{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,2]],"date-time":"2025-08-02T16:20:54Z","timestamp":1754151654427,"version":"3.41.2"},"publisher-location":"Cham","reference-count":34,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030816513"},{"type":"electronic","value":"9783030816520"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-81652-0_10","type":"book-chapter","created":{"date-parts":[[2021,7,20]],"date-time":"2021-07-20T06:26:19Z","timestamp":1626762379000},"page":"252-272","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Boolean Ring Cryptographic Equation\u00a0Solving"],"prefix":"10.1007","author":[{"given":"Sean","family":"Murphy","sequence":"first","affiliation":[]},{"given":"Maura","family":"Paterson","sequence":"additional","affiliation":[]},{"given":"Christine","family":"Swart","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2021,7,21]]},"reference":[{"key":"10_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"338","DOI":"10.1007\/978-3-540-30539-2_24","volume-title":"Advances in Cryptology - ASIACRYPT 2004","author":"G Ars","year":"2004","unstructured":"Ars, G., Faug\u00e8re, J.-C., Imai, H., Kawazoe, M., Sugita, M.: Comparison between XL and Gr\u00f6bner basis algorithms. In: Lee, P.J. (ed.) ASIACRYPT 2004. LNCS, vol. 3329, pp. 338\u2013353. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-30539-2_24"},{"key":"10_CR2","volume-title":"Introduction to Commutative Algebra","author":"M Atiyah","year":"1994","unstructured":"Atiyah, M., MacDonald, I.: Introduction to Commutative Algebra. Westview Press, Boulder (1994)"},{"key":"10_CR3","unstructured":"Bardet, M., Faug\u00e8re, J., Salvy, B.: Complexity of Gr\u00f6bner basis computation for semi-regular overdetermined sequences over GF(2) with solutions in GF(2). Technical report, INRIA research report 5049 (2003). http:\/\/www-polsys.lip6.fr\/~jcf\/Papers\/RR-5049.pdf"},{"key":"10_CR4","unstructured":"Bardet, M., Faug\u00e8re, J., Salvy, B.: On the complexity of Gr\u00f6bner basis computation of semi-regular overdetermined algebraic equations. In: International Conference on Polynomial System Solving - ICPSS, pp. 71\u201375 (2004). http:\/\/www-polsys.lip6.fr\/~jcf\/Papers\/43BF.pdf"},{"key":"10_CR5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10623-012-9617-2","volume":"69","author":"L Bettale","year":"2013","unstructured":"Bettale, L., Faug\u00e8re, J.C., Peret, L.: Cryptanalysis of HFE, multi-HFE and variants for odd and even characteristic. Des. Codes Crypt. 69, 1\u201352 (2013). https:\/\/doi.org\/10.1007\/s10623-012-9617-2","journal-title":"Des. Codes Crypt."},{"key":"10_CR6","doi-asserted-by":"publisher","first-page":"263","DOI":"10.1007\/978-3-540-93806-4_15","volume-title":"Gr\u00f6bener Bases, Coding, and Cryptography","author":"O Billet","year":"2009","unstructured":"Billet, O., Ding, J.: Overview of cryptanalysis techniques in multivariate public key cryptography. In: Sala, M., Sakata, S., Mora, T., Traverso, C., Perret, L. (eds.) Gr\u00f6bener Bases, Coding, and Cryptography, pp. 263\u2013283. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-540-93806-4_15"},{"key":"10_CR7","doi-asserted-by":"publisher","first-page":"506","DOI":"10.1145\/792538.792543","volume":"50","author":"A Blum","year":"2003","unstructured":"Blum, A., Kalai, A., Wasserman, H.: Noise-tolerant learning, the parity problem, and the statistical query model. J. ACM 50, 506\u2013519 (2003)","journal-title":"J. ACM"},{"key":"10_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"667","DOI":"10.1007\/978-3-642-25385-0_36","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2011","author":"C Bouillaguet","year":"2011","unstructured":"Bouillaguet, C., Fouque, P.-A., Macario-Rat, G.: Practical key-recovery for all possible parameters of SFLASH. In: Lee, D.H., Wang, X. (eds.) ASIACRYPT 2011. LNCS, vol. 7073, pp. 667\u2013685. