Paper 2026/351
Lie algebras and the security of cryptosystems based on classical varieties in disguise
Abstract
In 2006 de Graaf et al. devised a Lie-algebra-based strategy for finding a linear transformation $T \in PGL_{N+1}(\mathbb{Q})$ connecting two linearly equivalent projective varieties $X, X' \subseteq \mathbb{P}^N$ over $\mathbb{Q}$. The method succeeds for several families of "classical" varieties such as Veronese varieties, which have large automorphism groups. In this paper, we study the Lie algebra method over finite fields, which comes with new technicalities when compared to $\mathbb{Q}$ due to, e.g., the characteristic being positive. Concretely, we make the method work for Veronese varieties of dimension $r \geq 2$ and (heuristically) for secant varieties of Grassmannians of planes. This leads to classical polynomial-time attacks against two candidate-post-quantum key exchange protocols based on disguised Veronese surfaces and threefolds, which were recently proposed by Alzati et al., as well as a digital signature scheme based on secant varieties of Grassmannians of planes due to Di Tullio and Gyawali. We provide an implementation in Magma.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- A major revision of an IACR publication in EUROCRYPT 2026
- Contact author(s)
-
wouter castryck @ esat kuleuven be
mjchennn555 @ gmail com
kutasp @ gmail com
laujunbo @ gmail com
alexanderlemmens @ hotmail com
mickael @ montessinos fr - History
- 2026-02-23: approved
- 2026-02-21: received
- See all versions
- Short URL
- https://ia.cr/2026/351
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/351,
author = {Wouter Castryck and Mingjie Chen and Péter Kutas and Jun Bo Lau and Alexander Lemmens and Mickael Montessinos},
title = {Lie algebras and the security of cryptosystems based on classical varieties in disguise},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/351},
year = {2026},
url = {https://eprint.iacr.org/2026/351}
}