首页 > 最新文献

Designs, Codes and Cryptography最新文献

英文 中文
Simulation secure multi-input quadratic functional encryption: applications to differential privacy 模拟安全的多输入二次函数加密:差分隐私的应用
IF 1.6 2区 数学 Q3 COMPUTER SCIENCE, THEORY & METHODS Pub Date : 2025-12-09 DOI: 10.1007/s10623-025-01754-1
Ferran Alborch Escobar, Sébastien Canard, Fabien Laguillaumie
{"title":"Simulation secure multi-input quadratic functional encryption: applications to differential privacy","authors":"Ferran Alborch Escobar, Sébastien Canard, Fabien Laguillaumie","doi":"10.1007/s10623-025-01754-1","DOIUrl":"https://doi.org/10.1007/s10623-025-01754-1","url":null,"abstract":"","PeriodicalId":11130,"journal":{"name":"Designs, Codes and Cryptography","volume":"3 1","pages":""},"PeriodicalIF":1.6,"publicationDate":"2025-12-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"145703980","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"数学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
(k, n)-Consecutive access structures (k, n)-连续存取结构
IF 1.6 2区 数学 Q3 COMPUTER SCIENCE, THEORY & METHODS Pub Date : 2025-05-24 DOI: 10.1007/s10623-025-01651-7
Javier Herranz, Germán Sáez

We consider access structures over a set of n participants, defined by a parameter k with (1 le k le n) in the following way: a subset is authorized if it contains at least k consecutive participants. Depending on whether we consider the participants placed in a line (that is, participant 1 is not next to participant n) or in a circle, we obtain two different families, that we call (kn)-line-consecutive and (kn)-circle-consecutive access structures, respectively. Such access structures can appear in real-life situations involving distributed cryptography, which makes it more interesting to look for the best secret sharing schemes that can realize them. For both families, we characterize which are the configurations (kn) that admit ideal secret sharing schemes. For the non-ideal (kn)-consecutive access structures, we give both upper and lower bounds on the information ratio of the best secret sharing schemes that can realize them. Some of these bounds are obtained after proving relations between the information ratios of access structures in the two considered families.

我们考虑由参数k用(1 le k le n)定义的n个参与者集合上的访问结构:如果一个子集包含至少k个连续的参与者,则该子集被授权。根据我们考虑的参与者是放在一条直线上(即参与者1不在参与者n旁边)还是放在一个圆上,我们得到了两个不同的族,我们分别称之为(k, n)-线连续访问结构和(k, n)-圆连续访问结构。这种访问结构可能出现在涉及分布式加密的实际情况中,这使得寻找能够实现它们的最佳秘密共享方案变得更加有趣。对于这两个族,我们描述了哪些构型(k, n)允许理想的秘密共享方案。对于非理想(k, n)连续访问结构,给出了实现它们的最佳秘密共享方案的信息比的上界和下界。在证明了两个考虑族的访问结构的信息比率之间的关系之后,得到了其中的一些界限。
{"title":"(k, n)-Consecutive access structures","authors":"Javier Herranz, Germán Sáez","doi":"10.1007/s10623-025-01651-7","DOIUrl":"https://doi.org/10.1007/s10623-025-01651-7","url":null,"abstract":"<p>We consider access structures over a set of <i>n</i> participants, defined by a parameter <i>k</i> with <span>(1 le k le n)</span> in the following way: a subset is authorized if it contains at least <i>k</i> consecutive participants. Depending on whether we consider the participants placed in a line (that is, participant 1 is not next to participant <i>n</i>) or in a circle, we obtain two different families, that we call (<i>k</i>, <i>n</i>)-line-consecutive and (<i>k</i>, <i>n</i>)-circle-consecutive access structures, respectively. Such access structures can appear in real-life situations involving distributed cryptography, which makes it more interesting to look for the best secret sharing schemes that can realize them. For both families, we characterize which are the configurations (<i>k</i>, <i>n</i>) that admit ideal secret sharing schemes. For the non-ideal (<i>k</i>, <i>n</i>)-consecutive access structures, we give both upper and lower bounds on the information ratio of the best secret sharing schemes that can realize them. Some of these bounds are obtained after proving relations between the information ratios of access structures in the two considered families.</p>","PeriodicalId":11130,"journal":{"name":"Designs, Codes and Cryptography","volume":"56 1","pages":""},"PeriodicalIF":1.6,"publicationDate":"2025-05-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"144130293","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"数学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Hilbert series and degrees of regularity of Oil & Vinegar and mixed quadratic systems 油醋混合二次系统的希尔伯特级数和正则度
IF 1.6 2区 数学 Q3 COMPUTER SCIENCE, THEORY & METHODS Pub Date : 2025-05-24 DOI: 10.1007/s10623-025-01644-6
Antonio Corbo Esposito, Rosa Fera, Francesco Romeo

In this paper, we analyze the algebraic invariants for two classes of multivariate quadratic systems: systems made by oil and vinegar quadratic polynomials and systems made by both oil and vinegar polynomials and fully-quadratic ones. For such systems, we explicitly compute the Hilbert series in the homogeneous case, and we also give bounds on the degree of regularity, solving degree and first fall degree. Such degrees can be relevant to compute the complexity of solving those systems and to estimate their cryptographic security.

