讨论RSA公钥密码体制在素因子p满足等式ex+ by+ c-0(mod p)条件下的安全性,研究了对其格攻击的方法.利用方程小根求解问题对其进行攻击,攻击结果表明:当参数x,y满足|x| |y|<N3β-3+(2β+1)/1-β1时,通过格攻击方法可以有效的分解N,即满足这样条件的RSA公钥密码体制是不安全的.
>Dear editor,We present a new algorithm to search for effective disturbance vectors with a complexity of 2 38 based on the following two properties of disturbance vectors.One property is the weight correlation between the first 16-step disturbance vectors and the60-step disturbance vectors.The other property requires all the differences of the active bit positions of the first 16-step disturbance vectors to be
Ciphertext-policy attribute-based encryption, denoted by CP-ABE, extends identity based encryption by taking a set of attributes as users' public key which enables scalable access control over outsourced data in cloud storage services. However, a decryption key corresponding to an attribute set may be owned by multiple users. Then, malicious users are subjectively willing to share their decryption keys for profits. In addition, the authority who issues decryption keys in CP-ABE system is able to generate arbitrary decryption key for any (including unauthorized) user. Key abuses of both malicious users and the authority have been regarded as one of the major obstacles to deploy CP-ABE system in real-world commercial applications. In this paper, we try to solve these two kinds of key abuses in CP-ABE system, and propose two accountable CP-ABE schemes supporting any LSSS realizable access structures. Two proposed accountable CP-ABE schemes allow any third party (with the help of authorities if necessary) to publicly verify the identity of an exposed decryption key, allow an auditor to publicly audit whether a malicious user or authorities should be responsible for an exposed decryption key, and the key abuser can't deny it. At last, we prove the two schemes can achieve publicly verifiable traceability and accountability.
A single-radix Fast Fourier Transform(FFT) in-place permutation algorithm is proposed according to the original lookup table algorithm.A new lookup table configuration method is designed,and the computing method of original lookup table is optimized.The general law of selecting the optimal lookup table scale under different permutation calculation scale is obtained.Simulation results show that the scale of the lookup table is variable.The table can be searched by the cycle,the scale of the lookup table can be selected,the number of cycles can be reduced and the computing speed can be improved.
对于输入B和C,利用Sorenson的右移k-ary消减(right-shift k-ary reduction)思想提出一种算法用于寻找整数x和y,使得x和y满足Bx-Cy在二进制表示下低比特位部分为0,利用该算法能够大规模降低循环次数,再结合模算法,提出递归最大公因子算法.递归最大公因子算法复杂度虽然对Knuth-Sch(o)nhage算法的复杂度上没有提高,仍然是O(nlog2 nloglogn),但是该算法相比于Knuth-Sch(o)nhage算法实现简单,正确性分析和复杂度分析都比较容易.
Ciphertext-policy attribute-based encryption, denoted by CP-ABE, is a promising extension of identity-based encryption which enables fine-grained data access control by taking a set of attributes as users' public key. However, owing to the fact that an attribute set may be shared by multiple users, malicious users dare to share their decryption keys to others for profits. Furthermore, the central authority is able to issue arbitrary decryption keys for any unauthorized users. To prevent these two kinds of key abuses in CP-ABE system, we propose an accountable CP-ABE scheme which allows any third party to publicly verify the identity embedded in a leaked decryption key, allows an auditor to publicly check whether a malicious user or the authority should be responsible for an exposed decryption key, and the malicious user or the authority can't deny it. The proposed accountable CP-ABE scheme supports any LSSS realizable access structures. At last, the confidentiality and public verifiability of the proposed scheme can be proved to be tightly related to the atomic CP-ABE scheme and the signature scheme that it composed from.
