Practical Cryptanalysis of SFLASH.
Vivien Dubois, Pierre-Alain Fouque, Adi Shamir, Jacques Stern · 2007
Abstract. In this paper, we present a practical attack on the signature scheme SFLASH proposed by Patarin, Goubin and Courtois in 2001 fol-lowing a design they had introduced in 1998. The attack only needs the public key and requires about one second to forge a signature for any message, after a one-time computation of several minutes. It can be ap-plied to both SFLASHv2 which was accepted by NESSIE, as well as to SFLASHv3 which is a higher security version. 1