Cryptanalysis of the birational permutation signature scheme over a non-commutative ring

Naoki Ogura, Shigenori Uchiyama · JSIAM Letters · 2010

In 2008, Hashimoto and Sakurai proposed a new efficient signature scheme, which is a non-commutative version of Shamir's birational permutation signature scheme. Shamir's scheme is a generalization of the Ong-Schnorr-Shamir scheme and was broken by Coppersmith et al. using its linearity and commutativity. The HS (Hashimoto-Sakurai) scheme is expected to be secure against the attack from its non-commutative structure. In this paper, we propose an attack against the HS scheme, which is practical under the condition that its step size and the number of steps are small. We discuss its efficiency by using some experimental results.

Read the paper · More papers on PaperTik