本文分析了两类多元二次系统的代数不变量:油醋多项式系统和油醋多项式与全二次多项式系统。对于这样的系统,我们显式地计算了齐次情况下的Hilbert级数,并给出了正则度、解度和一阶降度的界。这种程度可能与计算解决这些系统的复杂性和估计其加密安全性相关。
{"title":"Hilbert series and degrees of regularity of Oil & Vinegar and mixed quadratic systems","authors":"Antonio Corbo Esposito, Rosa Fera, Francesco Romeo","doi":"10.1007/s10623-025-01644-6","DOIUrl":"https://doi.org/10.1007/s10623-025-01644-6","url":null,"abstract":"<p>In this paper, we analyze the algebraic invariants for two classes of multivariate quadratic systems: systems made by oil and vinegar quadratic polynomials and systems made by both oil and vinegar polynomials and fully-quadratic ones. For such systems, we explicitly compute the Hilbert series in the homogeneous case, and we also give bounds on the degree of regularity, solving degree and first fall degree. Such degrees can be relevant to compute the complexity of solving those systems and to estimate their cryptographic security.</p>","PeriodicalId":11130,"journal":{"name":"Designs, Codes and Cryptography","volume":"134 1","pages":""},"PeriodicalIF":1.6,"publicationDate":"2025-05-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"144130235","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"数学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Self-reversible generalized (L,G)-codes 自可逆广义(L,G)码
IF 1.6 2区 数学 Q3 COMPUTER SCIENCE, THEORY & METHODS Pub Date : 2025-05-23 DOI: 10.1007/s10623-025-01648-2
Sergey Bezzateev, Natalia Shekhunova

We consider a subclass of p-ary self-reversible generalized (LG) codes with a locator set (L={ frac{2x-alpha }{x^2-alpha x +1},alpha in mathbb {F}_q setminus {0}, q=p^m } cup {frac{1}{x+1}}), where p is a prime number. The numerator (2x-alpha ) of a rational function is the formal derivative of the denominator (x^2-alpha x +1). The Goppa polynomial (G(x) in mathbb {F}_q[x]) of degree 2t, t being odd, is either an irreducible self-reversible polynomial of degree 2t, or a non-irreducible self-reversible polynomial of degree 2t of the form (G_1^{-1}(0)cdot G_1(x)cdot x^tcdot G_1(x^{-1})), where (G_1(x)in mathbb {F}_q[x]) is any irreducible non self-reversible polynomial of degree t. Estimates for minimum distance and redundancy are obtained for codes from this subclass. It is shown that among these codes, there are codes lying on the Gilbert–Varshamov bound. As a special case, binary codes from this subclass that contains codes lying also on Gilbert–Varshamov bound are considered.

