Cryptanalysis of an Improved Multivariate Digital Signature Scheme
Wan‐Su Bao · Jisuanji gongcheng · 2012
In an improved multivariate signature scheme named W-scheme,affine transformation N is used to replaed affine transformation T,and the public key P2=N·Q·S to participate in verifying via replacing T with an affine transformation,but N can be turned to a new affine transformation with T,so the scheme can not hide the signature structure P1=T·Q·S.Aiming at the security loop,by depicting the relationship of the public key P2 and P1=T·Q·S,the structure of P1 can be determined by h·T-1(v)=h·N-1(w),so that attack is realized,which proves that adding the secret affine transformation can not lift the level of security of multivariate public key scheme.