提出新型非模块化攻击,突破格密码中模运算的建模难题。
NoMod: A Non-modular Attack on Module Learning With Errors
- 将模运算溢出视为统计噪声,转化为鲁棒线性估计问题。
- 在n=350时完全恢复二进制密钥,成功破解CRYSTALS-Kyber部分参数配置。
- 适合关注后量子密码安全性的研究人员与密码分析者。
量子计算威胁传统公钥密码体系,促使NIST采纳基于模块学习错误(Module-LWE)的后量子方案。本文提出NoMod ML-Attack,一种混合白盒密码分析方法,通过将模运算溢出视为统计噪声,将秘密恢复转化为鲁棒线性估计问题。该方法结合优化的格预处理技术(包括降维向量保存与代数增强)及基于Tukey双权重损失训练的鲁棒估计器。实验表明,该方法可在维度n=350时完全恢复二进制秘密,在n=256时恢复稀疏二项式秘密,并成功破解参数为(n,k)=(128,3)和(256,2)的CRYSTALS-Kyber设置。代码已匿名发布于https://anonymous.4open.science/r/NoMod-3BD4。
原文摘要 · Abstract (English)
The advent of quantum computing threatens classical public-key cryptography, motivating NIST's adoption of post-quantum schemes such as those based on the Module Learning With Errors (Module-LWE) problem. We present NoMod ML-Attack, a hybrid white-box cryptanalytic method that circumvents the challenge of modeling modular reduction by treating wrap-arounds as statistical corruption and casting secret recovery as robust linear estimation. Our approach combines optimized lattice preprocessing--including reduced-vector saving and algebraic amplification--with robust estimators trained via Tukey's Biweight loss. Experiments show NoMod achieves full recovery of binary secrets for dimension $n = 350$, recovery of sparse binomial secrets for $n = 256$, and successful recovery of sparse secrets in CRYSTALS-Kyber settings with parameters $(n, k) = (128, 3)$ and $(256, 2)$. We release our implementation in an anonymous repository https://anonymous.4open.science/r/NoMod-3BD4.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。