paper

Oracle-supported drawing of the Groebner {\em escalier}

arXiv:1006.3297

Abstract

The aim of this note is to discuss the following quite queer Problem: \noindent GIVEN \noindent i) the free non-commutative polynomial ring, ${\Cal P} := {\Bbb F}\langle X_1,\ldots,X_n\rangle$ {\em (public)}, \noindent ii) a bilateral ideal {\em (private)}, \noindent iii) a finite set of elements of the ideal {\em (public)}, \noindent a noetherian semigroup term-ordering {\rm (private)}, on the word semigroup ${\Cal T} := < X_1,\ldots,X_n>$, \noindent COMPUTE \noindent --a finite subset of the Gröbner basis of w.r.t. s.t., for each its {\em normal form} w.r.t. is zero, \noindent "by means of a finite number of queries to an oracle", which, \noindent given a term $τ\in{\Cal T}$ returns its {\em canonical form} $\Can(τ,{\sf I},\prec)$ w.r.t. the ideal and the term-ordering . \qed This queer problem has been suggested to us by Bulygin (2005) where a similar problem, but with stronger assumptions, is faced in order to set up a chosen-cyphertext attack against the cryptographic system proposed in Rai (2004).