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25385-0_36"},{"key":"10_CR9","doi-asserted-by":"publisher","first-page":"743","DOI":"10.1007\/s10623-017-0355-3","volume":"84","author":"R Bricout","year":"2018","unstructured":"Bricout, R., Murphy, S., Paterson, K., van der Merwe, T.: Analysing and exploiting the Mantin biases in RC4. Des. Codes Crypt. 84, 743\u2013770 (2018). https:\/\/doi.org\/10.1007\/s10623-017-0355-3","journal-title":"Des. Codes Crypt."},{"key":"10_CR10","doi-asserted-by":"crossref","unstructured":"Buchberger, B.: Ein Algorithmus zum Auffinden der Basiselemente des Restklassenringes nach einem nulldimensionalen Polynomideal (An algorithm for finding the basis elements in the residue class ring modulo a zero dimensional polynomial ideal). Ph.D. thesis, Mathematical Institute, University of Innsbruck, Austria (1965). English translation in J. Symb. Comput. Spec. Issue Log. Math. Comput. Sci. Interact. 41(3\u20134), 475\u2013511 (2006)","DOI":"10.1016\/j.jsc.2005.09.007"},{"key":"10_CR11","unstructured":"Buchmann, J., Ding, J., Mohamed, M., Mohamed, W.: MutantXL: solving multivariate polynomial equations for cryptanalysis. In: Handschuh, H., Lucks, S., Preneel, B., Rogaway, P. (eds.) Symmetric Cryptography. Dagstuhl Seminar Proceedings, vol. 09031 (2009)"},{"key":"10_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"182","DOI":"10.1007\/3-540-36552-4_13","volume-title":"Information Security and Cryptology\u2014ICISC 2002","author":"NT Courtois","year":"2003","unstructured":"Courtois, N.T.: Higher order correlation attacks, XL algorithm and cryptanalysis of Toyocrypt. In: Lee, P.J., Lim, C.H. (eds.) ICISC 2002. LNCS, vol. 2587, pp. 182\u2013199. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/3-540-36552-4_13"},{"key":"10_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1007\/3-540-44448-3_4","volume-title":"Advances in Cryptology\u2014ASIACRYPT 2000","author":"L Goubin","year":"2000","unstructured":"Goubin, L., Courtois, N.T.: Cryptanalysis of the TTM cryptosystem. In: Okamoto, T. (ed.) ASIACRYPT 2000. LNCS, vol. 1976, pp. 44\u201357. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/3-540-44448-3_4"},{"key":"10_CR14","unstructured":"Courtois, N., Goubin, L., Patarin, J.: SFLASHv3, a fast asymmetric signature scheme. IACR Cryptology ePrint Archive 2003\/211 (2003). http:\/\/eprint.iacr.org\/2003\/211"},{"key":"10_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"392","DOI":"10.1007\/3-540-45539-6_27","volume-title":"Advances in Cryptology\u2014EUROCRYPT 2000","author":"N Courtois","year":"2000","unstructured":"Courtois, N., Klimov, A., Patarin, J., Shamir, A.: Efficient algorithms for solving overdefined systems of multivariate polynomial equations. In: Preneel, B. (ed.) EUROCRYPT 2000. LNCS, vol. 1807, pp. 392\u2013407. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/3-540-45539-6_27"},{"key":"10_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1007\/3-540-36563-X_10","volume-title":"Topics in Cryptology\u2014CT-RSA 2003","author":"NT Courtois","year":"2003","unstructured":"Courtois, N.T., Patarin, J.: About the XL algorithm over GF(2). In: Joye, M. (ed.) CT-RSA 2003. LNCS, vol. 2612, pp. 141\u2013157. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/3-540-36563-X_10"},{"key":"10_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1007\/3-540-36178-2_17","volume-title":"Advances in Cryptology\u2014ASIACRYPT 2002","author":"NT Courtois","year":"2002","unstructured":"Courtois, N.T., Pieprzyk, J.: Cryptanalysis of block ciphers with overdefined systems of equations. In: Zheng, Y. (ed.) ASIACRYPT 2002. LNCS, vol. 2501, pp. 267\u2013287. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-36178-2_17"},{"key":"10_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"323","DOI":"10.1007\/978-3-540-30539-2_23","volume-title":"Advances in Cryptology - ASIACRYPT 2004","author":"C Diem","year":"2004","unstructured":"Diem, C.: The XL-algorithm and a conjecture from commutative algebra. In: Lee, P.J. (ed.) ASIACRYPT 2004. LNCS, vol. 3329, pp. 323\u2013337. