Pradhan CRT-RLWE中残留受限错误的密钥恢复
Key Recovery from Residue-Confined Errors in Pradhan CRT-RLWE
浏览论文内容
中文总结 AI 辅助
研究发现Pradhan CRT-RLWE方案存在密钥恢复漏洞,其CRT转换不保留误差分布,小误差前提无法消除归约差异,单个误差系数可反驳恒等式,方案不安全且不具备对应难度保障。
中文摘要 AI 辅助
我们证明了Pradhan等人提出的CRT-FHE方案在其假设的误差分布范围内的定律下是不安全的。当公开乘数为单位时,仅通过一次环逆即可从公钥中得到秘密密钥。对于这类定律,无需秘密密钥即可从任何密文中恢复明文,且对每个乘数都具有选择明文优势1/2。我们进一步证明,从普通Ring-LWE到CRT-RLWE的转换不保留误差分布,因此无法确立CRT-RLWE至少与Ring-LWE一样困难。两种问题背后的机制是同一的:中国剩余定理(CRT)函数在模p₁p₂下约简,而其输出在模互素模数q下使用,因此在每个保零段中,p₂ℝ中的误差编码为零。定律p₂B₁如此受限,满足所述条件且解密正确。这种受限并非规模弱点:将任何基线定律按p₂缩放后,其普通Ring-LWE问题完全等价,而约简编码器会消除其产生的所有误差。归约差异是p₁p₂的倍数而非q的倍数,因此证明的小误差前提无法消除该差异,且在报告的参数下,单个误差系数即可在满足该前提的同时反驳恒等式。中心二项分布B₂以总变差距离3/8分离系数定律,且在报告的维度下,诱导多项式定律间的该距离指数趋近于1。
英文摘要
We show that the CRT-FHE scheme of Pradhan et al.\ is insecure for laws within its assumed error distribution range. The secret key follows from the public key by a single ring inversion whenever the public multiplier is a unit. The plaintext is recovered from any ciphertext under such a law without the secret key, for every multiplier, giving chosen-plaintext advantage $1/2$. We further show that the transformation from ordinary Ring-LWE to CRT-RLWE does not preserve the error distribution, so it does not establish that CRT-RLWE is at least as hard as Ring-LWE. One mechanism underlies both. The Chinese remainder theorem (CRT) function is reduced modulo $p_1p_2$ while its output is used modulo a coprime modulus $q$, so under every zero-preserving section an error in $p_2\R$ encodes to zero. The law $p_2B_1$ is so confined, meets the stated conditions, and decrypts correctly. Confinement is not a weakness of scale: scaling any baseline law by $p_2$ leaves its ordinary Ring-LWE problem exactly equivalent, while the reduced encoder destroys every error it produces. The reduction discrepancy is a multiple of $p_1p_2$ and not of $q$, so the small-error premise of the proof cannot remove it, and at the reported parameters a single error coefficient refutes the identity while satisfying that premise. The centered binomial $B_2$ separates the coefficient laws at total variation distance $3/8$, and at the reported dimension that distance between the induced polynomial laws is exponentially close to one.