Paper 2026/2154
Recovering SNOVA Secret Keys from Biased Vinegar Sampling
Abstract
The Round-3 SNOVA signer samples vinegar variables, which are elements of $\mathbb{F}_q$, by reducing uniform byte strings modulo a power of $q$. We show that the resulting bias leaks secret-key information for the six odd-characteristic alternative parameter sets. Even though the leakage is small (the most leaky variables leak at most $0.086$ bits of information), this still leads to efficient key-recovery attacks which we demonstrate in practice. Key recovery becomes a $q$-ary LPN problem of dimension $o\ell$ with a known, full-support error distribution. A naive algorithm needs some ten thousand signatures and $2^{90}$ to $2^{130}$ operations, which is already far below the $170$ to $331$ bits claimed for the six affected sets. Using more signatures makes the attack practical: using standard LPN machinery - BKW reduction with Fourier hypothesis testing - we recover the secret key for four parameter sets in practice using between $9$ and $180$ million signatures, and at most 16 minutes of wall clock time. Fixing SNOVA to sample the vinegar variables uniformly would prevent the attack completely.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- Multivariate CryptoUOVSNOVALPNBKW
- Contact author(s)
-
wbe @ zurich ibm com
bhe @ zurich ibm com - History
- 2026-09-22: approved
- 2026-09-22: received
- See all versions
- Short URL
- https://ia.cr/2026/2154
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2154,
author = {Ward Beullens and Basil Hess},
title = {Recovering {SNOVA} Secret Keys from Biased Vinegar Sampling},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2154},
year = {2026},
url = {https://eprint.iacr.org/2026/2154}
}