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-30539-2_23"},{"key":"10_CR19","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1007\/978-3-540-88702-7_6","volume-title":"Post-Quantum Cryptography","author":"J Ding","year":"2009","unstructured":"Ding, J., Yang, B.Y.: Multivariate public key cryptography. In: Bernstein, D.J., Buchmann, J., Dahmen, E. (eds.) Post-Quantum Cryptography, pp. 193\u2013241. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-540-88702-7_6"},{"key":"10_CR20","doi-asserted-by":"crossref","unstructured":"Faug\u00e8re, J.C.: A new efficient algorithm for computing Gr\u00f6Bner bases without reduction to zero (F5). In: Proceedings of the 2002 International Symposium on Symbolic and Algebraic Computation, ISSAC 2002, pp. 75\u201383. ACM (2002)","DOI":"10.1145\/780506.780516"},{"key":"10_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"150","DOI":"10.1007\/978-3-662-46447-2_7","volume-title":"Public-Key Cryptography \u2013 PKC 2015","author":"J-C Faug\u00e8re","year":"2015","unstructured":"Faug\u00e8re, J.-C., Gligoroski, D., Perret, L., Samardjiska, S., Thomae, E.: A polynomial-time key-recovery attack on MQQ cryptosystems. In: Katz, J. (ed.) PKC 2015. LNCS, vol. 9020, pp. 150\u2013174. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-46447-2_7"},{"key":"10_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1007\/978-3-540-45146-4_3","volume-title":"Advances in Cryptology - CRYPTO 2003","author":"J-C Faug\u00e8re","year":"2003","unstructured":"Faug\u00e8re, J.-C., Joux, A.: Algebraic cryptanalysis of hidden field equation (HFE) cryptosystems using Gr\u00f6bner bases. In: Boneh, D. (ed.) CRYPTO 2003. LNCS, vol. 2729, pp. 44\u201360. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/978-3-540-45146-4_3"},{"key":"10_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1007\/978-3-540-85174-5_16","volume-title":"Advances in Cryptology \u2013 CRYPTO 2008","author":"J-C Faug\u00e8re","year":"2008","unstructured":"Faug\u00e8re, J.-C., Levy-dit-Vehel, F., Perret, L.: Cryptanalysis of MinRank. In: Wagner, D. (ed.) CRYPTO 2008. LNCS, vol. 5157, pp. 280\u2013296. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-85174-5_16"},{"key":"10_CR24","doi-asserted-by":"publisher","first-page":"178","DOI":"10.1016\/0020-0190(80)90134-9","volume":"10","author":"A Fraenkel","year":"1980","unstructured":"Fraenkel, A., Yesha, Y.: Complexity of solving algebraic equations. Inf. Process. Lett. 10, 178\u2013179 (1980)","journal-title":"Inf. Process. Lett."},{"key":"10_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1007\/BFb0055733","volume-title":"Advances in Cryptology\u2014CRYPTO 1998","author":"A Kipnis","year":"1998","unstructured":"Kipnis, A., Shamir, A.: Cryptanalysis of the oil and vinegar signature scheme. In: Krawczyk, H. (ed.) CRYPTO 1998. LNCS, vol. 1462, pp. 257\u2013266. Springer, Heidelberg (1998). https:\/\/doi.org\/10.1007\/BFb0055733"},{"key":"10_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/3-540-48405-1_2","volume-title":"Advances in Cryptology\u2014CRYPTO 1999","author":"A Kipnis","year":"1999","unstructured":"Kipnis, A., Shamir, A.: Cryptanalysis of the HFE public key cryptosystem by relinearization. In: Wiener, M. (ed.) CRYPTO 1999. LNCS, vol. 1666, pp. 19\u201330. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-48405-1_2"},{"key":"10_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"419","DOI":"10.1007\/3-540-45961-8_39","volume-title":"Advances in Cryptology\u2014EUROCRYPT 1988","author":"T Matsumoto","year":"1988","unstructured":"Matsumoto, T., Imai, H.: Public quadratic polynomial-tuples for efficient signature-verification and message-encryption. In: Barstow, D., et al. (eds.) EUROCRYPT 1988. LNCS, vol. 330, pp. 419\u2013453. Springer, Heidelberg (1988). https:\/\/doi.org\/10.1007\/3-540-45961-8_39"},{"issue":"1","key":"10_CR28","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1515\/JMC.2008.004","volume":"2","author":"S Murphy","year":"2008","unstructured":"Murphy, S., Paterson, M.: A geometric view of cryptographic equation solving. J. Math. Cryptol. 