The work is devoted to the influence of the algebraic structure of q-ary lattices on the complexity of cryptanalysis of cryptographic problems on lattices. The root-mean-square errors for existing lattice reduction models are obtained. It is shown that the deterministic Albrecht-Lee simulator shows the smallest mean square deviations on small lattices. Collapsibility estimates for nesting and decoding attacks on the algebraic structure of q-ary lattices have been found. A new method for selecting attack parameters has been proposed for the decoding attack. It is shown that a decoding attack with such a choice of parameters can be at the expense of nesting attacks. To distribute the power of the secret vector in decoding attacks, which differ from the normal one, the approximation method is used by the normal division, which minimizes the Kolmogorov-Smirnov equation and calculates the optimal values for some distributions. There are no parameters for any divisions. For the SIS problem, a new approach to safety assessment has been proposed, which takes into account the possibility of various Euclidean norms. Based on the new approach, estimates of the SIS problem for Crystals-Dilithium electronic signature schemes have been calculated.
Modern cryptographic transformations require provable security against a relatively wide class of threats. Typically, such evidentiary security is achieved through formal analysis within the chosen security model. The development of quantum computers led to the emergence of new attack vectors to which classical cryptography was vulnerable. However, there are cryptographic systems that are considered resistant to quantum attacks and some of them are even standardized. The formal analysis of such systems has faced difficulties for a long time, which were associated with the impossibility of applying classical methods of proof to formal models that take into account quantum effects. However, in recent years, many new results have appeared that allow obtaining formal security proofs for quite complex cryptographic transformations, and most of the existing post-quantum asymmetric encryption and key encapsulation schemes currently have corresponding formal proofs within the quantum random oracle model, the most widespread security model for of post-quantum cryptography. DSTU 8961:2019 is the Ukrainian post-quantum standard for asymmetric encryption and key encapsulation. However, security proofs in the quantum random oracle model have not yet been published for it. As part of this work, security evidence was obtained for the design of the key encapsulation mechanism described in DSTU 8961:209. The obtained result is generalized for an arbitrary asymmetric encryption scheme, which may contain decryption errors and can be used to assess the security of not only DSTU 8961:2019, but also other similar asymmetric transformations.
Для побудови сучасних механізмів інкапсуляції ключів використовується модульний підхід.За основу
The study of key encapsulation mechanisms on algebraic lattices is one of the important directions in modern post-quantum cryptography, since many mechanisms are already either standardized (ANSI X.9.98, DSTU 8961:2019 "Skelya") or are promising candidates for standardization (CRYSTALS-Kyber, FrodoKEM). The purpose of this work is to compare the security arguments of DSTU 8961:2019 "Skelya", CRYSTALS-Kyber, FrodoKEM key encapsulation mechanisms. The paper provides a comparison of theoretical evidence in the idealized random oracle (ROM) and quantum random oracle (QROM) models, as well as a comparison of specific values of security parameters in the core-SVP model, which is, in fact, a standard for lattice cryptography. Since all three key encapsulation mechanisms are based on different complex problems (NTRU, Module-LWE, LWE), a comparison of complex lattice theory problems and a comparison of their security arguments are additionally given. The strengths and weaknesses of the considered key encapsulation mechanisms are shown, and areas of research that require more detailed attention are highlighted.
Development and investigation of electronic signatures on algebraic lattices is one of the promising directions in post-quantum cryptography. Cryptosystems CRYSTALS-Dilithium and Falcon represent lattice cryptography in the category of electronic signatures in the NIST PQC open competition among the finalists. Most operations in these cryptosystems are reduced to addition and multiplication of polynomials in a finite field with a generating cyclotomic polynomial xN + 1. Using such a field allows the use of a number-theoretic transformation (NTT) to create fast and reliable software implementations. In practice, vectorized set (SIMD) instructions are used to achieve good performance. AVX2 instructions are most often used among existing implementations. At the same time, the possibility of using AVX512 instructions remains little explored. The purpose of this work is to investigate the feasibility of applying AVX512 instructions to optimization of the NTT, used in modern EPs on algebraic lattices. In particular, the paper presents a method for implementing a number-theoretic transformation using AVX512 for CRYSTALS-Dilithium and Falcon. An increase in performance is shown in comparison with the reference optimized author's implementations.
