[CFRG] Fwd: [pqc-forum] Re: HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1
Dmitry Belyavsky <beldmit@gmail.com> Sun, 09 August 2026 20:10 UTC
Return-Path: <beldmit@gmail.com>
X-Original-To: cfrg@mail2.ietf.org
Delivered-To: cfrg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 3AD65126BE070 for <cfrg@mail2.ietf.org>; Sun, 9 Aug 2026 13:10:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786306235; bh=IoQW9jDtxhQYmPY139QP7499ILGOzT45sjhqB/WHUzM=; h=References:In-Reply-To:From:Date:Subject:To; b=v75eHoPWFmg5MUxzebyKAdCXp1Y9/o55pvKgZotNajsGg8Il1UeL60t9v565U3WJj z+p177gDtrUxsH3LvZzShL2Pd8PplUmV6kk2gjAyEZbJRSnk5UQOFvBotcCKhzOb9i la9/h8bzGOLIL5fulUyqL4bifcwfDnmSk3Rcn+So=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: 0.911
X-Spam-Level:
X-Spam-Status: No, score=0.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_GMAIL_RCVD=1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, PDS_OTHER_BAD_TLD=1.999, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9kGnzFnwuVHf for <cfrg@mail2.ietf.org>; Sun, 9 Aug 2026 13:10:33 -0700 (PDT)
Received: from mail-qt1-x82d.google.com (mail-qt1-x82d.google.com [IPv6:2607:f8b0:4864:20::82d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 21066126BE06B for <cfrg@irtf.org>; Sun, 9 Aug 2026 13:10:33 -0700 (PDT)
Received: by mail-qt1-x82d.google.com with SMTP id d75a77b69052e-51c2cce930cso12413471cf.0 for <cfrg@irtf.org>; Sun, 09 Aug 2026 13:10:33 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1786306233; cv=none; d=google.com; s=arc-20260327; b=LHjT+2Vzpa6kENk91mrpZMRAywGTEUvvOPdwMh+DYGLgYK4lsRhkF5lNXTjjz/ApMg 1Vq8fzjhecMgcpwW/JFiQm4FqEXnFScehKvCKkEtwGfH1iB4BfLgYJSe2zc0ZaAlU0Wd gFSMJyGGFREoFIMNSwZhctwQKZV6x1j5o9hcUTFfl/+CzjawtfhXy7qd22U6z/zYpW9o ba1b+S+snbC8pH598rLAFdWorOqoHb62UjGBgnNXLdpNQnw49NMyKdYWTs99iesNQHII HT6g12jyA3BM4LnKi7QTfd0QmPKHwF8GsWliTpNV4Xlh/LuKWjhiAUOEC5yK03O5Xn7B RDsw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=IoQW9jDtxhQYmPY139QP7499ILGOzT45sjhqB/WHUzM=; fh=0OpMRY94qnbm+W1rj3DPPWa2vbm2oOGhvNxXhXnx9G4=; b=EzlKhFlUmGWKWw5pECt9GitcyNwbVSdsM/pHoY+pbsGsoCu3Q+B8EHHa0+P5c2QVSD lXgnjV2s4jkn0y7oAxOkyo9pb+Gkh/VZ03UxGgkY655mzESuELr8LtBK37G64mI1pasL jW2ACFlf+StP8ISHuEYRZCRo5Q2KFJ86sCxDRxGfl2LPoeDIxPBb2EtI3s3SnMnBx8BS aROinoG9MRZi2WBSGdx4blqVVhgyL5ANNljayX1Kp7bmbEwIwtnBUGwju9VuPUQBdhJV D7Bo/CR3ahikTaJeGCFzLesxoC4CjjU2wsFp/wJF4pUaBEX1wo7hEvR24/3HigmO2LyK 4rUA==; darn=irtf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786306233; x=1786911033; darn=irtf.org; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=IoQW9jDtxhQYmPY139QP7499ILGOzT45sjhqB/WHUzM=; b=T9VjAtiJHk2dZnrIxRgf16iNksuPwxv69pLy+JQeOoHVmpSjIhRs+004RMIIGzeTCA LI0I1cHiaviZkChCFWaHB+s5g43g5YgGOdMLz6WaRX1honL+lDJJgDh91lr5gzTn/pi+ i4s/YbRnJaEbFaC/QFSefnuHtOZ7Hlsrd4XCFLGxyv7LOBAhdL5cHHyBndsrgUO4KfwE r+UoWxBSsCsl9tZCGGRd8bVPFtDwAHLyRY6zMbTfSdggjpR3Vd8mrUDIFiExLpxoVdaV vSnUx47X8lKNrVKf2xQy+00JpRu49Aduw3ei9vE5CuqCHe7BkFd1qUrr1uqMxRURhpUq +sOg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786306233; x=1786911033; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=IoQW9jDtxhQYmPY139QP7499ILGOzT45sjhqB/WHUzM=; b=f9hhg8QPllIk3OlN9ttkeiQYX6NJ3J52ygJPHDPG8rXZGDHvG2r5VjM9oVgYI8re/Z mrbNbRC8UJva70WzR5aEkdbqIiHdHyUezz7f9cr0YmnlPu9G6yRPm4JE/iQzFkP4cNSH oIpWVktMnc7uUnRiKpRCWzv7/CJobTY20eI3KI7ToAKxa+eb9tTWOFLPS//Z/7EQW5e/ 3yWRVXULYgQ1nmDu8DgdAvLg9mdddyjI9U1tlP6obISYnCS5Ie46H0Y80z7Y51easZsr 67tHnLhQc5Iu1G+GAKNd2R+DtxWgzoheDUQxuw1nCy6OfT0HfZBO1boIn2sn6JILzNEK gU2A==
