arXiv · 2507.15449
Cryptanalysis of a multivariate CCZ scheme
Abstract
We consider the multivariate scheme Pesto, which was introduced by Calderini, Caminata, and Villa. In this scheme, the public polynomials are obtained by applying a CCZ transformation to a set of quadratic secret polynomials. As a consequence, the public key consists of polynomials of degree 4. In this work, we show that the public degree 4 polynomial system can be efficiently reduced to a system of quadratic polynomials. This seems to suggest that the CCZ transformation may not offer a significant increase in security, contrary to what was initially believed.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Alessio Caminata, Elisa Gorla, Madison Mabe, Martina Vigorito, Irene Villa. 2025-07-21. Cryptanalysis of a multivariate CCZ scheme. https://arxiv.org/abs/2507.15449
Cite the original work for its findings. Save a collection to share your selection of sources.