0단 자동
AI가 규칙대로 쓰고 그대로 게시했습니다. 사람이 따로 보지 않았습니다.
- 규칙 판
- 규칙 판 도입 이전 기사입니다.
- 남기는 것
- 규칙 판 · 모델 · 시각
- 판 기록
- 아직 없습니다.
Provable Subexponential Algorithms for NIST Third-Round Lattice Families
- 1.Kyber·FrodoKEM·SABER·NTRU LPRime·Dilithium 등 NIST 격자 전 계열에 준지수 비밀복구 알고리즘 제시
- 2.시간·공간 복잡도 2^((1/2+o(1))n/ln ln n)로 이론적 상한 수립
- 3.가우시안 리스트와 이분탐색으로 비밀 좌표를 차례로 복구하는 기법
- 4.다만 현재 표준 파라미터의 구체적 보안 강도는 낮추지 않는다고 명시
왜 중요한가?
표준화된 PQC 7개 후보 전부에 적용되는 범용적 준지수 공격 기법이 처음 제시됐지만, 실제 운영 파라미터의 보안 마진은 깨지 못한다는 점에서 이론적 진전과 실무 위험이 별개임을 보여준다.
본문 미리보기
We give provable classical subexponential algorithms for secret recovery in growing parameter families associated with NIST third-round lattice candidates. For the Kyber/ML-KEM, FrodoKEM, SABER, NTRU LPRime, and Dilithium/ML-DSA families studied here, polynomial moduli and polylogarithmic coefficient scales yield recovery of the short secret component in expected time and space $2^{(1/2+o(1))n/\ln\ln n}$. For noisy or rounded linear relations, we exploit an exact gap in the squared Euclidean
전체 내용이 궁금하다면?
원문을 직접 읽어보세요
이 글이 만들어진 과정
- 11:24AI 초안



