如何破解基于矩阵Gabidulin码的Miranda签名方案
How to break the Miranda signature scheme over matrix Gabidulin codes
- IRMAR, Université de Rennes(雷恩大学 IRMAR)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
针对Miranda签名方案,提出一种通过多项式时间归约为MinRank实例来恢复掩蔽矩阵Gabidulin码的Fqm-线性结构的密钥恢复攻击,使m=79时复杂度从146比特降至46比特。
AI中文摘要:
Miranda签名方案依赖于掩蔽一个矩阵码,该矩阵码具有被掩蔽的底层结构,而知晓该结构可实现高效的错误解码。我们考虑一个Gabidulin码,它被扩展为一个矩阵码,该矩阵码仅关于\Fq是线性的。随后对其施加额外的掩蔽。本文提出的攻击与文献[Le26, https://arxiv.org/abs/2608.03328]中对EGMC加密方案的攻击有相似之处,后者也遵循上述范式。该攻击通过将问题归约为在扩域\Fqm上求解的MinRank实例,来恢复被掩蔽的矩阵Gabidulin码的\Fqm-线性结构,但其中矩阵的系数属于\Fq。此类实例可被高效求解。然而,与之前的攻击不同,在Miranda签名方案的情形下,可以在多项式时间内归约到这样的MinRank实例。这导致针对Miranda所提议参数的一种特别高效的密钥恢复攻击。例如,对于提议的参数集m=79,此攻击的复杂度从146比特降至46比特。
英文摘要:
The Miranda signature scheme relies on masking a matrix code which disposes of a masked underlying structure, and the knowledge of which allows for efficient error decoding. We consider a Gabidulin code which is expanded into a matrix code, that is only \Fq-linear. An additional masking is then applied to it. The attack proposed here shares similarities with that of [Le26, https://arxiv.org/abs/2608.03328] on the EGMC encryption scheme, which also follows the paradigm described above. It consists in recovering the Fqm-linear structure of a masked matrix Gabidulin code by reducing to a MinRank instance to be solved over the extension field Fqm, but where the matrices have coefficients in Fq. Such an instance can be efficiently solved. However, unlike the previous attack, it is possible to reduce in polynomial time to such a MinRank instance in the case of the Miranda signature scheme. This results in a particularly efficient key recovery attack against the parameters proposed for Miranda. For example, for the proposed parameter set with m=79, the complexity drops from 146 bits to 46 bits in this attack.