首页> 外文会议>International Conference on the Theory and Application of Cryptology and Information Security >Algebraic Attack against Variants of McEliece with Goppa Polynomial of a Special Form
【24h】

Algebraic Attack against Variants of McEliece with Goppa Polynomial of a Special Form

机译:用特殊形式的GOPPA多项式对抗MECERIES变体的代数攻击

获取原文

摘要

In this paper, we present a new algebraic attack against some special cases of Wild McEliece Incognito, a generalization of the original McEliece cryptosystem. This attack does not threaten the original McEliece cryptosystem. We prove that recovering the secret key for such schemes is equivalent to solving a system of polynomial equations whose solutions have the structure of a usual vector space. Consequently, to recover a basis of this vector space, we can greatly reduce the number of variables in the corresponding algebraic system. From these solutions, we can then deduce the basis of a GRS code. Finally, the last step of the cryptanalysis of those schemes corresponds to attacking a McEliece scheme instantiated with particular GRS codes (with a polynomial relation between the support and the multipliers) which can be done in polynomial-time thanks to a variant of the Sidelnikov-Shestakov attack. For Wild McEliece & Incognito, we also show that solving the corresponding algebraic system is notably easier in the case of a non-prime base field F_q. To support our theoretical results, we have been able to practically break several parameters defined over a non-prime base field q ∈ {9, 16, 25, 27, 32}, t ≤ 6, extension degrees m ∈ {2, 3}, security level up to 2129 against information set decoding in few minutes or hours.
机译:在本文中,我们提出了一种针对一些特殊情况的新代数攻击,对野生粉煤隐身,是原始肉体密码系统的概括。此攻击不会威胁原始的MECELIECE密码系统。我们证明,恢复这些方案的秘密密钥相当于求解一个多项式方程系统,其解决方案具有通常的矢量空间的结构。因此,要恢复该矢量空间的基础,我们可以大大减少相应代数系统中的变量的数量。从这些解决方案中,我们可以推断出GRS代码的基础。最后,这些方案的密码分析的最后一步对应于攻击特定GRS代码的攻击方案(在支持和乘数之间的多项式关系),这是由于侧链尼克克科夫的变种在多项式时可以完成。 Shestakov攻击。对于野生Mcelife和Invognito,我们还表明,在非Prime基础字段F_Q的情况下,求解相应的代数系统非常容易。为了支持我们的理论结果,我们已经能够几乎在非Primime基础字段Q∈{9,16,25,27,32},T≤6,延伸度M∈{2,3}上突破几个参数。 ,安全级别高达2129,对信息设置在几分钟或几小时内的信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号