A wrap error attack against NTRUEncrypt




Meskanen T, Renvall A

PublisherELSEVIER SCIENCE BV

2006

 Discrete Applied Mathematics

DISCRETE APPLIED MATHEMATICS

DISCRETE APPL MATH

154

2

382

391

10

0166-218X

DOIhttps://doi.org/10.1016/j.dam.2005.03.019



We present a chosen plaintext attack on the NTRU encryption system. We assume that the attacker can detect wrap errors, that the blinding polynomial is generated from three parts (as specified in the standards) and that the attacker has a large database of carefully selected plaintexts. The attack is based on the fact that wrap errors occur more frequently if blinding polynomials with larger coefficients are used. (c) 2005 Elsevier B.V. All rights reserved.




Last updated on 14/10/2025 09:57:47 AM