X-Forwarded-Encrypted: i=1; AHgh+Rq4m2A+aHzUoXj1phShFEH929RuiJ7hVi59rzX1pgX9myyxWbshY8Ou7DXNSCxHAv9e4t8o@irtf.org
X-Gm-Message-State: AOJu0YzTF90GT2J9j8Pfc+rDNVToDKRX6DuWxuhb9aXAWTVDHPpZxw3B zazCflZRrsQ75l+07OpFjJHpYaRHJBmEP6A/fFV5HtUlqaY320za+QKTC4LC3QcJa0zJmtO6934 sh+Kd/qBwpMic5RvvRlZ0zj4vIXC6Gyo=
X-Gm-Gg: AR+sD1064jGpArRCB8RWs3DIDKholcPfMHFJOSflbbcn8ITLLQUAg+n+j1k9tLWLzja KIGp6m/KMTVqow2Om90H44P8loNvYb11n3Da1mt+jNgtNncetcI3Q+zTaIO4c0VLEKsKOPf2pve gr09jqTS3G4VOzTp8ag1Gfpoo/iH/kND4j7b9F1PblsKc9qW9jsBWJfKjRQ7xKyjJZSKFN3hYZ7 zx7WDb9YfLO4GHoLYuMMTaXdKUoFIYkwBloFiOLPehUIAHoDFNh3SHYRiCH61UZTu5jEhZ87ydT Ii/4C/3GG4kG+VC8vS2x4oOh3Kff1ltLWT+jTEzLYjbSLNRvWBDvwD0wlkqkFmv8TXdy
X-Received: by 2002:ac8:6903:0:b0:527:7027:cc1b with SMTP id d75a77b69052e-52d0b220c2cmr283478711cf.32.1786306232428; Sun, 09 Aug 2026 13:10:32 -0700 (PDT)
MIME-Version: 1.0
References: <CAAUmCcC6ERGedfyN2kWeiBmeg+4Q+UgMpLXGrXvBLwwfEPkJkA@mail.gmail.com> <09f45a33-bf7c-42cd-956d-ad4fecaccf3cn@list.nist.gov> <CANWGDp8sEpC7bH0phZO8dMW5zyeFMh3kyR=hDASG=w06HQ6prw@mail.gmail.com> <5d998299-9203-4171-9f42-7ec93d118786n@list.nist.gov> <43aea96a-98bd-46cb-a7e1-0b11d094d40cn@list.nist.gov> <CA+iU_qkUtn3xNxy0V1y7kKhpmK+kKsPyyW1ZCFOLtKs04f1xkw@mail.gmail.com>
In-Reply-To: <CA+iU_qkUtn3xNxy0V1y7kKhpmK+kKsPyyW1ZCFOLtKs04f1xkw@mail.gmail.com>
From: Dmitry Belyavsky <beldmit@gmail.com>
Date: Sun, 09 Aug 2026 22:10:19 +0200
X-Gm-Features: AUfX_mzDYcvwjx7YznowcuYuGKAWQCW97rixiCZBo5YEji-Xo6fncnjjbB6aBDo
Message-ID: <CADqLbz+XWy-DGt2XrSuFx3j5d4YStbsYBY01EQBZ6pb42smn0Q@mail.gmail.com>
To: ssh <ssh@ietf.org>, cfrg <cfrg@irtf.org>
Content-Type: multipart/alternative; boundary="00000000000071ae1e0658a2d44c"
Message-ID-Hash: 6FNNISPLEBCNDXZYTEEAKHFJ3VL2AIRX
X-Message-ID-Hash: 6FNNISPLEBCNDXZYTEEAKHFJ3VL2AIRX
X-MailFrom: beldmit@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; header-match-cfrg.irtf.org-1; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Fwd: [pqc-forum] Re: HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/up07pneeS0B07SzykD_lf5wV4PQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>
As the discussion of this paper takes place at multiple ML and this email looks like a relevant evaluation, I want to share it. SY, Dmitry Belyavsky ---------- Forwarded message --------- Od: Markku-Juhani O. Saarinen <mjos.crypto@gmail.com> Date: ne 9. 8. 