arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.26132cs.CR

高阶消失密钥恢复的Zeta变换评估

Zeta-Transform Evaluation for Higher-Order Vanishing Key Recovery

  • Korea University(韩国大学)
  • Nanyang Technological University(南洋理工大学)

机构由 AI 辅助整理,请以论文原文为准。

Sunyeop Kim, Insung Kim

AI总结:

本文针对Classic McEliece的高阶消失密钥恢复,提出将核计算中的求和转化为布尔格上的截断Zeta变换,从而降低矩阵-向量乘积成本,在两种模型下分别减少14.09-41.19比特和7.25-22.48比特的密钥恢复成本。

AI中文摘要:

Hemmert针对Classic McEliece的密钥恢复算法基于高阶消失。该算法计算$\ker(\widetilde\varphi_A^{(p)})$的一组基,其中$A=H'''$是攻击中使用的缩短校验矩阵。对于Classic McEliece参数,该核计算是攻击的主要成本。我们证明,定义$\widetilde\varphi_A^{(p)}$的和可以逐列地作为布尔格上的加权上Zeta变换进行评估。由于$\widetilde\varphi_A^{(p)}$仅需要这些变换的选定层级,将评估限制在第$p$层与最低所需层级之间的带状区域,即可精确评估$\widetilde\varphi_A^{(p)}$及其转置。在基于Wiedemann的核计算中使用由此得到的截断Zeta变换评估,可降低重复矩阵-向量乘积的成本,而不改变整体密钥恢复算法。确切成本取决于$H'''$的非主元列的权重分布。因此,我们考虑两种模型:全一模型,其中每个相关二进制坐标均为活跃;以及Bernoulli$(1/2)$模型,其中坐标以概率$1/2$独立活跃。对于五组Classic McEliece参数,我们的方法在全一模型中将估计的密钥恢复成本降低了$14.09$至$41.19$比特,在Bernoulli$(1/2)$模型中将成本降低了$7.25$至$22.48$比特。

英文摘要:

Hemmert's key-recovery algorithm for Classic McEliece is based on higher-order vanishing. It computes a basis of $\ker(\widetildeφ_A^{(p)})$, where $A=H'''$ is the shortened parity-check matrix used in the attack. For Classic McEliece parameters, this kernel computation is the dominant cost of the attack. We show that the sums defining $\widetildeφ_A^{(p)}$ can be evaluated, column by column, as weighted upper zeta transforms on the Boolean lattice. Since only selected levels of these transforms are required by $\widetildeφ_A^{(p)}$, restricting their evaluation to the band between level $p$ and the lowest required level yields exact evaluations of both $\widetildeφ_A^{(p)}$ and its transpose. Using the resulting truncated zeta-transform evaluation in the Wiedemann-based kernel computation reduces the cost of the repeated matrix--vector products without changing the overall key-recovery algorithm. The exact cost depends on the weight distribution of the non-pivot columns of $H'''$. We therefore consider two models: an all-one model, in which every relevant binary coordinate is active, and a Bernoulli$(1/2)$ model, in which the coordinates are independently active with probability $1/2$. For the five Classic McEliece parameter sets, our method reduces the estimated key-recovery cost by $14.09$--$41.19$ bits in the all-one model and by $7.25$--$22.48$ bits in the Bernoulli$(1/2)$ model.

补充信息

↑