Cryptanalysis of the SNOVA Signature Scheme.

Peigen Li,Jintai Ding
DOI: https://doi.org/10.1007/978-3-031-62746-0_4
2024-01-01
Abstract:SNOVA is a variant of a UOV-type signature scheme over a noncommutative ring. In this article, we demonstrate that certain parameters provided by authors in SNOVA fail to meet the NIST security level, and the complexities are lower than those claimed by SNOVA.
What problem does this paper attempt to address?