Discussion forum for Cryptology ePrint Archive reports posted in 2006. Please put the report number in the subject.  
Posted by: Skeptic (IP Logged)
Date: 16 April 2009 13:57

The subject and the methods introduce in the article are of high interest. I'm still currently working on it and I have a question about the perturbation polynomial.

1) Perturbation polynomial :

The construction implies the use of a multivariate polynomial. However in the AES system (part S), the equations for one round are multivariate but with univariate monomials. So if some multivariate monomials are used in the construction of Qf (as stated in the previous article[5]), the equation implied by Qf are founded by inspection,ie the permutation pi_1 of M_1 is ineffective. Or do I miss something?

