<p>The paper analyzes the security of two recently proposed code-based cryptosystems that employ encryption of the form <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10623_2025_1683_Article_IEq1.gif" Format="GIF" Height="19" Rendition="HTML" Resolution="72" Type="Linedraw" Width="139" /> </InlineMediaObject> <EquationSource Format="TEX">\(y = m G_{\texttt {pub}} + eE_{\texttt {pub}}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi>y</mi> <mo>=</mo> <mi>m</mi> <msub> <mi>G</mi> <mi mathvariant="monospace">pub</mi> </msub> <mo>+</mo> <mi>e</mi> <msub> <mi>E</mi> <mi mathvariant="monospace">pub</mi> </msub> </mrow> </math></EquationSource> </InlineEquation>: the Krouk–Kabatiansky–Tavernier (KKT) cryptosystem and the Lau-Ivanov-Ariffin-Chin-Yap (LIACY) cryptosystem. We demonstrate that the KKT cryptosystem can be efficiently reduced to a variant of the McEliece scheme, where a small set of columns in the public generator matrix is replaced with random ones. This reduction implies that the KKT cryptosystem is vulnerable to existing attacks on Wieschebrink’s encryption scheme, particularly when Generalized Reed-Solomon (GRS) codes are used. In addition, we present a full polynomial-time key-recovery attack on the LIACY cryptosystem by exploiting its linear-algebraic structure and leveraging distinguishers of subcodes of GRS codes. Our findings reveal critical vulnerabilities in both systems, effectively compromising their security despite their novel designs.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

On the security of two IKKR-type code-based cryptosystems

  • Kirill Vedenev

摘要

The paper analyzes the security of two recently proposed code-based cryptosystems that employ encryption of the form \(y = m G_{\texttt {pub}} + eE_{\texttt {pub}}\) y = m G pub + e E pub : the Krouk–Kabatiansky–Tavernier (KKT) cryptosystem and the Lau-Ivanov-Ariffin-Chin-Yap (LIACY) cryptosystem. We demonstrate that the KKT cryptosystem can be efficiently reduced to a variant of the McEliece scheme, where a small set of columns in the public generator matrix is replaced with random ones. This reduction implies that the KKT cryptosystem is vulnerable to existing attacks on Wieschebrink’s encryption scheme, particularly when Generalized Reed-Solomon (GRS) codes are used. In addition, we present a full polynomial-time key-recovery attack on the LIACY cryptosystem by exploiting its linear-algebraic structure and leveraging distinguishers of subcodes of GRS codes. Our findings reveal critical vulnerabilities in both systems, effectively compromising their security despite their novel designs.