模差分攻击技术是SHA-1随机碰撞攻击中重要分析方法之一.针对减宽的SHA-1算法,该文得出了减宽的部分碰撞定理并给出了减宽SHA-1算法单一部分碰撞的概率,证明了模差分攻击技术同样适用于减宽的SHA-1算法.通过理论分析和计算机搜索,该文证明了对于宽为n比特的SHA-1算法,当且仅当n>3时,最优扰动向量的汉明重为25;当且仅当n>8时,最优扰动向量只有type-Ⅰ与type-Ⅱ两个等价类.
借鉴遗传算法的基本策略,以SHA-1第1轮后4步差分路径的汉明重作为遗传算法适应性函数的输入参数,以SHA-1差分进位扩展的位数作为遗传操作的基本单元,提出了一种新的SHA-1差分路径搜索算法.在相同消息差分条件下,该算法搜索得到的差分路径第1轮后4步汉明重为5,文献[1]给出的差分路径第1轮后4步汉明重为4.该算法同样适用于具有与SHA-1结构相似的MD5、SHA-0等Hash函数的差分路径搜索.
Wireless mesh networks (WMNs) provide an efficient and flexible method to the field of wireless networking, but also bring many security issues. A mesh point may lose all of its available links during its movement. Thus, the mesh point needs to handover to a new mesh point in order to obtain access to the network again. For multi-domain WMNs, we proposed a new ID-based signcryption scheme and accordingly present a novel ID-based handover protocol for mesh points. The mutual authentication and key establishment of two mesh points which belong to different trust domains can be achieved by using a single one-round message exchange during the authentication phase. The authentication server is not involved in our handover authentication protocol so that mutual authentication can be completed directly by the mesh points. Meanwhile, the data transmitted between the two mesh points can be carried by the authentication messages. Moreover, there are no restrictions on the PKG system parameters in our proposed multi-domain ID-based signcryption scheme so our handover scheme can be easily applied to real WMNs circumstances. Security of the signcryption scheme is proved in the random oracle model. It shows that our protocol satisfies the basic security requirements and is resistant to existing attacks based on the security of the signcryption. The analysis of the performance demonstrates that the protocol is efficient and suitable for the multi-domain WMNs environment.
Normal bases with specific trace self-orthogonal relations over finite fields have been found to be very useful for many fast arithmetic computations, especially when the extensions of finite fields have no self-dual normal basis. Recent work in [1] has given the necessary and sufficient conditions for the existence of normal bases of GF(2(n)) with a prescribed trace vector when n is odd or n is a power of two. However, the methods in [1] cannot work in general cases. In this paper, using methods different from [1], we give a complete characterization of the trace self-orthogonal relations of arbitrary normal bases. Furthermore, we provide a combination method to construct normal elements with the prescribed trace vectors. These generalize the results in [1] to general cases. The main result of this paper is shown as follows. Let a = (a(0), a(1), ... , a(n-1)) be a prescribed n-vector over GF(q), with corresponding polynomial f(a)(x) = Sigma(n-1)(i=0) a(i)x(i). We present that there exists a normal element a of GF(q(n)) over GF(q), with trace vector a, such that a(i) = Tr-qn vertical bar q(alpha(1)+q(iota)) for all 0 <= i <= n-1, if and only if a(i) = a(n-i) for all 1 <= i <= n-1 and 1) when q is odd, f(a)(x) is prime to x(n) - 1; f(a)(1) is a quadratic residue in GF(q); for even n, if f(a)(-1) not equal 0, then f(a)(-1) is not a quadratic residue in GF(q); 2) when q is even, f(a)(x) is prime to x(n) - 1; for even n, a(n/2) = 0 and if 4 vertical bar n, then Tr-q vertical bar 2(Sigma(n/4-1)(i=0) a(0-1) a(2i+1)) = 1. (C) 2015 Elsevier Inc. All rights reserved.
