In the present paper, we implement a message recovery attack to all variants of the NTRU cryptosystem. Our approach involves a reduction from the NTRU-lattice to a Voronoi First Kind lattice, enabling the application of a polynomial CVP exact algorithm crucial for executing the Message Recovery. The efficacy of our attack relies on a specific oracle that permits us to approximate an unknown quantity. Furthermore, we outline the mathematical conditions under which the attack is successful. Finally, we delve into a well-established polynomial algorithm for CVP on VFK lattices and its implementation, shedding light on its efficacy in our attack. Subsequently, we present comprehensive experimental results on the NTRU-HPS and the NTRU-Prime variants of the NIST submissions and propose a method that could indicate the resistance of the NTRU cryptosystem to our attack.
翻译:本文针对NTRU密码系统的所有变体实施了一种消息恢复攻击。我们的方法涉及将NTRU格约简为Voronoi第一类格,从而能够应用多项式时间精确CVP算法,这一算法对于执行消息恢复至关重要。攻击的有效性依赖于一个特定的预言机,该预言机允许我们逼近一个未知量。此外,我们概述了攻击成功的数学条件。最后,我们深入探讨了VFK格上一种成熟的CVP多项式算法及其实现,阐明了其在攻击中的有效性。随后,我们展示了针对NIST提交方案中NTRU-HPS和NTRU-Prime变体的全面实验结果,并提出了一种可能表明NTRU密码系统抗攻击能力的方法。