The semidirect discrete logarithm problem (SDLP) is the following analogue of the standard discrete logarithm problem in the semidirect product semigroup $G\rtimes \mathrm{End}(G)$ for a finite semigroup $G$. Given $g\in G, \sigma\in \mathrm{End}(G)$, and $h=\prod_{i=0}^{t-1}\sigma^i(g)$ for some integer $t$, the SDLP$(G,\sigma)$, for $g$ and $h$, asks to determine $t$. As Shor's algorithm crucially depends on commutativity, it is believed not to be applicable to the SDLP. Previously, the best known algorithm for the SDLP was based on Kuperberg's subexponential time quantum algorithm. Still, the problem plays a central role in the security of certain proposed cryptosystems in the family of \textit{semidirect product key exchange}. This includes a recently proposed signature protocol called SPDH-Sign. In this paper, we show that the SDLP is even easier in some important special cases. Specifically, for a finite group $G$, we describe quantum algorithms for the SDLP in $G\rtimes \mathrm{Aut}(G)$ for the following two classes of instances: the first one is when $G$ is solvable and the second is when $G$ is a matrix group and a power of $\sigma$ with a polynomially small exponent is an inner automorphism of $G$. We further extend the results to groups composed of factors from these classes. A consequence is that SPDH-Sign and similar cryptosystems whose security assumption is based on the presumed hardness of the SDLP in the cases described above are insecure against quantum attacks. The quantum ingredients we rely on are not new: these are Shor's factoring and discrete logarithm algorithms and well-known generalizations.
翻译:半直积离散对数问题(SDLP)是标准离散对数问题在有限半群$G$的半直积半群$G\rtimes \mathrm{End}(G)$中的如下类比:给定$g\in G$、$\sigma\in \mathrm{End}(G)$以及某个整数$t$满足$h=\prod_{i=0}^{t-1}\sigma^i(g)$,SDLP$(G,\sigma)$问题要求针对$g$和$h$确定$t$。由于Shor算法严重依赖于交换性,通常认为该算法不适用于SDLP。此前,已知求解SDLP的最佳算法基于Kuperberg的亚指数时间量子算法。然而,该问题在《半直积密钥交换》系列某些拟议密码系统的安全性中扮演核心角色,包括近期提出的签名协议SPDH-Sign。本文证明,在某些重要特例下SDLP甚至更易求解。具体而言,对于有限群$G$,我们描述了$G\rtimes \mathrm{Aut}(G)$中两类实例的SDLP量子算法:第一类当$G$可解时,第二类当$G$为矩阵群且$\sigma$的某个多项式小指数幂是$G$的内自同构时。我们进一步将结果推广到由这些类因子组成的群上。由此得出,SPDH-Sign及类似密码系统(其安全性假设基于上述情况下SDLP的假定困难性)在量子攻击下是不安全的。我们依赖的量子工具并非新颖:包括Shor的质因数分解与离散对数算法及其已知推广。