Paper 2026/237

Exploiting SNOVA’s Structure in the Wedge Product Attack

Maxime Bros, National Institute of Standards and Technology (NIST), Maryland, USA, Izum Inc., Potomac, Maryland, USA
Thai Hung Le, LTCI, Telecom Paris, Institut Polytechnique de Paris, France, École normale supérieure, PSL University, CNRS, Inria, France
Jacob Lichtinger, National Institute of Standards and Technology (NIST), Maryland, USA
Brice Minaud, École normale supérieure, PSL University, CNRS, Inria, France
Ray Perlner, National Institute of Standards and Technology (NIST), Maryland, USA
Daniel Smith-Tone, National Institute of Standards and Technology (NIST), Maryland, USA, University of Louisville, Louisville KY, USA
Cristian Valenzuela, University of Louisville, Louisville KY, USA
Abstract

Post-quantum cryptography (PQC) aims to develop cryptographic schemes secure against quantum adversaries. One promising class of digital signature schemes is based on multivariate quadratic equations, where Unbalanced Oil and Vinegar (UOV) is a leading example. UOV has been extensively studied since its introduction in 1999, and it has remained secure. It offers very small signatures but suffers from very large public keys; to remediate this, some schemes---such as MAYO, QR-UOV, and SNOVA---add a structure to reduce the size of the public key. These four multivariate schemes are candidates that made it to the Second Round of the National Institute of Standards and Technology PQC Additional Call for Post-Quantum Signature schemes. In this work, we revisit a recently proposed algebraic attack by Ran on UOV and extend this approach to a new attack on SNOVA by exploiting its block-ring structure. In addition to improving the attack complexity, our exploitation of the block-ring structure rules out spurious solutions, which prevents generic version of Ran's attack from applying to SNOVA. Our attack breaks 6 of the 11 currently proposed SNOVA parameter sets and improves on the previous best result for an additional 2 sets; it is significantly more effective against larger $\ell$ in comparison to several earlier attacks. For example, for SNOVA-V with parameters $(v,o,\ell) = (29,6,5)$, the estimated security drops to $181$ bits, compared to $310$ bits for the previous best known attack.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Post-Quantum CryptographyUOVSNOVAAlgebraic Attack
Contact author(s)
maxime bros @ nist gov
hung le @ ens fr
jacob lichtinger @ nist gov
brice minaud @ ens fr
ray perlner @ nist gov
daniel smith @ nist gov
cristian valenzuena @ louisville edu
History
2026-02-13: approved
2026-02-12: received
See all versions
Short URL
https://ia.cr/2026/237
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/237,
      author = {Maxime Bros and Thai Hung Le and Jacob Lichtinger and Brice Minaud and Ray Perlner and Daniel Smith-Tone and Cristian Valenzuela},
      title = {Exploiting {SNOVA}’s Structure in the Wedge Product Attack},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/237},
      year = {2026},
      url = {https://eprint.iacr.org/2026/237}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.