HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1

302 views
Skip to first unread message

Steve Weis

unread,
1:06 PM (5 hours ago) 1:06 PM
to pqc-...@list.nist.gov
Hello pqc-forum. We would like to announce an improved key recovery attack against HAWK-n that reduces to SVP in dimension n/2 + 1. The paper will appear at https://anthropic.com/document/hawk_key_recovery.pdf and is linked to from an accompanying blog post that will shortly be live: https://www.anthropic.com/research/discovering-cryptographic-weaknesses

In the gate-count model of AGPS'20, the improved attack lowers the key-recovery cost of HAWK-512 from 2^150 to 2^108 and of HAWK-1024 from 2^288 to 2^182. We demonstrate this with a practical implementation that recovers a HAWK-256 secret key end-to-end in a few hours on a single server. The implementation can be found at: https://github.com/anthropics/cryptography-research-demo

This result does not impact Falcon, ML-DSA, or other latticed-based schemes.

We would like to thank the HAWK team for their help verifying this result and for their feedback. We would also like to acknowledge that this was found by Claude, with minimal technical guidance from people. For more information on the process, please refer to the above blog post.

Thank you very much.

Daniel Apon

unread,
5:54 PM (10 minutes ago) 5:54 PM
to pqc-forum, Steve Weis
Nice.

It checks out independently for me.
Reply all
Reply to author
Forward
0 new messages