Lune

EUROCRYPT2021顶会

Cryptanalytic Applications of the Polynomial Method for Solving Multivariate Equation Systems over GF(2)

Itai Dinur

2021年份
58被引次数
3顶会引用

摘要

At SODA 2017 Lokshtanov et al. presented the first worst-case algorithms with exponential speedup over exhaustive search for solving polynomial equation systems of degree dd in nn variables over finite fields. These algorithms were based on the polynomial method in circuit complexity which is a technique for proving circuit lower bounds that has recently been applied in algorithm design. Subsequent works further improved the asymptotic complexity of polynomial method-based algorithms for solving equations over the field F2\mathbb{F}_2. However, the asymptotic complexity formulas of these algorithms hide significant low-order terms, and hence they outperform exhaustive search only for very large values of nn.

In this paper, we devise a concretely efficient polynomial method-based algorithm for solving multivariate equation systems over F2\mathbb{F}_2. We analyze our algorithm's performance for solving random equation systems, and bound its complexity by about n2⋅20.815nn^2 \cdot 2^{0.815n} bit operations for d=2d = 2 and n2⋅2(1−1/2.7d)nn^2 \cdot 2^{\left(1 - 1/2.7d\right) n} for any d≥2d \geq 2.

We apply our algorithm in cryptanalysis of recently proposed instances of the Picnic signature scheme (an alternate third-round candidate in NIST's post-quantum standardization project) that are based on the security of the LowMC block cipher. Consequently, we show that 2 out of 3 new instances do not achieve their claimed security level. As a secondary application, we also improve the best-known preimage attacks on several round-reduced variants of the Keccak hash function.

Our algorithm combines various techniques used in previous polynomial method-based algorithms with new optimizations, some of which exploit randomness assumptions about the system of equations. In its cryptanalytic application to Picnic, we demonstrate how to further optimize the algorithm for solving structured equation systems that are constructed from specific cryptosystems.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

lune papers get c795d182-48ea-4e6a-a94a-5f4b03a06b1d

引用它的顶会 Paper3

问问它们各自怎么用它

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