Paper 2026/237

Exploiting SNOVA’s Structure in the Wedge Product Attack

Maxime Bros, National Institute of Standards and Technology (NIST), Maryland, USA, Izum Inc., Potomac, Maryland, USA
Thai Hung Le, École normale supérieure, PSL University, CNRS, Inria, France, LTCI, Telecom Paris, Institut Polytechnique de Paris, France
Jacob Lichtinger, National Institute of Standards and Technology (NIST), Maryland, USA
Brice Minaud, École normale supérieure, PSL University, CNRS, Inria, France
Ray Perlner, National Institute of Standards and Technology (NIST), Maryland, USA
Daniel Smith-Tone, National Institute of Standards and Technology (NIST), Maryland, USA, University of Louisville, Louisville KY, USA
Cristian Valenzuela, University of Louisville, Louisville KY, USA
Abstract

Post-quantum cryptography (PQC) aims to develop cryptographic schemes secure against quantum adversaries. One promising class of digital signature schemes is based on multivariate quadratic equations, where Unbalanced Oil and Vinegar (UOV) is a leading example. UOV has been extensively studied since its introduction by Kipnis, Patarin, and Goubin at Eurocrypt 1999, and it has remained secure. The signature sizes the scheme allows are quite small; however the key sizes are very large, making the scheme less attractive for some common protocols. To remediate this deficiency, some schemes---such as MAYO, QRUOV, and SNOVA---add a structure to reduce the size of the public key. These multivariate schemes are candidates that made it to the third round of the National Institute of Standards and Technology's Call for Additional Digital Signature Schemes for the Post-Quantum Cryptography Standardization Process. In this work, we revisit a recently proposed algebraic attack by Ran at Eurocrypt 2026 on UOV and extend this approach to a new attack on SNOVA by exploiting its block-ring structure. In addition to improving the attack complexity, the exploitation of the block-ring structure rules out spurious solutions, which prevents the generic version of Ran's attack from applying to SNOVA. This attack breaks 6 of the 11 second-round SNOVA parameter sets and improves on the previous best result for an additional 2 sets; it is significantly more effective against larger $\ell$ in comparison to several earlier attacks. For example, for SNOVA-V with parameters $(v,o,\ell) = (29,6,5)$, the estimated security drops to $181$ bits, compared to $310$ bits for the previous best known attack.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
A minor revision of an IACR publication in ASIACRYPT 2026
Keywords
Post-Quantum CryptographyUOVSNOVAAlgebraic Attack
Contact author(s)
maxime bros @ nist gov
hung le @ ens fr
jacob lichtinger @ nist gov
brice minaud @ ens fr
ray perlner @ nist gov
daniel smith @ nist gov
cristian valenzuela @ louisville edu
History
2026-09-16: revised
2026-02-12: received
See all versions
Short URL
https://ia.cr/2026/237
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/237,
      author = {Maxime Bros and Thai Hung Le and Jacob Lichtinger and Brice Minaud and Ray Perlner and Daniel Smith-Tone and Cristian Valenzuela},
      title = {Exploiting {SNOVA}’s Structure in the Wedge Product Attack},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/237},
      year = {2026},
      url = {https://eprint.iacr.org/2026/237}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.