Improved Attacks for SNOVA by Exploiting Stability Under a Group Action
Daniel Cabarcas, Peigen Li, Javier A. Verbel, Ricardo Villanueva-Polanco
Abstract
SNOVA is a post-quantum digital signature scheme based on multivariate polynomials. It is a second-round candidate in an ongoing NIST standardization process for post-quantum signatures, where it stands out for its efficiency and compactness. Since its initial submission, there have been several improvements to its security analysis, both on key recovery and forgery attacks. All these works reduce to solving a structured system of quadratic polynomials, which we refer to as SNOVA system.
In this work, we propose a polynomial solving algorithm tailored for SNOVA systems, which exploits the stability of the system under the action of a commutative group of matrices. This new algorithm reduces the complexity of solving SNOVA systems over generic ones. We show how to adapt the reconciliation and direct attacks in order to profit from the new algorithm. Consequently, we improve the reconciliation attack for all SNOVA parameter sets with speedup factors ranging between and . We also show how to use similar ideas to carry on a forgery attack. In this case, we use experimental results to estimate its complexity, and we discuss its impact. The empirical evidence suggests that our attack is more efficient than previous attacks, and it takes some SNOVA parameter sets below NIST's security threshold.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 9ffa839b-1c79-4ada-a243-6eebde703fa4Related papers
- Improved Cryptanalysis of SNOVAWard BeullensEUROCRYPT 2025 · 6 citations
- Just Guess: Improved (Quantum) Algorithm for the Underdetermined MQ ProblemAlexander May, Massimo Ostuzzi, Henrik ResslerEUROCRYPT 2026 · 3 citations
- Singular Points of UOV and VOXPierre PébereauEUROCRYPT 2025 · 2 citations
- Key Recovery Attacks on UOV Using pℓ-Truncated Polynomial RingsHiroki Furue, Yasuhiko IkematsuCRYPTO 2026
- On the (in)security of ROSFabrice Benhamouda, Tancrède Lepoint, Julian Loss, Michele Orrù et al.EUROCRYPT 2021 · 74 citations
