{"ID":2892171,"CreatedAt":"2026-06-01T04:54:23.091178241Z","UpdatedAt":"2026-06-01T04:54:23.091178241Z","DeletedAt":null,"paper_url":"https://arxiv.org/abs/2507.15449","arxiv_id":"2507.15449","title":"Cryptanalysis of a multivariate CCZ scheme","abstract":"We consider the multivariate scheme Pesto, which was introduced by Calderini, Caminata, and Villa. In this scheme, the public polynomials are obtained by applying a CCZ transformation to a set of quadratic secret polynomials. As a consequence, the public key consists of polynomials of degree 4. In this work, we show that the public degree 4 polynomial system can be efficiently reduced to a system of quadratic polynomials. This seems to suggest that the CCZ transformation may not offer a significant increase in security, contrary to what was initially believed.","short_abstract":"We consider the multivariate scheme Pesto, which was introduced by Calderini, Caminata, and Villa. In this scheme, the public polynomials are obtained by applying a CCZ transformation to a set of quadratic secret polynomials. As a consequence, the public key consists of polynomials of degree 4. In this work, we show th...","url_abs":"https://arxiv.org/abs/2507.15449","url_pdf":"https://arxiv.org/pdf/2507.15449v1","authors":"[\"Alessio Caminata\",\"Elisa Gorla\",\"Madison Mabe\",\"Martina Vigorito\",\"Irene Villa\"]","published":"2025-07-21T10:01:42Z","proceeding":"cs.CR","tasks":"[\"cs.CR\",\"cs.SC\"]","methods":"[]","has_code":false}
