Security Bounds for the Design of Code-based Cryptosystems
- M. Finiasz et N. Sendrier
Security Bounds for the Design of Code-based Cryptosystems M. - - PowerPoint PPT Presentation
Security Bounds for the Design of Code-based Cryptosystems M. Finiasz et N. Sendrier The Syndrome Decoding Problem e S r H n Syndrome Decoding (SD) Does e { 0 , 1 } n of weight w such that e H = S exist? NP-complete problem.
slide 1/22
slide 1/22
slide 2/22
2 columns of H:
w
r 2,
w 2
slide 3/22
2
w 2
slide 4/22
2.
slide 5/22
w),2r/2
.
slide 6/22
w),2r/2
.
slide 6/22
slide 7/22
w
slide 8/22
2 and length k + ℓ.
slide 9/22
p 2ℓ(n
w)
λ( r−ℓ
w−p)
p )
with ℓ=log
p)
slide 10/22
w
w−p
p
p 2ℓ 2r λ( r−ℓ
w−p)
p )
with ℓ=log
p)
w−p
p
p 2ℓ 2r/2
w−p)
with ℓ=log
2r/2
(
r w−p)
slide 11/22
i f(xi) = 0.
slide 12/22
r a+1
j of XORs of 2 f(xi). Keep only elements starting
r a+1 zeros.
j still contain 2
r a+1 elements in average.
a+1
r a+1.
slide 13/22
2a elements.
j so that they only contain unique
slide 14/22
j lists we keep the XORs of weight w 2a−1 having
w/2a−1
2w 2a
r−a a .
a 2
r−a a .
slide 15/22
(a) (c) (b)
slide 16/22
a 2
r−a a
with a such that 1
2a( n 2w 2a)=2 r−a a .
slide 17/22
slide 18/22
3⌉, w − ⌈w 3⌉ − ⌊w 3⌋ and ⌊w 3⌋ columns,
slide 19/22
2r
n w−⌊w/3⌋) ≥
n ⌊w/3⌋):
w−⌊w/3⌋
w−⌊w/3⌋
⌊w/3⌋
⌊w/3⌋
slide 20/22
slide 20/22
slide 21/22
slide 21/22
slide 22/22