A short comment on the affine parts of SFLASH v3 .
Willi Geiselmann, Rainer Steinwandt · IACR Cryptology ePrint Archive · 2003
In [3] SFLASH is presented, which supersedes SFLASH, one of the digital signature schemes in the NESSIE Portfolio of recommended cryptographic primitives [2]. We show that a known attack against the affine parts of SFLASH and SFLASH carries over immediately to the new version SFLASH: The 861 bit representing the affine parts of the secret key can easily be derived from the public key alone.