arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

破解基于矩阵码的ACDGV MinRank Gabidulin加密方案

Breaking ACDGV MinRank Gabidulin encryption schemes over matrix codes

Thai Hung Le

arXiv 2608.03328首次发表:更新:

发表机构

École normale supérieure, PSL University, CNRS, Inria, France; LTCI, Telecom Paris, Institut Polytechnique de Paris, France(巴黎高等师范学院,PSL大学,法国国家科学研究中心,Inria; 电信学院,巴黎理工学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出一种结合组合与代数技术的攻击,破解了Asiacrypt 2024提出的全部16个EGMC加密参数集,可在多项式时间内恢复等效密钥,大幅降低其安全级别。

AI 中文摘要

Aragon、Couvreur、Dyseryn、Gaborit和Vincotte在Asiacrypt 2024上提出的增强型Gabidulin矩阵码(EGMC),旨在隐藏Gabidulin矩阵码的代数结构,同时实现非常紧凑的McEliece型和Niederreiter型加密方案,在声称的128位安全级别下密文仅为65字节。其安全性基于一个假设:被掩码的EGMC码难以与随机矩阵码区分。我们证明,这种增强构造仍残留足够结构,可恢复出等效于密钥的码。与以往密码分析不同,我们的攻击结合组合技术与代数技术,以恢复Gabidulin等效压缩码,该码随后可在多项式时间内扩展为全长等效密钥。因此,该攻击对EGMC加密方案同时提供区分器和密钥恢复攻击,大幅突破了全部16个已提出的EGMC参数集。例如,对于声称的128位参数集(2,17,37,4,0),该攻击将安全级别从186位降至35位;在我们的实现中,等效密钥的恢复耗时不到10分钟。

英文摘要

Enhanced Gabidulin Matrix Codes (EGMC), introduced by Aragon, Couvreur, Dyseryn, Gaborit, and Vincotte at Asiacrypt 2024, were designed to hide the algebraic structure of Gabidulin matrix codes while enabling very compact McEliece- and Niederreiter-type encryption schemes, with ciphertexts as small as 65 bytes at the claimed 128-bit security level. Their security relies on the assumption that a masked EGMC code is hard to distinguish from a random matrix code. We show that this enhanced construction leaves enough structure for an equivalent code of the secret key to be recovered. Unlike previous cryptanalysis, our attack combines combinatorial and algebraic techniques to recover a Gabidulin-equivalent compressed code. This code can then be extended to a full-length equivalent secret key in polynomial time. As a result, the attack provides both a distinguisher and a key-recovery attack against the EGMC encryption schemes. The attack breaks all 16 proposed EGMC parameter sets by large margins. For example, for the claimed 128-bit parameter set (2,17,37,4,0), it reduces the security level from 186 bits to 35 bits and in our implementation, the equivalent secret key of this parameter set is recovered in less than 10 minutes.

Comments31 pages

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