arXiv ScienceSearch

arXiv · 1511.03870

A Practical Cryptanalysis of the Algebraic Eraser

Abstract

Anshel, Anshel, Goldfeld and Lemieaux introduced the Colored Burau Key Agreement Protocol (CBKAP) as the concrete instantiation of their Algebraic Eraser scheme. This scheme, based on techniques from permutation groups, matrix groups and braid groups, is designed for lightweight environments such as RFID tags and other IoT applications. It is proposed as an underlying technology for ISO/IEC 29167-20. SecureRF, the company owning the trademark Algebraic Eraser, has presented the scheme to the IRTF with a view towards standardisation. We present a novel cryptanalysis of this scheme. For parameter sizes corresponding to claimed 128-bit security, our implementation recovers the shared key using less than 8 CPU hours, and less than 64MB of memory.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Adi Ben-Zvi, Simon R. Blackburn, Boaz Tsaban. 2016-06-02. A Practical Cryptanalysis of the Algebraic Eraser. https://arxiv.org/abs/1511.03870

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Finiteness conditions on skew braces and solutions of the Yang-Baxter equation

A finite non-degenerate set-theoretic solution $(X,r)$ of the Yang-Baxter equation gives rise to a structure skew brace $B(X,r)$ that is a $λ_f$-skew brace, i.e. every element has finitely many $λ$-images, and whose additive group is $FC$. This motivates the study of finiteness conditions on skew braces. We first study the general class of $λ_f$ skew braces and the subclass where the additive group is $FC$, showing that these properties share a resemblance to finite conjugacy, having an analog of the $FC$-center and several analogous structural results. Furthermore, by passing through the structure skew brace of a solution, this property measures whether elements are contained in a finite decomposition factor, identifying a class of infinite solutions that may exhibit similar properties to finite ones. Finally, we show that for a sub skew brace where both groups have finite index, both indices need to coincide and that such a sub skew brace contains a strong left ideal of finite index.

math.GR

Non-uniform exponential growth and the decay of growth rates in growing dimensions

We provide the first example of a finitely presented, and the first example of a simple, group of non-uniform exponential growth. The example is given by Thompson's group $V$. Our methods also show that the infimal exponential growth rates of $\mathrm{Aut}(F_{2^{n+2}})$ and of $\mathrm{EL}_{2^{n+2}}(R)$, for every finitely generated ring $R$, tend to $1$. As an application, we obtain the first example of an acylindrically hyperbolic group, and the first example of a Kazhdan group, of non-uniform exponential growth.

math.GR

Solvable Supplements to Normalizers of Cyclic 2-Subgroups

Amberg and Kazarin proved that a finite group is solvable if the normalizer of every cyclic subgroup of prime power order has a solvable supplement. We substantially relax this hypothesis by requiring it only for cyclic $2$-subgroups. This condition, denoted by $\mathrm{SSN}_2$, sharply restricts the nonabelian composition factors of the group to the family $\PSL_2(q)$, where $q\geq7$ is a prime power satisfying $q\equiv3\pmod4$. Conversely, this family is precisely the nonabelian finite simple groups that satisfy $\mathrm{SSN}_2$. Consequently, a finite group satisfying $\mathrm{SSN}_2$ is solvable if and only if it has no section isomorphic to one of these groups.

math.GR