論文の概要: Full-Key Recovery and Forgery from One MQOM v2.1 Signature
- arxiv url: http://arxiv.org/abs/2608.09699v2
- Date: Thu, 13 Aug 2026 14:15:00 GMT
- ステータス: 翻訳完了
- システム内更新日: 2026-08-14 14:00:09.602774
- Title: Full-Key Recovery and Forgery from One MQOM v2.1 Signature
- Title(参考訳): 1つのMQOM v2.1署名からの完全キー回復と偽造
- Authors: José Luis Delgado,
- Abstract要約: NIST追加署名プロセスにおけるラウンド3候補であるMQOM v2.1に対して、完全なキー回復攻撃を与える。
承認された署名から完全な署名キーを復元し、新しいメッセージにサインするためにそれを使用します。
- 参考スコア(独自算出の注目度): 0.0
- License: http://creativecommons.org/licenses/by/4.0/
- Abstract: We give a full-key-recovery attack on MQOM v2.1, a Round-3 candidate in the NIST additional-signature process, that recovers the complete signing key from one accepted signature and uses it to sign a fresh message. If $δ=\operatorname{FirstBits}_λ(x)$ is the prefix of the witness $x$, the sibling path determines a public value $A$ such that tree parity gives $s=δ\oplus A$. Substitution into the hidden-leaf commitment yields $$\mathsf{Enc}_K(δ\oplus A)=T\oplus\mathsf{LinOrtho}(δ)$$ with public values $K$ and $T$. The correction in the same signature expands a solution into a complete witness, while the public MQ relation identifies those yielding valid signing keys; serializing such a witness gives the secret key, enabling a fresh-message signature accepted by the reference verifier. We evaluate this equation over the specified AES/Rijndael circuits using retained circuit state along a Gray traversal. Complete-domain scans for Categories I and V cost $2^{142.335112}$ and $2^{271.794162}$ Boolean gates. Category-III scans cover $1/2+2^{-20}$ and $0.580004770183$ of the domain at costs of $2^{206.774558}$ and $2^{206.988685}$ gates. All four totals are below the NIST security benchmarks. Reduced-domain runs against the reference implementation recover the byte-exact witness and key in all three categories and produce a fresh-message forgery accepted by the reference verifier. Independently generated source-syntax circuits evaluate the fixed ciphers over the stated domains and translated L3 prefixes, while an exact ideal-cipher factorial-moment bound controls additional equation preimages passed to public-key validation. Every value in the equation is fixed by the accepted transcript, so salt-bound global-root expansion changes its public constants without removing the one-signature recovery channel.
- Abstract(参考訳): 我々は、NIST追加署名プロセスのラウンド3候補であるMQOM v2.1に対して、完全なキー回復攻撃を施す。
もし$δ=\operatorname{FirstBits}_λ(x)$が証人$x$のプレフィックスであれば、兄弟パスは公開値$A$を決定し、ツリーパリティが$s=δ\oplus A$を与える。
隠されたリーフのコミットメントへの置換は$$\mathsf{Enc}_K(δ\oplus A)=T\oplus\mathsf{LinOrtho}(δ)$$で、公開値は$K$と$T$となる。
同じ署名の修正は、ソリューションを完全な証人へと拡張し、パブリックMQ関係は有効な署名キーを出力するものを識別し、そのような証人へのシリアライズは秘密鍵を与え、参照検証者が受け入れた新しいメッセージ署名を可能にする。
我々は,この方程式を,グレイトラバースに沿って保持された回路状態を用いて,指定されたAES/Rijndael回路上で評価する。
カテゴリIとVの完全なドメインスキャンは2.142.335112}$と2.271.794162}$ブールゲートである。
カテゴリーIIIスキャンは、$1/2+2^{-20}$と$0.580004770183$を、$2^{206.774558}$と$2^{206.988685}$ゲートでカバーしている。
4つの合計はいずれもNISTのセキュリティベンチマーク以下である。
Reduced-domainは、参照実装に対して実行され、3つのカテゴリのバイトエクサクタとキーが復元され、参照検証者が受け入れる新しいメッセージの偽造が生成される。
独立に生成されたソースシンタクス回路は、前述の領域上の固定暗号を評価し、L3プレフィックスを翻訳する。
方程式のすべての値は受け入れられた転写書によって固定されるので、塩分に結合したグローバルルート展開は、1つの符号の回復チャネルを取り除くことなく、その公定数を変化させる。
関連論文リスト
- Security Analysis for SCONE Logic Locking [8.289792786302579]
SCONE [DAC'25] は論理ロックインタフェースを拡張し、元のプライマリ入力から追加のエンコードされた入力を出力する。
両方の実現には脆弱性があるが、異なる理由がある。
本稿では、軽量な非線形緩和法を提案し、本論文で特定された脆弱性を示さないことを示す。
