SearcharxivSearch

arXiv · math/0311047

Assessing security of some group based cryptosystems

Abstract

One of the possible generalizations of the discrete logarithm problem to arbitrary groups is the so-called conjugacy search problem (sometimes erroneously called just the conjugacy problem): given two elements a, b of a group G and the information that a^x=b for some x \in G, find at least one particular element x like that. Here a^x stands for xax^{-1}. The computational difficulty of this problem in some particular groups has been used in several group based cryptosystems. Recently, a few preprints have been in circulation that suggested various "neighbourhood search" type heuristic attacks on the conjugacy search problem. The goal of the present survey is to stress a (probably well known) fact that these heuristic attacks alone are not a threat to the security of a cryptosystem, and, more importantly, to suggest a more credible approach to assessing security of group based cryptosystems. Such an approach should be necessarily based on the concept of the average case complexity (or expected running time) of an algorithm. These arguments support the following conclusion: although it is generally feasible to base the security of a cryptosystem on the difficulty of the conjugacy search problem, the group G itself (the "platform") has to be chosen very carefully. In particular, experimental as well as theoretical evidence collected so far makes it appear likely that braid groups are not a good choice for the platform. We also reflect on possible replacements.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Vladimir Shpilrain. 2003-11-04. Assessing security of some group based cryptosystems. https://arxiv.org/abs/math/0311047

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Reversibility and its asymptotic counting in Picard group

We investigate reversible elements in the Picard modular group $\mathrm{PSL}(2,\mathbb{Z}[i])$. We show that reversibility coincides with strong reversibility for Kleinian groups, in particular for the Picard group. We classify reversible elements in the Picard group and characterize loxodromic reversible elements up to conjugacy. We prove that each such conjugacy class contains exactly eight special representatives. We also obtain asymptotic estimates for the number of reversible conjugacy classes with bounded trace.

math.GR

Conjugator length in finitely generated groups

We describe all functions $\mathbb{N}\rightarrow \mathbb{N}$ that can be realized, up to the standard equivalence, as conjugator length functions of finitely generated groups. Furthermore, we show that any two increasing functions $f,g\colon \mathbb N\to \mathbb N$ can be simultaneously realized as conjugator length functions of finitely generated, commensurable (in particular, quasi-isometric) groups.

math.GR

The spectrum of conjugator length functions

A recent program tries to find which functions appear as conjugator length functions. In this note, we show that any (computable) increasing function larger than $n$ appears as $\mathrm{Cl}_G$ for some finitely generated (recursively presented) group. On the other hand, we demonstrate that either $\mathrm{Cl}_G$ must be constant or $\mathrm{Cl}_G(n)\succ n$. Combining these, we obtain a complete description of which functions appear as conjugator length functions of finitely generated groups.

math.GR