SearcharxivSearch

arXiv subjects

Elisa Gorla

Publications and source records attributed to Elisa Gorla.

At least 19 recordsLinked to original sources

A distance-free approach to generalized weights

We propose a unified theory of generalized weights for linear codes endowed with an arbitrary distance. Instead of relying on supports or anticodes, the weights of a code are defined via the intersections of the code with a chosen family of spaces, which we call a test family. The choice of test family determines the properties of the corresponding generalized weights and the characteristics of the code that they capture. In this general framework, we prove that generalized weights are weakly increasing and that certain subsequences are strictly increasing. We also prove a duality result reminiscent of Wei's Duality Theorem. The corresponding properties of generalized Hamming and rank-metric weights follow from our general results by selecting optimal anticodes as a test family. For sum-rank metric codes, we propose a test family that results in generalized weights that are closely connected to -- but not always the same as -- the usual generalized weights. This choice allows us to extend the known duality results for generalized sum-rank weights to some sum-rank-metric codes with a nonzero Hamming component. Finally, we explore a family of generalized weights obtained by intersecting the underlying code with MDS or MRD codes.

cs.IT

Code distances: a new family of invariants of linear codes

In this paper, we introduce code distances, a new family of invariants for linear codes. We establish some properties and prove bounds on the code distances, and show that they are not invariants of the matroid (for a linear block code) or $q$-polymatroid (for a rank-metric code) associated to the code. By means of examples, we show that the code distances allow us to distinguish some inequivalent MDS or MRD codes with the same parameters. We also show that no duality holds, i.e., the sequence of code distances of a code does not determine the sequence of code distances of its dual. Further, we define a greedy and an asymptotic version of code distances. Finally, we relate these invariants to other invariants of linear codes, such as the maximality degree, the covering radius, and the partial distances of polar codes.

cs.IT

Lifting Frobenius splittings through geometric vertex decomposition

Frobenius splitting, pioneered by Hochster and Roberts in the 1970s and Mehta and Ramanathan in the 1980s, is a technique in characteristic $p$ commutative algebra and algebraic geometry used to control singularities. In the aughts, Knutson showed that Frobenius splittings of a certain type descend through Gr\"obner degeneration of a certain type, called geometric vertex decomposition. In the present paper, we give a partial converse to Knutson's result. We show that a Frobenius splitting that compatibly splits both link and deletion of a geometric vertex decomposition can, under an additional hypothesis on the form of the splitting, be lifted to a splitting that compatibly splits the original ideal. We discuss an example showing that the additional hypothesis cannot be removed. Our argument uses the relationship between geometric vertex decomposition and Gorenstein liaison developed by Klein and Rajchgot. Additionally, we show that Li's double determinantal varieties defined by maximal minors are Frobenius split.

math.AC

Cryptanalysis of a multivariate CCZ scheme

We consider the multivariate scheme Pesto, which was introduced by Calderini, Caminata, and Villa. In this scheme, the public polynomials are obtained by applying a CCZ transformation to a set of quadratic secret polynomials. As a consequence, the public key consists of polynomials of degree 4. In this work, we show that the public degree 4 polynomial system can be efficiently reduced to a system of quadratic polynomials. This seems to suggest that the CCZ transformation may not offer a significant increase in security, contrary to what was initially believed.

cs.CR

Latroids and code invariants

Latroids were introduced by Vertigan, who associated a latroid to a linear block code and showed that its Tutte polynomial determines the weight enumerator of the code. The original definition of a latroid is in terms of its rank function. For a complemented lattice, we establish cryptomorphic definitions in terms of independent elements, bases, circuits, and flats. We then associate a latroid to a code over a ring or a field endowed with a general support function and show that the generalized weights of the code can be recovered from the associated latroid. This provides a uniform framework for studying generalized weights and other combinatorial invariants of linear block codes, linear codes over a ring, rank-metric, and sum-rank metric codes.

cs.IT

The complexity of solving a system of equations of the same degree

Many systems of interest in cryptography consist of equations of the same degree. Under the assumption that the degree of regularity is finite, we prove upper bounds on the degree of regularity of a system of equations of the same degree, with or without adding the field equations to the system. The bounds translate into upper bounds on the solving degree of the systems, and hence on the complexity of solving them via Gr\"obner bases methods. Our bounds depend on the number of equations in the system, the number of variables, and the degree of the equations.

cs.CR

Integer sequences that are generalized weights of a linear code

Which integer sequences are sequences of generalized weights of a linear code? In this paper, we answer this question for linear block codes, rank-metric codes, and more generally for sum-rank metric codes. We do so under an existence assumption for MDS and MSRD codes. We also prove that the same integer sequences appear as sequences of greedy weights of linear block codes, rank-metric codes, and sum-rank metric codes. Finally, we characterize the integer sequences which appear as sequences of relative generalized weights (respectively, relative greedy weights) of linear block codes.

cs.IT

MacWilliams' Extension Theorem for rank-metric codes

The MacWilliams' Extension Theorem is a classical result by Florence Jessie MacWilliams. It shows that every linear isometry between linear block-codes endowed with the Hamming distance can be extended to a linear isometry of the ambient space. Such an extension fails to exist in general for rank-metric codes, that is, one can easily find examples of linear isometries between rank-metric codes which cannot be extended to linear isometries of the ambient space. In this paper, we explore to what extent a MacWilliams' Extension Theorem may hold for rank-metric codes. We provide an extensive list of examples of obstructions to the existence of an extension, as well as a positive result.