2(1), 63\u2013107 (2008)","journal-title":"J. Math. Cryptol."},{"key":"10_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"202","DOI":"10.1007\/978-3-642-10868-6_12","volume-title":"Cryptography and Coding","author":"S Murphy","year":"2009","unstructured":"Murphy, S., Paterson, M.B.: Geometric ideas for cryptographic equation solving in even characteristic. In: Parker, M.G. (ed.) IMACC 2009. LNCS, vol. 5921, pp. 202\u2013221. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-10868-6_12"},{"key":"10_CR30","unstructured":"National Institute of Science and Technology (NIST): Post-quantum cryptographic standardization process. Technical report (2017). https:\/\/csrc.nist.gov\/projects\/post-quantum-cryptography"},{"key":"10_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/3-540-68339-9_4","volume-title":"Advances in Cryptology\u2014EUROCRYPT 1996","author":"J Patarin","year":"1996","unstructured":"Patarin, J.: Hidden fields equations (HFE) and isomorphisms of polynomials (IP): two new families of asymmetric algorithms. In: Maurer, U. (ed.) EUROCRYPT 1996. LNCS, vol. 1070, pp. 33\u201348. Springer, Heidelberg (1996). https:\/\/doi.org\/10.1007\/3-540-68339-9_4"},{"key":"10_CR32","doi-asserted-by":"publisher","first-page":"175","DOI":"10.1023\/A:1008341625464","volume":"20","author":"J Patarin","year":"2000","unstructured":"Patarin, J.: Cryptanalysis of the Matsumoto and Imai public key scheme of Eurocrypt\u201998. Des. Codes Crypt. 20, 175\u2013209 (2000). https:\/\/doi.org\/10.1023\/A:1008341625464","journal-title":"Des. Codes Crypt."},{"key":"10_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"349","DOI":"10.1007\/978-3-540-74619-5_22","volume-title":"Fast Software Encryption","author":"M Sugita","year":"2007","unstructured":"Sugita, M., Kawazoe, M., Perret, L., Imai, H.: Algebraic cryptanalysis of 58-round SHA-1. In: Biryukov, A. (ed.) FSE 2007. LNCS, vol. 4593, pp. 349\u2013365. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-74619-5_22"},{"key":"10_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"67","DOI":"10.1007\/11496618_7","volume-title":"Information Security and Cryptology \u2013 ICISC 2004","author":"B-Y Yang","year":"2005","unstructured":"Yang, B.-Y., Chen, J.-M.: All in the XL family: theory and practice. In: Park, C., Chee, S. (eds.) ICISC 2004. LNCS, vol. 3506, pp. 67\u201386. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11496618_7"}],"container-title":["Lecture Notes in Computer Science","Selected Areas in Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-81652-0_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,19]],"date-time":"2025-07-19T22:02:26Z","timestamp":1752962546000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-81652-0_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030816513","9783030816520"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-81652-0_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"21 July 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SAC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Selected Areas in Cryptography","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2020","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 October 2020","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 October 2020","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"sacrypt2020","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/sac2020.ca\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"iChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"52","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"27","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"52% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3-5","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"6-8","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}