45

Cryptanalysis of a multivariate CCZ scheme

IACR Cryptology ePrint Archive (IACR ePrint), 2025
Main:17 Pages
Appendix:2 Pages
Abstract

We consider the multivariate scheme Pesto, which was introduced by Calderini, Caminata, and Villa. In this scheme, the public polynomials are obtained by applying a CCZ transformation to a set of quadratic secret polynomials. As a consequence, the public key consists of polynomials of degree 4. In this work, we show that the public degree 4 polynomial system can be efficiently reduced to a system of quadratic polynomials. This seems to suggest that the CCZ transformation may not offer a significant increase in security, contrary to what was initially believed.

View on arXiv
Comments on this paper