Cryptanalysis of the revised NTRU signature scheme

被引:0
|
作者
Gentry, C [1 ]
Szydlo, M
机构
[1] DoCoMo USA Labs, San Jose, CA USA
[2] RSA Labs, Bedford, MA USA
关键词
NSS; NTRU; NTRUSign; signature scheme; lattice reduction; cryptanalysis; orthogonal lattice; cyclotomic integer; galois congruence;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In this paper, we describe a three-stage attack against Revised NSS, an NTRU-based signature scheme proposed at the Eurocrypt 2001 conference as an enhancement of the (broken) proceedings version of the scheme. The first stage, which typically uses a transcript of only 4 signatures, effectively cuts the key length in half while completely avoiding the intended hard lattice problem. After an empirically fast second stage, the third stage of the attack combines lattice-based and congruence-based methods in a novel way to recover the private key in polynomial time. This cryptanalysis shows that a passive adversary observing only a few valid signatures can recover the signer's entire private key. We also briefly address the security of NTRUSign, another NTRU-based signature scheme that was recently proposed at the rump session of Asiacrypt 2001. As we explain, some of our attacks on Revised NSS may be extended to NTRUSign, but a much longer transcript is necessary. We also indicate how the security of NTRUSign is based on the hardness of several problems, not solely on the hardness of the usual NTRU lattice problem.
引用
收藏
页码:299 / 320
页数:22
相关论文
共 50 条
  • [1] Cryptanalysis of Wang's original and revised digital signature scheme
    Dai, ZD
    Yang, JH
    Ye, DF
    Gong, G
    ELECTRONICS LETTERS, 2001, 37 (04) : 220 - 220
  • [2] Cryptanalysis of the SHMW signature scheme
    Lau, Terry Shue Chien
    Ariffin, Muhammad Rezal Kamel
    Yip, Sook-Chin
    Chin, Ji-Jian
    Ting, Choo-Yee
    HELIYON, 2024, 10 (02)
  • [3] Cryptanalysis of the SNOVA Signature Scheme
    Li, Peigen
    Ding, Jintai
    POST-QUANTUM CRYPTOGRAPHY, PQCRYPTO 2024, PT II, 2024, 14772 : 79 - 91
  • [4] Cryptanalysis of the SFLASH signature scheme
    Dubois, Vivien
    Fouque, Pierre-Alain
    Shamir, Adi
    Stern, Jacques
    INFORMATION SECURITY AND CRYPTOLOGY, 2008, 4990 : 1 - 4
  • [5] Efficient Certificateless Signature Scheme on NTRU Lattice
    Xie, Jia
    Hu, Yupu
    Gao, Juntao
    Gao, Wen
    Jiang, Mingming
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2016, 10 (10): : 5190 - 5208
  • [6] Cryptanalysis of Quantum Blind Signature Scheme
    Zuo, Huijuan
    INTERNATIONAL JOURNAL OF THEORETICAL PHYSICS, 2013, 52 (01) : 322 - 329
  • [7] Cryptanalysis and improvement of a group signature scheme
    College of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, China
    Tien Tzu Hsueh Pao, 2007, 4 (778-781):
  • [8] Cryptanalysis of the oil and vinegar signature scheme
    Kipnis, A
    Shamir, A
    ADVANCES IN CRYPTOLOGY - CRYPTO'98, 1998, 1462 : 257 - 266
  • [9] Cryptanalysis of Quantum Blind Signature Scheme
    Huijuan Zuo
    International Journal of Theoretical Physics, 2013, 52 : 322 - 329
  • [10] Fault cryptanalysis of ElGamal signature scheme
    Biernat, J
    Nikodem, M
    COMPUTER AIDED SYSTEMS THEORY - EUROCAST 2005, 2005, 3643 : 327 - 336