Could SFLASH be Repaired?

Jintai Ding Dept. of Mathematics and Computer Sciences, University of Cincinnati Vivien Dubois CELAR, France Bo-Yin Yang Institute of Information Sciences, Academia Sinica, Taiwan Owen Chia-Hsin Chen Institute of Information Sciences, Academia Sinica, Taiwan Chen-Mou Cheng Dept. of Electrical Engineering, National Taiwan University

TBD mathscidoc:2207.43037

ICALP 2008, 691-701, 2008.7
The SFLASH signature scheme stood for a decade as the most successful cryptosystem based on multivariate polynomials, before an efficient attack was finally found in 2007. In this paper, we review its recent cryptanalysis and we notice that its weaknesses can all be linked to the fact that the cryptosystem is built on the structure of a large field. As the attack demonstrates, this richer structure can be accessed by an attacker by using the specific symmetry of the core function being used. Then, we investigate the effect of restricting this large field to a purely linear subset and we find that the symmetries exploited by the attack are no longer present. At a purely defensive level, this defines a countermeasure which can be used at a moderate overhead. On the theoretical side, this informs us of limitations of the recent attack and raises interesting remarks about the design itself of multivariate schemes.
No keywords uploaded!
[ Download ] [ 2022-07-12 10:12:42 uploaded by dingjt ] [ 430 downloads ] [ 0 comments ]
  title={Could SFLASH be Repaired?},
  author={Jintai Ding, Vivien Dubois, Bo-Yin Yang, Owen Chia-Hsin Chen, and Chen-Mou Cheng},
  booktitle={ICALP 2008},
Jintai Ding, Vivien Dubois, Bo-Yin Yang, Owen Chia-Hsin Chen, and Chen-Mou Cheng. Could SFLASH be Repaired?. 2008. In ICALP 2008. pp.691-701.
Please log in for comment!
Contact us: | Copyright Reserved