 本論文包含三個部份。第一部份，我們指出另一個LUC系統的弱點。主要 的工作是推導出一個公式可正確估算在LUC中不被隱藏明文的個數。從這 公式我們可推論出LUC系統在許多情形下， 比RSA系統擁有更多如此的明 文。這公式也同時意指著LUC系統在選擇公開金匙時，需要更多的限制。 因此，我們推導出的公式，對於實踐LUC型式的系統的設計者是非常有用 的。在第二部份，我們是分析Lin等人所提出的系統，並且定義出另一種 新得易解迷袋序列。 在這部份，我們証明從他們的系統所產生的公開金 匙序列，均可找出滿足我們所定袋序列。 在這部份，我們証明從他們的 系統所產生的公開金匙序列， 均可找出滿足我們所定義的序列。因此， 我們可以成功破解他們的系統。最後，我們提出一個函數，滿足Simmon's 的黑盒子的定義 ，並使用這函數去實踐Simmon's的ZKIP協定。以我們所 知， Simmon's的 ZKIP計劃，我們是第一個提出實踐方法的人。另於附 錄 ，我們列出對Merkle-Hellman迷袋型密碼系統分析的結果。
 In this thesis, three public key systems are discussed. At first, we analyze another possible weakness of LUC cry- ptosystem that does not figure out before. We derive a gen- eral formula for the number of messages which cannot be con- cealed in LUC system. From the formula, we can know that the number of messages which cannot be concealed in LUC is grea- ter than in RSA in many cases. It implies that the choice of public keys in LUC system need more limitations than that used in RSA system. Hence, the formula is useful to design a LUC type system. Second, we present a cryptoanalysis of Lin et al's kna- psack cryptosystem and define a new easy knapsack sequence. Due to the fact that Lin et al's scheme generates a new easy knapsack sequence. We show that there exists an easy method to obtain the message from ciphertext that does not need se- cret key. Hence, Lin et al's public key scheme is insecure under ciphertext only attack. Finally, we propose an indistinguished box satisfied ho- morphism under addition operation and use the proposed black box to implement Simmon's ZKIP(Zero-Knowledge Identification Proof) scheme whose security is based on knapsack problem. The indistinguished box has not been proposed since Simmon's scheme was proposed.As to our best knowledge,it is the first concrete implementation of Simmon's ZKIP scheme.We also impl ement the well-known low- density attack on knapsack public key cryptosystem which was first proposed by Lagarias and Odlyzko. In our experiments, even if low-density attack can be used to break Merkle-Hellman knapsack public key crypt- osystem it still can not be used to attack the proposed Simmon's ZKIP scheme.
