Paper 2026/903

Magic Pot: Cryptanalysis of full AIM2 in the standard and related-/reused-key settings using new elimination framework

Alex Biryukov, University of Luxembourg
Pablo García Fernández, University of Luxembourg
Aleksei Udovenko, University of Luxembourg
Abstract

In this work, we cryptanalyse the post-quantum signature scheme AIMer v2.1, which is one of the winners of the Korean Post-Quantum Cryptography competition (KpqC), and whose earlier version was a candidate in the US NIST's additional post-quantum digital signatures call. We show that AIM2, the underlying symmetric-key primitive, is not secure up to the claimed level by developing and applying a new algebraic attack framework based on extended linearization over a univariate polynomial ring and a novel algorithm for finding a null vector of a polynomial matrix. In particular misuse scenarios, such as reused-key or related-key settings, our attacks become practically feasible, allowing experimental verification and benchmarking. We also evaluate the approach on the RAIN block cipher used in the Rainier post-quantum signature scheme and obtain improved attacks, although not threatening its claimed security.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
A major revision of an IACR publication in EUROCRYPT 2026
DOI
10.1007/978-3-032-25333-0_3
Keywords
Post-quantumAIMerAIM2RAINRelated-keyReused-keyAlgebraic attacksLinearizationXLEliminationPolynomial matrices
Contact author(s)
alex biryukov @ uni lu
pablo garciafernandez @ uni lu
aleksei @ affine group
History
2026-05-10: approved
2026-05-08: received
See all versions
Short URL
https://ia.cr/2026/903
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/903,
      author = {Alex Biryukov and Pablo García Fernández and Aleksei Udovenko},
      title = {Magic Pot: Cryptanalysis of full {AIM2} in the standard and related-/reused-key settings using new elimination framework},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/903},
      year = {2026},
      doi = {10.1007/978-3-032-25333-0_3},
      url = {https://eprint.iacr.org/2026/903}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.