首页|未知参数多重递归发生器的截低位还原

未知参数多重递归发生器的截低位还原

Predicting Low-Order-Truncated Multiple Recursive Generators with Unknown Parameters

扫码查看
多重递归发生器的可预测性问题,即能否由一段截位序列还原多重递归发生器未知的参数与初态,进而预测后面的序列,是评估发生器的重要指标,也是设计发生器的主要考量.目前截高位情形下的可预测性问题已被解决,但截低位情形有待补充,且截高位情形的方法不能平凡推广到截低位情形.研究表明,截低位情形下多重递归发生器的可预测性问题可通过3步解决.首先通过格基约化找到序列的零化多项式,其次计算零化多项式的结式与最大公因式还原模数与系数,最后构造格还原初态并估计所需的截位数据量.对于模数是偶数的情形,还原初态还可以采用带模高位的格方法.实验结果表明,模数为偶数时,同时使用两种初态还原方法可提高成功率.
The predictability of multiple recursive generators means one can correctly predict the out-put of generators by recovering the unknown parameters and initial state.It is a crucial aspect of e-valuating the security of generators,as well as a main concern in their design.High-order-truncated sequences have been proved to predict multiple recursive generators,while the low-order case has not been proved yet,and the method of high-order case cannot be trivially generalized to the low-or-der case.Research shows that the low-order-truncated multiple recursive generators can be predicted in three steps.First,lattice reduction algorithms are used to find several polynomials that annihilate the sequences,then their resultant and greatest common divisor are computed to recover the modulus and the coefficients,and finally a lattice is constructed to recover the initial state and estimate the number of truncated digits required.In particular,when the modulus is even,the initial state can al-so be recovered by a lattice-based method with modulo the high-order bits.Extensive experiments have confirmed that the success rate of recovering the initial state can be improved by using two methods above simultaneously when the modulus is even.

multiple recursive generatorssequences over ringslattice reduction algorithmtrun-cated prediction

于寒冰、郑群雄

展开 >

信息工程大学,河南郑州 450001

多重递归发生器 环上序列 格基约化算法 截位还原

国家自然科学基金

61872383

2024

信息工程大学学报
中国人民解放军信息工程大学科研部

信息工程大学学报

影响因子:0.276
ISSN:1671-0673
年,卷(期):2024.25(2)
  • 20