### Paper: Cryptanalysis of HFE

Authors: Ilia Toli URL: http://eprint.iacr.org/2003/101 Search ePrint Search Google Out of the public key ($\mathcal{PK}$) we recover a polynomial of the same shape as the private polynomial. Then we give an algorithm for solving such a special-form polynomial. This fact puts an eavesdropper in the same position with a legitimate user in decryption. An upper bound for the complexity of that all is $\mathcal{O}(n^6)$ bit operations for $n$ the degree of the field extension.
