English

On the last fall degree of zero-dimensional Weil descent systems

Commutative Algebra 2015-06-19 v2 Symbolic Computation

Abstract

In this article we will discuss a new, mostly theoretical, method for solving (zero-dimensional) polynomial systems, which lies in between Gr\"obner basis computations and the heuristic first fall degree assumption and is not based on any heuristic. This method relies on the new concept of last fall degree. Let kk be a finite field of cardinality qnq^n and let kk' be its subfield of cardinality qq. Let Fk[X0,,Xm1]\mathcal{F} \subset k[X_0,\ldots,X_{m-1}] be a finite subset generating a zero-dimensional ideal. We give an upper bound of the last fall degree of the Weil descent system of F\mathcal{F}, which depends on qq, mm, the last fall degree of F\mathcal{F}, the degree of F\mathcal{F} and the number of solutions of F\mathcal{F}, but not on nn. This shows that such Weil descent systems can be solved efficiently if nn grows. In particular, we apply these results for multi-HFE and essentially show that multi-HFE is insecure. Finally, we discuss that the degree of regularity (or last fall degree) of Weil descent systems coming from summation polynomials to solve the elliptic curve discrete logarithm problem might depend on nn, since such systems without field equations are not zero-dimensional.

Keywords

Cite

@article{arxiv.1505.02532,
  title  = {On the last fall degree of zero-dimensional Weil descent systems},
  author = {Ming-Deh A. Huang and Michiel Kosters and Yun Yang and Sze Ling Yeo},
  journal= {arXiv preprint arXiv:1505.02532},
  year   = {2015}
}

Comments

16 pages, changed definition of tau and revised Section 5