考虑一类具有定位集(L={ frac{2x-alpha }{x^2-alpha x +1},alpha in mathbb {F}_q setminus {0}, q=p^m } cup {frac{1}{x+1}})的p元自可逆广义(L, G)码,其中p为素数。有理函数的分子(2x-alpha )是分母(x^2-alpha x +1)的形式导数。2t次的Goppa多项式(G(x) in mathbb {F}_q[x]), t为奇数,要么是2t次的不可约自可逆多项式,要么是形式为(G_1^{-1}(0)cdot G_1(x)cdot x^tcdot G_1(x^{-1}))的不可约自可逆多项式,其中(G_1(x)in mathbb {F}_q[x])为任意t次的不可约非自可逆多项式。得到了该子类码的最小距离和冗余估计。证明了在这些码中,有一些码位于吉尔伯特-瓦尔沙莫夫界上。作为一种特殊情况,考虑这个子类中包含同样位于Gilbert-Varshamov界上的码的二进制码。
{"title":"Self-reversible generalized (L,G)-codes","authors":"Sergey Bezzateev, Natalia Shekhunova","doi":"10.1007/s10623-025-01648-2","DOIUrl":"https://doi.org/10.1007/s10623-025-01648-2","url":null,"abstract":"<p>We consider a subclass of <i>p</i>-ary self-reversible generalized (<i>L</i>, <i>G</i>) codes with a locator set <span>(L={ frac{2x-alpha }{x^2-alpha x +1},alpha in mathbb {F}_q setminus {0}, q=p^m } cup {frac{1}{x+1}})</span>, where <i>p</i> is a prime number. The numerator <span>(2x-alpha )</span> of a rational function is the formal derivative of the denominator <span>(x^2-alpha x +1)</span>. The Goppa polynomial <span>(G(x) in mathbb {F}_q[x])</span> of degree 2<i>t</i>, <i>t</i> being odd, is either an irreducible self-reversible polynomial of degree 2<i>t</i>, or a non-irreducible self-reversible polynomial of degree 2<i>t</i> of the form <span>(G_1^{-1}(0)cdot G_1(x)cdot x^tcdot G_1(x^{-1}))</span>, where <span>(G_1(x)in mathbb {F}_q[x])</span> is any irreducible non self-reversible polynomial of degree <i>t</i>. Estimates for minimum distance and redundancy are obtained for codes from this subclass. It is shown that among these codes, there are codes lying on the Gilbert–Varshamov bound. As a special case, binary codes from this subclass that contains codes lying also on Gilbert–Varshamov bound are considered.</p>","PeriodicalId":11130,"journal":{"name":"Designs, Codes and Cryptography","volume":"45 1","pages":""},"PeriodicalIF":1.6,"publicationDate":"2025-05-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"144123081","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"数学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Primitive rank 3 groups, binary codes, and 3-designs 原始秩3组,二进制代码和3-设计
IF 1.6 2区 数学 Q3 COMPUTER SCIENCE, THEORY & METHODS Pub Date : 2025-05-20 DOI: 10.1007/s10623-025-01647-3
B. G. Rodrigues, Patrick Solé

Let G be a primitive rank 3 permutation group acting on a set of size v. Binary codes of length v globally invariant under G are well-known to hold PBIBDs in their (A_w) codewords of weight w. The parameters of these designs are (bigg (A_w,v,w,frac{wA_w}{v},lambda _1,lambda _2bigg ).) When (lambda _1=lambda _2=lambda ,) the PBIBD becomes a 2-((v,w,lambda )) design. We obtain computationally 111 such designs when G ranges over (textrm{L}_2(8){:}3, textrm{U}_{4}(2), textrm{U}_{3}(3){:}2, textrm{A}_8, textrm{S}_6(2),) (textrm{S}_{4}(4), textrm{U}_{5}(2), textrm{M}_{11}, textrm{M}_{22}, textrm{HS}, textrm{G}_2(4), textrm{S}_{8}(2),textrm{O}^{+}_{10}(2),) and (textrm{O}^{-}_{10}(2)) in the notation of the Atlas. Included in the counting are 2-designs which are held by nonzero weight codewords of the binary adjacency codes of the triangular and square lattice graphs, respectively. The 2-designs in this paper can be obtained neither from Assmus–Mattson theorem, nor by the classical 2-tra nsitivity (or 2-homogeneity) argument of the automorphism group of the code. Further, the extensions of the codes that hold 2-designs sometimes hold 3-designs. We thus obtain nine self-complementary 3-designs on 16 (4), (28,, 36) (2), (,56,, 176) points respectively. The design on 176 points is invariant under the Higman–Sims group.

