IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences
Online ISSN : 1745-1337
Print ISSN : 0916-8508
Lifting approach against the SNOVA scheme
Shuhei NAKAMURAYusuke TANIHiroki FURUE
著者情報
ジャーナル フリー 早期公開

論文ID: 2024EAP1124

詳細
抄録

In 2022, Wang et al. proposed the multivariate signature scheme SNOVA as a UOV variant over the non-commutative ring of l × l matrices over 𝔽q. This scheme has small public key and signature size and is a second round candidate of NIST PQC additional digital signature project. Recently, Ikematsu and Akiyama, and Li and Ding show that the core matrices of SNOVA with v vinegar-variables and o oil-variables are regarded as the representation matrices of UOV with lv vinegar-variables and lo oil-variables over 𝔽q, and thus we can apply existing key recovery attacks as a plain UOV. In this article, we propose a method that reduces SNOVA to smaller UOV with v vinegar-variables and o oil-variables over 𝔽ql. As a result, we show that the previous first round parameter sets at l = 2 do not meet the NIST PQC security levels. We also confirm that the present parameter sets are secure from existing key recovery attacks with our approach.

著者関連情報
© 2025 The Institute of Electronics, Information and Communication Engineers
前の記事 次の記事
feedback
Top