Submitted:
11 October 2023
Posted:
11 October 2023
You are already at the latest version
Abstract
Keywords:
1. Introduction
-
First, we modify the range of parameters and in the Ding-Tao’s algorithm, so that we need to build lattice and call LLL for only once, and the success rate for recovering p reaches , under the merged conditionNote that (2) also implies , no matter whether holds.
- Second, based on the above modification, we give a proof on why in our algorithm AIOL, the only once calling LLL will give us solutions for . This can be viewed as a theoretical answer towards the Ding-Tao’s amazing question;
- Third, we give the possible differences between the recovered of p and the actual hidden common divisor when the error vector is recovered. Knowing these differences is in turn helpful for recovering p, and thus expanding the scope of OL attacks.
2. Preliminaries
3. Orthogonal Lattice (OL) based approach
3.1. The basic idea of OL algorithm
3.2. Our Proposal
| Algorithm 1: AIOL: An improved OL algorithm for GACD |
|
Input: The GACD parameters , and t ACD samples , with t satisfying
Output: The approximate greatest common divisor p.
1. Randomly choose . And then constract a lattice with the basis
2. Reduce lattice by calling the LLL algorithm with . Let the reduced basis be , where
3. Collect short vectors from so that , , where . And then, solve the following Diophantine equations with t unknowns :
4. Rewrite the integer solutions of (15) as follows:
5. Let .
6. Compute .
|
3.3. The proof of AIOL algorithm
4. Experiments and Comparisons
- Fix ;
- Let respectively;
- Then, for each case, collect the success rate for recovering the hidden common divisor p, as well as the maximal (resp. the minimal t) that enables the related algorithms work. These results are summaried in Table 1, where the symbol ’–’ indicates that in this case the related failed to work out.
- The overall success rate of our algorithm is 100%, which is observably higher than that of in the Ding-Tao’s algorithm, under the same settings on and a similar scale of t. Moreover, even for bigger settings on in AIOL, the success rates are still higher than those of obtained by the Ding-Tao’s algorithm for the smaller settings on . 1
- The condition on given by the Ding-Tao’s condition (11) is irrelevant, considering for and , the maximal values of for ensuring the Ding-Tao’s a high success rate are 103 and 30, respectively. They are respectively either observably bigger or smaller than the given bound .
- The condition on given by AIOL is relaxed to the case of . And this condition is tight in the sense that for all these cases, the the maximal values of for ensuring AIOL success are almost same with the bound given by (18).
- The condition on t given by the Ding-Tao’s condition (11) is rigorous in the sense that for even small t, our tests on the Ding-Tao’s algorithm failed, whereas the condition on t given by (13) in AIOL is loose since for even small t, our algorithm still works well. At present, we have no idea to give a tight bound on choicing t for the AIOL algorithm.
- Fix and ;
- Let respectively;
- Both our algorithm AIOL and the Ding-Tao’s algorithm have good performance in scalability in the parameter . Moreover, the AIOL algorithm can find the correct solutions with even smaller t, this in turn means less space cost for storing the ACD samples.
- With the sample computational environments (i.e. MAPLE coding on an Intel i5 CPU with 1.30 GHz clocks), our AIOL algorithm runs much quicker than the Ding-Tao’s algorithm, under the same settings on and .
- Ding-Tao’s tests given in [8] (i.e. MAGMA coding on two Quad-Core Intel Processor Q9400 CPUs with 2.66 GHz clocks) are much quicker than our tests on both AIOL and the Ding-Tao’s algorithm. We think that this might be mainly attributed to the differences of computational environments.
5. Conclusions
Author Contributions
Funding
Conflicts of Interest
References
- N. Howgrave-Graham. Approximate integer common divisors. Cryptography and Lattices. Springer Berlin Heidelberg, 2001: 51–66.
- M. Van Dijk, C.Gentry, S. Halevi, V. Vaikuntanathan, Fully homomorphic encryption over the integers, in: H. Gilbert (ed.), Advances in Cryptology–EUROCRYPT 2010, Lecture Notes in Comput. Sci. Springer, Berlin, Heidelberg, 2010, 6110: 24–43.
- J. S. Coron, A. Mandal, D. Naccache, M. Tibouchi, Fully homomorphic encryption over the integers with shorter public keys, in: P. Rogaway (ed.), Advances in Cryptology-CRYPTO 2011, Lecture Notes in Comput. Sci, Springer, Berlin, Heidelberg, 2011, 6841: 487–504.