Nonlinear substitutions (S-boxes) are used in most modern symmetric cryptoalgorithms. They are designed to mix input data and play a significant role in ensuring resistance against known cryptanalytic attacks (differential, linear, algebraic and other cryptanalysis methods). However, random generation of nonlinear substitutions with the desired indicators is an extremely difficult mathematical problem. This article explores the heuristic techniques for S-boxes informed search, in particular, discusses various cost functions used in most of the known algorithms (for example, local search, hill climbing, simulated annealing, genetic search, etc.). The aim of the study is to determine the specific parameters of heuristic functions, which, on the one hand, do not reduce the degree of awareness of the search nodes, and on the other hand, do not require significant computational costs. The article examines the influence of individual parameters on the value of the cost function and complexity of its calculation. It also provides specific recommendations for the formation of parameters for heuristic search for S-boxes, which significantly affect the efficiency of generating nonlinear substitutions for symmetric cryptography.
Nonlinear substitutions (S-boxes) are an important component of modern symmetric cryptography algorithms. They complicate symmetric transformations and introduce nonlinearity into the input-output relationship, which ensures the stability of the algorithms against some cryptanalysis methods. Generation of S-boxes can be done in different ways. However, heuristic techniques are the most promising ones. On the one hand, the generated S-boxes are in the form of random substitutions, which complicates algebraic cryptanalysis. On the other hand, heuristic search allows one to achieve high rates of nonlinearity and δ-uniformity, which complicates linear and differential cryptanalysis. This article studies the simplest local search algorithm for generating S-boxes. To assess the efficiency of the algorithm, the concept of a track of a cost function is introduced in the article. Numerous experiments are carried out, in particular, the influence of the number of internal and external loops of local search on the complexity of generating the target S-box is investigated. The optimal (from the point of view of minimum time consumption) parameters of the local search algorithm for generating S-blocks with a target nonlinearity of 104 and the number of parallel computing threads 30 are substantiated. It is shown that with the selected (optimal) parameters it is possible to reliably form S-blocks with a nonlinearity of 104.
The modern electronic voting system is an interconnected set of rules, methods, processes, tools and technologies, as well as legal norms that ensure and regulate the remote legitimate will of authorized users (voters). This article proposes, investigates, and verifies by physical prototyping the two-tier architecture of the electronic blockchain voting system. The lower (first) level enables all components of the electronic identification process to be fulfilled by existing systems such as BankID, MobileID, electronic signature, and the like. This will ensure interoperability of electronic voting, inheritance of already implemented national information systems, in particular, of the national system of electronic confidential services, reproducibility of the results of physical prototyping of blockchain voting. The upper (second) level is intended for the implementation of the expression of votes and the counting of votes, with the provision of independent control over the correctness of the compilation of voter lists; the possibility of anonymous voting only by those who are entitled to it; the invariability and irrevocability of the results of the will; ease and transparency of checking the correctness of the vote count and the like. The obtained results of physical prototyping make it possible to confirm the validity and weight of the developed architecture, its ability to meet the basic requirements of decentralized electronic voting, the requirements of information and functional security and reliability of information technologies. The practical implementation of the developed blockchain voting architecture will increase trust in information resources and services (which is especially relevant for government agencies) and will reduce time and overhead; will make impossible the intervention of centralized institutions and possible corruption; will increase the reliability of information storage and the quality of services provided.
