Paper 2026/1927

A Forgery Attack against Frobenius-UOV

Augustin Bariant, ANSSI
Abstract

Frobenius-UOV (F-UOV) is a multivariate signature scheme by Macario-Rat over $\mathbb{F}_{p^e}$ whose public equations are quadratic over $\mathbb{F}_p$ but have high degree over $\mathbb{F}_{p^e}$. A message can be forged by solving a six-term univariate equation in $\mathbb{F}_{p^e}$, which can be reduced to a univariate equation containing three monomials with exponents $p^{a_k}+p^{b_k}$ for $k=0,1,2$ and a constant term, where the constants $a_k$ and $b_k$ are fixed by the specification. We show that the choice of constants $a_k,b_k$ of F-UOV allows one to solve the univariate equation efficiently without knowledge of the secret key, leading to a forgery attack. The attack introduces a variable representing a Frobenius power of $x$, derives two low-degree bivariate equations, and solves them using a so-called linearized resultant. Under heuristics assumptions on the success probabilities, the average complexity is $\tilde{\mathcal{O}}(ep^6)$ field operations. For the $128$-, $192$-, and $256$-bit security instances, our estimates are approximately $2^{45}$, $2^{52}$, and $2^{53}$ field operations, respectively. This attack may be mitigated by changing the choice of the exponents $a_k$ and $b_k$.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
MultivariateUOVFrobeniusForgeryAttack
Contact author(s)
augustin bariant @ ssi gouv fr
History
2026-09-12: approved
2026-09-08: received
See all versions
Short URL
https://ia.cr/2026/1927
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2026/1927,
      author = {Augustin Bariant},
      title = {A Forgery Attack against Frobenius-{UOV}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1927},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1927}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.