- J. S. Coron, D. Naccache, M. Tibouchi. Public Key Compression and Modulus Switching for Fully Homomorphic Encryption over the Integers. In D. Pointcheval and T. Johansson (ed.), EUROCRYPT’12, Springer LNCS, 2012, 7237: 446–464.
- J. H. Cheon, D. Stehlé. Fully Homomorphic Encryption over the Integers Revisited. In E. Oswald and M. Fischlin (eds.), EUROCRYPT’15, Springer LNCS, 2015, 9056: 513-536.
- Y. Chen, P. Q. Nguyen. Faster algorithms for approximate common divisors: Breaking fully homomorphic encryption challenges over the integers. Advances in Cryptology-EUROCRYPT 2012. Springer Berlin Heidelberg, 2012: 502–519.
- H. Cohn, N. Heninger. Approximate common divisors via lattices. In proceedings of ANTS X, vol. 1 of The Open Book Series, 2013: 271–293.
- J. Ding, C. Tao. A New Algorithm for Solving the General Approximate Common Divisors Problem and Cryptanalysis of the FHE Based on the GACD problem. Cryptology ePrint Archive, Report 2014/042, 2014.
- S. Gebregiyorgis. Algorithms for the Elliptic Curve Discrete Logarithm Problem and the Approximate Common Divisor Problem. PhD thesis, The University of Auckland, Auckland, New Zealand, 2016.
- S. Galbraith, S. Gebregiyorgis, S. Murphy. Algorithms for the approximate common divisor problem. LMS Journal of Computation and Mathematics. 19(A), 2016.: 58-72. [CrossRef]
- Xiaoling Yu, Yuntao Wang, Chungen Xu, Tsuyoshi Takagi. Studying the Bounds on Required Samples Numbers for Solving the General Approximate Common Divisors Problem. 2018 5th International Conference on Information Science and Control Engineering. [CrossRef]
- J. Xu, S. Sarkar, L. Hu, Revisiting orthogonal lattice attacks on approximate common divisor problems and their applications. Cryptology ePrint Archive, 2018.
- J. H. Cheon, W. Cho, M. Hhan, Algorithms for CRT-variant of approximate greatest common divisor problem. Journal of Mathematical Cryptology, 2020, 14(1): 397–413. [CrossRef]
- W. Cho, J. Kim, C. Lee. Extension of simultaneous Diophantine approximation algorithm for partial approximate common divisor variants. IET Information Security, 2021, 15(6): 417–427. [CrossRef]
- Claus-Peter Schnorr. Lattice reduction by random sampling and birthday methods. In STACS 2003, 20th Annual Symposium on Theoretical Aspects of Computer Science, Berlin, Germany, February 27–March 1, Proceedings, 2003: 145-156.
- J. Hoffstein, J. Pipher, and J. H. Silverman. An Introduction to Mathematical Cryptography. Springer Publishing Company, 2nd edition, 2014.
- P. Q. Nguyen and Jacques Stern. The Two Faces of Lattices in Cryptology. In J. Silverman (ed.), Cryptography and Lattices, Springer LNCS 2146, 2001: 146–180.
| 1 | Intuitively, the bigger , the more errors involved in the given ACD samples, and this in turn means the harder for solving the given GACD instances. |
| Ding-Tao | AIOL | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| (11) | t (11) | succ % | (18) | t (13) | succ % | |||||
| 300 | 79 | 103 | 11 | 11 | 137 | 137 | 35 | 17 | ||
| 400 | 79 | 91 | 12 | 12 | 134 | 134 | 34 | 19 | ||
| 500 | 79 | 80 | 13 | 13 | 131 | 132 | 39 | 23 | ||
| 1000 | 79 | 30 | 16 | 16 | 122 | 123 | 54 | 33 | ||
| 1500 | 79 | – | 19 | – | – | 115 | 115 | 60 | 40 | |
| 2000 | 79 | – | 21 | – | – | 109 | 109 | 72 | 46 | |
| Ding-Tao | AIOL | ||||||
|---|---|---|---|---|---|---|---|
| t | time (s)1 | time (s)2 | time (s)2 | ||||
| 5000 | 450 | 18 | 2.386 | 207.09 | 450 | 10 | 40.15 |
| 10000 | 450 | 40 | 91.447 | 7436.85 | 450 | 20 | 1162.34 |
| 15000 | 450 | 59 | 749.179 | 61767.34 | 450 | 29 | 3793.10 |
| 20000 | 450 | 85 | 4245.879 | 141303.98 | 450 | 38 | 32651.77 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2023 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).