Paper 2026/1593
HAWK-$n$ Key Recovery Reduces to SVP in Dimension $n/2 + 1$
Abstract
HAWK is a lattice signature scheme that is currently a third-round candidate in NIST's post-quantum signature competition. We give an unconditional, deterministic polynomial-time reduction from HAWK-$n$ key recovery over $K_n=\mathbb{Q}(\zeta_{2^\ell})$ to $\mathrm{poly}(n)$ calls to an exact Shortest Vector Problem (SVP) oracle in dimension $n/2+1$, where $n=2^{\ell-1}$ is the ring degree. The reduction uses a nontrivial automorphism of the key lattice, supplied by the Galois involution $\tau:\zeta\mapsto-\zeta$ and recoverable as a shortest vector of a public rank-$n$ lattice isometric, up to scaling, to $\mathbb{Z}^{n/2+1}\oplus\sqrt{2}\,\mathbb{Z}^{n/2-1}$. Ducas's block reduction on this near-hypercubic class finds the automorphism, and the descent of van Gent and Pulles recovers the key from it. In the gate-count model, the attack lowers the key-recovery cost of HAWK-512 from $2^{150}$ to $2^{108}$ and of HAWK-1024 from $2^{288}$ to $2^{182}$. We demonstrate this with a practical implementation that recovers a HAWK-256 secret key end-to-end in a few hours on a single server. The construction does not transfer to Falcon. Conductors $m\in\{p^k,2p^k\}$ ($p$ an odd prime), i.e.\ the $m>4$ with cyclic $(\mathbb{Z}/m)^\times$, evade the attack.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- HAWKLattice Isomorphism ProblemModule-LIPCyclotomic fieldsKey recoverySVP
- Contact author(s)
-
zygi @ anthropic com
sweis @ anthropic com - History
- 2026-08-06: approved
- 2026-08-03: received
- See all versions
- Short URL
- https://ia.cr/2026/1593
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1593,
author = {Zygimantas Straznickas and Stephen A. Weis},
title = {{HAWK}-$n$ Key Recovery Reduces to {SVP} in Dimension $n/2 + 1$},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1593},
year = {2026},
url = {https://eprint.iacr.org/2026/1593}
}