Paper 2026/2390
A Universal Forgery Attack on the Origami Signature Scheme from the Public Key Alone
Abstract
Origami is a multivariate signature scheme submitted to the NGCC round-1 public-key call. We show that the submitted bilinear construction is a Rainbow-type scheme whose central map is exposed. The verification map is the layered signing map in a public coordinate order. The public key therefore gives an equivalent secret key, allowing signature forgery at about the cost of one verification (about $0.01$s at Origami-128). Our attack exploits this public layered structure and succeeds against the unmodified reference implementation on all four parameter sets and the official test vectors. We also refute the security proof's inversion assumption in a bilinear independent-coefficient model. The hidden local algebras introduced by Origami do not prevent the attack. They raise a separate problem: the specification treats constrained matrix coordinates as independent, and honest signatures lie in a proper subspace.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- multivariatepost-quantum cryptographycryptanalysisUOV
- Contact author(s)
-
Hugo Louiso26 @ student xjtlu edu cn
guoh22 @ mails tsinghua edu cn
lpg22 @ bimsa cn
pierre pebereau @ esat kuleuven be
taosy22 @ mails tsinghua edu cn
jintai ding @ gmail com - History
- 2026-10-08: approved
- 2026-10-07: received
- See all versions
- Short URL
- https://ia.cr/2026/2390
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2390,
author = {Hugo Louiso and Hao Guo and Peigen Li and Pierre Pébereau and Siyong Tao and Jintai Ding},
title = {A Universal Forgery Attack on the Origami Signature Scheme from the Public Key Alone},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2390},
year = {2026},
url = {https://eprint.iacr.org/2026/2390}
}