SearcharxivSearch

arXiv · 1709.02079

A Non-commutative Cryptosystem Based on Quaternion Algebras

Abstract

We propose BQTRU, a non-commutative NTRU-like cryptosystem over quaternion algebras. This cryptosystem uses bivariate polynomials as the underling ring. The multiplication operation in our cryptosystem can be performed with high speed using quaternions algebras over finite rings. As a consequence, the key generation and encryption process of our cryptosystem is faster than NTRU in comparable parameters. Typically using Strassen's method, the key generation and encryption process is approximately $16/7$ times faster than NTRU for an equivalent parameter set. Moreover, the BQTRU lattice has a hybrid structure that makes inefficient standard lattice attacks on the private key. This entails a higher computational complexity for attackers providing the opportunity of having smaller key sizes. Consequently, in this sense, BQTRU is more resistant than NTRU against known attacks at an equivalent parameter set. Moreover, message protection is feasible through larger polynomials and this allows us to obtain the same security level as other NTRU-like cryptosystems but using lower dimensions.

Explore related subjects

Keep this discovery

BibTeXRIS

Khadijeh Bagheri, Mohammad-Reza Sadeghi, Daniel Panario. 2017-09-07. A Non-commutative Cryptosystem Based on Quaternion Algebras. https://arxiv.org/abs/1709.02079

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Invariants of Nilpotent Lie Algebras via Geometry and Algebra with a Focus on Computation

We consider the problem of computing rational invariants of nilpotent Lie algebras. We compare two methods that are commonly used for this task: the method of integral curves and the Dixmier map. Given a derivation of a rational function field with polynomial coefficients, we formulate a condition under which the kernel can be recovered from a family of rational integral curves, and we show that triangular derivations satisfy this hypothesis. This yields an explicit description of the kernel as a purely transcendental extension and produces algebraically independent generators. We also show that, in the triangular case, the resulting generators agree with those obtained from the Dixmier map via a local slice. A careful analysis of the generating set obtained from this method leads to an algorithm for computing generators of the rational invariant field of a nilpotent Lie algebra. An implementation of the methods is available in the SageMath system.

math.RA

Quasilinear multiplication in the real Cayley--Dickson tower

Direct evaluation of the defining product in the real Cayley--Dickson algebra $A_n$, of dimension $N=2^n$, has quadratic arithmetic complexity. This paper gives a uniform algorithm for multiplication using $O(N\log N)$ real arithmetic operations and $O(N)$ auxiliary storage. The algorithm reduces multiplication to the alternating product on the imaginary subspace, then evaluates that product by a two-call recursion over one fixed quadratic coefficient extension. For $n\ge1$, the resulting bilinear algorithm uses at most $(9n-15)2^{n-1}+10$ input-dependent real multiplications, and for $n\ge3$, the specified arithmetic schedule uses $(34n-83)2^{n-1}+50$ real operations in total. Under this counting convention, the quasilinear schedule uses fewer operations than direct multiplication for $N\ge16$ and than the uniform Cariow--Cariowa method for $N\ge32$. The algorithm is implemented in the MIT-licensed C11 library fastCD, with a NumPy-backed Python interface, and its results are checked against an independent implementation of the defining recursion. In single-core benchmarks against direct multiplication and the uniform Cariow--Cariowa method, the quasilinear implementation had the lowest mean time of the three at every tested dimension $N\ge32$, for both single and batched products, and was roughly $16$ times faster than direct multiplication at $N=1024$.

math.RA

Graded classification of Leavitt path algebras in terms of strong shift equivalence

Given two finite essential adjacency matrices $A$ and $B$, Hazrat's graded classification conjectures posit that an order preserving $\mathbb{Z}[x,x^{-1}]$-module isomorphism of $K_0$ groups implies graded Morita equivalence of the Leavitt path algebras of $A$ and $B$, while the pointed version predicts a graded isomorphism of the Leavitt path algebras when the $K_0$ group isomorphism additionally preserves the class of the regular module. For any field $k$, we show that the Leavitt path algebras over $k$ of $A$ and $B$ are graded Morita equivalent if and only if $A$ and $B$ are strong shift equivalent. By appealing to counterexamples of Kim and Roush from symbolic dynamics, this shows that Hazrat's graded classification conjectures are false.

math.RA