SearcharxivSearch

arXiv subjects

Massimiliano Sala

Publications and source records attributed to Massimiliano Sala.

At least 19 recordsLinked to original sources

A Note on Binary Quadratic Systems and their relation to complexity theory

Deciding whether a system of multivariate quadratic equations over $\mathbb F_2$ has a solution is a classical NP-complete problem, and remains so for square systems, with as many equations as variables. The hardness of this problem is one of the cornerstones of nowadays post-quantum cryptography. Let $\MQ_0(n)$ and $\MQ_1(n)$ denote the sets of square quadratic systems in $n$ variables having respectively no solutions and exactly one solution. $\cup_{n\geq 2} \MQ_0(n)$ is a coNP-complete language, while $\cup_{n\geq 2} \MQ_1(n)$ lies in DP. It is known that $\lim_{n\to \infty} |\MQ_1(n)|/|\MQ_0(n)|=1$. Here we prove the explicit finite-$n$ bounds \[ |\MQ_0(n)|<|\MQ_1(n)| \le \left(1+\frac{1}{2^n-1}\right)|\MQ_0(n)|, \] More generally, let $Q_d$ be the space of polynomial functions $(\FF_2)^n\to\mathbb F_2$ of degree at most $d$, and let $\alpha_k$ count square systems in $(Q_d)^n$ having exactly $k$ solutions. Then \[ \alpha_0<\alpha_1 \le \left(1+\frac{1}{2^n-1}\right)\alpha_0\,, \qquad 2\le d\le n \,. \] The proof combines matroid and coding-theoretic methods. We interpret $(\FF_2)^n$ as the ground set of the evaluation matroid of $Q_d$, express $\alpha_0$ and $\alpha_1$ through characteristic polynomials, and use a Whitney-type sign-reversing involution to show that the only terms that can push $\alpha_1-\alpha_0$ below $\alpha_1/2^n$ come from the elements of a matroid port. These are identified with minimal-support words of the Reed--Muller code $\RM(n-d-1,n)=\RM(d,n)^\perp$; the required estimate then follows from the MacWilliams identity, the minimum-distance bound $2^{d+1}$, and the even-weight structure of the code.

cs.IT

Stabilizing the Staking Rate, Dynamically Distributed Inflation and Delay Induced Oscillations

Dynamically distributed inflation is a common mechanism used to guide a blockchain's staking rate towards a desired equilibrium between network security and token liquidity. However, the high sensitivity of the annual percentage yield to changes in the staking rate, coupled with the inherent feedback delays in staker responses, can induce undesirable oscillations around this equilibrium. This paper investigates this instability phenomenon. We analyze the dynamics of inflation-based reward systems and propose a novel distribution model designed to stabilize the staking rate. Our solution effectively dampens oscillations, stabilizing the yield within a target staking range.

cs.CR

A Note on Vectorial Boolean Functions as Embeddings

Let $F$ be a vectorial Boolean function from $\mathbb{F}_2^n$ to $\mathbb{F}_2^m$, with $m \geq n$. We define $F$ as an embedding if $F$ is injective. In this paper, we examine the component functions of $F$, focusing on constant and balanced components. Our findings reveal that at most $2^m - 2^{m-n}$ components of $F$ can be balanced, and this maximum is achieved precisely when $F$ is an embedding, with the remaining $2^{m-n}$ components being constants. Additionally, for partially-bent embeddings, we demonstrate that there are always at least $2^n - 1$ balanced components when $n$ is even, and $2^{m-1} + 2^{n-1} - 1$ balanced components when $n$ is odd. A relation with APN functions is shown.

