Paper 2024/196

Subfield attack: leveraging composite-degree extensions in the Quotient Ring transform

Pierre Pébereau, KU Leuven
Abstract

The VOX signature scheme is a multivariate signature scheme which was submitted to the Round 1 Additional Digital Signature Schemes NIST process. VOX relies on the Hat Plus perturbation and the Quotient-Ring transform (QR). We formalize a dimension criterion enabling the direct attack to be used as a key recovery attack against UOV schemes. This enables a practical cryptanalysis of the Round 1 VOX parameters. Next, we show that some of the alternative parameters proposed for VOX after attacks on the Round 1 submission are still vulnerable. More precisely, these parameters were chosen to defeat an attack of Furue and Ikematsu in the field extension defined by the QR parameter. We observe that one may use a smaller field extension of any degree dividing the QR parameter, in which case the attacks apply again. These attacks are relevant for a subset of the parameter sets proposed for VOX: I, Ic, III, IIIa, V, Vb. In particular, we apply the subfield framework to our previous dimension criterion for the direct attack. We estimate the cost of our attack on these parameter sets and find costs of at most 2^67 gates, and significantly lower in most cases. In practice on a commercial laptop, our attack requires 0.3s, 1.35s, 0.56s for parameter sets I, III, V for VOX, and 56.7s, 6.11s for the alternative parameter sets IIIa, Vb. Our analysis also improves the cryptanalysis of some alternative parameters proposed by Guo and Ding, and of the ``Minus'' variant of VOX.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published by the IACR in CIC 2026
Keywords
Multivariate cryptography
Contact author(s)
pierre pebereau @ esat kuleuven be
History
2026-08-04: revised
2024-02-09: received
See all versions
Short URL
https://ia.cr/2024/196
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2024/196,
      author = {Pierre Pébereau},
      title = {Subfield attack: leveraging composite-degree extensions in the Quotient Ring transform},
      howpublished = {Cryptology {ePrint} Archive, Paper 2024/196},
      year = {2024},
      url = {https://eprint.iacr.org/2024/196}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.