Efficient Key Recovery for All HFE Signature Variants

Efficient Key Recovery for All HFE Signature Variants
复制标题

DOI:
10.1007/978-3-030-84242-0_4
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Chengdong Tao;Albrecht Petzoldt;Jintai Ding
Chengdong Tao;Albrecht Petzoldt;Jintai Ding
中科院分区:
其他
文献类型:
--
作者:
Chengdong Tao;Albrecht Petzoldt;Jintai Ding

文献摘要

被引文献

相似文献

HFE密码体制是目前最流行的多变量密码体制之一。特别是在数字签名领域,HFEv变体提供了短签名和高性能。最近,在第三轮NIST后量子加密(PQC)标准化项目中,一个名为GeMSS的HFEv签名方案实例被选为签名方案的备选方案之一。本文提出了一种新的HFEv签名方案的密钥恢复攻击方法。我们的攻击表明,Minus和Vinegar修改并没有显著提高基本HFE方案的安全性。这说明在HFE的基础上构建一个安全高效的签名方案是非常困难的。特别是,我们使用我们的攻击来证明GeMSS方案的提议参数并不像声称的那样安全。
The HFE cryptosystem is one of the most popular multi- variate schemes. Especially in the area of digital signatures, the HFEv- variant offers short signatures and high performance. Recently, an instance of the HFEv- signature scheme called GeMSS was selected as one of the alternative candidates for signature schemes in the third round of the NIST Post-Quantum Crypto (PQC) Standardization Project.In this paper, we propose a new key recovery attack on the HFEv- signature scheme. Our attack shows that both the Minus and the Vinegar modification do not enhance the security of the basic HFE scheme significantly. This shows that it is very difficult to build a secure and efficient signature scheme on the basis of HFE. In particular, we use our attack to show that the proposed parameters of the GeMSS scheme are not as secure as claimed.