AI 中文总结
该研究提出自主密码分析工作流,发现八项已发表密码构造在声明参数或属性上失效,还指出两类失效模式及其他相关问题。
AI 中文摘要
我们提出了一种自主密码分析工作流,其中智能体在人工审核前生成、测试并完善假设。自主阶段返回可复现的候选结果,包含确切的见证、控制项、代码及运行记录,之后研究人员会判定证据是否足以证明存在破解、缺陷或覆盖缺口。两种失效模式反复出现:一是公开代数映射或输入表示会擦除或暴露构造必须隐藏的关系,示例包括零乘法、多项式乘积的边界系数、商、特征、Schur平方以及无边界的可变长度字节编码;二是模拟器、误差定律或参数认证使用的分布与声明的分布不同。多个目标在这两种模式下均失效。所有结果都有确切见证和可区分的控制项,所有声明的边界都有证明。另有三个目标未产生攻击,但支持的保证比通用解读所暗示的更窄。八项已发表的构造在声明的参数或声明上失效:一项Ring-LWR承诺以概率1打开到任意消息;一项密文泄露两个中间乘积加密行;一个格型电子投票协议失去收据隐私性;针对可更新加密的置换恢复攻击通过线性代数扩展到旧解密密钥;一个显式正规基将63次实例拆分为七个9次实例;格型设置外的签名哈希将两个可打印的等长消息映射到同一摘要;可重随机化方案的接受位是其解密噪声上的阈值预言机。此外,一项群环判定声明和一项多元MinRank加固在假设或核算层面失效,而非作为完整构造的破解,每种失效都发生在其支持假设之上的一个层级。
英文摘要
We present an autonomous cryptanalysis workflow in which agents generate, test, and refine hypotheses before human review. The autonomous stage returns reproducible candidates with exact witnesses, controls, code, and run records. A researcher then decides whether the evidence establishes a break, defect, or coverage gap. Two failure modes recur. First, a public algebraic map or input representation erases or exposes a relation that a construction must hide. Examples include multiplication by zero, boundary coefficients of a polynomial product, quotients, characters, Schur squares, and variable-length byte encodings without boundaries. Second, a simulator, error law, or parameter certification uses a distribution different from the one claimed. Several targets fail in both ways. Every result has an exact witness and a discriminating control; every stated boundary has a proof. Three further targets yielded no attack but support narrower guarantees than a generic reading suggests. Eight published constructions fail at stated parameters or claims. A Ring-LWR commitment opens to every message with probability one. One ciphertext reveals two middle-product encryption rows. A lattice e-voting protocol loses receipt-freeness. A permutation-recovery attack against updatable encryption extends by linear algebra to the old decryption key. An explicit normal basis splits a degree-63 instance into seven degree-nine instances. A signature hash outside the lattice setting maps two printable equal-length messages to the same digest. A rerandomisable scheme's accept bit is a threshold oracle on its decryption noise. Separately, a group-ring decision claim and a multivariate MinRank hardening fail at the assumption or accounting level rather than as complete construction breaks. Each failure occurs one level above its supporting assumption.