2026 20:57 Subject: Re: [pqc-forum] Re: HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1 To: Cong Ling <cling74@googlemail.com> Cc: pqc-forum <pqc-forum@list.nist.gov> On Sun, Aug 9, 2026 at 5:58 PM 'Cong Ling' via pqc-forum < pqc-forum@list.nist.gov> wrote: > A Polynomial-Time Quantum Algorithm for the Dihedral Coset Problem > <https://eprint.iacr.org/2026/1591> > > Has anyone independently checked the proof in this paper, either manually > or using a formal proof assistant such as Lean? > Dear Cong Ling & Co, Well, the paper just came out a couple of days ago (and many of the lemmas are sketches.) Initial, direct attempts to check the proofs fail -- Lemma 3's central independence claim doesn't work as stated (it spends randomness in D twice), and Lemma 4 applies unconditional hashing bounds after heavy quantum conditioning. So the main proofs don't hold exactly as stated. But it is important to note that a bug in the proofs doesn't demonstrate that the algorithm itself doesn't work (which is really the more important point from a cryptanalytic viewpoint). One can also restate the main Theorem, if necessary. So the community would indeed be very curious to know whether anyone has found a way to repair the paper -- or found substantial evidence against the algorithm. However, there is a consensus that even if the paper's proof of correctness and reductions were repaired, this would not threaten the quantum security claims of NIST PQC algorithms. Such a result would be asymptotically important, but its concrete quantum resource costs are too high. ps. I'm obviously not the only one who has used GPT-5.6 Sol and Fable 5 on this, and ran extensive computational experiments.I have a fairly generous 45-minute slot at WAC 8 (Workshop on Attacks in Cryptography, a Crypto 2026-affiliated event at UCSB on Sunday, August 16). I'm turning the original title (on Hawk Guessing Game) into a subtitle and will intead talk mostly about AI Cryptanalysis, including my attempts to prove this DCP paper. https://wac8.cryptanalysis.fun/ Best Regards, -markku Dr. Markku-Juhani O. Saarinen <mjos@iki.fi> > > On Monday, August 3, 2026 at 11:03:33 AM UTC+1 Alice Pellet-Mary wrote: > >> Dear Betül, >> >> To answer your questions, we have worked on this since the end of May, so >> for approximatively 2 months (maybe a few weeks more for Guilhem). In terms >> of budget, we did not use any costly tool, so that would be mostly human >> (salary) cost. We weren't working full time on it at all, so I would say a >> safe upper bound on the cost would be 2 person*month. >> >> Best regards, >> Alice >> Le samedi 1 août 2026 à 00:31:14 UTC+2, Betül Durak a écrit : >> >>> That’s pretty cool. Did they say how much budget they had/used and how >>> long it took? >>> >>> On Fri, Jul 31, 2026 at 08:10 Damien Robert <damien.oli...@gmail.com> >>> wrote: >>> >>>> Here is a message by Guilhem Mureau and Alice Pellet-Mary that they >>>> asked me to post on their behalf. >>>> >>>> -------------------------------------------- >>>> >>>> Dear all, >>>> >>>> We would also like to share a third key recovery attack on Hawk whose >>>> result is very similar to the one of Hengyi Luo [2], even though we use >>>> yet another mathematical tool. Our article should appear soon on >>>> ePrint, >>>> and is accessible for the moment here: >>>> >>>> https://apelletm.pages.math.cnrs.fr/page-perso/documents/articles/trace-zero-attack.pdf >>>> < >>>> https://apelletm.pages.math.cnrs.fr/page-perso/documents/articles/trace-zero-attack.pdf >>>> > >>>> >>>> Our attack