Paper 2026/2181
Attacking UOV-based Signatures with Schur--Macaulay Matrices
Abstract
Unbalanced Oil and Vinegar (UOV) and its variants are among the candidates in the NIST call for additional post-quantum signatures. Their security rests on the hardness of recovering a hidden subspace on which a public system of quadratic forms vanishes. In characteristic $2$ the polar forms of such a system are alternating, which a recent attack exploits by working in the exterior algebra rather than the polynomial ring. Unlike its polynomial-ring counterparts, it either applies at a threshold fixed by the parameters or not at all, and for most proposed parameter sets it does not. We remove this threshold and improve complexity in two independent ways. First, over the integers the square of an alternating polar form is $\omega \wedge \omega = 2\,\omega^{(2)}$, so in characteristic $2$ it vanishes only because the factor $2$ does. Dividing that factor out before reducing leaves the divided square $\omega^{(2)}$, which still vanishes on the oil space but is in general not a consequence of the original equations. Iterating gives a whole tower $\omega^{(2^j)}$ of new equations. Second, the symmetric powers $\textrm{Sym}^d\mathbb{F}_q^n$ and the exterior powers $\bigwedge^a\mathbb{F}_q^n$ are the two extreme shapes of the Schur modules $L_\lambda\mathbb{F}_q^n$. We introduce an extension of Macaulay matrices to an arbitrary shape $\lambda$ which we call Schur--Macaulay matrices. For both constructions we conjecture a Hilbert series and verify it experimentally. We also extend the approach to odd characteristic. The attack then applies to every Round-2 parameter set of UOV, MAYO, SNOVA, and QR-UOV but one. Four of the alternate Round-2 parameter sets of MAYO fall below their claimed security level while being out of reach of all previous attacks. After disclosing preliminary results to the MAYO team, a parameter set designated for Round-3 was discarded and parameters increased. For SNOVA, the divided powers remove the spurious kernel elements that obstructed the exterior algebra attack, and seven of the eleven Round-2 parameter sets fall below their claimed security level, and the complexity estimates drop further compared to previous attacks.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- UOVMacaulay matricesXLAlgebraic cryptanalysis
- Contact author(s)
-
research @ simon-philipp com
lars ran @ ru nl - History
- 2026-09-26: approved
- 2026-09-23: received
- See all versions
- Short URL
- https://ia.cr/2026/2181
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2181,
author = {Simon-Philipp Merz and Lars Ran},
title = {Attacking {UOV}-based Signatures with Schur--Macaulay Matrices},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2181},
year = {2026},
url = {https://eprint.iacr.org/2026/2181}
}