Cryptanalysis of Multivariate and Odd-Characteristic HFE Variants

نویسندگان

  • Luk Bettale
  • Jean-Charles Faugère
  • Ludovic Perret
چکیده

We investigate the security of a generalization of HFE (multivariate and odd-characteristic variants). First, we propose an improved version of the basic Kipnis-Shamir key recovery attack against HFE. Second, we generalize the Kipnis-Shamir attack to Multi-HFE. The attack reduces to solve a MinRank problem directly on the public key. This leads to an improvement of a factor corresponding to the square of the degree of the extension field. We used recent results on MinRank to show that our attack is polynomial in the degree of the extension field. It appears that multi-HFE is less secure than original HFE for equal-sized keys. Finally, adaptations of our attack overcome several variants (i.e. minus modifier and embedding). As a proof of concept, we have practically broken the most conservative parameters given by Chen, Chen, Ding, Werner and Yang in 9 days for 256 bits security. All in all, our results give a more precise picture on the (in)security of several variants of HFE proposed these last years.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Cryptanalysis of HFE, multi-HFE and variants for odd and even characteristic

We investigate in this paper the security of HFE and Multi-HFE schemes as well as their minus and embedding variants. Multi-HFE is a generalization of the well-known HFE schemes. The idea is to use a multivariate quadratic system – instead of a univariate polynomial in HFE – over an extension field as a private key. According to the authors, this should make the classical direct algebraic (mess...

متن کامل

Cryptanalysis of multi-HFE

Multi-HFE (Chen et al., 2009) is one of cryptosystems whose public key is a set of multivariate quadratic forms over a finite field. Its quadratic forms are constructed by a set of multivariate quadratic forms over an extension field. Recently, Bettale et al. (2013) have studied the security of HFE and multi-HFE against the min-rank attack and found that multi-HFE is not more secure than HFE of...

متن کامل

Equivalent Keys in HFE, C*, and Variations

In this article, we investigate the question of equivalent keys for two Multivariate Quadratic public key schemes HFE and C∗−− and improve over a previously known result, to appear at PKC 2005. Moreover, we show a new non-trivial extension of these results to the classes HFE, HFEv, HFEv-, and C∗−−, which are cryptographically stronger variants of the original HFE and C∗ / MIA schemes. In partic...

متن کامل

Odd-Char Multivariate Hidden Field Equations

We present a multivariate version of Hidden Field Equations (HFE) over a nite eld of odd characteristic, with an extra embedding modi er. Combining these known ideas makes our new MPKC (multivariate public key cryptosystem) more e cient and scalable than any other extant multivariate encryption scheme. Switching to odd characteristics in HFE-like schemes a ects how an attacker can make use of e...

متن کامل

GeMSS: A Great Multivariate Short Signature

The purpose of this document is to present GeMSS : a Great Multivariate Signature Scheme. As suggested by its name, GeMSS is a multivariate-based [14, 22, 4, 2, 20, 19] signature scheme producing small signatures. It has a fast verification process, and a medium/large public-key. GeMSS is in direct lineage from QUARTZ [18] and borrows some design rationale of the Gui multivariate signature sche...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2011