Globally, the efforts of a significant number of crypto-theorists, mathematicians and cryptologists-practitioners are focused on the NIST PQC open competition. One of the main tasks of the competition consists in development and adoption of a post-quantum ES standard or standards. The finalists of the second stage of the NIST competition were three ES mechanisms – CRYSTALS-DILITHIUM, Falcon and Rainbow. In addition, three alternative candidates were identified that require more detailed research. In general, a comprehensive analysis of the finalists is an important task for cryptologists in the global cryptocommunity. Moreover, security, i.e. bringing the cryptographic stability of two finalist candidates, to the ES standard – CRYSTALS-DILITHIUM and Falcon, is based on problems in the theory and practice of algebraic lattices. The EP Dilithium method (scheme) is based on the approach called "Fiat-Shamir Interruptions". The essence of the CRYSTALS-DILITHIUM ES algorithm is considered in the article. A detailed analysis of possible attacks on the algorithm and the mechanisms of their implementation is also carried out. Models of violator, threats and security are considered and analyzed. The main definitions of ES security models are provided. The main design elements of the mechanism of perspective post-quantum ES Dilithium are described in the generalized form. General estimations of the ES Dilithium security level are given. The substantiation and essence of models of threats, violator and security are given. The stability of the ES Dilithium algorithm is investigated. The purpose of the article is to substantiate a security model, classification, primary analysis and assessment of known attacks on the CRYSTALS-DILITHIUM EP cryptosystem, to establish restrictions and develop practical algorithms for calculating (generating) system-wide parameters to ensure 128, 256, 384 and 512 bits of security relative to classical and 64, 128, 192 and 256 bits relative to quantum cryptanalysis.
Globally, the efforts of a significant number of crypto-theorists, mathematicians and cryptologists-practitioners are focused on the NIST PQC open competition. One of the main tasks of the competition consists in development and adoption of a post-quantum ES standard or standards. The finalists of the second stage of the NIST competition were three ES mechanisms – CRYSTALS-DILITHIUM, Falcon and Rainbow. In addition, three alternative candidates were identified that require more detailed research. In general, a comprehensive analysis of the finalists is an important task for cryptologists in the global cryptocommunity. Moreover, security, i.e. brining the cryptographic stability of two finalist candidates, to the ES standard – CRYSTALS-DILITHIUM and Falcon, is based on problems in the theory and practice of algebraic lattices. Studies show that among the ES schemes on lattices it differs slightly from other candidates and has prospects for the adoption as the Falcon algorithm standard. The main and dominant approach to the design of the Falcon ES mechanism is the use of the Fiat-Shamir transformation with interruptions. The sets of system-wide parameters that ensure resistance to all known and potential attacks should be found for the safe use of the Falcon ES. In the process of forming the requirements for ES within the competition, the NIST was interested only in sets of system-wide parameters up to 256 bits of classical security inclusive. However, according to the authors of this work, in the future it is advisable to provide at least 384 and 512 bits of security for classical cryptanalysis and at least 192 and 256 bits of security for quantum cryptanalysis. The article briefly considers the essence of the Falcon electronic signature (ES) algorithm. An analysis of possible attacks on the algorithm and the mechanisms of their implementation is also performed. The process of generating system-wide parameters for 256, 384, 512 stability bits is considered. Conclusions and recommendations are given. The objective of the work is the classification and initial analysis of known attacks on the ES Falcon cryptosystem, setting limits and developing practical algorithms for calculating (generating) system-wide parameters to provide not less than 256, 384 and 512 security bits for classical and not less than 128, 192 and 256 security bits for quantum cryptanalysis.
