The Algebraic FreeLunch: Efficient Gröbner Basis Attacks Against Arithmetization-Oriented Primitives
Augustin Bariant, Aurélien Boeuf, Axel Lemoine, Irati Manterola Ayala, Morten Øygarden, Léo Perrin, Håvard Raddum
摘要
. In this paper, we present a new type of algebraic attack that applies to many recent arithmetization-oriented families of permutations, such as those used in Griffin , Anemoi , ArionHash , and XHash8 , whose security relies on the hardness of the constrained-input constrained-output (CICO) problem. We refer to the attack as the FreeLunch approach: the monomial ordering is chosen so that the natural polynomial system encoding the CICO problem already is a Gröbner basis. In addition, we present a new dedicated resolution algorithm for FreeLunch systems of complexity lower than current state-of-the-art resolution algorithms. We show that the FreeLunch approach challenges the security of full-round instances of Anemoi , Arion and Griffin , and we experimentally confirm these theoretical results. In particular, combining the FreeLunch attack with a new technique to bypass 3 rounds of Griffin , we recover a CICO solution for 7 out of 10 rounds of Griffin in less than four hours on one core of AMD EPYC 7352 (2.3GHz).
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Transistor: a TFHE-Friendly Stream CipherJules Baudrin, Sonia Belaïd, Nicolas Bon, Christina Boura 等CRYPTO 2025 · 被引用 6 次
- Improved Resultant Attack Against Arithmetization-Oriented PrimitivesAugustin Bariant, Aurélien Boeuf, Pierre Briaud, Maël Hostettler 等CRYPTO 2025 · 被引用 4 次
它引用的顶会 Paper4
- Rubato: Noisy Ciphers for Approximate Homomorphic EncryptionJincheol Ha, Seongkwang Kim, ByeongHak Lee, Jooyoung Lee 等EUROCRYPT 2022 · 被引用 44 次
- Horst Meets Fluid-SPN: Griffin for Zero-Knowledge ApplicationsLorenzo Grassi, Yonglin Hao, Christian Rechberger, Markus Schofnegger 等CRYPTO 2023 · 被引用 38 次
- Chaghri - A FHE-friendly Block CipherTomer Ashur, Mohammad Mahzoun, Dilara ToprakhisarCCS 2022 · 被引用 31 次
- Effective and Efficient Masking with Low Noise Using Small-Mersenne-Prime CiphersLoïc Masure, Pierrick Méaux, Thorben Moos, François-Xavier StandaertEUROCRYPT 2023 · 被引用 20 次
相关 Paper
- New Design Techniques for Efficient Arithmetization-Oriented Hash Functions: ttAnemoi Permutations and ttJive Compression ModeClémence Bouvier, Pierre Briaud, Pyrros Chaidos, Léo Perrin 等CRYPTO 2023 · 被引用 37 次
- Gröbner Basis Cryptanalysis of AnemoiLuca Campa, Arnab RoyEUROCRYPT 2025 · 被引用 1 次
- Coefficient Grouping: Breaking Chaghri and MoreFukang Liu, Ravi Anand, Libo Wang, Willi Meier 等EUROCRYPT 2023 · 被引用 24 次
- Meet-in-the-Middle Attacks Revisited: Key-Recovery, Collision, and Preimage AttacksXiaoyang Dong, Jialiang Hua, Siwei Sun, Zheng Li 等CRYPTO 2021 · 被引用 54 次
- Graeffe-Based Attacks on Poseidon and NTT Lower BoundsZiyu Zhao, Antonio Sanso, Giuseppe Vitto, Jintai DingCRYPTO 2026 · 被引用 2 次
