Stronger bounds on the cost of computing Gröbner bases for HFE systems

Research output: Contribution to journalArticlepeer-review


Colleges, School and Institutes

External organisations

  • Universite de Neuchatel, Switzerland
  • University College Dublin


We give upper bounds for the solving degree and the last fall degree of the polynomial system associated to the HFE (Hidden Field Equations) cryptosystem. Our bounds improve the known bounds for this type of systems. We also present new results on the connection between the solving degree and the last fall degree and prove that, in some cases, the solving degree is independent of coordinate changes.


Original languageEnglish
JournalJournal of Symbolic Computation
Early online date8 Jul 2020
Publication statusE-pub ahead of print - 8 Jul 2020


  • Multivariate cryptography, Gröbner bases, HFE, (Fake) Weil descent, Last fall degree, Solving degree