Search arXivSearch

arXiv · 0801.4786

Cryptanalysis of Anshel-Anshel-Goldfeld-Lemieux key agreement protocol

Abstract

The Anshel-Anshel-Goldfeld-Lemieux (abbreviated AAGL) key agreement protocol is proposed to be used on low-cost platforms which constraint the use of computational resources. The core of the protocol is the concept of an Algebraic Eraser (abbreviated AE) which is claimed to be a suitable primitive for use within lightweight cryptography. The AE primitive is based on a new and ingenious idea of using an action of a semidirect product on a (semi)group to obscure involved algebraic structures. The underlying motivation for AAGL protocol is the need to secure networks which deploy Radio Frequency Identification (RFID) tags used for identification, authentication, tracing and point-of-sale applications. In this paper we revisit the computational problem on which AE relies and heuristically analyze its hardness. We show that for proposed parameter values it is impossible to instantiate the secure protocol. To be more precise, in 100% of randomly generated instances of the protocol we were able to find a secret conjugator z generated by TTP algorithm (part of AAGL protocol).

Explore related subjects

Keep this discovery

BibTeXRIS

Alex D. Myasnikov, Alexander Ushakov. 2008-01-30. Cryptanalysis of Anshel-Anshel-Goldfeld-Lemieux key agreement protocol. https://arxiv.org/abs/0801.4786

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Reversibility and its asymptotic counting in Picard group

We investigate reversible elements in the Picard modular group $\mathrm{PSL}(2,\mathbb{Z}[i])$. We show that reversibility coincides with strong reversibility for Kleinian groups, in particular for the Picard group. We classify reversible elements in the Picard group and characterize loxodromic reversible elements up to conjugacy. We prove that each such conjugacy class contains exactly eight special representatives. We also obtain asymptotic estimates for the number of reversible conjugacy classes with bounded trace.

math.GR

Conjugator length in finitely generated groups

We describe all functions $\mathbb{N}\rightarrow \mathbb{N}$ that can be realized, up to the standard equivalence, as conjugator length functions of finitely generated groups. Furthermore, we show that any two increasing functions $f,g\colon \mathbb N\to \mathbb N$ can be simultaneously realized as conjugator length functions of finitely generated, commensurable (in particular, quasi-isometric) groups.

math.GR

The spectrum of conjugator length functions

A recent program tries to find which functions appear as conjugator length functions. In this note, we show that any (computable) increasing function larger than $n$ appears as $\mathrm{Cl}_G$ for some finitely generated (recursively presented) group. On the other hand, we demonstrate that either $\mathrm{Cl}_G$ must be constant or $\mathrm{Cl}_G(n)\succ n$. Combining these, we obtain a complete description of which functions appear as conjugator length functions of finitely generated groups.

math.GR