The paper deals with the concept of homomorphic encryption and the possibility of its use in the mechanism of electronic voting. One of the problematic requirements for electronic voting systems is voter anonymity. On the one hand, each voter must be identified, and on the other, the content of his or her vote must be unknown. Currently, the methods and mechanisms used in real voting systems do not provide real anonymity. Therefore, both theoretical and practical content is an urgent and necessary problem of developing mechanisms for anonymous counting of votes with the protection of their distortion. The paper also provides a general analysis of the security level of prospective homomorphic encryption schemes. The essence of homomorphic encryption is that there is some set of operations whose result of executing over ciphertexts (with subsequent decryption) coincides with similar actions over plaintexts. Homomorphic encryption allows you to perform some calculations on information without having access to the information itself. However, there are a number of problems when trying to apply such calculations. The main ones are the choice of the method of asymmetric encryption, which provides the necessary cryptographic stability from both classical and quantum attacks, the identification of possible candidates for asymmetric cryptotransformations in homomorphic encryption, their evaluation of comparison with each other, and, of course, the choice of the most rational for a given multiple restrictions. The asymmetric schemes of homomorphic encryption are compared using the hierarchy analysis process. The method of asymmetric encryption with zero knowledge is substantiated. The objective of this article is to substantiate the possibilities, conditions, and constraints on the use of standardized asymmetric cryptotransformations in the creation of modern homomorphic encryption-type transformations, when anonymity of electronic voting and practical implementation of anonymous voting based on proof of zero knowledge must be guaranteed.
The problem of cryptographic protection against classical and potential crypto-analytic attacks with the use of quantum computer and quantum mathematics has become an urgent issue. Understanding this problem, technologically advanced states are making significant efforts to analyze the cryptographic stability of existing standards for cryptographic information security in the post-quantum period and are seeking to establish post-quantum standards for asymmetric cryptography. A practical solution to this problem is being pursued globally during the NIST USA international competition. As previous studies have shown, algebraic lattices are now considered to be a reliable mathematical basis on which post-quantum asymmetric encryptions and PIK can be created. NTRU-like algorithms are a class of crypto-transformations algorithms that satisfy basically the requirements of post-quantum cryptography. Algorithms for key generation direct and reverse cryptographic transformations are the basic components in NTRU-like algorithms for asymmetric crypto-transformations. A number of authors today focus on optimizing polynomial multiplication for these algorithms by the criterion of time complexity. A special requirement for them is the independence of the time of the multiplication operation from the polynomials themselves, which makes it impossible to attack by side channels. This paper proposes the use of the NTT and Toom-Kuk algorithms. It proposes a new solution to this problematic issue, which made it possible to obtain an acceleration of almost 2 times while providing a constant polynomial multiplication time. The objective of this article is to optimize the polynomial multiplication algorithm by the time complexity criterion, used to generate keys and perform direct and reverse cryptographic transformations of asymmetric encryptions and PIK on algebraic lattices.
An important feature of the post-quantum period in cryptography is the significant uncertainty about the input data for cryptanalysis and counteracting the capabilities of quantum computers, their mathematical and software, and the application of quantum cryptanalysis to existing cryptoprotocols and cryptotransformations. Mathematical electronic signature (ES) methods have been selected as the main methods in the work, which have undergone significant analysis and substantiation in the process of extensive research by cryptologists and mathematicians at the highest level. The article analyzes the existing electronic signature algorithms based on the lattices of stage 2 of the NIST competition. The possibility of using the post-quantum electronic signature mechanism based on algebraic lattices as the post-quantum national electronic signature standard is considered. It is proposed to use the post-quantum Сrystals-Dilithium algorithm as such electronic signature algorithm. The article considers this algorithm and substantiates the possibility of its application. The algorithm parameters and rules for their construction are considered. The differences and features of safe implementation of the algorithm in comparison with stage 1 are analyzed. The analysis is conducted and it is concluded that the Crystals-Dilithium algorithm can be taken as one of the candidates for the development of a national electronic signature standard using cryptographic algorithms, standardized in Ukraine, such as the hashing function described in DSTU 7564:2014. According to the authors of the article, the post-quantum period national standard of Ukraine should include at least 3 algorithms based on different types of mathematical transformations, which are recognized by the world cryptographic community as those that can provide the necessary level of stability in the conditions of quantum cryptanalysis.