Cryptanalysis of the NTRU Signature Scheme (NSS) from Eurocrypt 2001
نویسندگان
چکیده
In 1996, a new cryptosystem called NTRU was introduced, related to the hardness of finding short vectors in specific lattices. At Eurocrypt 2001, the NTRU Signature Scheme (NSS), a signature scheme apparently related to the same hard problem, was proposed. In this paper, we show that the problem on which NSS relies is much easier than anticipated, and we describe an attack that allows efficient forgery of a signature on any message. Additionally, we demonstrate that a transcript of signatures leaks information about the secret key: using a correlation attack, it is possible to recover the key from a few tens of thousands of signatures. The attacks apply to the recently proposed parameter sets NSS251-3-SHA1-1, NSS347-3-SHA1-1, and NSS5033-SHA1-1 in [15]. Following the attacks, NTRU researchers have investigated enhanced encoding/verification methods in [8].
منابع مشابه
Cryptanalysis of the Revised NTRU Signature Scheme
In this paper, we describe a three-stage attack against Revised NSS, an NTRU-based signature scheme proposed at the Eurocrypt 2001 conference as an enhancement of the (broken) proceedings version of the scheme. The first stage, which typically uses a transcript of only 4 signatures, effectively cuts the key length in half while completely avoiding the intended hard lattice problem. After an emp...
متن کاملNSS: An NTRU Lattice-Based Signature Scheme
A new authentication and digital signature scheme called the NTRU Signature Scheme (NSS) is introduced. NSS provides an authentication/signature method complementary to the NTRU public key cryptosystem. The hard lattice problem underlying NSS is similar to the hard problem underlying NTRU, and NSS similarly features high speed, low footprint, and easy key creation.
متن کاملTitle: Enhanced Encoding and Verification Methods for the Ntru Signature Scheme Section 1. the Hard Problem Underlying Ntru and Nss
The NTRU Signature Scheme (NSS) is a digital signature scheme based on a hard lattice problem. This lattice problem also underlies the NTRU Public Key Cryptosystem described in [1]. In this section we remind the reader of the standard description of the NTRU lattice problem in terms of products of polynomials in convolution rings. For further details, see [1]. Fix three positive integer paramet...
متن کاملNSS: The NTRU Signature Scheme
A new authentication and digital signature scheme called the NTRU Signature Scheme (NSS) is introduced. NSS provides an authentication/signature method complementary to the NTRU public key cryptosystem. The hard lattice problem underlying NSS is similar to the hard problem underlying NTRU, and NSS similarly features high speed, low footprint, and easy key creation.
متن کاملNSS: A Lattice-Based Signature Scheme
The purpose of this paper is to submit the NSS lattice based signature scheme for consideration for inclusion in the IEEE P1363.1 standard. At the rump session of CRYPTO ’96 the authors introduced a highly efficient new public key cryptosystem called NTRU. (See [4] for details.) Underlying NTRU is a hard mathematical problem of finding short vectors in certain lattices. In this paper we introdu...
متن کامل