Crypton密码算法是韩国学者提出的一种AES候选算法.通过研究Crypton算法的结构特征和一类截断差分路径的性质,利用差分枚举技术权衡存储复杂度和数据复杂度,提出了4轮和4.5轮中间相遇区分器.新的区分器减少了预计算表中的多重集数量,降低了存储复杂度.基于4轮区分器首次给出对7轮Crypton-128的中间相遇攻击,时间复杂度为2113,数据复杂度为2113,存储复杂度为290.72.基于4.5轮区分器首次给出对8轮Crypton-192的中间相遇攻击,时间复杂度为2172,数据复杂度为2113,存储复杂度为2138.
Information spread maximization is to find a small subset of nodes in social network such that they can maximize the expected spread of information.In this paper, we attempt harnessing historical information cascades data to learn how information propagates in social networks and how to maximize its spread.In particular, we proposed a voting algorithm to learn diffusion probabilities of edges from cascades data.Then a pruning method is developed to remove trivial edges whose weights are smaller than a threshold.Moreover, motivated by the social influence locality, we propose a Local Influence Model to evaluate node's influence within a local area instead of the whole network, which can effectively reduce the computational complexity.Based on Local Influence Model, we use greedy algorithm to find an approximate optimal solution.Experimental results show that our method significantly outperforms state-of-the-art models both in terms of information spread and algorithm runtime.
Network diffusion, such as spread of ideas, rumors, contagious disease, or a new type of behaviors, is one of the fundamental processes within networks. Designing effective strategies for influence spread maximization, rumor spread minimization, or epidemic immunization has attracted considerable research attention. However, a key challenge is that many times we can only observe the trace of contagion spreading across network, but the underlying network structure is unknown and the transmission rates between node pairs are unclear to us. In this paper, given the observed information cascades, we aim to address two problems: diffusion network structure inferring and information diffusion pathways tracking. We propose a novel probabilistic model called Network Inferring from Multidimensional Features of Cascades (NIMFC) which takes into account heterogeneous features, including temporal and topological features of cascades, node attributes, and information content, to infer the latent network structure and transmission rates of edges. Also, based on the inferred network structure, we may track diffusion pathways of a cascade in social networks. We use blocked coordinate descent method to learn a sparse estimation of the latent network. Our proposed model NIMFC is evaluated both on large synthetic and real-world data sets, and experimental results show that our method significantly outperforms state-of-the-art models both in terms of recovering the latent network structure and information pathway tracking.
ARIA密码算法是韩国学者提出的韩国分组密码标准,该文对ARIA算法扩散层固定点进行了研究,结合固定点和S盒的差分性质,构造了达到概率上界2-144的6轮差分传递链.此外,利用特殊固定点构造了新的形式为4→4的截断差分路径,实现了7轮截断差分攻击.新的攻击数据和时间复杂度约为2106,存储复杂度约为256.
Abstract:Current identity-based authenticated key agreement schemes still have restriction on PKG system parameters.The assumption limits the application in real network environment.In order to solve these problems,an identity-based cross-domain authenticated key agreement protocol was proposed.There is no restriction on PKG system parameters so that public system parameters,system master keys and system public keys can be totally different.The security of this scheme was analyzed under the eCK model,and the result showed that this protocol satisfies the basic security requirements,perfect forward secrecy and PKG forward secrecy.Moreover,this protocol is robust to the existing attacks such as key compromise impersonation attack and ephemeral key compromise impersonation attack. Comparison with some typical identity-based multi-domain authenticated key agreement protocols showed that this scheme is more secure and efficient.
Abstract:A method for breaking the generalized RSA public key scheme was proposed using Lagrange’s reduction algorithm based on the two-dimension lattice and the lower bound of Euler's totient function. Moreover, the corresponding attack algorithm was also given and it was proved that the RSA modulus N could be factorized in polynomial time. Compared with the original continued fraction attack, this method removed the steps of computing and repeatedly verifying the convergent of continued fraction, obtained the prime factor p directly, so it simplified the whole solving procedures and improved the factoring efficiency. The results show that this method has lower time complexity, works faster in the experiment, and can be efficiently used to attack the generalized RSA public key scheme.