Unbalanced Oil and Vinegar Signature Schemes -extended Version

نویسندگان

  • Aviad Kipnis
  • Jacques Patarin
  • Louis Goubin
چکیده

In 16], J. Patarin designed a new scheme, called \Oil and Vinegar", for computing asymmetric signatures. It is very simple, can be computed very fast (both in secret and public key) and requires very little RAM in smartcard implementations. The idea consists in hiding quadratic equations in n unknowns called \oil" and v = n unknowns called \vinegar" over a nite eld K, with linear secret functions. This original scheme was broken in 10] by A. Kipnis and A. Shamir. In this paper, we study some very simple variations of the original scheme where v > n (instead of v = n). These schemes are called \Unbalanced Oil and Vinegar" (UOV), since we have more \vinegar" unknowns than \oil" unknowns. We show that, when v ' n, the attack of 10] can be extended, but when v 2n for example, the security of the scheme is still an open problem. Moreover, when v ' n 2 2 , the security of the scheme is exactly equivalent (if we accept a very natural but not proved property) to the problem of solving a random set of n quadratic equations in n 2 2 unknowns (with no trapdoor). However, we show that (in characteristic 2) when v n 2 , nding a solution is generally easy. In this paper, we also present some practical values of the parameters, for which no attacks are known. We also study schemes with public keys of degree three instead of two. We show that no signiicant advantages exist at the present to recommend schemes of degree three instead of two. However, we show that it is very easy to combine the Oil and Vinegar idea and the HFE schemes of 14]. The resulting scheme, called HFEV, looks at the present also very interesting both from a practical and theoretical point of view. In UOV, the number of vinegar variables must be > n, but in HFEV this number can be very small or very large. Then length of a UOV signature can be as short as 192 bits and for HFEV it can be as short as 80 bits.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Rainbow, a New Multivariable Polynomial Signature Scheme

Balanced Oil and Vinegar signature schemes and the unbalanced Oil and Vinegar signature schemes are public key signature schemes based on multivariable polynomials. In this paper, we suggest a new signature scheme, which is a generalization of the Oil-Vinegar construction to improve the efficiency of the unbalanced Oil and Vinegar signature scheme. The basic idea can be described as a construct...

متن کامل

On the security of Cubic UOV and its variants

The unbalanced oil and vinegar signature scheme (UOV) is one of signature schemes whose public key is a set of multivariate quadratic forms. Recently, a new variant of UOV called Cubic UOV was proposed at Inscrypt 2015. It was claimed that the cubic UOV was more efficient than the original UOV and its security was enough. However, an equivalent secret key of the cubic UOV can be recovered easil...

متن کامل

Cryptanalysis of the Oil & Vinegar Signature Scheme

Several multivariate algebraic signature schemes had been proposed in recent years, but most of them had been broken by exploiting the fact that their secret trapdoors are low rank algebraic structures. One of the few remaining variants is Patarin’s ”Oil & Vinegar” scheme, which is based on a system of n quadratic forms in 2n variables of two flavors (n ”oil” variables and n ”vinegar” variables...

متن کامل

MQ Signature and Proxy Signature Schemes with Exact Security Based on UOV Signature

Multivariate public key cryptography which relies on MQ (Multivariate Quadratic) problems is one of the main approaches to guarantee the security of communication in the post-quantum world. In this paper, we propose a combined MQ signature scheme based on the yet unbroken UOV (Unbalanced Oil and Vinegar) signature if parameters are properly chosen. Our scheme can not only reduce the public key ...

متن کامل

A Study of the Security of Unbalanced Oil and Vinegar Signature Schemes

The Unbalanced Oil and Vinegar scheme (UOV) is a signature scheme based on multivariate quadratic equations. It uses m equations and n variables. A total of v of these are called “vinegar variables”. In this paper, we study its security from several points of view. First, we are able to demonstrate that the constant part of the affine transformation does not contribute to the security of UOV an...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 1999