引用本文:唐樨瑾,冯勇.Dixon结式在密码学中的应用.软件学报,2007,18(7):1738-1745
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 5192次   下载 6544 本文二维码信息
码上扫一扫!
分享到: 微信 更多
Dixon结式在密码学中的应用
唐樨瑾1, 冯勇1
中国科学院,成都计算机应用研究所,自动推理实验室,四川,成都,610041
摘要:
针对密码学中的多变元多项式二次方程系统求解问题,基于扩展Dixon结式提出了一种求解算法DR(Dixon resultants).基本思想为对于MQ(multivariate quadratic)问题,把x1,x2,…,xn-1当作变元,而把xn当作参数,然后利用和改进扩展Dixon结式方法求解该类系统.分析了该算法对于一般情况的复杂度,并且基于实验证据猜测:对于某些稀疏问题,新算法的复杂度很有可能也是多项式的.实验结果表明,对于m=n的一般和稀疏的问题,DR效率优于已有的两种算法.除了高效性,新算法还具有复杂度容易度量、计算时间可以预测的优点.
关键词:  多变元密码学  有限域上的多项式方程  代数攻击  Dixon结式  DR(Dixon resultants)
DOI:
分类号:
基金项目:Supported by the National Basic Research Program of China under Grant No.2004CB318003 (国家重点基础研究发展计划(973))
Applying Dixon Resultants in Cryptography
TANG Xi-Jin,FENG Yong
Abstract:
Based on extended Dixon resultants, a new algorithm DR (Dixon resultants) is proposed to solve the system of multivariate polynomial equations. The basic idea of DR is to apply the extended Dixon resultants method to the system of multivariate polynomial equations, by taking x1,x2,…,xn-1 as variables and xn as parameter. The time complexity of DR technique is evaluated. It seems to be polynomial when the system is sparse and m=n, and the mixed volume is polynomial. Moreover, DR technique is compared with Buchberger’s algorithm and XL technique in this paper. It is shown that DR is far more efficient than Buchberger’s algorithm and XL when m=n. DR is a quite efficient algorithm and makes a good use of the sparsity of the sparse system. Besides its efficiency, another advantage of DR is that its complexity is easy to determine.
Key words:  multivariate cryptography  polynomial equations over finite field  algebraic attack  Dixon resultants  DR (Dixon resultants)