the key-recovery problem on the original quasi-cyclic code to the same problem on a smaller code derived from the public key. This result is obtained thanks to the invariant code operation which gives the subcode whose elements are fixed by a permutation in Perm(C). The fundamental advantage is that the invariant subcode of an alternant code is an alternant code. This approach improves the technique of Faugere, Otmani, Tillich, Perret and Portzamparc which uses folded codes of alternant codes obtained by using supports globally stable by an affine map. We use a simpler approach with a unified view on quasi-cyclic alternant codes and we treat the case of automorphisms arising from a non affine homography. In addition, we provide an efficient algorithm to recover the full structure of the alternant code from the structure of the invariant code.
研究动机与目标
- 分析使用非平凡置换群的准循环交替码的紧凑McEliece方案的安全性。
- 通过引入基于不变码的更通用且统一的方法,改进基于折叠码的现有密钥恢复攻击。
- 将密钥恢复技术的适用范围从仿射诱导自同构扩展至射影线性变换。
- 提供一种仅使用线性代数即可从不变码高效重构原始码结构的算法。
- 证明原始方案的安全性可归约为较小不变码的安全性,从而实现更高抗性的参数选择。
提出的方法
- 引入不变码为映射 c ↦ c − σ(c) 的核,其中 σ 是码的自同构群中的置换。
- 证明在阶为 ℓ 的置换作用下,准循环GRS码或交替码的不变码本身是长度为 n/ℓ 且参数减小的GRS或交替码。
- 从代数几何的几何视角出发,统一处理在射影直线上定义的准循环交替码。
- 表明不变码操作保持交替码结构,而此前的折叠码方法作用于对偶码,无法保持该结构。
- 开发一种线性代数算法,从不变码中恢复原始的支撑集与除子,即使在置换非仿射时也适用。
- 将攻击扩展至由射影线性变换诱导的非仿射自同构,包括在扩域上可对角化的特殊情况。
实验结果
研究问题
- RQ1准循环交替码的密钥恢复问题能否在置换群作用下归约为其不变码上的更小等价问题?
- RQ2不变码操作是否保持交替码结构,从而实现比折叠码更简单且更通用的攻击?
- RQ3该方法能否扩展至由射影线性群诱导的自同构,而不仅限于仿射群?
- RQ4能否高效地仅通过线性代数从不变码重构原始码参数(支撑集与除子)?
- RQ5所提出的密钥恢复算法的计算成本是多少?与ISD的明文恢复相比如何?
主要发现
- 阶为 ℓ 的置换作用下,准循环GRS码的不变码是长度为 n/ℓ 且维度为 ⌊k/ℓ⌋ 的GRS码。
- 阶为 ℓ 的置换作用下,准循环交替码的不变码是长度为 n/ℓ 且阶为 r/ℓ 的交替码。
- 不变码操作为分析准循环交替码(包括由射影线性变换诱导的)提供了一个统一框架。
- 所提出的从不变码重构原始码的算法在 𝔽_{q^m} 上的运算量为 O(ℓn²(n−k)k),实验结果显示在参数 (q=2, m=12, n=3600, k=2825, ℓ=3) 下耗时约27分钟。
- 原始方案的安全性可归约为较小不变码的安全性,即破解不变码即等价于破解原始方案。
- 通过合理选择参数,可使对不变码的密钥恢复攻击在计算上变得昂贵,从而在安全性降低的前提下仍保持安全。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。