arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

从一个MQOM v2.1签名实现全密钥恢复与伪造

Full-Key Recovery and Forgery from One MQOM v2.1 Signature

José Luis Delgado

arXiv 2608.09699首次发表:更新:

AI 中文总结

本研究针对NIST附加签名流程第三轮候选MQOM v2.1,提出从单个签名恢复完整密钥并伪造新消息签名的攻击,相关开销低于NIST安全基准,降域运行已实现实际密钥与见证恢复及伪造。

AI 中文摘要

我们针对NIST附加签名流程第三轮候选方案MQOM v2.1提出了全密钥恢复攻击,该攻击可从一个已接受的签名中恢复完整签名密钥,并利用该密钥对新消息进行签名。若δ=FirstBits_λ(x)为见证x的前缀,兄弟路径会确定一个公开值A,使得树奇偶校验给出s=δ⊕A。将其代入隐藏叶子承诺可得Enc_K(δ⊕A)=T⊕LinOrtho(δ),其中K和T为公开值。同一签名中的修正项会将一个解扩展为完整见证,而公开的MQ关系可识别出那些能生成有效签名密钥的见证;对该见证进行序列化即可得到秘密密钥,进而生成可被参考验证器接受的新消息签名。我们使用保留的电路状态并结合格雷遍历,在指定的AES/Rijndael电路上对该方程进行评估。I类和V类的全域扫描分别需要2^142.335112和2^271.794162个布尔门;III类扫描覆盖了1/2+2^-20和0.580004770183的域,所需门数分别为2^206.774558和2^206.988685。这四类的总开销均低于NIST安全基准。针对参考实现的降域运行在所有三类情况下均能恢复字节级精确的见证和密钥,并生成可被参考验证器接受的新消息伪造签名。独立生成的源语法电路会在指定域和转换后的L3前缀上评估固定密码,而精确的理想密码阶乘矩界则控制传递给公钥验证的额外方程原像。方程中的每个值均由已接受的记录固定,因此盐约束的全局根扩展会修改其公开常数,但不会消除单签名恢复通道。

英文摘要

We give a full-key-recovery attack on MQOM v2.1, a Round-3 candidate in the NIST additional-signature process, that recovers the complete signing key from one accepted signature and uses it to sign a fresh message. If $δ=\operatorname{FirstBits}_λ(x)$ is the prefix of the witness $x$, the sibling path determines a public value $A$ such that tree parity gives $s=δ\oplus A$. Substitution into the hidden-leaf commitment yields $$\mathsf{Enc}_K(δ\oplus A)=T\oplus\mathsf{LinOrtho}(δ)$$ with public values $K$ and $T$. The correction in the same signature expands a solution into a complete witness, while the public MQ relation identifies those yielding valid signing keys; serializing such a witness gives the secret key, enabling a fresh-message signature accepted by the reference verifier. We evaluate this equation over the specified AES/Rijndael circuits using retained circuit state along a Gray traversal. Complete-domain scans for Categories I and V cost $2^{142.335112}$ and $2^{271.794162}$ Boolean gates. Category-III scans cover $1/2+2^{-20}$ and $0.580004770183$ of the domain at costs of $2^{206.774558}$ and $2^{206.988685}$ gates. All four totals are below the NIST security benchmarks. Reduced-domain runs against the reference implementation recover the byte-exact witness and key in all three categories and produce a fresh-message forgery accepted by the reference verifier. Independently generated source-syntax circuits evaluate the fixed ciphers over the stated domains and translated L3 prefixes, while an exact ideal-cipher factorial-moment bound controls additional equation preimages passed to public-key validation. Every value in the equation is fixed by the accepted transcript, so salt-bound global-root expansion changes its public constants without removing the one-signature recovery channel.

CommentsThe separation against generic search was deemed not enough. As such, the attack is not considered to affect MQOM security

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