Improved Cryptanalysis of SNOVA
Ward Beullens
摘要
SNOVA is a multivariate signature scheme submitted to the NIST project for additional signature schemes by Cho, Ding, Kuan, Li, Tseng, Tseng, and Wang. With small key and signature sizes good performance, SNOVA is one of the more efficient schemes in the competition, which makes SNOVA an important target for cryptanalysis.
In this paper, we observe that SNOVA implicitly uses a structured version of the ``whipping'' technique developed for the MAYO signature scheme. We show that the extra structure makes the construction vulnerable to new forgery attacks. Concretely, we formulate new attacks that reduce the security margin of the proposed SNOVA parameter sets by a factor between and . Furthermore, we show that large fractions of public keys are vulnerable to more efficient versions of our attack. For example, for SNOVA-37-17-2, a parameter set targeting NIST's first security level, we show that roughly one out of every public keys is vulnerable to a universal forgery attack with bit complexity , and roughly one out of every public keys is even breakable in practice within a few minutes.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Improved Attacks for SNOVA by Exploiting Stability Under a Group ActionDaniel Cabarcas, Peigen Li, Javier A. Verbel, Ricardo Villanueva-PolancoCRYPTO 2025 · 被引用 3 次
- Just Guess: Improved (Quantum) Algorithm for the Underdetermined MQ ProblemAlexander May, Massimo Ostuzzi, Henrik ResslerEUROCRYPT 2026 · 被引用 3 次
- Singular Points of UOV and VOXPierre PébereauEUROCRYPT 2025 · 被引用 2 次
- Cryptanalysis of the Lifted Unbalanced Oil Vinegar Signature SchemeJintai Ding, Joshua Deaton, Kurt Schmidt, Vishakha 等CRYPTO 2020 · 被引用 15 次
- Practical Attack on All Parameters of the DME Signature SchemePierre Briaud, Maxime Bros, Ray A. Perlner, Daniel Smith-ToneEUROCRYPT 2024 · 被引用 1 次
