Cryptanalysis of Symmetric Primitives over Rings and a Key Recovery Attack on Rubato
Lorenzo Grassi, Irati Manterola Ayala, Martha Norberg Hovd, Morten Øygarden, Håvard Raddum, Qingju Wang
Abstract
Symmetric primitives are a cornerstone of cryptography, and have traditionally been defined over fields, where cryptanalysis is now well understood. However, a few symmetric primitives defined over rings Z_q for a composite number q have recently been proposed, a setting where security is much less studied. In this paper we focus on studying established algebraic attacks typically defined over fields and the extent of their applicability to symmetric primitives defined over the ring of integers modulo a composite q. Based on our analysis, we present an attack on full Rubato, a family of symmetric ciphers proposed by Ha et al. at Eurocrypt 2022 designed to be used in a transciphering framework for approximate fully homomorphic encryption. We show that at least 25% of the possible choices for q satisfy certain conditions that lead to a successful key recovery attack with complexity significantly lower than the claimed security level for five of the six ciphers in the Rubato family.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get d82a7b60-0d5e-4921-8732-9f9f53116d90Cited by top-tier papers1
Ask how each one uses itRelated papers
- The ABC of Symmetric Primitives over Integer Rings: Milk Before MeatTim Beyne, Lorenzo Grassi, Morten Øygarden, Berenika Richterová et al.CRYPTO 2026
- Rubato: Noisy Ciphers for Approximate Homomorphic EncryptionJincheol Ha, Seongkwang Kim, ByeongHak Lee, Jooyoung Lee et al.EUROCRYPT 2022 · 44 citations
- Block Ciphers in Idealized Models: Automated Proofs and New Security ResultsMiguel Ambrona, Pooya Farshim, Patrick HarasserCCS 2024
- Coefficient Grouping: Breaking Chaghri and MoreFukang Liu, Ravi Anand, Libo Wang, Willi Meier et al.EUROCRYPT 2023 · 24 citations
- Coefficient Grouping for Complex Affine LayersFukang Liu, Lorenzo Grassi, Clémence Bouvier, Willi Meier et al.CRYPTO 2023 · 10 citations
