SLIDE 18 XL Variants
FXL – XL with k variables guessed or “hybridized” Joux-Vitse (“Hybridized XL-related method”)
1 eXtend: multiply each polynomial f1, . . . , fm by monomials, up to
total degree ≤ D
2 Linearize: Apply linear algebra to eliminate all monomials of total
degree ≥ 2 in the first k variables (and get at least k such equations).
3 Fix n − k variables, solve for the initial k in linear equations.
XL2 – simplified F4
1 eXtend: multiply each polynomial f1, . . . , fm by monomials, up to
total degree ≤ D
2 Linearize: Apply linear algebra to eliminate top level monomials 3 Multiply degree D − 1 equations by variables, Eliminate Again. B.-Y. Yang (Academia Sinica) Multivariate Cryptography PQC Exec. Summer School 10 / 13