; TeX output 2001.08.05:1955eM $2+:ecrm0500HFE\LandMinRankPublicKeyCryptographӑyNML$cu ecbx0900Slide13zoIv?ꍄ?I5xߧ@src:133hfemr.texUsGGecrm1728HFEhandMinRank. 5RKfsrc:135hfemr.tex"ecrm0800(in(publickÒeycryptography)܍ZWsrc:138hfemr.texSuppKort,biblioetc: ܍UGsrc:139hfemr.tex. ecrm0900h;:1u cmex108 1< 1:~+bi?;cmmi6k=n P \ti=0Ein MgP jY=ii?ijYk a8:i,ra8:j?+with&qk=\t1::m; $aq0=1#dsrc:324hfemr.texCase(n\t=m=1.}< lcircle10˟  Afe?}1#L1#L  Afe? Ɵfe$l Ɵ}fe$l 0K*=\tZZ ^<X.N4^ټis(hard,factoringNJ[Rabin].:ˮ˟ &jfefe?:: &jfefe? Ɵfefe)W䎍 Ɵfe)W䎎 0K*=\tGF.:(qI{)=J< >:0\t=x_y- _z s1\t=:t윍㏼...S h8 S h>S h< S h>S h:a0\t=xyI{z:+xy- +yz:+xz+x+y- +z sa1\t=1+t윍a.a.a. src:384hfemr.texTJrasform(cubic;quadratic.Weput:src:388hfemr.tex(newv$ariablesy8:ij=\tx8:i,rx8:j 5(newtrivialequations0\t=y8:ijzx8:i,rx8:jۼ.L?w USlideD83zoIv?ꍄ?I5d,ٶjv0ff7 򴍄 ff@Solving$MQ6Jل ffffff7 &J33 &Jnv337=]f ecbx1000Case b> cmmi10m> K 0ercmmi7nrZcmr52K&fe؞nٓRcmr72:xsrc:405hfemr.texMQ(issolvÒedbylinearization(folklore):2usrc:409hfemr.texNew(v$ariablesy8:ij=\tx8:i,rx8:jۼ.,"usrc:410hfemr.texAÒt(leastmlinearequationswithmv$ariables.̍CasemK`y cmr10=" 33nr233&fe؞n2 ?:xsrc:413hfemr.texMQ(isexp100.ōٶ^ 0ffMy 򴍄 ff@T:rapAdoors$inMQL ffffffMyXR &J33 &Jb 33Mysrc:455hfemr.texGeneral(principleso33r dsrc:513hfemr.texIf(b\t=f(a)=a-:q7{qO \cmmi5s ҫthenalltheb8:i=f8:i,r(aq1*;j::: ;jan7)areK-linear. =src:517hfemr.texIf(f(a)\t=PU[a-:q7{qs+q7{qtdPthenallthef8:iarequadratic.YV@ff]-ffExample$oB$< B$>B$:=Pbq2bv6=saq27+aq2*aq1+aq2*aq0+aq1 sPbq1bv6=saq2*aq17+aq1aq0+aq2Pbq0bv6=saq07+aq2+aq1*aq0+aq2*aq0L?w USlideD123zoIv?ꍄ?I5iYAM@lffCppff$Hidden$FieldEquation(HFE).w,pffffffCɕ B<33 BEM33C src:578hfemr.tex U=Zf(a)\t= X vލq7Gs+q7Gtd!x8 =st Ֆa:q7{qs+q7{qt7usrc:582hfemr.texRe-write(asnmÒultiv$ariatequadraticequations:_src:584hfemr.texf>;:\tfbvύ1src:586hfemr.texHRb8:i=\tf8:i,r(aq1*;j::: ;jan7)Z)fb _i=1::nVusrc:592hfemr.texHide(theuniv$ariaterepresenÒtationoffǼ:5src:594hfemr.texApply(tÒwoaneinvertiblev$ariablechangesSGandT.:.ong=\tTfWSj܍eedg:\tx㍍XS7! 8a㍍꫍"fU7!b㍍T7!yL?$Nicolas\LT.Courtois C60XeM $HFE\LandMinRankPublicKeyCryptographӑyN~qaSlide133zoIv?ꍄ?I5d,ٶkџ0ff4 򴍄 ff@Using$HFE3B# ffffff4z &J33 &Joщ334 Esrc:643hfemr.tex} 7 wfe?}..ߟ 7 wfe??fe*ߎ?}fe*ߎfepublic(kÒey:4Ԕn(quadraticp 򴍄 ff@Ac &J33 &Jg33D> src:852hfemr.texTJwÒo(waystosolvethisMinRank:expressitasusrc:854hfemr.tex[Shamir-Kipnis](MQwithn(nr96isstillsecure.src:1076hfemr.tex$MoAdied,com3fb}Hq1*(m)+fǟ-:1 >3fbhHq2(m)+fǟ-:1 Ӈ(Hq1(m))fbfb+src:1192hfemr.texThis(metho cmmi10 0ercmmi7O \cmmi5K`y cmr10ٓRcmr7Zcmr5< lcircle10u cmex10