Search arXivSearch

arXiv · 0804.0629

Short expressions of permutations as products and cryptanalysis of the Algebraic Eraser

Abstract

On March 2004, Anshel, Anshel, Goldfeld, and Lemieux introduced the \emph{Algebraic Eraser} scheme for key agreement over an insecure channel, using a novel hybrid of infinite and finite noncommutative groups. They also introduced the \emph{Colored Burau Key Agreement Protocol (CBKAP)}, a concrete realization of this scheme. We present general, efficient heuristic algorithms, which extract the shared key out of the public information provided by CBKAP. These algorithms are, according to heuristic reasoning and according to massive experiments, successful for all sizes of the security parameters, assuming that the keys are chosen with standard distributions. Our methods come from probabilistic group theory (permutation group actions and expander graphs). In particular, we provide a simple algorithm for finding short expressions of permutations in $S_n$, as products of given random permutations. Heuristically, our algorithm gives expressions of length $O(n^2\log n)$, in time and space $O(n^3)$. Moreover, this is provable from \emph{the Minimal Cycle Conjecture}, a simply stated hypothesis concerning the uniform distribution on $S_n$. Experiments show that the constants in these estimations are small. This is the first practical algorithm for this problem for $n\ge 256$. Remark: \emph{Algebraic Eraser} is a trademark of SecureRF. The variant of CBKAP actually implemented by SecureRF uses proprietary distributions, and thus our results do not imply its vulnerability. See also arXiv:abs/12020598

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Arkadius Kalka, Mina Teicher, Boaz Tsaban. 2012-03-06. Short expressions of permutations as products and cryptanalysis of the Algebraic Eraser. https://doi.org/10.1016/j.aam.2012.03.001

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Word Measures on Wreath Products II

Every word $w$ in $F_r$, the free group of rank $r$, induces a probability measure (the $w$-measure) on every finite group $G$, by substitution of random $G$-elements in the letters. This measure is determined by its Fourier coefficients: the $w$-expectations $E_w[χ]$ of the irreducible characters of $G$. For every finite group $G$, every stable character $χ$ of $G\wr S_n$ (trace of a finitely generated $FI_G$-module), and every word $w\in F_r$, we approximate $E_w[χ]$ up to an error term of $O(n^{-π(w)})$, where $π(w)$ is the primitivity rank of $w$. This generalizes previous works by Puder, Hanany, Magee and the author. As an application we show that random Schreier graphs of representation-stable actions of $G\wr S_n$ are close-to-optimal expanders. The paper reveals a surprising relation between stable representation theory of wreath products and not-necessarily connected Stallings core graphs.

math.GR

Robust quasi-isometric embeddings inapproximable by Anosov representations

Let $\mathbb{K}=\mathbb{R}$ or $\mathbb{C}$. For all but finitely many $m\in \mathbb{N}$, we exhibit the first examples of non-locally rigid, Zariski dense, robust quasi-isometric embeddings of hyperbolic groups in $\mathsf{SL}_m(\mathbb{K})$ which are not limits of Anosov representations. As a consequence, we show that higher rank analogues of Sullivan's structural stabilty theorem and of the density theorem for Kleinian groups fail for Anosov representations in $\mathsf{SL}_m(\mathbb{C}), m\geq 30$.

math.GR

$\mathcal{C}$-Hereditarily conjugacy separable groups and wreath products

We provide a necessary and sufficient condition for the restricted wreath product $A\wr B$ to be $\mathcal{C}$-hereditarily conjugacy separable where $\mathcal{C}$ is an extension-closed pseudovariety of finite groups. Moreover, we prove that the Grigorchuk group is 2-hereditarily conjugacy separable. As an application, we demonstrate that the lamplighter groups and $\mathbb{Z} \wr \mathbb{Z}$ are hereditarily conjugacy separable (but not $p$-conjugacy separable for any prime $p$). This provides infinitely many new examples of solvable, non-polycyclic hereditarily conjugacy separable groups. Furthermore, we study wreath products of cyclic subgroup separable groups and the derived length of iterated wreath products of solvable groups with an abelian base group and, as an application, we give an explicit construction of non-polycyclic hereditarily conjugacy separable groups of arbitrary derived length as iterated wreath products of abelian groups.

math.GR