論文 参考訳(メタデータ) (2026-07-03T12:57:29Z) - Isolating LLM Alignment from Regex: Zero Coverage and Metric-Dependent Divergence Under Adversarial Mutation [51.56484100374058]
以前の作業では、アクティブフィルタの背後にライブのGeminiバックエンドを追加することで、測定可能なカバレッジが得られなかった。
L_4$-real(Gemini-2.5-flash, token-budget cap, rate limit, output scrub)と同様の$L_5$-no-regexを導入するが、9パターンフィルタは無効である。
3つのサブ言語にまたがる敵対的プローブに対して評価を行った。
論文 参考訳(メタデータ) (2026-06-12T18:54:24Z) - Imbuing Large Language Models with Bidirectional Logic for Robust Chain Repair [44.80087038178069]
本稿では,デコーダのみのトランスフォーマーをネイティブに組み込んだトレーニングフレームワークであるTeleological Reasoning Infilling (TRI)を紹介する。
推測では、TRIは二重システムループ内の外科的修復モジュールとして動作する。
3つのベンチマークの実験では、TRIは全てのタスクで最先端のパフォーマンスを達成し、プロブレム当たりのトークン支出を31.2%削減した。
論文 参考訳(メタデータ) (2026-06-03T15:58:48Z) - The Security Budget of Code-LLM Prompt Hardening: Provable Limits Under Pass-Only Acceptance [0.0]
本稿では,emphTri-Audit Protocolとしてフロアを運用する。このプロトコルは,プロンプト側推論レジストリ属性をモデル側実証ログから分離する2軸レポーティングプロトコルである。
CodeLlama-7B, Qwen2.5-Coder-7B/1.5B and DeepSeek-Coder-6.7B at $n=164$ yields the emphCross-Model Tri-Audit Invariance: of 28 pass-serving rows, 12-changed-of-record learned-can
論文 参考訳(メタデータ) (2026-06-02T08:22:14Z) - Copy-as-Decode: Grammar-Constrained Parallel Prefill for LLM Editing [2.6382975801439836]
LLMは、入力中にほとんどのトークンが冗長に見える場合でも、全出力を自動回帰的に再生することでテキストとコードを編集する。
Copy-as-Decodeは、2プリミティブ文法上の構造化復号化として生成を再キャストする復号化機構である。
論文 参考訳(メタデータ) (2026-04-20T12:29:53Z) - Rényi exponent landscape of multipartite entanglement in free-fermion systems [51.56484100374058]
我々は、Rényi tripartite information $I_3() が小フェルミ運動量での質的に $exclusion-dependent scaling を示すことを示した。
I_m(n)/I_m(1) sim zm-1 to 0$ for all integer $n geq 2$, so the leading von Neumann signal can builded from integer Rényi data。
論文 参考訳(メタデータ) (2026-03-09T22:27:00Z) - Burau representation, Squier's form, and non-Abelian anyons [53.92822954974537]
ブレイド群 $B_3$ のブラウ表現から構築した周波数可変2次元非アベリア的演算順序制御を導入する。
Squier 陽性ウィンドウの向こう側にある$Delta(omega)$の符号変更は、因果順序の交互に構成的かつ破壊的干渉を示す。
数値シミュレーションにより、拡張と抑制の両方が確認され、最小の$B_3$ブレイド制御が確立される。
論文 参考訳(メタデータ) (2025-10-21T00:25:21Z) - A Symmetric-Key Cryptosystem Based on the Burnside Ring of a Compact Lie Group [0.0]
我々は、コンパクトリー群$G$のバーンサイド環$A(G)$で代わりに線形作用が起こる対称鍵暗号系を提案する。
任意の有限長のメッセージは$A(G)$の有限サポート元としてエンコードされ、$k$のBurnside製品を介して暗号化される。
有限ランク部分加群 $W_Lsubset A(O(2))$ 上でのみ作用が制限されることを示し、そのようなデータから鍵の情報理論的非識別性を示す。
論文 参考訳(メタデータ) (2025-10-13T01:57:22Z) - Sign Operator for Coping with Heavy-Tailed Noise in Non-Convex Optimization: High Probability Bounds Under $(L_0, L_1)$-Smoothness [74.18546828528298]
SignSGD with Majority Votingは,Kappakappakappa-1right,Kappakappakappa-1right,Kappakappakappa-1right,Kappakappakappa-1right,Kappaka ppakappa-1right,Kappakappakappa-1right,Kappakappakappa-1right,Kappakappakappa-1right,Kappakappakappa -1right,Kappakappakappa-1right,Kappakappakappa-1right,Kappakappappapa-1right,Kappaを用いて,複雑性の全範囲で堅牢に動作することを示す。
論文 参考訳(メタデータ) (2025-02-11T19:54:11Z) - Extending Asynchronous Byzantine Agreement with Crusader Agreement [23.27199615640474]
多値BAから二値BAへの新たな削減を提案する。
削減には多値CAを用いるため、$ell$-bit入力のための2つの情報理論CAプロトコルも設計する。
論文 参考訳(メタデータ) (2025-02-04T13:44:41Z) - WR-ONE2SET: Towards Well-Calibrated Keyphrase Generation [57.11538133231843]
キーワード生成は、入力文書を要約する短いフレーズを自動的に生成することを目的としている。
最近登場したONE2SETパラダイムは、キーフレーズをセットとして生成し、競争性能を達成した。
本稿では, ONE2SET を拡張した WR-ONE2SET を提案する。
論文 参考訳(メタデータ) (2022-11-13T09:56:24Z)
関連論文リストは本サイト内にある論文のタイトル・アブストラクトから自動的に作成しています。
指定された論文の情報です。
本サイトの運営者は本サイト(すべての情報・翻訳含む)の品質を保証せず、本サイト(すべての情報・翻訳含む)を使用して発生したあらゆる結果について一切の責任を負いません。