Paper 2026/1787

A Practical Optimization for Wiedemann XL

Tung Chou, Academia Sinica
Ruben Niederhagen, Academia Sinica, University of Southern Denmark
Abstract

Wiedemann XL is a variant of the XL algorithm that has been widely used in algebraic attacks. Usually, the cost of applying Widemann XL is estimated as 3N^2 ω, where N is the width of the Macaulay matrix, and ω is the average row weight of the Macaulay matrix. Among 3N^2 ω, 2N^2 ω is from the 1st phase of the algorithm, while N^2 ω is from the 3rd phase of the algorithm. This paper shows a practical optimization that reduces the cost of the 3rd phase by a huge factor so that its cost becomes essentially negligible compared to that of the 1st phase. Our optimization makes use of the fact that to obtain a solution of the multivariate system, only a small part of the kernel vectors is needed.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
algebraic attacksmultivariate cryptographyimplementation
Contact author(s)
blueprint @ crypto tw
ruben @ polycephaly org
History
2026-08-24: approved
2026-08-24: received
See all versions
Short URL
https://ia.cr/2026/1787
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1787,
      author = {Tung Chou and Ruben Niederhagen},
      title = {A Practical Optimization for Wiedemann {XL}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1787},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1787}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.