Key Recovery Attacks on UOV Using pℓ-Truncated Polynomial Rings
Hiroki Furue, Yasuhiko Ikematsu
摘要
The unbalanced oil and vinegar signature scheme (UOV) was proposed by Kipnis et al. in 1999 as a multivariate-based scheme. UOV is regarded as one of the most promising candidates for post-quantum cryptography owing to its short signatures and fast performance. Recently, Ran proposed a new key recovery attack on UOV over a field of even characteristic, reducing the security of its proposed parameters. Furthermore, Jin et al. generalized Ran’s attack to schemes over a field of arbitrary characteristic by exploiting the structure of the symmetric algebra. In this work, we propose a new framework for recovering the secret subspace of UOV over a finite field by generalizing these preceding results. First, we show that a key recovery against UOV can be successfully performed using the XL algorithm by exploiting the structure of the -truncated polynomial ring . This result simplifies the description of the attacks proposed by Jin et al. by formulating them in terms of the polynomial ring, independent of the structure of the symmetric algebra. Second, we generalize this result to the polynomial rings of more general forms, namely, the -truncated polynomial rings for any . This result is due to our description in terms of the polynomial ring and can relax the constraints on the solving degree of the XL algorithm using by taking a larger . Finally, we consider performing the reconciliation and intersection attacks using the -truncated polynomial rings against UOV. In particular, we consider the intersection attack using this framework, which has not been addressed in previous analyses. Based on our complexity estimation, we confirm that the optimal complexity of the reconciliation attack using the proposed framework is consistent with that of the symmetric-algebra attack by Jin et al. We further show that the intersection attack using the proposed framework outperforms the reconciliation attack against the proposed parameters of UOV and reduces the security of multiple parameters compared to their claimed security levels.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Wedges, Oil, and Vinegar - An Analysis of UOV in the Exterior AlgebraLars RanEUROCRYPT 2026 · 被引用 1 次
- Improved Cryptanalysis of UOV and RainbowWard BeullensEUROCRYPT 2021 · 被引用 96 次
- Cryptanalysis of the Lifted Unbalanced Oil Vinegar Signature SchemeJintai Ding, Joshua Deaton, Kurt Schmidt, Vishakha 等CRYPTO 2020 · 被引用 15 次
- mUOV: Masking the Unbalanced Oil and Vinegar Digital Signature Scheme at First- and Higher-OrderSuparna Kundu, Quinten Norga, Angshuman Karmakar, Uttam Kumar Ojha 等CCS 2025
- Singular Points of UOV and VOXPierre PébereauEUROCRYPT 2025 · 被引用 2 次
