Cryptanalysis of a multivariate CCZ scheme
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866913950775377920 |
|---|---|
| author | Caminata, Alessio Gorla, Elisa Mabe, Madison Vigorito, Martina Villa, Irene |
| author_facet | Caminata, Alessio Gorla, Elisa Mabe, Madison Vigorito, Martina Villa, Irene |
| contents | We consider the multivariate scheme Pesto, which was introduced by Calderini, Caminata, and Villa. In this scheme, the public polynomials are obtained by applying a CCZ transformation to a set of quadratic secret polynomials. As a consequence, the public key consists of polynomials of degree 4. In this work, we show that the public degree 4 polynomial system can be efficiently reduced to a system of quadratic polynomials. This seems to suggest that the CCZ transformation may not offer a significant increase in security, contrary to what was initially believed. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2507_15449 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Cryptanalysis of a multivariate CCZ scheme Caminata, Alessio Gorla, Elisa Mabe, Madison Vigorito, Martina Villa, Irene Cryptography and Security Symbolic Computation We consider the multivariate scheme Pesto, which was introduced by Calderini, Caminata, and Villa. In this scheme, the public polynomials are obtained by applying a CCZ transformation to a set of quadratic secret polynomials. As a consequence, the public key consists of polynomials of degree 4. In this work, we show that the public degree 4 polynomial system can be efficiently reduced to a system of quadratic polynomials. This seems to suggest that the CCZ transformation may not offer a significant increase in security, contrary to what was initially believed. |
| title | Cryptanalysis of a multivariate CCZ scheme |
| topic | Cryptography and Security Symbolic Computation |
| url | https://arxiv.org/abs/2507.15449 |