On the algebraic structure of $E_p^{(m)}$ and applications to cryptography
Karan Khathuria, Giacomo Micheli, Violetta Weger

TL;DR
This paper reveals the algebraic structure of the ring $E_p^{(m)}$, enabling efficient solutions to linear systems over it and breaking certain cryptographic protocols based on this ring.
Contribution
It establishes an isomorphism between $E_p^{(m)}$ and a submodule of matrix rings, facilitating cryptanalysis of protocols using $E_p^{(m)}$.
Findings
Linear systems over $E_p^{(m)}$ can be solved efficiently.
Cryptographic protocols based on $E_p^{(m)}$ are vulnerable.
The algorithm runs in $O(m^{6})$ time.
Abstract
In this paper we show that the -module structure of the ring is isomorphic to a -submodule of the matrix ring over . Using this intrinsic structure of , solving a linear system over becomes computationally equivalent to solving a linear system over . As an application we break the protocol based on the Diffie-Hellman Decomposition problem and ElGamal Decomposition problem over . Our algorithm terminates in a provable running time of -operations.
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
