Paper 2026/1927
A Forgery Attack against Frobenius-UOV
Abstract
Frobenius-UOV (F-UOV) is a multivariate signature scheme by Macario-Rat over $\mathbb{F}_{p^e}$ whose public equations are quadratic over $\mathbb{F}_p$ but have high degree over $\mathbb{F}_{p^e}$. A message can be forged by solving a six-term univariate equation in $\mathbb{F}_{p^e}$, which can be reduced to a univariate equation containing three monomials with exponents $p^{a_k}+p^{b_k}$ for $k=0,1,2$ and a constant term, where the constants $a_k$ and $b_k$ are fixed by the specification. We show that the choice of constants $a_k,b_k$ of F-UOV allows one to solve the univariate equation efficiently without knowledge of the secret key, leading to a forgery attack. The attack introduces a variable representing a Frobenius power of $x$, derives two low-degree bivariate equations, and solves them using a so-called linearized resultant. Under heuristics assumptions on the success probabilities, the average complexity is $\tilde{\mathcal{O}}(ep^6)$ field operations. For the $128$-, $192$-, and $256$-bit security instances, our estimates are approximately $2^{45}$, $2^{52}$, and $2^{53}$ field operations, respectively. This attack may be mitigated by changing the choice of the exponents $a_k$ and $b_k$.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- MultivariateUOVFrobeniusForgeryAttack
- Contact author(s)
- augustin bariant @ ssi gouv fr
- History
- 2026-09-12: approved
- 2026-09-08: received
- See all versions
- Short URL
- https://ia.cr/2026/1927
- License
-
CC0
BibTeX
@misc{cryptoeprint:2026/1927,
author = {Augustin Bariant},
title = {A Forgery Attack against Frobenius-{UOV}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1927},
year = {2026},
url = {https://eprint.iacr.org/2026/1927}
}