cs.CR

Elliptic Loops

Given a local ring $(R,\mathfrak{m})$ and an elliptic curve $E(R/\mathfrak{m})$, we define elliptic loops as the points of $\mathbb{P}^2(R)$ projecting to $E$ under the canonical modulo-$\mathfrak{m}$ reduction, endowed with an operation that extends the curve's addition. While their subset of points satisfying the curve's Weierstrass equation is a group, these larger objects are proved to be power associative abelian algebraic loops, which are seldom completely associative. When an elliptic loop has no points of order $3$, its affine part is obtained as a stratification of a one-parameter family of elliptic curves defined over $R$, which we call layers. Stronger associativity properties are established when $\mathfrak{m}^e$ vanishes for small values of $e \in \mathbb{Z}$. When the underlying ring is $R = \mathbb{Z}/p^e\mathbb{Z}$, the infinity part of an elliptic loop is generated by two elements, the group structure of layers may be established and the points with the same projection and same order possess a geometric description.

math.AC

An algebraic attack on stream ciphers with application to nonlinear filter generators and WG-PRNG

In this paper, we propose a new algebraic attack on stream ciphers. Starting from the well-known attack due to Courtois and Meier, we design an attack especially effective against nonlinear filter generators. We test it on two toy stream ciphers and we show that the level of security of one of stream ciphers submitted to the NIST competition on Lightweight Cryptography, WG-PRNG, is less than that stated before now.

cs.CR

On the equivalence of two post-quantum cryptographic families

The Maximum Likelihood Decoding Problem (MLD) is known to be NP-hard and its complexity is strictly related to the security of some post-quantum cryptosystems, that is, the so-called code-based primitives. Analogously, the Multivariate Quadratic System Problem (MQ) is NP-hard and its complexity is necessary for the security of the so-called multivariate-based primitives. In this paper we present a closed formula for a polynomial-time reduction from any instance of MLD to an instance of MQ, and viceversa. We also show a polynomial-time isomorphism between MQ and MLD, thus demonstrating the direct link between the two post-quantum cryptographic families.

cs.CC

A survey on Functional Encryption

Functional Encryption (FE) expands traditional public-key encryption in two different ways: it supports fine-grained access control and allows learning a function of the encrypted data. In this paper, we review all FE classes, describing their functionalities and main characteristics. In particular, we mention several schemes for each class, providing their security assumptions and comparing their properties. To our knowledge, this is the first survey that encompasses the entire FE family.

cs.CR

Rational points on cubic surfaces and AG codes from the Norm-Trace curve

In this paper we give a complete characterization of the intersections between the Norm-Trace curve over $\mathbb{F}_{q^3}$ and the curves of the form $y=ax^3+bx^2+cx+d$, generalizing a previous result by Bonini and Sala, providing more detailed information about the weight spectrum of one-point AG codes arising from such curve. We also derive, with explicit computations, some general bounds for the number of rational points on a cubic surface defined over $\mathbb{F}_{q}$.

math.AG

The group structure of elliptic curves over Z/NZ

We characterize the possible groups $E(\mathbb{Z}/N\mathbb{Z})$ arising from elliptic curves over $\mathbb{Z}/N\mathbb{Z}$ in terms of the groups $E(\mathbb{F}_p)$, with $p$ varying among the prime divisors of $N$. This classification is achieved by showing that the infinity part of any elliptic curve over $\mathbb{Z}/p^e\mathbb{Z}$ is a $\mathbb{Z}/p^e\mathbb{Z}$-torsor, of which a generator is exhibited. As a first consequence, when $E(\mathbb{Z}/N\mathbb{Z})$ is a $p$-group, we provide an explicit and sharp bound on its rank. As a second consequence, when $N = p^e$ is a prime power and the projected curve $E(\mathbb{F}_p)$ has trace one, we provide an isomorphism attack to the ECDLP, which works only by means of finite rings arithmetic.

