Degree of regularity for HFE-
نویسندگان
چکیده
In this paper, we prove a closed formula for the degree of regularity of the family of HFE(HFE Minus) multivariate public key cryptosystems over a finite field of size q. The degree of regularity of the polynomial system derived from an HFEsystem is less than or equal to (q − 1)(blogq(D − 1)c+ a) 2 + 2 if q is even and r + a is odd, (q − 1)(blogq(D − 1)c+ a + 1) 2 + 2 otherwise. Here q is the base field size, D the degree of the HFE polynomial, r = blogq(D−1)c+1 and a is the number of removed equations (Minus number). This allows us to present an estimate of the complexity of breaking the HFE Challenge 2: • the complexity to break the HFE Challenge 2 directly using algebraic solvers is about 296.
منابع مشابه
The Degree of Regularity of HFE Systems
Vivien Dubois1 and Ni olas Gama2 1 DGA-MI, Fran e vivien.dubois m4x.org 2 EPFL, Switzerland ni olas.gama ens.fr Abstra t. HFE is a publi key s heme introdu ed by Patarin in 1996. An HFE publi key is a large system of polynomials in many variables over a small nite eld. This system results from some se ret omposition, based on whi h the owner an solve it to any arbitrary ve tor. While the se uri...
متن کاملDegree of Regularity for HFEv and HFEv-
In this paper, we rst prove an explicit formula which bounds the degree of regularity of the family of HFEv ( HFE with vinegar ) and HFEv( HFE with vinegar and minus ) multivariate public key cryptosystems over a nite eld of size q. The degree of regularity of the polynomial system derived from an HFEvsystem is less than or equal to (q − 1)(r + v + a− 1) 2 + 2 if q is even and r + a is odd,
متن کاملInverting HFE Systems Is Quasi-Polynomial for All Fields
In this paper, we present and prove the first closed formula bounding the degree of regularity of an HFE system over an arbitrary finite field. Though these bounds are not necessarily optimal, they can be used to deduce 1. if D, the degree of the corresponding HFE polynomial, and q, the size of the corresponding finite field, are fixed, inverting HFE system is polynomial for all fields; 2. if D...
متن کاملOn the last fall degree of zero-dimensional Weil descent systems
In this article we will discuss a new, mostly theoretical, method for solving (zero-dimensional) polynomial systems, which lies in between Gröbner basis computations and the heuristic first fall degree assumption and is not based on any heuristic. This method relies on the new concept of last fall degree. Let k be a finite field of cardinality qn and let k be its subfield of cardinality q. Let ...
متن کاملNew candidates for multivariate trapdoor functions
We present a new method for building pairs of HFE polynomials of high degree, such that the map constructed with such a pair is easy to invert. The inversion is accomplished using a low degree polynomial of Hamming weight three, which is derived from a special reduction via Hamming weight three polynomials produced by these two HFE polynomials. This allows us to build new candidates for multiva...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- IACR Cryptology ePrint Archive
دوره 2011 شماره
صفحات -
تاریخ انتشار 2011