A quantum-resistant cryptography algorithm under consideration for a US standard has been withdrawn after an AI model developed by Anthropic identified a critical flaw. The algorithm, known as HAWK, was designed to withstand attacks from quantum computers. It had passed two rounds of testing by NIST for evaluating post-quantum cryptographic algorithms. The flaw was discovered by Anthropic's Mythos AI model, which prompted the developer to withdraw HAWK from further consideration. The findings highlight the potential of AI in uncovering cryptographic weaknesses that could impact digital security.

The flaw in HAWK, a digital signature scheme, was identified through a method that reduced its key strength by half. According to Anthropic, the attack required about 60 hours of work and $100,000 in compute costs. The method involved finding automorphism symmetries, which broke the algorithm's security. While the weakness can be mitigated by doubling the key size, this makes HAWK less desirable than existing PQC signing algorithms. Matthew Green, a cryptography expert, noted that the attack combined several existing methods in a novel way, raising concerns about the potential of AI in cryptanalysis.

The results of the Mythos model's analysis were shared in a blog post, which also included findings on an improved attack against AES. The attack on AES reduced the number of required plaintext inputs for a meet-in-the-middle attack from 2105 to 289, making the method more feasible. However, the actual speed-up remains unknown, as the tested AES variant used only 7 rounds, while specification-compliant AES uses 10, 12, or 14 rounds. Anthropic emphasized that the findings, while incremental, could signal significant advances in cryptanalysis and raise questions about the future of human involvement in cryptographic research.

Source: arstechnica