Cryptanalysis of Definite and Indefinite Lattice Isomorphism Problems with Applications to DEFI
Markus Kirschmer, Cong Ling, Ali Sadreddin
Abstract
We study the Lattice Isomorphism Problem (LIP) for both indefinite and definite quadratic forms, with applications to the DEFI signature scheme. By combining arithmetic and algorithmic techniques, we obtain efficient attacks on DEFIv2, a digital signature scheme based on isotropic quadratic forms. Our approach to the Decision Distinguishing-LIP draws on the arithmetic theory of quadratic forms, with particular emphasis on indefinite forms of dimension at least 3. We show that such forms arise naturally in the analysis of DEFI and prove that, under suitable assumptions, the genus, spinor genus, and equivalence class coincide. This structural collapse leads to a classical polynomial-time algorithm for the Decision Distinguishing-LIP instances obtained from DEFI. In addition, we present an efficient algorithm for recovering the secret key of DEFIv2 and demonstrate practical signature forgeries within minutes using the authors' public challenge instances. Finally, we evaluate the impact of our methods on HAWK and show that, in contrast to DEFI, they do not compromise its security.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Practical Post-Quantum Signature Schemes from Isomorphism Problems of Trilinear FormsGang Tang, Dung Hoang Duong, Antoine Joux, Thomas Plantard et al.EUROCRYPT 2022 · 36 citations
- On the Hardness of the Finite Field Isomorphism ProblemDipayan Das, Antoine JouxEUROCRYPT 2023 · 2 citations
- Finding Short Integer Solutions When the Modulus Is SmallLéo Ducas, Thomas Espitau, Eamonn W. PostlethwaiteCRYPTO 2023 · 18 citations
- Cryptanalysis of Rank-2 Module-LIP in Totally Real Number FieldsGuilhem Mureau, Alice Pellet-Mary, Georgii Pliatsok, Alexandre WalletEUROCRYPT 2024 · 17 citations
- Graph-Theoretic Algorithms for the Alternating Trilinear Form Equivalence ProblemWard BeullensCRYPTO 2023 · 5 citations
