Paper 2026/1830
The Extended Wedge Attack
Abstract
The wedge attack of Ran (EUROCRYPT 2026) recovers the secret oil space of a UOV public key over fields of characteristic two by exploiting the fact that the polar forms of the public map are alternating. It has since been generalized in several directions, each carrying its own algebraic tools, e.g., Jin et al. (PKC 2026). Working directly with the polynomials of an oil and vinegar map, we give a simpler description of the attack, based on a dual decomposition of oil-vinegar polynomials, and we recover the original wedge attack and its odd-characteristic analogue as special cases. This framework leads to a generalization, which we call the extended wedge attack. We identify two explicit conditions on the parameters that guarantee that the attack terminates with the recovery of the secret space. We also prove that the matrix of the extended wedge attack is permutation equivalent to the truncated Macaulay matrix in the attack by Furue-Ikematsu (CRYPTO 2026).
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- Oil-vinegar signature schemewedge attackmultivariate public key cryptographyXL algorithm
- Contact author(s)
-
jbbaena @ unal edu co
javier verbel @ tii ae
ldvillotav @ unal edu co - History
- 2026-08-30: approved
- 2026-08-29: received
- See all versions
- Short URL
- https://ia.cr/2026/1830
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1830,
author = {John Baena and Javier Verbel and Luis Villota},
title = {The Extended Wedge Attack},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1830},
year = {2026},
url = {https://eprint.iacr.org/2026/1830}
}