









Giuseppe Vitto, LayerZero Labs, University of Luxembourg
Poseidon is one of the most widely deployed arithmetization-oriented cryptographic permutations and plays a central role in modern zero-knowledge proof systems. Although several algebraic attacks on reduced-round variants have been proposed, the security of the recommended parameter sets remains intact. A central difficulty in such attacks is controlling the degree growth of the polynomial representations induced by the permutation. In this work, we develop degree annihilation, extending coefficient cancellation in round-skipping attacks to cubic Poseidon. Degree annihilation reduces the contribution of existing rounds by imposing algebraic constraints that force dominant degree terms to vanish. This yields polynomial systems of substantially lower effective degree. We first present a simple bivariate form of degree annihilation and show how it combines naturally with classical round-skipping techniques. For cubic S-boxes with six full rounds, making the first partial-round input affine reduces the final degree bound by a factor of three. We then generalize the technique to multivariate settings, where systems of control equations are used to annihilate successive partial-round degree contributions. We find control solutions using elimination, resultants, and Gröbner basis techniques. As a proof of concept, we apply the framework to reduced-round Poseidon instances and obtain new CICO-2 attacks. More broadly, our results suggest that constructing algebraic varieties that actively control degree growth may provide a direction for the cryptanalysis of arithmetization-oriented primitives.
BibTeX
@misc{cryptoeprint:2026/1254,
author = {Antonio Sanso and Giuseppe Vitto},
title = {Top Gun: Degree Annihilation Attacks on Poseidon},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1254},
year = {2026},
url = {https://eprint.iacr.org/2026/1254}
}
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。