New Cryptanalysis of the Fiat-Shamir Protocol
最近一篇论文展示了针对Fiat-Shamir变换的新攻击方法,尽管理论上重要,但在实际应用中影响有限。研究显示,虽然该变换在某些特殊情况下存在安全隐患,但要将其扩展到自然环境仍具挑战性,这也使得为Fiat-Shamir提供通用安全证明变得不可能,表明我们对其安全性理解尚不完全。 2025-9-9 11:2:0 Author: www.schneier.com(查看原文) 阅读量:7 收藏

A couple of months ago, a new paper demonstrated some new attacks against the Fiat-Shamir transformation. Quanta published a good article that explains the results.

This is a pretty exciting paper from a theoretical perspective, but I don’t see it leading to any practical real-world cryptanalysis. The fact that there are some weird circumstances that result in Fiat-Shamir insecurities isn’t new—many dozens of papers have been published about it since 1986. What this new result does is extend this known problem to slightly less weird (but still highly contrived) situations. But it’s a completely different matter to extend these sorts of attacks to “natural” situations.

What this result does, though, is make it impossible to provide general proofs of security for Fiat-Shamir. It is the most interesting result in this research area, and demonstrates that we are still far away from fully understanding what is the exact security guarantee provided by the Fiat-Shamir transform.

Tags: , , ,

Posted on September 9, 2025 at 7:02 AM0 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.


文章来源: https://www.schneier.com/blog/archives/2025/09/new-cryptanalysis-of-the-fiat-shamir-protocol.html
如有侵权请联系:admin#unsafe.sh