arXiv論文メモ
新着一覧
cs.CR · 査読状況未確認

線形計算で結ばれた秘密をMassey秘密分散から漏らす条件

On the Leakage of Massey Secret Sharing Schemes under Linear Computations

Nadja Aoutouf (X, SURYCAT), Daniel Augot (X, SURYCAT)

この論文をやさしく読む

ひとことで言うと

線形計算で関係付けられた複数の秘密を共有すると、断片情報から秘密が漏れる条件が広がることを解析しています。

何に役立つ?

秘密分散を使う計算システムで、入力だけでなく計算結果からの漏えいも含めて安全性を評価するための基礎研究です。

この研究の面白いところ

符号理論の線形修復との対応を使い、加算から一般の線形関係へ解析を広げます。共有する値どうしの関係を無視すると見落とすパラメータ範囲を示しています。

どこまで分かった?

一般線形符号の次元や拡大次数などに条件のある存在解析とシミュレーションです。任意の秘密分散が常に破れるという主張ではなく、同一漏えい関数が使えるのも特定の関係の場合です。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

秘密分散方式に対する漏洩攻撃は、個々のシェアの部分情報を利用して元の秘密を復元する。符号理論では、符号率が十分に低ければ、線形厳密修復方式(LERS)によって、他のシンボルから得た少量の情報を用い、符号語の1シンボルを復元できる。これは、シェアの部分情報、具体的には部分体のシンボルから秘密を復元することと解釈できる。近年、一般の線形符号に基づくMassey秘密分散方式に対し、LERSから導かれる漏洩攻撃を構成するため、部分体部分符号に基づくランダム化構成法が提案された。 本研究では、この枠組みを、対応するシェアが線形計算によって関係付けられた複数の共有秘密へ拡張し、計算結果からの漏洩も許す。具体的には、N個の秘密のうちK ≤ N個が線形独立な入力値で、残りのN − K個はこれらの入力への線形計算で決まる場合を考える。この構造を利用するLERS由来の漏洩が存在する条件を解析する。まず加算の場合を調べ、その後、構成法を任意の線形計算に一般化する。 解析は、F_{q^m}上で長さn + 1、次元k、かつk ≤ Nn/(Km)を満たす一般の線形符号に適用でき、任意の線形計算に対応する。一方、従来の部分体部分符号による構成法が適用できるのはk ≤ n/m − 1の場合だけである。したがって、線形関係を利用すると、この種の攻撃に弱い符号パラメータの範囲を広げるLERSに基づく漏洩が可能になる。最後に、特定の線形関係では同一の漏洩関数が現れ得るため、より現実的でありながら依然として強力になり得る攻撃モデルが得られる。さらにシミュレーションも、特定の線形関係では同一の漏洩関数を利用でき、より現実的な攻撃モデルになることを示唆する。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-17(UTC)
最新改訂
2026-09-17 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Leakage attacks on secret sharing schemes exploit partial information about individual shares to recover the underlying secret. In coding theory, linear exact repair schemes (LERSs) enable the recovery of one codeword symbol from a small amount of information obtained from the remaining symbols, provided that the code has sufficiently low rate. This can be interpreted as recovering the secret from partial information, namely subfield symbols, of the shares. Recently, a randomized construction based on subfield subcodes was proposed for constructing LERS-derived leakage attacks against Massey secret sharing schemes based on general linear codes. We extend this framework to multiple shared secrets whose corresponding shares are related through linear computations, with leakage also allowed on the computation outcomes. More precisely, we consider N secrets, of which K $\le$ N are linearly independent input values and the remaining N -K secrets are determined by linear computations on these inputs. We analyse the existence of LERS-derived leakage that exploits this structure. We first study the case of addition and then generalize our construction to arbitrary linear computations. Our analysis applies to general linear codes of length n+1 and dimension k over F\_{q^m} with k $\le$ N n/(Km), and supports arbitrary linear computations, whereas the previous subfield subcode construction only applies to k $\le$ n/m -1. Consequently, exploiting the linear relations enables LERS based leakage which extend the range of code parameters vulnerable to such attacks. Finally, identical leakage functions can arise for certain linear relations, making this a more realistic yet still potentially powerful attack model. Finally, simulations indicate that identical leakage functions can be used for certain linear relations, yielding a more realistic attack model.

arXiv ID: 2609.19929 / 要約の誤りについて