builds on our previous reduction from rank-2 module-LIP in a >>>> cyclotomic field K to the norm reduced principal ideal problem (nrdPIP) >>>> in a quaternion algebra [1]. We show that this nrdPIP instance can >>>> itself be reduced to module-LIP in a module of rank 3 over the maximal >>>> totally real subfield F of K. This allows us to reduce module-LIP in >>>> modules of rank 2 in K to module-LIP in modules of rank 3 in F (note >>>> that the degree of F is half the degree of K, so we are reducing the >>>> lattice dimension by a factor 3/4). >>>> >>>> Applying this to Hawk, we obtain a key recovery attack on Hawk which >>>> makes SVP calls in lattices of dimension at most 3n/4+1 (where n is the >>>> degree of K), which is similar to the attack obtained by Hengyi Luo >>>> [2]. >>>> The attack of Zygimantas Straznickas and Steve Weis [3] achieves an >>>> even >>>> smaller dimension for the SVP calls (namely n/2+1). >>>> >>>> The attack itself is quite simple. We wrote a detailed technical >>>> overview section which we hope can be understood by any cryptographer >>>> interested in module-LIP, so that they can get an idea of how the >>>> attack >>>> works without reading the full paper. >>>> >>>> In the upcoming weeks, we plan to investigate the relationship between >>>> the three attacks. Given the strong similarities between the results, >>>> it >>>> seems that the three attacks may be doing very similar things with >>>> different formalism. >>>> >>>> Implementation: we did a toy implementation of our attack in SageMath >>>> (available here: >>>> https://plmlab.math.cnrs.fr/apelletm/attack_hawk-trace-zero) We only >>>> implemented the new part of the attack, i.e., the algorithm that solves >>>> nrdPIP via module-LIP in modules of rank 3 over F. Due to limited >>>> computational resources, we were able to run the attack only until n = >>>> 128 (which runs in 2 hours on a laptop and uses BKZ with blocksize 30). >>>> The point of the implementation was mostly to make sure that there was >>>> no mistake in our proofs or that we did not overlook something, and the >>>> results are satisfactory. >>>> >>>> >>>> Guilhem Mureau and Alice Pellet-Mary >>>> >>>> >>>> LLM disclaimer: We would like to acknowledge that this was found by >>>> humans, with minimal technical guidance from LLMs. More precisely, we >>>> used LLMs for improving the editorial quality of some parts of the >>>> article, and for answering some technical mathematical questions that >>>> we >>>> had about quaternion algebras. >>>> >>>> References: >>>> [1] Chevignard, C., Mureau, G., Espitau, T., Pellet-Mary, A., Pliatsok, >>>> H., & Wallet, A. A reduction from hawk to the principal ideal problem >>>> in >>>> a quaternion algebra. Eurocrypt 2025. ePrint 2025/287 >>>> <https://eprint.iacr.org/2025/287.pdf>[2] Luo, H. Adjoint-Lattice >>>> Reduction for the HAWK Gram-Factor Problem. link >>>> < >>>> https://harylo.github.io/files/preprints/adjoint-lattice-reduction-for-the-hawk-gram-factor-problem.pdf >>>> > >>>> [3] Straznickas, Z. and Weis, S. HAWK-n Key Recovery Reduces to SVP in >>>> Dimension n/2 + 1. link >>>> < >>>> https://www-cdn.anthropic.com/e8d50c167ad47beeb03d6109a4a484be95cb38ea/hawk_key_recovery.pdf >>>> > >>>> >>>> >>>> On Tuesday, July 28, 2026 at 7:06:14 PM UTC+2 Steve Weis wrote: >>>> >>>>> Hello pqc-forum. We would like to announce an improved key recovery >>>>> attack against HAWK-n that reduces to SVP in dimension n/2 + 1. The paper >>>>> will appear at https://anthropic.com/document/hawk_key_recovery.pdf and >>>>> is linked to from an accompanying blog post that will shortly be live: >>>>> https://www.anthropic.com/research/discovering-cryptographic-weaknesses >>>>> >>>>> In the gate-count model of AGPS'20, the improved attack lowers the >>>>> key-recovery cost of HAWK-512 from 2^150 to 2^108 and of HAWK-1024 from >>>>> 2^288 to 2^182. We demonstrate this with a practical implementation that >>>>> recovers a HAWK-256 secret key end-to-end in a few hours on a single >>>>> server. The implementation can be found at: >>>>> https://github.com/anthropics/cryptography-research-demo >>>>> >>>>> This result does not impact Falcon, ML-DSA, or other latticed-based >>>>> schemes. >>>>> >>>>> We would like to thank the HAWK team for their help verifying this >>>>> result and for their feedback. We would also like to acknowledge that this >>>>> was found by Claude, with minimal technical guidance from people. For more >>>>> information on the process, please refer to the above blog post. >>>>> >>>>> Thank you very much. >>>>> >>>> -- >>>> >>> You received this message because you are subscribed to the Google >>>> Groups "pqc-forum" group. >>>> To unsubscribe from this group and stop receiving emails from it, send >>>> an email to pqc-forum+...@list.nist.gov. >>>> >>> To view this discussion visit >>>> https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/09f45a33-bf7c-42cd-956d-ad4fecaccf3cn%40list.nist.gov >>>> <https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/09f45a33-bf7c-42cd-956d-ad4fecaccf3cn%40list.nist.gov?utm_medium=email&utm_source=footer> >>>> . >>>> >>> -- > You received this message because you are subscribed to the Google Groups > "pqc-forum" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to pqc-forum+unsubscribe@list.nist.gov. > To view this discussion visit > https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/43aea96a-98bd-46cb-a7e1-0b11d094d40cn%40list.nist.gov > <https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/43aea96a-98bd-46cb-a7e1-0b11d094d40cn%40list.nist.gov?utm_medium=email&utm_source=footer> > . > -- You received this message because you are subscribed to the Google Groups "pqc-forum" group. To unsubscribe from this group and stop receiving emails from it, send an email to pqc-forum+unsubscribe@list.nist.gov. To view this discussion visit https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/CA%2BiU_qkUtn3xNxy0V1y7kKhpmK%2BkKsPyyW1ZCFOLtKs04f1xkw%40mail.gmail.com <https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/CA%2BiU_qkUtn3xNxy0V1y7kKhpmK%2BkKsPyyW1ZCFOLtKs04f1xkw%40mail.gmail.com?utm_medium=email&utm_source=footer> .
- [CFRG] Fwd: [pqc-forum] Re: HAWK-n Key Recovery R… Dmitry Belyavsky