结构化欧拉函数原像问题:重构、碰撞与密码学意义
The Structured Totient Preimage Problem: Reconstruction, Collisions, and Cryptographic Implications
浏览论文内容
中文总结 AI 辅助
本文定义结构化欧拉函数原像(STP)问题,给出其重构、碰撞分析的算法与实验结果,区分其与一般逆欧拉函数计算的差异,为相关密码构造提供计算基础与参数约束。
中文摘要 AI 辅助
我们定义并研究结构化欧拉函数原像(Structured Totient Preimage,STP)问题,这是一个具有直接密码学动机的受限重构关系。设$p_1,\boldsymbol{\rm ...},p_k$为相同比特长度的不同素数,仅公开$x=\boldsymbol{\rm \textstyle \text{\normalsize $\boldsymbol \times$}}_{i=1}^k(p_i-1)$;给定$(x,\boldsymbol \times,k)$,STP问题要求找到任意一组满足该乘积的$k$个不同的$\boldsymbol \times$比特素数。该关系可高效验证,但其重构复杂度尚不明确。我们得到三个具体结果:第一,对已分解的$x$,我们推导了有序指数分配的精确数量,并给出一个界,表明当$\boldsymbol \times(x)=O(\boldsymbol \times)$时,固定$k$的直接重构为多项式时间,这排除了该场景作为强安全性断言的基础;第二,我们给出用于重构和碰撞分析的穷举算法;第三,我们对28组参数对($2 \boldsymbol \times k \boldsymbol \times 5$)进行了穷举评估,参数对最大$\boldsymbol \times=16$,最大普查中包含4588935个素数集合。这些数据通过碰撞参与度、最大重数和比特的条件模糊性量化了非单射性。这些结果将STP与一般逆欧拉函数计算区分开来,并为明确扩展参数族的结构化欧拉函数原像假设提供了动机。在该假设下,STP成为候选抗原像关系,其对承诺、乘法见证的知识证明及认证的影响可被精确表述。本文为这些构造建立了计算基础和参数约束,但未声称安全归约或后量子安全性。
英文摘要
We define and study the Structured Totient Preimage (STP) problem as a restricted reconstruction relation with a direct cryptographic motivation. Let $p_1,\ldots,p_k$ be distinct primes of the same bit length and reveal only $x=\prod_{i=1}^k(p_i-1)$. Given $(x,λ,k)$, STP asks for any set of $k$ distinct $λ$-bit primes satisfying this product. The relation is efficiently verifiable, but its reconstruction complexity is not known. We establish three concrete results. First, for factored $x$ we derive the exact number of ordered exponent allocations and a bound showing that direct reconstruction is polynomial for fixed $k$ when $Ω(x)=O(\logλ)$; this rules out that regime as a basis for a strong hardness claim. Second, we give exhaustive algorithms for reconstruction and collision analysis. Third, we exhaustively evaluate 28 parameter pairs, with $2\leq k\leq5$, up to $λ=16$ for pairs and 4,588,935 prime sets in the largest census. The data quantify non-injectivity through collision participation, maximum multiplicity, and conditional ambiguity in bits. These results isolate STP from general inverse-totient computation and motivate a Structured Totient Preimage Assumption for explicitly growing parameter families. Under such an assumption, STP becomes a candidate preimage-resistant relation whose implications for commitments, proofs of knowledge of multiplicative witnesses, and authentication can be stated precisely. The paper establishes the computational foundation and parameter constraints for those constructions; it does not claim a security reduction or post-quantum hardness.