Related Experiment Video
Updated: Aug 13, 2025

Silicon Metal-oxide-semiconductor Quantum Dots for Single-electron Pumping
Published on: June 3, 2015
Solving HNP with One Bit Leakage: An Asymmetric Lattice Sieving Algorithm.
Wenhao Shi1,2, Haodong Jiang1,2, Zhi Ma1,2
1State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou 450001, China.
Researchers developed a new asymmetric lattice sieving algorithm to solve the Hidden Number Problem (HNP) with only 1-bit nonce leakage. This breakthrough extends the vulnerability of cryptographic schemes like Diffie-Hellman and (EC)DSA to lattice attacks.
Area of Science:
- Cryptography and Information Security
- Computational Number Theory
- Lattice-based Cryptanalysis
Background:
- The Hidden Number Problem (HNP) is crucial for analyzing the security of cryptographic schemes, notably the Diffie-Hellman key exchange and (EC)DSA.
- Lattice reduction algorithms have expanded the scope of cryptanalytic attacks on HNP, but 1-bit nonce leakage remains a significant challenge.
- Previous lattice attacks struggled with minimal nonce leakage due to the inherent difficulty of solving HNP under such constraints.
Purpose of the Study:
- To propose a novel asymmetric lattice sieving algorithm capable of solving the Hidden Number Problem (HNP) with only 1-bit nonce leakage.
- To extend the practical vulnerability of cryptographic parameters against lattice-based side-channel attacks.
- To demonstrate the effectiveness of the proposed algorithm on a concrete instance of HNP.
Main Methods:
- Development of an asymmetric lattice sieving algorithm combining Block Korkin-Ziv (BKZ) pre-processing and a lattice sieving step.
- Utilizing lattices of different dimensions in the BKZ and sieving phases: higher dimensions for basis derivation and truncated dimensions for sieving.
- Application of the algorithm to solve HNP with 1-bit nonce leakage and a 116-bit modulus.
Main Results:
- Successfully solved the Hidden Number Problem (HNP) with 1-bit nonce leakage using the proposed asymmetric lattice sieving algorithm.
- Demonstrated that the novel approach, employing different lattice dimensions for BKZ and sieving, effectively tackles the 1-bit leakage challenge.
- Verified the algorithm's capability on a 116-bit modulus, confirming its practical applicability.
Conclusions:
- The proposed asymmetric lattice sieving algorithm significantly advances the cryptanalysis of HNP, particularly in scenarios with minimal nonce leakage.
- This work challenges the assumption that 1-bit leakage is intractable for lattice attacks, broadening the understanding of cryptographic vulnerabilities.
- The findings have implications for the security analysis of widely used cryptographic protocols like Diffie-Hellman and (EC)DSA.
More Related Videos
09:32Stable DNA Motifs, 1D and 2D Nanostructures Constructed from Small Circular DNA Molecules
Published on: April 12, 2019
06:57Theoretical Calculation and Experimental Verification for Dislocation Reduction in Germanium Epitaxial Layers with Semicylindrical Voids on Silicon
Published on: July 17, 2020
Related Concept Videos
Lattice Centering and Coordination Number
Types of Unit Cells
Imagine taking a large number of identical...
Bewley Lattice Diagram
Castigliano's Theorem: Problem Solving
Theorems of Pappus and Guldinus: Problem Solving
Ampere-Maxwell's Law: Problem-Solving
To solve the problem, we can use the equations from the analysis of an RC circuit and Maxwell's version of Ampère's law.
For the first part of...
Biot-Savart Law: Problem-Solving
Consider a mobile phone battery bank as a source of steady current, which flows through the wire connected between the two. What is the magnitude of the magnetic field created by this current at a field point P?
To estimate the magnitude of the total magnetic field, we first consider a small current element of length dl, at a distance r from the field point. Now the following...