Revisiting the security analysis of SNOVA

Yasuhiko Ikematsu, Rika Akiyama · 2024

SNOVA is a multivariate signature scheme submitted to the additional NIST PQC standardization project started in 2022. SNOVA is constructed by incorporating the structure of the matrix ring over a finite field into the UOV signature scheme, and the core part of its public key is the UOV public key whose coefficients consist of matrices. As a result, SNOVA dramatically reduces the public key size compared to UOV. In this paper, we recall the construction of SNOVA, and reconsider its security analysis. In particular, we investigate key recovery attacks applied to the core part of the public key of SNOVA in detail. Due to our analysis, we show that some parameters of SNOVA submitted in the additional NIST PQC standardization do not satisfy the claimed security levels.

Read the paper · More papers on PaperTik