发表机构
Hefei National Laboratory, Hefei, China(合肥国家实验室)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对NIST第三轮全部七个格候选族,提出可证明的经典次指数秘密恢复算法,基于Wagner式高斯采样框架等技术,可在期望时间与空间内恢复短秘密分量,但未证明当前参数集具体安全性降低。
AI 中文摘要
我们针对与NIST第三轮格候选相关的增长参数族的秘密恢复问题,给出了可证明的经典次指数算法。对于本文研究的Kyber/ML-KEM、FrodoKEM、SABER、NTRU LPRime和Dilithium/ML-DSA族,多项式模和多对数系数尺度可在期望时间与空间$2^{(1/2+o(1))n/\text{ln ln }n}$内恢复短秘密分量。对于含噪或取整的线性关系,我们利用由每个坐标猜测定义的比较向量的平方欧氏范数中的精确间隙,仅需一个高斯列表即可通过二分法识别每个秘密坐标,无需枚举其他坐标。我们通过针对素数模和2的幂模上结构化公开算子的新几何界,建立所需的采样保证。该构造基于Ducas、Engelberts和Loyer(CRYPTO 2025)的Wagner式高斯采样框架,以及Han、Gao和Hu(2026)的低误差决策-LWE算法。对于NTRU型的商关系,我们提出仿射切片搜索:固定坐标可将候选对限制在公开格的切片中,其估计高斯质量指导每个后续坐标的选择。在所述模窗口内,Falcon的密钥生成质量条件提供所需的质量界。该算法随后可在时间与空间$2^{O(n/\text{ln ln }n)}$内以高概率恢复等效签名密钥,相同搜索还可恢复循环NTRU-HPS/HRSS的短密钥核心。综上,这些结果为与所有七个NIST第三轮格候选相关的问题族提供了次指数算法。尽管复杂度为次指数,但我们的结果并未证明当前指定参数集的具体安全性降低。
英文摘要
We give provable classical subexponential algorithms for secret recovery in growing parameter families associated with NIST third-round lattice candidates. For the Kyber/ML-KEM, FrodoKEM, SABER, NTRU LPRime, and Dilithium/ML-DSA families studied here, polynomial moduli and polylogarithmic coefficient scales yield recovery of the short secret component in expected time and space $2^{(1/2+o(1))n/\ln\ln n}$. For noisy or rounded linear relations, we exploit an exact gap in the squared Euclidean norm of a comparison vector defined by each coordinate guess. One Gaussian list suffices to identify every secret coordinate by binary search, without enumerating the others. We establish the required sampling guarantees through new geometric bounds for structured public operators over prime and power of two moduli. The construction builds on the Wagner-style Gaussian sampling framework of Ducas, Engelberts, and Loyer (CRYPTO 2025) and the low-error decision-LWE algorithm of Han, Gao, and Hu (2026). For quotient relations of NTRU type, we develop an affine slice search: fixing coordinates restricts candidate pairs to slices of the public lattice, and their estimated Gaussian masses guide the choice of each next coordinate. In the stated modulus window, Falcon's key generation quality condition supplies the required mass bound. The algorithm then recovers an equivalent signing key with high probability in time and space $2^{O(n/\ln\ln n)}$. The same search recovers the short key core for cyclic NTRU-HPS/HRSS. Together, these results give subexponential algorithms for problem families associated with all seven NIST third-round lattice candidates. Despite the subexponential complexity, our results do not establish a reduction in the concrete security of the currently specified parameter sets.