Paper 2026/1898

Cryptanalysis of a knot-based key exchange

Simon-Philipp Merz, ETH Zurich
Abstract

We present an efficient attack on a knot-based Diffie--Hellman key exchange proposed by Sconza and Wildi. In the proposal, the two parties exchange oriented knots, combine them under connected sum to obtain a common knot, and derive the shared secret by evaluating a finite type invariant of degree $m$ on it. We show the scheme is insecure for every choice of finite type invariant. The shared secret can be computed from the public transcript at roughly three times the cost of running the scheme honestly. The attack maps knots into a truncated Polyak space $\mathcal{P}_m$, in which connected sum becomes multiplication and every element of the image is invertible, so the public knot can simply be divided out. This bypasses all countermeasures put in place by the proposed protocol. Independently of the attack, we show that the key space is too small for the parameters proposed. A degree-$m$ invariant takes $O(c^{m})$ values on knots represented with diagrams consisting of $c$ crossings. For the suggested crossing number, reaching the $128$ bits claimed would require $m\ge 10$, at which point a single evaluation of the invariant costs in the order of $2^{50}$ operations.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
cryptanalysisknot-based DH
Contact author(s)
research @ simon-philipp com
History
2026-09-10: approved
2026-09-05: received
See all versions
Short URL
https://ia.cr/2026/1898
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1898,
      author = {Simon-Philipp Merz},
      title = {Cryptanalysis of a knot-based key exchange},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1898},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1898}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.