Paper 2026/290

Improved Cryptanalysis of HFERP

Max Cartor, Bellarmine University
Ryann Cartor, Clemson University
Hiroki Furue, University of Tokyo
Daniel Smith-Tone, University of Louisville, National Institute of Standards and Technology
Abstract

In this paper we introduce a new attack on the multivariate encryption scheme HFERP, a big field scheme including an extra variable set, additional equations of the UOV or Rainbow shape as well as addi- tional random polynomials. Our attack brings several parameter sets well below their claimed security levels. The attack combines novel methods applicable to multivariate schemes with multiple equation types with in- sights from the Simple Attack that broke Rainbow in early 2022, though interestingly the technique is applied in an orthogonal way. In addition to this attack, we apply support minors techniques on a MinRank instance drawing coefficients from the big field, which was effective against other multivariate big field schemes. This work demonstrates that there exist previously unknown impacts of the above works well beyond the scope in which they were derived.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published by the IACR in PKC 2024
DOI
10.1007/978-3-031-57718-5_14
Keywords
Multivariate CryptographyHFERPCryptanalysisMinRankSimple Attack
Contact author(s)
mcartor01 @ bellarmine edu
rcartor @ clemson edu
hiroki furue @ ntt com
daniel smith @ nist gov
History
2026-02-18: approved
2026-02-17: received
See all versions
Short URL
https://ia.cr/2026/290
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2026/290,
      author = {Max Cartor and Ryann Cartor and Hiroki Furue and Daniel Smith-Tone},
      title = {Improved Cryptanalysis of {HFERP}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/290},
      year = {2026},
      doi = {10.1007/978-3-031-57718-5_14},
      url = {https://eprint.iacr.org/2026/290}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.