


























We present a structural attack on the DME cryptosystem with paramenters (3,2,q). The attack recovers 10 of the 12 coefficients of the first linear map. We also show that, if those 12 coefficients were known, the rest of the private key can be efficiently obtained by solving systems of quadratic equations with just two variables.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。