Solving Degree and Degree of Regularity for Polynomial Systems over a Finite Fields

  • Jintai Ding
  • Dieter Schmidt
Part of the Lecture Notes in Computer Science book series (LNCS, volume 8260)


In this paper, we try to clarify some of the questions related to a key concept in multivariate polynomial solving algorithm over a finite field: the degree of regularity. By the degree of regularity, here we refer to a concept first presented by Dubois and Gama, namely the lowest degree at which certain nontrivial degree drop of a polynomial system occurs. Currently, it is somehow commonly accepted that we can use this degree to estimate the complexity of solving a polynomial system, even though we do not have systematic empirical data or a theory to support such a claim. In this paper, we would like to clarify the situation with the help of experiments. We first define a concept of solving degree for a polynomial system. The key question we then need to clarify is the connection of solving degree and the degree of regularity with focus on quadratic systems. To exclude the cases that do not represent the general situation, we need to define when a system is degenerate and when it is irreducible. With extensive computer experiments, we show that the two concepts, the degree of regularity and the solving degree, are related for irreducible systems in the sense that the difference between the two degrees is indeed small, less than 3. But due to the limitation of our experiments, we speculate that this may not be the case for high degree cases.


Solving degree degree of regularity HFE HFEv random polynomial system non-degenerate system 


Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.


  1. 1.
    Bardet, M., Faugère, J.-C., Salvy, B., Yang, B.-Y.: Asymptotic expansion of the degree of regularity for semi-regular systems of equations. In: Gianni, P. (ed.) MEGA 2005, Sardinia, Italy (2005)Google Scholar
  2. 2.
    Courtois, N.T., Klimov, A., Patarin, J., Shamir, A.: Efficient algorithms for solving overdefined systems of multivariate polynomial equations. In: Preneel, B. (ed.) EUROCRYPT 2000. LNCS, vol. 1807, pp. 392–407. Springer, Heidelberg (2000), CrossRefGoogle Scholar
  3. 3.
    Diem, C.: The XL-algorithm and a conjecture from commutative algebra. In: Lee, P.J. (ed.) ASIACRYPT 2004. LNCS, vol. 3329, pp. 323–337. Springer, Heidelberg (2004)CrossRefGoogle Scholar
  4. 4.
    Ding, J.: Inverting the square systems is exponential. Cryptology ePrint Archive, Report 2011/275 (2011),
  5. 5.
    Ding, J., Buchmann, J., Mohamed, M.S.E., Mohamed, W.S.A.E., Weinmann, R.-P.: Mutant XL. In: Talk at the First International Conference on Symbolic Computation and Cryptography (SCC 2008), Beijing (2008)Google Scholar
  6. 6.
    Ding, J., Gower, J., Schmidt, D.: Multivariate Public-Key Cryptosystems. In: Advances in Information Security. Springer (2006) ISBN 0-387-32229-9Google Scholar
  7. 7.
    Ding, J., Hodges, T.J.: Inverting hfe systems is quasi-polynomial for all fields. In: Rogaway, P. (ed.) CRYPTO 2011. LNCS, vol. 6841, pp. 724–742. Springer, Heidelberg (2011)CrossRefGoogle Scholar
  8. 8.
    Ding, J., Kleinjung, T.: Degree of regularity for HFE−. Journal of Math-for-Industry 4(2012B-3), 97–104 (2012), MathSciNetzbMATHGoogle Scholar
  9. 9.
    Ding, J., Yang, B.-Y.: Post-Quantum Cryptography. Springer, Berlin (2009) ISBN: 978-3-540-88701-0, e-ISBN: 978-3-540-88702-7Google Scholar
  10. 10.
    Ding, J., Yang, B.-Y.: Degree of regularity for hfev and hfev-. In: Gaborit, P. (ed.) PQCrypto 2013. LNCS, vol. 7932, pp. 52–66. Springer, Heidelberg (2013)CrossRefGoogle Scholar
  11. 11.
    Dubois, V., Gama, N.: The degree of regularity of hfe systems. In: Abe, M. (ed.) ASIACRYPT 2010. LNCS, vol. 6477, pp. 557–576. Springer, Heidelberg (2010)CrossRefGoogle Scholar
  12. 12.
    Faugère, J.-C.: A new efficient algorithm for computing Gröbner bases (F 4). Journal of Pure and Applied Algebra 139, 61–88 (1999)MathSciNetCrossRefzbMATHGoogle Scholar
  13. 13.
    Kipnis, A., Patarin, J., Goubin, L.: Unbalanced Oil and Vinegar signature schemes. In: Stern, J. (ed.) EUROCRYPT 1999. LNCS, vol. 1592, pp. 206–222. Springer, Heidelberg (1999)CrossRefGoogle Scholar
  14. 14.
    Lazard, D.: Gröbner-bases, Gaussian elimination and resolution of systems of algebraic equations. In: ISSAC 1983 and EUROCAL 1983. LNCS, vol. 162, pp. 146–156. Springer (March 1983)Google Scholar
  15. 15.
    Mayr, E.W., Meyer, A.: The complexity of the word problems for commutative semigroups and polynomial ideals. Adv. in Math. 46(3), 305–329 (1982)MathSciNetCrossRefzbMATHGoogle Scholar
  16. 16.
    Mohamed, M.S.E., Cabarcas, D., Ding, J., Buchmann, J., Bulygin, S.: MXL3: An efficient algorithm for computing Gröbner bases of zero-dimensional ideals. In: Lee, D., Hong, S. (eds.) ICISC 2009. LNCS, vol. 5984, pp. 87–100. Springer, Heidelberg (2010)CrossRefGoogle Scholar
  17. 17.
    Mohamed, M.S.E., Mohamed, W.S.A.E., Ding, J., Buchmann, J.: MXL2: Solving polynomial equations over GF(2) using an improved mutant strategy. In J. Buchmann and J. Ding, editors, PQCrypto. In: Buchmann, J., Ding, J. (eds.) PQCrypto 2008. LNCS, vol. 5299, pp. 203–215. Springer, Heidelberg (2008)CrossRefGoogle Scholar
  18. 18.
    Yang, B.-Y., Chen, J.-M.: Theoretical analysis of XL over small fields. In: Wang, H., Pieprzyk, J., Varadharajan, V. (eds.) ACISP 2004. LNCS, vol. 3108, pp. 277–288. Springer, Heidelberg (2004)CrossRefGoogle Scholar

Copyright information

© Springer-Verlag Berlin Heidelberg 2013

Authors and Affiliations

  • Jintai Ding
    • 1
    • 2
  • Dieter Schmidt
    • 2
  1. 1.Chongqing UniversityChina
  2. 2.University of CincinnatiUSA

Personalised recommendations