math.NT

A Provably-Unforgeable Threshold EdDSA with an Offline Recovery Party

A $(t,n)$-threshold signature scheme enables distributed signing among $n$ players such that any subset of size at least $t$ can sign, whereas any subset with fewer players cannot. The goal is to produce threshold digital signatures that are compatible with an existing centralized signature scheme. Starting from the threshold scheme for the ECDSA signature due to Battagliola et al., we present the first protocol that supports EdDSA multi-party signatures with an offline participant during the key-generation phase, without relying on a trusted third party. Under standard assumptions we prove our scheme secure against adaptive malicious adversaries. Furthermore we show how our security notion can be strengthen when considering a rushing adversary. We discuss the resiliency of the recovery in the presence of a malicious party. Using a classical game-based argument, we prove that if there is an adversary capable of forging the scheme with non-negligible probability, then we can build a forger for the centralized EdDSA scheme with non-negligible probability.

cs.CR

Threshold ECDSA with an Offline Recovery Party

A $(t,n)-$ threshold signature scheme enables distributed signing among $n$ players such that any subgroup of size $t$ can sign, whereas any group with fewer players cannot. Our goal is to produce signatures that are compatible with an existing centralized signature scheme: the key generation and signature algorithm are replaced by a communication protocol between the parties, but the verification algorithm remains identical to that of a signature issued using the centralized algorithm. Starting from the threshold schemes for the ECDSA signature due to R. Gennaro and S. Goldfeder, we present the first protocol that supports multiparty signatures with an offline participant during the Key Generation Phase, without relying on a trusted third party. Following well-established approaches, we prove our scheme secure against adaptive malicious adversaries.

cs.CR

A formula on the weight distribution of linear codes with applications to AMDS codes

The determination of the weight distribution of linear codes has been a fascinating problem since the very beginning of coding theory. There has been a lot of research on weight enumerators of special cases, such as self-dual codes and codes with small Singleton's defect. We propose a new set of linear relations that must be satisfied by the coefficients of the weight distribution. From these relations we are able to derive known identities (in an easier way) for interesting cases, such as extremal codes, Hermitian codes, MDS and NMDS codes. Moreover, we are able to present for the first time the weight distribution of AMDS codes. We also discuss the link between our results and the Pless equations.

math.CO

A new ECDLP-based PoW model

We lay the foundations for a blockchain scheme, whose consensus is reached via a proof of work algorithm based on the solution of consecutive discrete logarithm problems over the point group of elliptic curves. In the considered architecture, the curves are pseudorandomly determined by block creators, chosen to be cryptographically secure and changed every epoch. Given the current state of the chain and a prescribed set of transactions, the curve selection is fully rigid, therefore trust is needed neither in miners nor in the scheme proposers.

cs.CR

On the linear structures of Balanced functions and quadratic APN functions

The set of linear structures of most known balanced Boolean functions is nontrivial. In this paper, some balanced Boolean functions whose set of linear structures is trivial are constructed. We show that any APN function in even dimension must have a component whose set of linear structures is trivial. We determine a general form for the number of bent components in quadratic APN functions in even dimension and some bounds on the number are produced. We also count bent components in any quadratic power functions.

cs.CR

On some cryptographic properties of Boolean functions and their second-order derivatives

In this paper some cryptographic properties of Boolean functions, including weight, balancedness and nonlinearity, are studied, particularly focusing on splitting functions and cubic Boolean functions. Moreover, we present some quantities derived from the behaviour of second-order derivatives which allow us to determine whether a quadratic or cubic function is APN.

cs.CR

Public Ledger for Sensitive Data

Satoshi Nakamoto's Blockchain allows to build publicly verifiable and almost immutable ledgers, but sometimes privacy has to be factored in. In this work an original protocol is presented that allows sensitive data to be stored on a ledger where its integrity may be publicly verified, but its privacy is preserved and owners can tightly manage the sharing of their information with efficient revocation.

cs.CR

Two-tier blockchain timestamped notarization with incremental security

Digital notarization is one of the most promising services offered by modern blockchain-based solutions. We present a digital notary design with incremental security and cost reduced with respect to current solutions. A client of the service receives evidence in three steps. In the first step, evidence is received almost immediately, but a lot of trust is required. In the second step, less trust is required, but evidence is received seconds later. Finally, in the third step evidence is received within minutes via a public blockchain.

cs.CR