arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Z-Sigil:一种基于模格密钥纤维丛上链式选择的公钥密码系统

Z-Sigil: A Public-Key Cryptosystem with Chained Selection over a Fiber Bundle of Module-Lattice Keys

Andrea Rondelli

arXiv 2609.38668首次发表:更新:

发表机构

Z-Sigil SRL(Z-Sigil有限责任公司)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

提出Z-Sigil公钥密码系统,利用模格密钥纤维丛上的链式选择机制,在判定性模块LWE假设下证明量子对手下的IND-CPA安全性,并给出噪声预算与验证规范。

AI 中文摘要

Z-Sigil是一种公钥密码系统,其中明文从固定的模格族中选择连续的密钥。消息经过长度前缀、零填充,并划分为32字节的块。每个公开向量是共享公开矩阵作用于一个小秘密向量,再加上一个小误差。密钥索引标记平坦Kähler环面的挠点;秘密族构成这些点上的密钥丛的一个截面。公开随机数初始化一个哈希状态,该状态选择每个块的密钥和位掩码。发送方用明文块更新状态;接收方在恢复明文块后也进行更新。流和随机数确定一个离散游走,解密沿此游走读取秘密截面。我们详细说明算法,在明确的噪声条件下证明正确性,并为公钥后选择的消息界定解码失败概率。在所述的判定性模块LWE假设下,我们建立了链的IND-CPA保密性,而无需将状态哈希建模为随机预言机。该归约涵盖量子硬度假设下的量子对手,使用经典密钥、消息和密文;未建立具体安全级别。在独立均匀选择器下,受限直接解密模型量化了部分密钥暴露下片段恢复的减少,而未提高相对于独立块基线的全消息恢复概率。已知明文和候选消息攻击,以及并行候选表解密,界定了这一结果。既未建立通用顺序下界,也未建立认证或选择密文安全性。取代先前暴露标量的提议,我们给出增广格解释、积分输运障碍和噪声预算,用于弯曲非平凡丛的研究。字节级规范、伪代码、测试向量和数值检查支持验证。

英文摘要

Z-Sigil is a public-key cryptosystem in which the plaintext selects successive keys from a fixed module-lattice family. Messages are length-prefixed, zero-padded and divided into 32-byte blocks. Each public vector is a shared public matrix applied to a small secret vector, plus a small error. Key indices label torsion points of a flat Kähler torus; the secret family forms a section of a key bundle over them. A public nonce initializes a hash state that selects each block's key and bit mask. The sender updates the state with the plaintext block; the receiver does so after recovering it. The stream and nonce determine a discrete walk along which decryption reads the secret section. We specify the algorithms, prove correctness under an explicit noise condition and bound decoding failure for messages chosen after the public key. Under stated decisional Module-LWE assumptions, we establish IND-CPA confidentiality for the chain without modelling the state hash as a random oracle. The reduction covers quantum adversaries under quantum hardness assumptions, with classical keys, messages and ciphertexts; no concrete security level is established. With independent uniform selectors, a restricted direct-decryption model quantifies reduced fragment recovery under partial key exposure, without improving full-message recovery probability over an independent-block baseline. Known-plaintext and candidate-message attacks, and parallel candidate-table decryption, delimit this result. Neither a universal sequential lower bound nor authentication or chosen-ciphertext security is established. Replacing an earlier scalar-exposing proposal, we give an augmented-lattice interpretation, integral-transport obstructions and a noise budget for research on curved, nontrivial bundles. A byte-level specification, pseudocode, test vectors and numerical checks support verification.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