Block-Anti-Circulant Unbalanced Oil and Vinegar

Authors: Alan Szepieniec, Bart Preneel


We introduce a new technique for compressing the public keys of the UOV signature scheme that makes use of block-anti-circulant matrices. These matrices admit a compact representation as for every block, the remaining elements can be inferred from the first row. This space saving translates to the public key, which as a result of this technique can be shrunk by a small integer factor. We propose parameters sets that take into account several important attacks.

ePrint: https://eprint.iacr.org/2019/046