设G为作用于大小为v的集合上的原始3阶置换群。众所周知,在G下,长度为v的全局不变二进制码在其权重为w的(A_w)码字中包含PBIBD。当(lambda _1=lambda _2=lambda ,)将PBIBD变为2- ((v,w,lambda ))设计时,这些设计的参数为(bigg (A_w,v,w,frac{wA_w}{v},lambda _1,lambda _2bigg ).)。在图集符号中,当G的范围大于(textrm{L}_2(8){:}3, textrm{U}_{4}(2), textrm{U}_{3}(3){:}2, textrm{A}_8, textrm{S}_6(2),)(textrm{S}_{4}(4), textrm{U}_{5}(2), textrm{M}_{11}, textrm{M}_{22}, textrm{HS}, textrm{G}_2(4), textrm{S}_{8}(2),textrm{O}^{+}_{10}(2),)和(textrm{O}^{-}_{10}(2))时,我们计算得到111个这样的设计。计数中包括2种设计,它们分别由三角形格图和方形格图的二进制邻接码的非零权码字保存。本文的2-设计既不能由Assmus-Mattson定理得到,也不能由码的自同构群的经典2-透性(或2-齐性)论证得到。此外,适用于2种设计的规范的扩展有时也适用于3种设计。因此,我们分别在16 (4),(28,, 36) (2), (,56,, 176)点上获得了9个自互补的3-设计。在Higman-Sims组下,176点的设计是不变的。
{"title":"Primitive rank 3 groups, binary codes, and 3-designs","authors":"B. G. Rodrigues, Patrick Solé","doi":"10.1007/s10623-025-01647-3","DOIUrl":"https://doi.org/10.1007/s10623-025-01647-3","url":null,"abstract":"<p>Let <i>G</i> be a primitive rank 3 permutation group acting on a set of size <i>v</i>. Binary codes of length <i>v</i> globally invariant under <i>G</i> are well-known to hold PBIBDs in their <span>(A_w)</span> codewords of weight <i>w</i>. The parameters of these designs are <span>(bigg (A_w,v,w,frac{wA_w}{v},lambda _1,lambda _2bigg ).)</span> When <span>(lambda _1=lambda _2=lambda ,)</span> the PBIBD becomes a 2-<span>((v,w,lambda ))</span> design. We obtain computationally 111 such designs when <i>G</i> ranges over <span>(textrm{L}_2(8){:}3, textrm{U}_{4}(2), textrm{U}_{3}(3){:}2, textrm{A}_8, textrm{S}_6(2),)</span> <span>(textrm{S}_{4}(4), textrm{U}_{5}(2), textrm{M}_{11}, textrm{M}_{22}, textrm{HS}, textrm{G}_2(4), textrm{S}_{8}(2),textrm{O}^{+}_{10}(2),)</span> and <span>(textrm{O}^{-}_{10}(2))</span> in the notation of the Atlas. Included in the counting are 2-designs which are held by nonzero weight codewords of the binary adjacency codes of the triangular and square lattice graphs, respectively. The 2-designs in this paper can be obtained neither from Assmus–Mattson theorem, nor by the classical 2-tra nsitivity (or 2-homogeneity) argument of the automorphism group of the code. Further, the extensions of the codes that hold 2-designs sometimes hold 3-designs. We thus obtain nine self-complementary 3-designs on 16 (4), <span>(28,, 36)</span> (2), <span>(,56,, 176)</span> points respectively. The design on 176 points is invariant under the Higman–Sims group.</p>","PeriodicalId":11130,"journal":{"name":"Designs, Codes and Cryptography","volume":"40 1","pages":""},"PeriodicalIF":1.6,"publicationDate":"2025-05-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"144097130","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"数学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Information-set decoding for convolutional codes 卷积码的信息集解码
IF 1.6 2区 数学 Q3 COMPUTER SCIENCE, THEORY & METHODS Pub Date : 2025-05-20 DOI: 10.1007/s10623-025-01649-1
Niklas Gassner, Julia Lieb, Abhinaba Mazumder, Michael Schaller

In this paper, we present a framework for generic decoding of convolutional codes, which allows us to do cryptanalysis of code-based systems that use convolutional codes as public keys. We then apply this framework to information set decoding, study success probabilities and give tools to choose variables. Finally, we use this to attack two cryptosystems based on convolutional codes. In the case of Bolkema et al. (Variations of the McEliece cryptosystem. In: Algebraic geometry for coding theory and cryptography: IPAM, Los Angeles, CA, Feb 2016. Springer, Cham, pp 129-150, 2017. https://doi.org/10.1007/978-3-319-63931-4_5), our code recovered about 74% of errors in less than 10 h each, and in the case of Almeida et al. (Smaller keys for code-based cryptography: McEliece cryptosystems with convolutional encoders. CoRR abs/2104.06809, 2021. arXiv: https://arxiv.org/abs/2104.06809v1), we give experimental evidence that 80% of the errors can be recovered in times corresponding to about 70 bits of operational security, with some instances being significantly lower.

