Papers1 provider · 1 record
April 9, 2024· IACR Communications in Cryptology
article
Open access

Preliminary Cryptanalysis of the Biscuit Signature Scheme

Authors:Charles BouillaguetJulia Sauvage

Abstract

Biscuit is a recent multivariate signature scheme based on the MPC-in-the-Head paradigm. It has been submitted to the NIST competition for additional signature schemes. Signatures are derived from a zero-knowledge proof of knowledge of the solution of a structured polynomial system. This extra structure enables efficient proofs and compact signatures. This short note demonstrates that it also makes these polynomial systems easier to solve than random ones. As a consequence, the original parameters of Biscuit failed to meet the required security levels and had to be upgraded.

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.