cs.IT

Sum-rank metric codes

Sum-rank metric codes are a natural extension of both linear block codes and rank-metric codes. They have several applications in information theory, including multishot network coding and distributed storage systems. The aim of this chapter is to present the mathematical theory of sum-rank metric codes, paying special attention to the $\mathbb{F}_q$-linear case in which different sizes of matrices are allowed. We provide a comprehensive overview of the main results in the area. In particular, we discuss invariants, optimal anticodes, and MSRD codes. In the last section, we concentrate on $\mathbb{F}_{q^m}$-linear codes.

cs.IT

The complexity of solving Weil restriction systems

The solving degree of a system of multivariate polynomial equations provides an upper bound for the complexity of computing the solutions of the system via Groebner bases methods. In this paper, we consider polynomial systems that are obtained via Weil restriction of scalars. The latter is an arithmetic construction which, given a finite Galois field extension $k\hookrightarrow K$, associates to a system $\mathcal{F}$ defined over $K$ a system $\mathrm{Weil}(\mathcal{F})$ defined over $k$, in such a way that the solutions of $\mathcal{F}$ over $K$ and those of $\mathrm{Weil}(\mathcal{F})$ over $k$ are in natural bijection. In this paper, we find upper bounds for the complexity of solving a polynomial system $\mathrm{Weil}(\mathcal{F})$ obtained via Weil restriction in terms of algebraic invariants of the system $\mathcal{F}$.

cs.CR

Generalized column distances

We define a notion of r-generalized column distances for the j-truncation of a convolutional code. Taking the limit as j tends to infinity allows us to define r-generalized column distances of a convolutional code. We establish some properties of these invariants and compare them with other invariants of convolutional codes which appear in the literature.

cs.IT

Solving multivariate polynomial systems and an invariant from commutative algebra

The complexity of computing the solutions of a system of multivariate polynomial equations by means of Groebner bases computations is upper bounded by a function of the solving degree. In this paper, we discuss how to rigorously estimate the solving degree of a system, focusing on systems arising within public-key cryptography. In particular, we show that it is upper bounded by, and often equal to, the Castelnuovo-Mumford regularity of the ideal generated by the homogenization of the equations of the system, or by the equations themselves in case they are homogeneous. We discuss the underlying commutative algebra and clarify under which assumptions the commonly used results hold. In particular, we discuss the assumption of being in generic coordinates (often required for bounds obtained following this type of approach) and prove that systems that contain the field equations or their fake Weil descent are in generic coordinates. We also compare the notion of solving degree with that of degree of regularity, which is commonly used in the literature. We complement the paper with some examples of bounds obtained following the strategy that we describe.

cs.CR

Generalized weights of convolutional codes

In 1997 Rosenthal and York defined generalized Hamming weights for convolutional codes, by regarding a convolutional code as an infinite dimensional linear code endowed with the Hamming metric. In this paper, we propose a new definition of generalized weights of convolutional codes, that takes into account the underlying module structure of the code. We derive the basic properties of our generalized weights and discuss the relation with the previous definition. We establish upper bounds on the weight hierarchy of MDS and MDP codes and show that that, depending on the code parameters, some or all of the generalized weights of MDS codes are determined by the length, rank, and internal degree of the code. We also prove an anticode bound for convolutional codes and define optimal anticodes as the codes which meet the anticode bound. Finally, we classify optimal anticodes and compute their weight hierarchy.

cs.IT

Solving degree, last fall degree, and related invariants

In this paper we study and relate several invariants connected to the solving degree of a polynomial system. This provides a rigorous framework for estimating the complexity of solving a system of polynomial equations via Groebner bases methods. Our main results include a connection between the solving degree and the last fall degree and one between the degree of regularity and the Castelnuovo-Mumford regularity.

cs.CR

Radical support for multigraded ideals

Can one tell if an ideal is radical just by looking at the degrees of the generators? In general, this is hopeless. However, there are special collections of degrees in multigraded polynomial rings, with the property that any multigraded ideal generated by elements of those degrees is radical. We call such a collection of degrees a radical support. In this paper, we give a combinatorial characterization of radical supports. Our characterization is in terms of properties of cycles in an associated labelled graph. We also show that the notion of radical support is closely related to that of Cartwright-Sturmfels ideals. In fact, any ideal generated by multigraded generators whose multidegrees form a radical support is a Cartwright-Sturmfels ideal. Conversely, a collection of degrees such that any multigraded ideal generated by elements of those degrees is Cartwright-Sturmfels is a radical support.

math.AC

The complexity of MinRank

In this note, we leverage some of our results from arXiv:1706.06319 to produce a concise and rigorous proof for the complexity of the generalized MinRank Problem in the under-defined and well-defined case. Our main theorem recovers and extends previous results by Faugère, Safey El Din, Spaenlehauer (arXiv:1112.4411).

cs.SC

Quasi optimal anticodes: structure and invariants

It is well-known that the dimension of optimal anticodes in the rank-metric is divisible by the maximum m between the number of rows and columns of the matrices. Moreover, for a fixed k divisible by m, optimal rank-metric anticodes are the codes with least maximum rank, among those of dimension k. In this paper, we study the family of rank-metric codes whose dimension is not divisible by m and whose maximum rank is the least possible for codes of that dimension, according to the Anticode bound. As these are not optimal anticodes, we call them quasi optimal anticodes (qOACs). In addition, we call dually qOAC a qOAC whose dual is also a qOAC. We describe explicitly the structure of dually qOACs and compute their weight distributions, generalized weights, and associated q-polymatroids.

cs.IT