SearcharxivSearch

arXiv · 0707.1501

Random subgroups and analysis of the length-based and quotient attacks

Abstract

In this paper we discuss generic properties of "random subgroups" of a given group G. It turns out that in many groups G (even in most exotic of them) the random subgroups have a simple algebraic structure and they "sit" inside G in a very particular way. This gives a strong mathematical foundation for cryptanalysis of several group-based cryptosystems and indicates on how to chose "strong keys". To illustrate our technique we analyze the Anshel-Anshel-Goldfeld (AAG) cryptosystem and give a mathematical explanation of recent success of some heuristic length-based attacks on it. Furthermore, we design and analyze a new type of attacks, which we term the quotient attacks. Mathematical methods we develop here also indicate how one can try to choose "parameters" in AAG to foil the attacks.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Alexei G. Myasnikov, Alexander Ushakov. 2007-07-10. Random subgroups and analysis of the length-based and quotient attacks. https://arxiv.org/abs/0707.1501

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Hyperfiniteness of boundary actions via tree decompositions

We study conditions for a countable group acting on a connected locally finite hyperbolic graph to induce a hyperfinite orbit equivalence relation on the Gromov boundary of the graph in terms of tree-decompositions of the graph. We prove that for a connected locally finite hyperbolic graph $X$ equipped with an action of a countable group $G$, if $(T, β)$ is a $G$-invariant tree-decomposition of $X$ such that each bag induces a connected subgraph $X_t$ of $X$ for each $t \in V(T)$, each adhesion set is finite and such that there are only finitely many $G$-orbits of edges of $T$, then the orbit equivalence relation of $G$ acting on the Gromov boundary $\partial X$ is hyperfinite provided the orbit equivalence relation of $G$ acting on $\partial T$ is hyperfinite and the orbit equivalence relations of the bag stabilizers acting on $\partial X_t$ are all hyperfinite. We show that the converse also holds if $(T, β)$ satisfies the additional property that each adhesion set distinguishes at least two ends of $X$.

math.GR

Compatible additions on a six-element commutative semigroup: equational bases and subvariety lattices

Let $M$ be the six-element commutative semigroup occurring as the common multiplicative reduct of the semirings $SR_6$ and $TR_6$. The closing paragraph of Shao, Ren, and Gao~\cite{ShaoRenGao2026} asks for the finite-basis and subvariety questions for the four remaining compatible additions on $M$. We answer these questions for the four isomorphism types $R_{01},R_{02},R_{11},R_{12}$. First, we classify all compatible additions on $M$: there are nine labelled additions and six isomorphism types, parametrized by $R_{ij}$ with $0\leq i\leq j\leq 2$. For each of the four new types we give a graph-theoretic criterion for every identity, an explicit infinite basis, and a proof of nonfinite basability. The generated varieties $\V(R_{01})$ and $\V(R_{02})$ have eleven subvarieties each, while $\V(R_{11})$ has sixty-six. The lattice $\Sub(\V(R_{12}))$ is countably infinite. Every identity in this variety reduces to a subset of twenty-five fixed identities together with two monotone path families $γ_n$ and $\gammaD_n$. This yields a canonical signature $(H,p,q)$, complete normal forms, explicit meet and join operations, and a formula for all covers. There are 153 fixed nodes, 43 one-parameter families, and 9 two-parameter families; exactly eighteen subvarieties are finitely based, and the unique limit subvariety is $\V(SR_6)$. The strong nonfinite-basis status of the four finite semirings remains open.

math.GR