Lune

CRYPTO2026顶会

Key Recovery Attacks on UOV Using pℓ-Truncated Polynomial Rings

Hiroki Furue, Yasuhiko Ikematsu

2026年份

摘要

The unbalanced oil and vinegar signature scheme (UOV) was proposed by Kipnis et al. in 1999 as a multivariate-based scheme. UOV is regarded as one of the most promising candidates for post-quantum cryptography owing to its short signatures and fast performance. Recently, Ran proposed a new key recovery attack on UOV over a field of even characteristic, reducing the security of its proposed parameters. Furthermore, Jin et al. generalized Ran’s attack to schemes over a field of arbitrary characteristic by exploiting the structure of the symmetric algebra. In this work, we propose a new framework for recovering the secret subspace of UOV over a finite field Fpe\mathbb{F}_{p^e} by generalizing these preceding results. First, we show that a key recovery against UOV can be successfully performed using the XL algorithm by exploiting the structure of the pp-truncated polynomial ring R(p)=Fpe[x1,…,xn]/⟨x1p,…,xnp⟩R^{(p)}=\mathbb{F}_{p^e}[x_1,\dots,x_n]/ \langle x_1^p,\dots,x_n^p\rangle. This result simplifies the description of the attacks proposed by Jin et al. by formulating them in terms of the polynomial ring, independent of the structure of the symmetric algebra. Second, we generalize this result to the polynomial rings of more general forms, namely, the pℓp^\ell-truncated polynomial rings R(pℓ)R^{(p^\ell)} for any 1≤ℓ≤e1 \le \ell \le e. This result is due to our description in terms of the polynomial ring and can relax the constraints on the solving degree of the XL algorithm using R(pℓ)R^{(p^\ell)} by taking a larger ℓ\ell. Finally, we consider performing the reconciliation and intersection attacks using the pℓp^\ell-truncated polynomial rings against UOV. In particular, we consider the intersection attack using this framework, which has not been addressed in previous analyses. Based on our complexity estimation, we confirm that the optimal complexity of the reconciliation attack using the proposed framework is consistent with that of the symmetric-algebra attack by Jin et al. We further show that the intersection attack using the proposed framework outperforms the reconciliation attack against the proposed parameters of UOV and reduces the security of multiple parameters compared to their claimed security levels.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