Key Recovery Attacks on UOV Using pℓ-Truncated Polynomial Rings
Hiroki Furue, Yasuhiko Ikematsu
Abstract
The unbalanced oil and vinegar signature scheme (UOV) was proposed by Kipnis et al. in 1999 as a multivariate-based scheme. UOV is regarded as one of the most promising candidates for post-quantum cryptography owing to its short signatures and fast performance. Recently, Ran proposed a new key recovery attack on UOV over a field of even characteristic, reducing the security of its proposed parameters. Furthermore, Jin et al. generalized Ran’s attack to schemes over a field of arbitrary characteristic by exploiting the structure of the symmetric algebra. In this work, we propose a new framework for recovering the secret subspace of UOV over a finite field by generalizing these preceding results. First, we show that a key recovery against UOV can be successfully performed using the XL algorithm by exploiting the structure of the -truncated polynomial ring . This result simplifies the description of the attacks proposed by Jin et al. by formulating them in terms of the polynomial ring, independent of the structure of the symmetric algebra. Second, we generalize this result to the polynomial rings of more general forms, namely, the -truncated polynomial rings for any . This result is due to our description in terms of the polynomial ring and can relax the constraints on the solving degree of the XL algorithm using by taking a larger . Finally, we consider performing the reconciliation and intersection attacks using the -truncated polynomial rings against UOV. In particular, we consider the intersection attack using this framework, which has not been addressed in previous analyses. Based on our complexity estimation, we confirm that the optimal complexity of the reconciliation attack using the proposed framework is consistent with that of the symmetric-algebra attack by Jin et al. We further show that the intersection attack using the proposed framework outperforms the reconciliation attack against the proposed parameters of UOV and reduces the security of multiple parameters compared to their claimed security levels.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 51c8614c-1062-4e12-b448-9b36c7ffd4ffRelated papers
- Wedges, Oil, and Vinegar - An Analysis of UOV in the Exterior AlgebraLars RanEUROCRYPT 2026 · 1 citation
- Improved Cryptanalysis of UOV and RainbowWard BeullensEUROCRYPT 2021 · 96 citations
- Cryptanalysis of the Lifted Unbalanced Oil Vinegar Signature SchemeJintai Ding, Joshua Deaton, Kurt Schmidt, Vishakha et al.CRYPTO 2020 · 15 citations
- mUOV: Masking the Unbalanced Oil and Vinegar Digital Signature Scheme at First- and Higher-OrderSuparna Kundu, Quinten Norga, Angshuman Karmakar, Uttam Kumar Ojha et al.CCS 2025
- Singular Points of UOV and VOXPierre PébereauEUROCRYPT 2025 · 2 citations