在本文中,我们提出了一个卷积码的通用解码框架,它允许我们对使用卷积码作为公钥的基于代码的系统进行密码分析。然后,我们将该框架应用于信息集解码,研究成功概率并给出选择变量的工具。最后,我们用它来攻击两个基于卷积码的密码系统。在Bolkema等人的案例中(McEliece密码系统的变体)。见:编码理论和密码学的代数几何:IPAM,洛杉矶,CA, 2016年2月。[j],《中国科学》,2017年第129-150页。https://doi.org/10.1007/978-3-319-63931-4_5),我们的代码在不到10小时的时间内恢复了大约74%的错误,并且在Almeida等人的情况下(基于代码的加密的较小密钥:带有卷积编码器的McEliece密码系统)。CoRR abs/2104.06809, 2021。arXiv: https://arxiv.org/abs/2104.06809v1),我们给出的实验证据表明,80%的错误可以在大约70位操作安全的时间内恢复,其中一些实例明显更低。
{"title":"Information-set decoding for convolutional codes","authors":"Niklas Gassner, Julia Lieb, Abhinaba Mazumder, Michael Schaller","doi":"10.1007/s10623-025-01649-1","DOIUrl":"https://doi.org/10.1007/s10623-025-01649-1","url":null,"abstract":"<p>In this paper, we present a framework for generic decoding of convolutional codes, which allows us to do cryptanalysis of code-based systems that use convolutional codes as public keys. We then apply this framework to information set decoding, study success probabilities and give tools to choose variables. Finally, we use this to attack two cryptosystems based on convolutional codes. In the case of Bolkema et al. (Variations of the McEliece cryptosystem. In: Algebraic geometry for coding theory and cryptography: IPAM, Los Angeles, CA, Feb 2016. Springer, Cham, pp 129-150, 2017. https://doi.org/10.1007/978-3-319-63931-4_5), our code recovered about 74% of errors in less than 10 h each, and in the case of Almeida et al. (Smaller keys for code-based cryptography: McEliece cryptosystems with convolutional encoders. CoRR abs/2104.06809, 2021. arXiv: https://arxiv.org/abs/2104.06809v1), we give experimental evidence that 80% of the errors can be recovered in times corresponding to about 70 bits of operational security, with some instances being significantly lower.</p>","PeriodicalId":11130,"journal":{"name":"Designs, Codes and Cryptography","volume":"4 1","pages":""},"PeriodicalIF":1.6,"publicationDate":"2025-05-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"144097131","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"数学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
More on codes for combinatorial composite DNA 更多关于组合复合DNA的代码
IF 1.6 2区 数学 Q3 COMPUTER SCIENCE, THEORY & METHODS Pub Date : 2025-05-15 DOI: 10.1007/s10623-025-01634-8
Zuo Ye, Omer Sabary, Ryan Gabrys, Eitan Yaakobi, Ohad Elishco

In this paper, we focus on constructing unique-decodable and list-decodable codes for the recently studied (te)-composite-asymmetric error-correcting codes ((te)-CAECCs). Let (mathcal {X}) be an (m times n) binary matrix in which each row has Hamming weight w. If at most t rows of (mathcal {X}) contain errors, and in each erroneous row, there are at most e occurrences of (1 rightarrow 0) errors, we say that a (te)-composite-asymmetric error occurs in (mathcal {X}). For general values of mnwt, and e, we propose new constructions of (te)-CAECCs with redundancy at most ((t-1)log (m) + O(1)), where O(1) is independent of the code length m. In particular, this yields a class of (2, e)-CAECCs that are optimal in terms of redundancy. When m is a prime power, the redundancy can be further reduced to ((t-1)log (m) - O(log (m))). To further increase the code size, we introduce a combinatorial object called a weak (B_e)-set. When (e = w), we present an efficient encoding and decoding method for our codes. Finally, we explore potential improvements by relaxing the requirement of unique decoding to list-decoding. We show that when the list size is t! or an exponential function of t, there exist list-decodable (te)-CAECCs with constant redundancy. When the list size is two, we construct list-decodable (3, 2)-CAECCs with redundancy (log (m) + O(1)).

