Paper 2026/1542
Passive Full-Key Recovery for the MQOM v2 Lineage from Saltless Root Expansion
Abstract
MQOM v2 derives every correlated-GGM root from a fresh \(\lambda\)-bit master seed using a fixed PRG call with zero salt. A public opening reveals either the corresponding root or its XOR with a fixed prefix of the long-term MQ witness. Because the resulting root functions are shared by all signatures, keys, salts, and v2 releases, repeated master seeds expose linear equations in the witness. We give a passive classical EUF-CMA attack in which an optimal three-record parity-indexed XOR triangle detects every usable collision, recovers the complete signing key, and produces a fresh-message forgery. In Category I at the permitted \(Q=2^{64}\) signing-query boundary, the attack has birthday-regime success \(0.393395296381\) with error \(O(2^{-64})\). A rank-two extension recovers two unrelated keys, while reusable global tables attain membership-certified lower bounds of \(0.632030733547\) for the complete triangle and \(0.776706354579\) for the record-optimal one-root allocation at \(P=Q=2^{64}\). The same fixed root functions support full-key recovery in every security category and allow precomputation to be reused across targets and versions. A streaming first-distinguished-point construction replaces storage of the signature corpus by certified chain coverage and an identifier-free endpoint index. Its membership-hit law is exact conditional on realized distinct coverage, with separate forecasts for chain construction, tags, fingerprints, and MPHF storage. A Category-I \(\mathrm{GF}(2)\) design point uses 52 GiB, \(2^{52}\) signatures, and target coverage \(C=2^{77}\); conditional on that coverage, its success is \(0.631940886333\) and its normalized serial forecast is below \(2^{94}\). Pinned probes reproduce the fixed roots for every official tag from v2.0.0 through v2.1.1 and a pinned current revision in Categories I, III, and V. Salt-bound, domain-separated root expansion eliminates the collision and reusable-precomputation channels.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- MQOMpost-quantum signaturesfull-key recoveryMPC-in-the-headmultivariate quadratic cryptography
- Contact author(s)
- jdelgado13 @ uoc edu
- History
- 2026-08-03: approved
- 2026-07-28: received
- See all versions
- Short URL
- https://ia.cr/2026/1542
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1542,
author = {José Luis Delgado},
title = {Passive Full-Key Recovery for the {MQOM} v2 Lineage from Saltless Root Expansion},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1542},
year = {2026},
url = {https://eprint.iacr.org/2026/1542}
}