Search arXiv⌕ Search

arXiv · 0707.1501

Random subgroups and analysis of the length-based and quotient attacks

Abstract

In this paper we discuss generic properties of "random subgroups" of a given group G. It turns out that in many groups G (even in most exotic of them) the random subgroups have a simple algebraic structure and they "sit" inside G in a very particular way. This gives a strong mathematical foundation for cryptanalysis of several group-based cryptosystems and indicates on how to chose "strong keys". To illustrate our technique we analyze the Anshel-Anshel-Goldfeld (AAG) cryptosystem and give a mathematical explanation of recent success of some heuristic length-based attacks on it. Furthermore, we design and analyze a new type of attacks, which we term the quotient attacks. Mathematical methods we develop here also indicate how one can try to choose "parameters" in AAG to foil the attacks.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Alexei G. Myasnikov, Alexander Ushakov. 2007-07-10. Random subgroups and analysis of the length-based and quotient attacks. https://arxiv.org/abs/0707.1501

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Random Quotients of Free Products

We introduce a density model for random quotients of a free product of finitely generated groups. We prove that a random quotient in this model has the following properties with overwhelming probability: if the density is below $1/2$, the free factors embed into the random quotient and the random quotient is hyperbolic relative to the free factors. Further, there is a phase transition at $1/2$, with the random quotient being a finite group above this density. If the density is below $1/6$, the random quotient is cubulated relative to the free factors. Moreover, if the free factors are cubulated, then so is the random quotient.

math.GR↗

Inherently nonfinitely based additively idempotent semirings

We establish a sufficient condition for an additively idempotent semiring to be inherently nonfinitely based: if its generated variety is locally finite and every Zimin word is minimal in the additive order, then it is contained in no finitely based locally finite variety. For every positive integer $n$, we construct an infinite finitely generated flat semiring satisfying all identities in at most $n$ variables of every ai-semiring with this minimality property. We also characterize Zimin minimality by the membership of a countable flat factor semiring $\Finf$ in the generated variety, and prove that$\V(\Finf)$ is locally finite and inherently nonfinitely based. As applications, we show that the six-element ai-semirings $\A$ and $\B$ are inherently nonfinitely based. In contrast, we prove that the six-element ai-semiring $\overline{A_2^1}$ is not inherently nonfinitely based, although its multiplicative reduct $A_2^1$ is inherently nonfinitely based. To the best of our knowledge, this is the first example of an ai-semiring whose multiplicative reduct is inherently nonfinitely based while the ai-semiring itself is not.

math.GR↗

On the residual finiteness of the non-abelian tensor square $G \otimes G$, the non-abelian exterior square $G \wedge G$ and the weak commutativity construction $\X(G)$

We prove that if $G$ is a residually finite group, $\widehat{G}$ is its profinite completion and the map $H_2(G, \mathbb{Z}) $ $ \to H_2(\widehat{G}, \widehat{\mathbb{Z}}),$ induced by the canonical map $G \to \widehat{G}$, is injective, then the non-abelian exterior square $G \wedge G$ is residually finite. We show that if $G$ is a finitely presented centre-by-metabelian group then $ν(G)$, the non-abelian tensor product $G \otimes G$ and the non-abelian tensor square $G \wedge G$ are residually finite. Furthermore we prove that if $G$ be a finitely presented metabelian group then the weak commutative construction $\X(G)$ is residually finite. We discuss a criterion for the $q$-exterior square $G \wedge^q G$ to be residually finite.

math.GR↗