Annual International Conference on the Theory and Applications of Cryptographic Techniques

EUROCRYPT 2005: Advances in Cryptology – EUROCRYPT 2005 pp 341-353

Differential Cryptanalysis for Multivariate Schemes

  • Pierre-Alain Fouque
  • Louis Granboulan
  • Jacques Stern
Conference paper

DOI: 10.1007/11426639_20

Volume 3494 of the book series Lecture Notes in Computer Science (LNCS)

Abstract

In this paper we propose a novel cryptanalytic method against multivariate schemes, which adapts differential cryptanalysis to this setting. In multivariate quadratic systems, the differential of the public key is a linear map and has invariants such as the dimension of the kernel. Using linear algebra, the study of this invariant can be used to gain information on the secret key. We successfully apply this new method to break the original Matsumoto-Imai cryptosystem using properties of the differential, thus providing an alternative attack against this scheme besides the attack devised by Patarin. Next, we present an attack against a randomised variant of the Matsumoto-Imai cryptosystem, called PMI. This scheme has recently been proposed by Ding, and according to the author, it resists all previously known attacks. We believe that differential cryptanalysis is a general and powerful method that can give additional insight on most multivariate schemes proposed so far.

Download to read the full conference paper text

Copyright information

© Springer-Verlag Berlin Heidelberg 2005

Authors and Affiliations

  • Pierre-Alain Fouque
    • 1
  • Louis Granboulan
    • 1
  • Jacques Stern
    • 1
  1. 1.Département d’InformatiqueÉcole normale supérieureParis cedex 05France