<p>Multivariate cryptography is one of the candidates for post-quantum cryptography. Multivariate schemes are usually constructed by applying two secret affine invertible transformations <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="145_2025_9544_Article_IEq1.gif" Format="GIF" Height="17" Rendition="HTML" Resolution="72" Type="Linedraw" Width="33" /> </InlineMediaObject> <EquationSource Format="TEX">\({\mathcal {S}},{\mathcal {T}}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="script">S</mi> <mo>,</mo> <mi mathvariant="script">T</mi> </mrow> </math></EquationSource> </InlineEquation> to a set of multivariate polynomials <InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="145_2025_9544_Article_IEq2.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="17" /> </InlineMediaObject> <EquationSource Format="TEX">\(\mathcal {F}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="script">F</mi> </math></EquationSource> </InlineEquation> (often quadratic). The polynomials <InlineEquation ID="IEq3"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="145_2025_9544_Article_IEq2.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="17" /> </InlineMediaObject> <EquationSource Format="TEX">\(\mathcal {F}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="script">F</mi> </math></EquationSource> </InlineEquation> possess a trapdoor that allows the legitimate user to find a solution of the corresponding system, while the public polynomials <InlineEquation ID="IEq4"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="145_2025_9544_Article_IEq4.gif" Format="GIF" Height="15" Rendition="HTML" Resolution="72" Type="Linedraw" Width="107" /> </InlineMediaObject> <EquationSource Format="TEX">\({\mathcal {G}}={\mathcal {S}}\circ {\mathcal {F}}\circ {\mathcal {T}}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="script">G</mi> <mo>=</mo> <mi mathvariant="script">S</mi> <mo>∘</mo> <mi mathvariant="script">F</mi> <mo>∘</mo> <mi mathvariant="script">T</mi> </mrow> </math></EquationSource> </InlineEquation> look like random polynomials. The polynomials <InlineEquation ID="IEq5"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="145_2025_9544_Article_IEq5.gif" Format="GIF" Height="15" Rendition="HTML" Resolution="72" Type="Linedraw" Width="16" /> </InlineMediaObject> <EquationSource Format="TEX">\({\mathcal {G}}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="script">G</mi> </math></EquationSource> </InlineEquation> and <InlineEquation ID="IEq6"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="145_2025_9544_Article_IEq6.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="17" /> </InlineMediaObject> <EquationSource Format="TEX">\({\mathcal {F}}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="script">F</mi> </math></EquationSource> </InlineEquation> are said to be affine equivalent. In this article, we present a more general way of constructing a multivariate scheme by considering the CCZ equivalence, which has been introduced and studied in the context of vectorial Boolean functions.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A New Multivariate Primitive from CCZ Equivalence

  • Marco Calderini,
  • Alessio Caminata,
  • Irene Villa

摘要

Multivariate cryptography is one of the candidates for post-quantum cryptography. Multivariate schemes are usually constructed by applying two secret affine invertible transformations \({\mathcal {S}},{\mathcal {T}}\) S , T to a set of multivariate polynomials \(\mathcal {F}\) F (often quadratic). The polynomials \(\mathcal {F}\) F possess a trapdoor that allows the legitimate user to find a solution of the corresponding system, while the public polynomials \({\mathcal {G}}={\mathcal {S}}\circ {\mathcal {F}}\circ {\mathcal {T}}\) G = S F T look like random polynomials. The polynomials \({\mathcal {G}}\) G and \({\mathcal {F}}\) F are said to be affine equivalent. In this article, we present a more general way of constructing a multivariate scheme by considering the CCZ equivalence, which has been introduced and studied in the context of vectorial Boolean functions.