Paper 2026/1620
Extending the Applicability of Algebraic Key Recovery Attacks on the UOV Signature Scheme
Abstract
The Unbalanced Oil and Vinegar (UOV) scheme was proposed by Kipnis et al. in 1999 as a multivariate signature scheme. Owing to its small signature size and its resistance to various attacks over more than two decades, UOV has become one of the leading candidates in multivariate public key cryptography. In 2025, Ran proposed a novel algebraic key recovery attack exploiting the algebraic structure of UOV, which reduced the security of several parameter sets of UOV and its variants submitted to the second round of the NIST PQC standardization process for additional signatures. This attack was improved by Jin et al., and Furue and Ikematsu, forming a line of attacks that has significantly advanced the cryptanalysis of UOV. However, Ran's attack is applicable only when $v<2m$, where $v$ denotes the number of vinegar variables and $m$ the number of public polynomials. In fact, when $v\ge 2m$, an additional kernel element of the ideal generated by the public polynomials appears, preventing the attack from recovering the oil subspace. A similar issue arises in the improvements by Jin et al., and Furue and Ikematsu. In this paper, we propose a method that overcomes this issue, extending the applicability of this line of attacks to the case where such an additional kernel element appears. Applying our method to SNOVA via the lifting technique of Nakamura et al., we show that the claimed security levels of some parameter sets of SNOVA in the second round of NIST PQC standardization process for additional signatures are reduced. In particular, for the parameter set $(v,o,q,l)=(37,17,16,2)$ of NIST security level I, although Ran's attack is not applicable, our method reduces the estimated security to $2^{103}$ gate operations, which matches the complexity of the attack by Bros et al. in 2026.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- post-quantum cryptographymultivariate public key cryptographyunbalanced oil and vinegar (UOV)
- Contact author(s)
-
ikematsu @ imi kyushu-u ac jp
hiroki furue @ ntt com - History
- 2026-08-06: approved
- 2026-08-05: received
- See all versions
- Short URL
- https://ia.cr/2026/1620
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1620,
author = {Yasuhiko Ikematsu and Hiroki Furue},
title = {Extending the Applicability of Algebraic Key Recovery Attacks on the {UOV} Signature Scheme},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1620},
year = {2026},
url = {https://eprint.iacr.org/2026/1620}
}