发表机构
Department of Mathematics, University of Trento(特伦托大学数学系)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文证明二元方阵二次系统无解与唯一解数量满足严格不等式,推广到高次多项式系统,结合拟阵与编码理论给出有限界限。
AI 中文摘要
判定一个定义在 $\mathbb F_2$ 上的多元二次方程组是否有解是经典的 NP 完全问题,并且对于方程个数与变量个数相等的方阵系统,该问题仍然是 NP 完全的。该问题的困难性是当今后量子密码学的基石之一。设 $\MQ_0(n)$ 和 $\MQ_1(n)$ 分别表示在 $n$ 个变量中无解和恰有一个解的方阵二次系统的集合。$\cup_{n\geq 2} \MQ_0(n)$ 是一个 coNP 完全语言,而 $\cup_{n\geq 2} \MQ_1(n)$ 属于 DP。已知 $\lim_{n\to \infty} |\MQ_1(n)|/|\MQ_0(n)|=1$。本文证明了显式的有限 $n$ 界限:\\[ |\MQ_0(n)|<|\MQ_1(n)| \le \left(1+\frac{1}{2^n-1}\right)|\MQ_0(n)|, \\] 更一般地,设 $Q_d$ 为从 $(\FF_2)^n$ 到 $\mathbb F_2$ 的次数至多为 $d$ 的多项式函数空间,并设 $\alpha_k$ 统计 $(Q_d)^n$ 中恰好有 $k$ 个解的方阵系统的个数。则 \\[ \alpha_0<\alpha_1 \le \left(1+\frac{1}{2^n-1}\right)\alpha_0\\,, \qquad 2\le d\le n \\,. \\] 证明结合了拟阵和编码理论方法。我们将 $(\FF_2)^n$ 解释为 $Q_d$ 的求值拟阵的基集,通过特征多项式表达 $\alpha_0$ 和 $\alpha_1$,并使用 Whitney 型符号反转对合来证明,唯一可能将 $\alpha_1-\alpha_0$ 推至低于 $\alpha_1/2^n$ 的项来自拟阵端口元素。这些元素被识别为 Reed--Muller 码 $\RM(n-d-1,n)=\RM(d,n)^\perp$ 的最小支撑字;所需估计随后由 MacWilliams 恒等式、最小距离界 $2^{d+1}$ 以及码的偶权重结构得出。
英文摘要
Deciding whether a system of multivariate quadratic equations over $\mathbb F_2$ has a solution is a classical NP-complete problem, and remains so for square systems, with as many equations as variables. The hardness of this problem is one of the cornerstones of nowadays post-quantum cryptography. Let $\MQ_0(n)$ and $\MQ_1(n)$ denote the sets of square quadratic systems in $n$ variables having respectively no solutions and exactly one solution. $\cup_{n\geq 2} \MQ_0(n)$ is a coNP-complete language, while $\cup_{n\geq 2} \MQ_1(n)$ lies in DP. It is known that $\lim_{n\to \infty} |\MQ_1(n)|/|\MQ_0(n)|=1$. Here we prove the explicit finite-$n$ bounds \[ |\MQ_0(n)|<|\MQ_1(n)| \le \left(1+\frac{1}{2^n-1}\right)|\MQ_0(n)|, \] More generally, let $Q_d$ be the space of polynomial functions $(\FF_2)^n\to\mathbb F_2$ of degree at most $d$, and let $α_k$ count square systems in $(Q_d)^n$ having exactly $k$ solutions. Then \[ α_0<α_1 \le \left(1+\frac{1}{2^n-1}\right)α_0\,, \qquad 2\le d\le n \,. \] The proof combines matroid and coding-theoretic methods. We interpret $(\FF_2)^n$ as the ground set of the evaluation matroid of $Q_d$, express $α_0$ and $α_1$ through characteristic polynomials, and use a Whitney-type sign-reversing involution to show that the only terms that can push $α_1-α_0$ below $α_1/2^n$ come from the elements of a matroid port. These are identified with minimal-support words of the Reed--Muller code $\RM(n-d-1,n)=\RM(d,n)^\perp$; the required estimate then follows from the MacWilliams identity, the minimum-distance bound $2^{d+1}$, and the even-weight structure of the code.