AI 中文总结
针对高速率麦利密码系统,利用广义里德-所罗门码,提出区分公开码的方法及密钥恢复攻击框架,在矩阵M行和列权重为2时,借助立方码区分器成功实施攻击。
AI 中文摘要
由于用广义里德-所罗门码实例化的麦利密码系统存在不安全性,已有多个麦利型系统提案,用行和列权重更大的矩阵M取代置换矩阵,许多方案中秘密密钥仍是GRS码。已有对一些行和列权重在1到1+R之间的方案的成功攻击,权重为2及更大的情况在这些工作中未解决。随后有作者提出权重恰好为2及更高权重的方案。我们为高速率情况下这些密码系统中出现的公开码提供区分器,还给出将足够好的区分器转化为密钥恢复攻击的框架。在矩阵M行和列权重为2的情况下,我们能用立方码区分器在高速率情况下成功攻击该方案。
英文摘要
Due to the insecurity of McEliece cryptosystems instantiated with Generalized Reed-Solomon codes, there have been several proposals of McEliece type systems that replace the permutation matrix by a matrix $M$ with larger row and column weight. In many of them, the secret key is still a GRS code. There have been successful attacks on some of those schemes with row and column weight between $1$ and $1 + R$, where $R$ is the rate of the code. The case of weight two and larger has been left open in these works. Subsequently, several authors proposed schemes with weight exactly two and with even higher weight. We provide distinguishers for the public codes appearing in these cryptosystems in the high rate regime. In addition, we give a framework to turn a good enough distinguisher into a key-recovery attack. In the case where the matrix $M$ has row and column weight $2$, we can successfully attack the scheme in the high rate regime using a cube code distinguisher.