Total Break of the IC Signature Scheme
17 pages
English

Découvre YouScribe en t'inscrivant gratuitement

Je m'inscris

Total Break of the IC Signature Scheme

Découvre YouScribe en t'inscrivant gratuitement

Je m'inscris
Obtenez un accès à la bibliothèque pour le consulter en ligne
En savoir plus
17 pages
English
Obtenez un accès à la bibliothèque pour le consulter en ligne
En savoir plus

Description

Total Break of the -IC Signature Scheme Pierre-Alain Fouque1, Gilles Macario-Rat2, Ludovic Perret3, and Jacques Stern1 1 ENS/CNRS/INRIA , 2 Orange Labs 3 UMPC/LIP6/SPIRAL & INRIA/SALSA Abstract. In this paper, we describe efficient forgery and full-key re- covery attacks on the -IC? signature scheme recently proposed at PKC 2007. This cryptosystem is a multivariate scheme based on a new internal quadratic primitive which avoids some drawbacks of previous multivari- ate schemes: the scheme is extremely fast since it requires one exponen- tiation in a finite field of medium size and the public key is shorter than in many multivariate signature schemes. Our attacks rely on the recent cryptanalytic tool developed by Dubois et al. against the SFLASH sig- nature scheme. However, the final stage of the attacks require the use of Grobner basis techniques to conclude to actually forge a signature (resp. to recover the secret key). For the forgery attack, this is due to the fact that Patarin's attack is much more difficult to mount against -IC. The key recovery attack is also very efficient since it is faster to recover equivalent secret keys than to forge.

  • can perform

  • f4 can

  • linear mappings

  • scheme

  • public key

  • ic? scheme

  • grobner basis

  • f5 algorithms

  • algebra problems


Sujets

Informations

Publié par
Nombre de lectures 17
Langue English

Extrait

TotalBreakofthe`-ICSignatureSchemePierre-AlainFouque1,GillesMacario-Rat2,LudovicPerret3,andJacquesStern11ENS/CNRS/INRIAPierre-Alain.Fouque@ens.fr,Jacques.Stern@ens.fr2OrangeLabsgilles.macariorat@orange-ftgroup.com3UMPC/LIP6/SPIRAL&INRIA/SALSAludovic.perret@lip6.frAbstract.Inthispaper,wedescribeefficientforgeryandfull-keyre-coveryattacksonthe`-ICsignatureschemerecentlyproposedatPKC2007.Thiscryptosystemisamultivariateschemebasedonanewinternalquadraticprimitivewhichavoidssomedrawbacksofpreviousmultivari-ateschemes:theschemeisextremelyfastsinceitrequiresoneexponen-tiationinafinitefieldofmediumsizeandthepublickeyisshorterthaninmanymultivariatesignatureschemes.OurattacksrelyontherecentcryptanalytictooldevelopedbyDuboisetal.againsttheSFLASHsig-naturescheme.However,thefinalstageoftheattacksrequiretheuseofGro¨bnerbasistechniquestoconcludetoactuallyforgeasignature(resp.torecoverthesecretkey).Fortheforgeryattack,thisisduetothefactthatPatarin’sattackismuchmoredifficulttomountagainst`-IC.Thekeyrecoveryattackisalsoveryefficientsinceitisfastertorecoverequivalentsecretkeysthantoforge.1IntroductionMultivariatecryptographyproposesefficientcryptographicschemeswell-suitedforlowcomputationaldevices.Sincetheunderlyingproblemisnotknowntobeeasyinthequantummodel,theseschemeshavebeenconsideredbystandard-izationbodiesasalternativestoRSAorDLogbasedschemes.Forinstance,in2003,onepromisingsignaturescheme,calledSFLASH,hasbeenselectedbytheNESSIEproject.SFLASHisbasedontheCcryptosystem[20]proposedbyMatsumotoandImaiin1988andbrokenbyPatarinin1995[21].FollowinganideaofShamir[25],Patarin,GoubinandCourtoisproposedSFLASH[24]byremovingsomeequationsofthesystem.TheschemeisalsocalledC∗−andthegenerictransformationofremovingequationsiscalledthe“Minus”transforma-tionwhichcanbeappliedtomanymultivariateschemes.Multivariatecryptographyprovidespublic-keycryptosystemswhosesecurityisrelatedtotheproblemofsolvingsystemsofquadraticorhigherdegreeequa-tionsinmanyvariables.ThisproblemisknowntobeNP-hardanditseemstobealsodifficultonaverage.ThetodaymostefficientalgorithmstosolvethisgenericproblemareGro¨bnerbasisalgorithmswhosecomplexityisexponential44forsystemswithafinitenumberofsolutions.
  • Univers Univers
  • Ebooks Ebooks
  • Livres audio Livres audio
  • Presse Presse
  • Podcasts Podcasts
  • BD BD
  • Documents Documents