Paper 2026/1898
Cryptanalysis of a knot-based key exchange
Abstract
We present an efficient attack on a knot-based Diffie--Hellman key exchange proposed by Sconza and Wildi. In the proposal, the two parties exchange oriented knots, combine them under connected sum to obtain a common knot, and derive the shared secret by evaluating a finite type invariant of degree $m$ on it. We show the scheme is insecure for every choice of finite type invariant. The shared secret can be computed from the public transcript at roughly three times the cost of running the scheme honestly. The attack maps knots into a truncated Polyak space $\mathcal{P}_m$, in which connected sum becomes multiplication and every element of the image is invertible, so the public knot can simply be divided out. This bypasses all countermeasures put in place by the proposed protocol. Independently of the attack, we show that the key space is too small for the parameters proposed. A degree-$m$ invariant takes $O(c^{m})$ values on knots represented with diagrams consisting of $c$ crossings. For the suggested crossing number, reaching the $128$ bits claimed would require $m\ge 10$, at which point a single evaluation of the invariant costs in the order of $2^{50}$ operations.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- cryptanalysisknot-based DH
- Contact author(s)
- research @ simon-philipp com
- History
- 2026-09-10: approved
- 2026-09-05: received
- See all versions
- Short URL
- https://ia.cr/2026/1898
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1898,
author = {Simon-Philipp Merz},
title = {Cryptanalysis of a knot-based key exchange},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1898},
year = {2026},
url = {https://eprint.iacr.org/2026/1898}
}