Paper 2025/1341

Practical Attack on All Parameters of the HPPC Signature Scheme

Pierre Briaud, Simula UiB
Maxime Bros, National Institute of Science and Technology (NIST)
Ray Perlner, National Institute of Science and Technology (NIST)
Daniel Smith-Tone, National Institute of Science and Technology (NIST), University of Louisville
Abstract

HPPC is a multivariate signature scheme submitted to the NIST PQC standardization process in response to the recent call for additional signature schemes. We show that, despite some non-standard notational choices in the submission document, HPPC can be viewed as a special case of the well-studied, but broken for all practical parameters, HFE signature scheme. We further show that the HPPC construction introduces additional structure that further weakens the scheme. For instance, the central map has $Q$-rank $2$ independently from the degree $D$ of the central polynomial that is used. Using these observations, we show that HPPC is weaker against the direct attack than claimed in the submission document and more crucially that all parameter sets can be practically broken using MinRank techniques. For instance, with a very naive implementation, we have been able to recover an equivalent key in approximately 8 minutes for security level 2, an hour and a half for security level 4, and slightly more than 7 hours for security level 5.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published elsewhere. SAC 2025
Keywords
Public Key CryptographyMultivariate CryptographyHFENIST CandidatesAlgebraic Cryptanalysis
Contact author(s)
pierre @ simula no
maxime bros @ nist gov
ray perlner @ nist gov
daniel smith @ nist gov
History
2025-07-23: approved
2025-07-23: received
See all versions
Short URL
https://ia.cr/2025/1341
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1341,
      author = {Pierre Briaud and Maxime Bros and Ray Perlner and Daniel Smith-Tone},
      title = {Practical Attack on All Parameters of the {HPPC} Signature Scheme},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1341},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1341}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.