Cryptanalysis of the quaternion Rainbow
Cryptanalysis of the quaternion Rainbow
复制标题
四元数 Rainbow 的密码分析
DOI:
10.1007/978-3-642-41383-4_16
复制
发表时间:
2015
期刊:
影响因子:
--
通讯作者:
Yasufumi Hashimoto
中科院分区:
文献类型:
--
作者:
Taisei Motomura;Kazunori Takahashi; Yuji Kasashima;Fumihiko Uesugi and Akira Ando;土岡俊介;土岡俊介;土岡俊介;Shunsuke Tsuchioka;Shunsuke Tsuchioka;Shunsuke Tsuchioka;Yasufumi Hashimoto;橋本康史;橋本康史;Yasufumi Hashimoto
Rainbow is one of signature schemes based on the problem solving a set of multivariate quadratic equations. While its signature generation and verification are fast and the security is presently sufficient under suitable parameter selections, the key size is relatively large. Recently, Quaternion Rainbow — Rainbow over a quaternion ring — was proposed by Yasuda, Sakurai and Takagi (CT-RSA'12) to reduce the key size of Rainbow without impairing the security. However, a new vulnerability emerges from the structure of quaternion ring; in fact, Thomae (SCN'12) found that Quaternion Rainbow is less secure than the same-size original Rainbow. In the present paper, we further study the structure of Quaternion Rainbow and show that Quaternion Rainbow is one of sparse versions of the Rainbow. Its sparse structure causes a vulnerability of Quaternion Rainbow. Especially, we find that Quaternion Rainbow over even characteristic field, whose security level is estimated as about the original Rainbow of at most 3/4 by Thomae's analysis, is almost as secure as the original Rainbow of at most 1/4-size.