Analysis of the Security of the PSSI Problem and Cryptanalysis of the Durandal Signature Scheme
Nicolas Aragon, Victor Dyseryn, Philippe Gaborit
Abstract
We present a new attack against the PSSI problem, one of the three problems at the root of security of Durandal, an efficient rank metric code-based signature scheme with a public key size of 15 kB and a signature size of 4 kB, presented at EUROCRYPT'19. Our attack recovers the private key using a leakage of information coming from several signatures produced with the same key. Our approach is to combine pairs of signatures and perform Cramer-like formulas in order to build subspaces containing a secret element. We break all existing parameters of Durandal: the two published sets of parameters claiming a security of 128 bits are broken in respectively and elementary bit operations, and the number of signatures required to finalize the attack is 1,792 and 4,096 respectively. We implemented our attack and ran experiments that demonstrated its success with smaller parameters.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 5be203a8-2907-4e6c-b801-3e665e802e04Related papers
- Graph-Theoretic Algorithms for the Alternating Trilinear Form Equivalence ProblemWard BeullensCRYPTO 2023 · 5 citations
- An Algebraic Attack on Rank Metric Code-Based CryptosystemsMagali Bardet, Pierre Briaud, Maxime Bros, Philippe Gaborit et al.EUROCRYPT 2020 · 72 citations
- FuLeakage: Breaking FuLeeca by Learning AttacksFelicitas Hörmann, Wessel P. J. van WoerdenCRYPTO 2024 · 8 citations
- Breaking Rainbow Takes a Weekend on a LaptopWard BeullensCRYPTO 2022 · 170 citations
- Highway to Hull: An Algorithm for Solving the General Matrix Code Equivalence ProblemAlain Couvreur, Christophe LevratCRYPTO 2025
