Probability Method for Cryptanalysis of General Multivariate Modular Linear Equation

HaiJian Zhou,Ping Luo,DaoShun Wang,YiQi Dai
DOI: https://doi.org/10.1007/s11432-009-0159-9
2009-01-01
Science in China Series F Information Sciences
Abstract:Finding the solution to a general multivariate modular linear equation plays an important role in cryptanalysis field. Earlier results show that obtaining a relatively short solution is possible in polynomial time. However, one problem arises here that if the equation has a short solution in given bounded range, the results outputted by earlier algorithms are often not the ones we are interested in. In this paper, we present a probability method based on lattice basis reduction to solve the problem. For a general multivariate modular linear equation with short solution in the given bounded range, the new method outputs this short solution in polynomial time, with a high probability. When the number of unknowns is not too large (smaller than 68), the probability is approximating 1. Experimental results show that Knapsack systems and Lu-Lee type systems are easily broken in polynomial time with this new method.
What problem does this paper attempt to address?