Paper 2026/2181

Attacking UOV-based Signatures with Schur--Macaulay Matrices

Simon-Philipp Merz, ETH Zurich
Lars Ran, Radboud University Nijmegen
Abstract

Unbalanced Oil and Vinegar (UOV) and its variants are among the candidates in the NIST call for additional post-quantum signatures. Their security rests on the hardness of recovering a hidden subspace on which a public system of quadratic forms vanishes. In characteristic $2$ the polar forms of such a system are alternating, which a recent attack exploits by working in the exterior algebra rather than the polynomial ring. Unlike its polynomial-ring counterparts, it either applies at a threshold fixed by the parameters or not at all, and for most proposed parameter sets it does not. We remove this threshold and improve complexity in two independent ways. First, over the integers the square of an alternating polar form is $\omega \wedge \omega = 2\,\omega^{(2)}$, so in characteristic $2$ it vanishes only because the factor $2$ does. Dividing that factor out before reducing leaves the divided square $\omega^{(2)}$, which still vanishes on the oil space but is in general not a consequence of the original equations. Iterating gives a whole tower $\omega^{(2^j)}$ of new equations. Second, the symmetric powers $\textrm{Sym}^d\mathbb{F}_q^n$ and the exterior powers $\bigwedge^a\mathbb{F}_q^n$ are the two extreme shapes of the Schur modules $L_\lambda\mathbb{F}_q^n$. We introduce an extension of Macaulay matrices to an arbitrary shape $\lambda$ which we call Schur--Macaulay matrices. For both constructions we conjecture a Hilbert series and verify it experimentally. We also extend the approach to odd characteristic. The attack then applies to every Round-2 parameter set of UOV, MAYO, SNOVA, and QR-UOV but one. Four of the alternate Round-2 parameter sets of MAYO fall below their claimed security level while being out of reach of all previous attacks. After disclosing preliminary results to the MAYO team, a parameter set designated for Round-3 was discarded and parameters increased. For SNOVA, the divided powers remove the spurious kernel elements that obstructed the exterior algebra attack, and seven of the eleven Round-2 parameter sets fall below their claimed security level, and the complexity estimates drop further compared to previous attacks.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
UOVMacaulay matricesXLAlgebraic cryptanalysis
Contact author(s)
research @ simon-philipp com
lars ran @ ru nl
History
2026-09-26: approved
2026-09-23: received
See all versions
Short URL
https://ia.cr/2026/2181
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2181,
      author = {Simon-Philipp Merz and Lars Ran},
      title = {Attacking {UOV}-based Signatures with Schur--Macaulay Matrices},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2181},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2181}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.