arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

超越显式生成器:对公钥加密的无分布线性分解攻击

Beyond Explicit Generators: Distribution-Free Linear-Decomposition Attacks on Public-Key Encryption

Ziyan Chen, Ding-Xuan Zhou

arXiv 2608.20798首次发表:更新:

AI 中文总结

本文提出针对公钥加密的无分布线性分解攻击框架,将其应用于2024年基于扭曲斜群环的概率PKE,实现明文恢复与恒定IND-CPA优势,通过实验验证了攻击有效性。

AI 中文摘要

线性分解攻击可在不恢复秘密代数作用的情况下破解公钥方案:当目标公开状态位于已知线性张成空间中时,其分解系数会通过未知作用传递以揭示共享值。我们研究的场景中,敌手仅使用诚实参与者可用的公开采样与评估预言机,诱导的分布是任意的,目标是攻击未来密文而非恢复完整代数张成空间。我们在固定秘密线性传输下对公开配对样本建模,将采样轨道维度定义为加密分布的有效维度。我们证明了无分布单次恢复、采样张成空间对未来密文覆盖的高概率证明,以及最优采样张成复杂度 $m^\text{\star}_\text{span}(r,\varepsilon,\delta)=\Theta((r+\log(1/\delta))/\varepsilon)$。这些结果得出一个通用不可能性定理:当传输值决定解密载荷时,具有多项式采样轨道维度的可公开采样线性密钥传输与IND-CPA安全性不兼容。我们将该框架应用于2024年基于扭曲斜群环的概率PKE,其底层计算扭曲斜问题允许使用独立生成的公开协议样本进行仅采样的线性攻击,实现明文恢复和恒定IND-CPA优势。实验验证了线性传输和端到端恢复,显示在完整代数张成空间恢复前可能出现高未来密文覆盖。

英文摘要

Linear-decomposition attacks can break public-key schemes without recovering the secret algebraic action: when a target public state lies in a known linear span, its decomposition coefficients transfer through the unknown action to reveal the shared value. We study a setting in which the adversary uses only the public sampling-and-evaluation oracle available to honest participants, the induced distribution is arbitrary, and the goal is to attack future ciphertexts rather than recover the full algebraic span. We model public paired samples under a fixed secret linear transport and define the sampled-orbit dimension as the effective dimension of the encryption distribution. We prove distribution-free one-shot recovery, a high-probability certificate for the future-ciphertext coverage of a sampled span, and the optimal sampled-span complexity $m^\star_{\mathrm{span}}(r,\varepsilon,δ) =Θ((r+\log(1/δ))/\varepsilon)$. These results yield a generic impossibility theorem: publicly samplable linear key transport with polynomial sampled-orbit dimension is incompatible with IND--CPA security when the transported value determines the decryption payload. We apply the framework to the 2024 probabilistic PKE from twisted--skew group rings. Its underlying Computational Twisted--Skew Problem admits a sampler-only linear attack using independently generated public protocol samples, yielding plaintext recovery and constant IND--CPA advantage. Experiments verify the linear transport and end-to-end recovery, and show that high future-ciphertext coverage may precede recovery of the full algebraic span.

Comments15 pages, 5 figures

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