Paper 2026/1830

The Extended Wedge Attack

John Baena, Universidad Nacional de Colombia
Javier Verbel, Technology Innovation Institute
Luis Villota, Universidad Nacional de Colombia
Abstract

The wedge attack of Ran (EUROCRYPT 2026) recovers the secret oil space of a UOV public key over fields of characteristic two by exploiting the fact that the polar forms of the public map are alternating. It has since been generalized in several directions, each carrying its own algebraic tools, e.g., Jin et al. (PKC 2026). Working directly with the polynomials of an oil and vinegar map, we give a simpler description of the attack, based on a dual decomposition of oil-vinegar polynomials, and we recover the original wedge attack and its odd-characteristic analogue as special cases. This framework leads to a generalization, which we call the extended wedge attack. We identify two explicit conditions on the parameters that guarantee that the attack terminates with the recovery of the secret space. We also prove that the matrix of the extended wedge attack is permutation equivalent to the truncated Macaulay matrix in the attack by Furue-Ikematsu (CRYPTO 2026).

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Oil-vinegar signature schemewedge attackmultivariate public key cryptographyXL algorithm
Contact author(s)
jbbaena @ unal edu co
javier verbel @ tii ae
ldvillotav @ unal edu co
History
2026-08-30: approved
2026-08-29: received
See all versions
Short URL
https://ia.cr/2026/1830
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1830,
      author = {John Baena and Javier Verbel and Luis Villota},
      title = {The Extended Wedge Attack},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1830},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1830}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.