Multivariate cryptography is one of the candidates for post-quantum cryptography. Multivariate schemes are usually constructed by applying two secret affine invertible transformations S,T to a set of multivariate polynomials F (often quadratic). The polynomials F possess a trapdoor that allows the legitimate user to find a solution of the corresponding system, while the public polynomials G=S∘F∘T look like random polynomials. The polynomials G and F are said to be affine equivalent. In this article, we present a more general way of constructing a multivariate scheme by considering the CCZ equivalence, which has been introduced and studied in the context of vectorial Boolean functions.

A New Multivariate Primitive from CCZ Equivalence

Caminata A.;Villa I.
2025-01-01

Abstract

Multivariate cryptography is one of the candidates for post-quantum cryptography. Multivariate schemes are usually constructed by applying two secret affine invertible transformations S,T to a set of multivariate polynomials F (often quadratic). The polynomials F possess a trapdoor that allows the legitimate user to find a solution of the corresponding system, while the public polynomials G=S∘F∘T look like random polynomials. The polynomials G and F are said to be affine equivalent. In this article, we present a more general way of constructing a multivariate scheme by considering the CCZ equivalence, which has been introduced and studied in the context of vectorial Boolean functions.
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11567/1302217
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 2
  • ???jsp.display-item.citation.isi??? 2
social impact