Cryptanalysis of the revised NTRU signature scheme

被引:0
|
作者
Gentry, C [1 ]
Szydlo, M
机构
[1] DoCoMo USA Labs, San Jose, CA USA
[2] RSA Labs, Bedford, MA USA
来源
ADVANCES IN CRYPTOLOGY - EUROCRYPT 2002, PROCEEDINGS | 2002年 / 2332卷
关键词
NSS; NTRU; NTRUSign; signature scheme; lattice reduction; cryptanalysis; orthogonal lattice; cyclotomic integer; galois congruence;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In this paper, we describe a three-stage attack against Revised NSS, an NTRU-based signature scheme proposed at the Eurocrypt 2001 conference as an enhancement of the (broken) proceedings version of the scheme. The first stage, which typically uses a transcript of only 4 signatures, effectively cuts the key length in half while completely avoiding the intended hard lattice problem. After an empirically fast second stage, the third stage of the attack combines lattice-based and congruence-based methods in a novel way to recover the private key in polynomial time. This cryptanalysis shows that a passive adversary observing only a few valid signatures can recover the signer's entire private key. We also briefly address the security of NTRUSign, another NTRU-based signature scheme that was recently proposed at the rump session of Asiacrypt 2001. As we explain, some of our attacks on Revised NSS may be extended to NTRUSign, but a much longer transcript is necessary. We also indicate how the security of NTRUSign is based on the hardness of several problems, not solely on the hardness of the usual NTRU lattice problem.
引用
收藏
页码:299 / 320
页数:22
相关论文
共 50 条
  • [21] Cryptanalysis of LRainbow: The Lifted Rainbow Signature Scheme
    Srivastava, Vikas
    Debnath, Sumit Kumar
    PROVABLE AND PRACTICAL SECURITY, PROVSEC 2021, 2021, 13059 : 296 - 308
  • [22] Cryptanalysis of the TRMS signature scheme of PKC'05
    Bettale, Luk
    Faugere, Jean-Charles
    Perret, Ludovic
    PROGRESS IN CRYPTOLOGY - AFRICACRYPT 2008, 2008, 5023 : 143 - 155
  • [23] CRYPTANALYSIS OF CERTAIN VARIANTS OF RABINS SIGNATURE SCHEME
    SHAMIR, A
    SCHNORR, CP
    INFORMATION PROCESSING LETTERS, 1984, 19 (03) : 113 - 115
  • [24] Cryptanalysis of an NTRU-Based Proxy Encryption Scheme from ASIACCS'15
    Liu, Zhen
    Pan, Yanbin
    Zhang, Zhenfei
    POST-QUANTUM CRYPTOGRAPHY, PQCRYPTO 2019, 2019, 11505 : 153 - 166
  • [25] Cryptanalysis of a certificateless signature scheme without pairings
    Tian, Miaomiao
    Huang, Liusheng
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2013, 26 (11) : 1375 - 1381
  • [26] Cryptanalysis and improvement of a certificateless aggregate signature scheme
    Cheng, Lin
    Wen, Qiaoyan
    Jin, Zhengping
    Zhang, Hua
    Zhou, Liming
    INFORMATION SCIENCES, 2015, 295 : 337 - 346
  • [27] DSA signature scheme immune to the fault cryptanalysis
    Nikodem, Maciej
    SMART CARD RESEARCH AND ADVANCED APPLICATIONS, PROCEEDINGS, 2008, 5189 : 61 - 73
  • [28] Cryptanalysis and Improvement of an Efficient Certificateless Signature Scheme
    Wu, Chenhuang
    Lan, Xiaolin
    Zhang, Jinhui
    Chen, Zhixiong
    NETWORK COMPUTING AND INFORMATION SECURITY, 2012, 345 : 221 - 228
  • [29] Cryptanalysis and improvement of a new proxy signature scheme
    Lu, Rong-Bo
    He, Da-Ke
    Wang, Chang-Ji
    Miao, Xiang-Hua
    Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2007, 29 (10): : 2529 - 2532
  • [30] Cryptanalysis and improvement of an efficient certificateless signature scheme
    Li, Jiguo
    Huang, Xinyi
    Mu, Yi
    Wu, Wei
    JOURNAL OF COMMUNICATIONS AND NETWORKS, 2008, 10 (01) : 10 - 17