本文主要研究了(t, e)-复合非对称纠错码((t, e)-CAECCs)的唯一可解码码和列表可解码码。设(mathcal {X})是一个(m times n)二元矩阵,其中每一行都有汉明权值w。如果(mathcal {X})中最多t行包含错误,并且在每个错误行中,最多e次出现(1 rightarrow 0)错误,我们说(mathcal {X})中出现了一个(t, e)-复合-不对称错误。对于m, n, w, t和e的一般值,我们提出了冗余度最多为((t-1)log (m) + O(1))的(t, e)-CAECCs的新结构,其中O(1)与代码长度m无关。特别是,这产生了一类冗余度最优的(2,e)-CAECCs。当m为素数幂时,冗余可进一步简化为((t-1)log (m) - O(log (m)))。为了进一步增加代码大小,我们引入了一个称为弱(B_e) -set的组合对象。当(e = w),我们提出了一个有效的编码和解码方法为我们的代码。最后,我们探讨了将唯一解码的要求放宽到列表解码的潜在改进。当列表大小为t!或t的指数函数,则存在具有常冗余的list- decoable (t, e)-CAECCs。当列表大小为2时,我们构建具有冗余(log (m) + O(1))的列表可解码(3,2)- caecc。
{"title":"More on codes for combinatorial composite DNA","authors":"Zuo Ye, Omer Sabary, Ryan Gabrys, Eitan Yaakobi, Ohad Elishco","doi":"10.1007/s10623-025-01634-8","DOIUrl":"https://doi.org/10.1007/s10623-025-01634-8","url":null,"abstract":"<p>In this paper, we focus on constructing unique-decodable and list-decodable codes for the recently studied (<i>t</i>, <i>e</i>)-composite-asymmetric error-correcting codes ((<i>t</i>, <i>e</i>)-CAECCs). Let <span>(mathcal {X})</span> be an <span>(m times n)</span> binary matrix in which each row has Hamming weight <i>w</i>. If at most <i>t</i> rows of <span>(mathcal {X})</span> contain errors, and in each erroneous row, there are at most <i>e</i> occurrences of <span>(1 rightarrow 0)</span> errors, we say that a (<i>t</i>, <i>e</i>)-composite-asymmetric error occurs in <span>(mathcal {X})</span>. For general values of <i>m</i>, <i>n</i>, <i>w</i>, <i>t</i>, and <i>e</i>, we propose new constructions of (<i>t</i>, <i>e</i>)-CAECCs with redundancy at most <span>((t-1)log (m) + O(1))</span>, where <i>O</i>(1) is independent of the code length <i>m</i>. In particular, this yields a class of (2, <i>e</i>)-CAECCs that are optimal in terms of redundancy. When <i>m</i> is a prime power, the redundancy can be further reduced to <span>((t-1)log (m) - O(log (m)))</span>. To further increase the code size, we introduce a combinatorial object called a weak <span>(B_e)</span>-set. When <span>(e = w)</span>, we present an efficient encoding and decoding method for our codes. Finally, we explore potential improvements by relaxing the requirement of unique decoding to list-decoding. We show that when the list size is <i>t</i>! or an exponential function of <i>t</i>, there exist list-decodable (<i>t</i>, <i>e</i>)-CAECCs with constant redundancy. When the list size is two, we construct list-decodable (3, 2)-CAECCs with redundancy <span>(log (m) + O(1))</span>.</p>","PeriodicalId":11130,"journal":{"name":"Designs, Codes and Cryptography","volume":"1 1","pages":""},"PeriodicalIF":1.6,"publicationDate":"2025-05-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"144066263","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"数学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
A combinatorial approach to avoiding weak keys in the BIKE cryptosystem 避免BIKE密码系统中弱密钥的组合方法
IF 1.6 2区 数学 Q3 COMPUTER SCIENCE, THEORY & METHODS Pub Date : 2025-05-14 DOI: 10.1007/s10623-025-01643-7
Gretchen L. Matthews, Emily McMillon

Bit Flipping Key Encapsulation (BIKE) is a code-based cryptosystem that was considered in Round 4 of the NIST Post-Quantum Cryptography Standardization process. It is based on quasi-cyclic moderate-density parity-check (QC-MDPC) codes paired with an iterative decoder. While (low-density) parity-check codes have been shown to perform well in practice, their capabilities are governed by the code’s graphical representation and the choice of decoder rather than the traditional code parameters, making it difficult to determine the decoder failure rate (DFR). Moreover, decoding failures have been demonstrated to lead to attacks that recover the BIKE private key. In this paper, we demonstrate a strong correlation between weak keys and 4-cycles in their associated Tanner graphs. We give concrete ways to enumerate the number of 4-cycles in a BIKE key and use these results to present a filtering algorithm that will filter BIKE keys with large numbers of 4-cycles. These results also apply to more general parity check codes.

比特翻转密钥封装(BIKE)是一种基于代码的密码系统,在NIST后量子加密标准化过程的第4轮中被考虑。它基于准循环中密度奇偶校验(QC-MDPC)码与迭代解码器配对。虽然(低密度)奇偶校验码在实践中表现良好,但它们的能力受代码的图形表示和解码器的选择而不是传统代码参数的控制,这使得难以确定解码器故障率(DFR)。此外,已经证明解码失败会导致恢复BIKE私钥的攻击。在本文中,我们证明了弱键与4环在它们的相关Tanner图中的强相关性。我们给出了具体的方法来枚举一个BIKE密钥中4个循环的个数,并利用这些结果提出了一种过滤具有大量4个循环的BIKE密钥的过滤算法。这些结果也适用于更一般的奇偶校验码。
{"title":"A combinatorial approach to avoiding weak keys in the BIKE cryptosystem","authors":"Gretchen L. Matthews, Emily McMillon","doi":"10.1007/s10623-025-01643-7","DOIUrl":"https://doi.org/10.1007/s10623-025-01643-7","url":null,"abstract":"<p>Bit Flipping Key Encapsulation (BIKE) is a code-based cryptosystem that was considered in Round 4 of the NIST Post-Quantum Cryptography Standardization process. It is based on quasi-cyclic moderate-density parity-check (QC-MDPC) codes paired with an iterative decoder. While (low-density) parity-check codes have been shown to perform well in practice, their capabilities are governed by the code’s graphical representation and the choice of decoder rather than the traditional code parameters, making it difficult to determine the decoder failure rate (DFR). Moreover, decoding failures have been demonstrated to lead to attacks that recover the BIKE private key. In this paper, we demonstrate a strong correlation between weak keys and 4-cycles in their associated Tanner graphs. We give concrete ways to enumerate the number of 4-cycles in a BIKE key and use these results to present a filtering algorithm that will filter BIKE keys with large numbers of 4-cycles. These results also apply to more general parity check codes.</p>","PeriodicalId":11130,"journal":{"name":"Designs, Codes and Cryptography","volume":"52 1","pages":""},"PeriodicalIF":1.6,"publicationDate":"2025-05-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"143945973","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"数学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Evaluation codes arising from symmetric polynomials 由对称多项式产生的计算代码
IF 1.6 2区 数学 Q3 COMPUTER SCIENCE, THEORY & METHODS Pub Date : 2025-05-12 DOI: 10.1007/s10623-025-01637-5
Barbara Gatti, Gábor Korchmáros, Gábor P. Nagy, Vincenzo Pallozzi Lavorante, Gioia Schulte

Datta and Johnsen (Des Codes Cryptogr 91:747–761, 2023) introduced a new family of evaluation codes in an affine space of dimension (ge 2) over a finite field ({mathbb {F}}_q) where linear combinations of elementary symmetric polynomials are evaluated on the set of all points with pairwise distinct coordinates. In this paper, we propose a generalization by taking low dimensional linear systems of symmetric polynomials. Computation for small values of (q=7,9) shows that carefully chosen generalized Datta–Johnsen codes (left[ frac{1}{2}q(q-1),3,dright] ) have minimum distance d equal to the optimal value minus 1.

Datta和Johnsen (Des Codes Cryptogr 91:747-761, 2023)在有限域({mathbb {F}}_q)上,在维度为(ge 2)的仿射空间中引入了一组新的评估码,其中初等对称多项式的线性组合在具有对偶不同坐标的所有点的集合上进行评估。本文以低维对称多项式线性系统为例,提出一种推广方法。对于较小的(q=7,9)值的计算表明,精心选择的广义data - johnsen码(left[ frac{1}{2}q(q-1),3,dright] )的最小距离d等于最优值- 1。
{"title":"Evaluation codes arising from symmetric polynomials","authors":"Barbara Gatti, Gábor Korchmáros, Gábor P. Nagy, Vincenzo Pallozzi Lavorante, Gioia Schulte","doi":"10.1007/s10623-025-01637-5","DOIUrl":"https://doi.org/10.1007/s10623-025-01637-5","url":null,"abstract":"<p>Datta and Johnsen (Des Codes Cryptogr 91:747–761, 2023) introduced a new family of evaluation codes in an affine space of dimension <span>(ge 2)</span> over a finite field <span>({mathbb {F}}_q)</span> where linear combinations of elementary symmetric polynomials are evaluated on the set of all points with pairwise distinct coordinates. In this paper, we propose a generalization by taking low dimensional linear systems of symmetric polynomials. Computation for small values of <span>(q=7,9)</span> shows that carefully chosen generalized Datta–Johnsen codes <span>(left[ frac{1}{2}q(q-1),3,dright] )</span> have minimum distance <i>d</i> equal to the optimal value minus 1.</p>","PeriodicalId":11130,"journal":{"name":"Designs, Codes and Cryptography","volume":"41 1","pages":""},"PeriodicalIF":1.6,"publicationDate":"2025-05-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"143940084","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"数学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
On tweakable correlation robust hashing against key leakages 针对键泄漏的可调整相关性鲁棒散列
IF 1.6 2区 数学 Q3 COMPUTER SCIENCE, THEORY & METHODS Pub Date : 2025-05-12 DOI: 10.1007/s10623-025-01641-9
Chun Guo, Xiao Wang, Kang Yang, Yu Yu

We continue the study of blockcipher-based (tweakable) correlation robust hash functions, which are central building blocks of circuit garbling and oblivious-transfer extension schemes. Motivated by Roy (CRYPTO 2022), we first enhance the multi-user tweakable correlation robust notion of Guo et al. (CRYPTO 2020) with a key leaking oracle that tells the adversary whether a certain user key satisfies adversarially-chosen predicates. We then investigate the state-of-the-art hash construction of Guo et al. with respect to our new security definition, providing security proof as well as attacks in relevant settings. As an application, we exhibit an OT extension protocol with non-trivial multi-user security.

我们继续研究基于块密码的(可调整的)相关鲁棒哈希函数,这是电路乱码和遗忘传输扩展方案的中心构建块。在Roy (CRYPTO 2022)的激励下,我们首先增强了Guo等人(CRYPTO 2020)的多用户可调相关鲁棒概念,使用密钥泄漏oracle告诉对手某个用户密钥是否满足对手选择的谓词。然后,我们根据新的安全定义研究了Guo等人最先进的哈希构造,提供了安全证明以及相关设置中的攻击。作为一个应用程序,我们展示了一个具有重要多用户安全性的OT扩展协议。
{"title":"On tweakable correlation robust hashing against key leakages","authors":"Chun Guo, Xiao Wang, Kang Yang, Yu Yu","doi":"10.1007/s10623-025-01641-9","DOIUrl":"https://doi.org/10.1007/s10623-025-01641-9","url":null,"abstract":"<p>We continue the study of blockcipher-based (tweakable) correlation robust hash functions, which are central building blocks of circuit garbling and oblivious-transfer extension schemes. Motivated by Roy (CRYPTO 2022), we first enhance the multi-user tweakable correlation robust notion of Guo et al. (CRYPTO 2020) with a <i>key leaking oracle</i> that tells the adversary whether a certain user key satisfies adversarially-chosen predicates. We then investigate the state-of-the-art hash construction of Guo et al. with respect to our new security definition, providing security proof as well as attacks in relevant settings. As an application, we exhibit an OT extension protocol with non-trivial multi-user security.\u0000</p>","PeriodicalId":11130,"journal":{"name":"Designs, Codes and Cryptography","volume":"3 1","pages":""},"PeriodicalIF":1.6,"publicationDate":"2025-05-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"143933568","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"数学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
期刊
Designs, Codes and Cryptography
全部 Acc. Chem. Res. ACS Applied Bio Materials ACS Appl. Electron. Mater. ACS Appl. Energy Mater. ACS Appl. Mater. Interfaces ACS Appl. Nano Mater. ACS Appl. Polym. Mater. ACS BIOMATER-SCI ENG ACS Catal. ACS Cent. Sci. ACS Chem. Biol. ACS Chemical Health & Safety ACS Chem. Neurosci. ACS Comb. Sci. ACS Earth Space Chem. ACS Energy Lett. ACS Infect. Dis. ACS Macro Lett. ACS Mater. Lett. ACS Med. Chem. Lett. ACS Nano ACS Omega ACS Photonics ACS Sens. ACS Sustainable Chem. Eng. ACS Synth. Biol. Anal. Chem. BIOCHEMISTRY-US Bioconjugate Chem. BIOMACROMOLECULES Chem. Res. Toxicol. Chem. Rev. Chem. Mater. CRYST GROWTH DES ENERG FUEL Environ. Sci. Technol. Environ. Sci. Technol. Lett. Eur. J. Inorg. Chem. IND ENG CHEM RES Inorg. Chem. J. Agric. Food. Chem. J. Chem. Eng. Data J. Chem. Educ. J. Chem. Inf. Model. J. Chem. Theory Comput. J. Med. Chem. J. Nat. Prod. J PROTEOME RES J. Am. Chem. Soc. LANGMUIR MACROMOLECULES Mol. Pharmaceutics Nano Lett. Org. Lett. ORG PROCESS RES DEV ORGANOMETALLICS J. Org. Chem. J. Phys. Chem. J. Phys. Chem. A J. Phys. Chem. B J. Phys. Chem. C J. Phys. Chem. Lett. Analyst Anal. Methods Biomater. Sci. Catal. Sci. Technol. Chem. Commun. Chem. Soc. Rev. CHEM EDUC RES PRACT CRYSTENGCOMM Dalton Trans. Energy Environ. Sci. ENVIRON SCI-NANO ENVIRON SCI-PROC IMP ENVIRON SCI-WAT RES Faraday Discuss. Food Funct. Green Chem. Inorg. Chem. Front. Integr. Biol. J. Anal. At. Spectrom. J. Mater. Chem. A J. Mater. Chem. B J. Mater. Chem. C Lab Chip Mater. Chem. Front. Mater. Horiz. MEDCHEMCOMM Metallomics Mol. Biosyst. Mol. Syst. Des. Eng. Nanoscale Nanoscale Horiz. Nat. Prod. Rep. New J. Chem. Org. Biomol. Chem. Org. Chem. Front. PHOTOCH PHOTOBIO SCI PCCP Polym. Chem.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1