<?xml version="1.0" encoding="UTF-8"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-07-23T13:07:48Z</responseDate>
  <request identifier="1015" metadataPrefix="oai_dc" verb="GetRecord">https://drops.dagstuhl.de/oai</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:drops-oai.dagstuhl.de:1015</identifier>
        <datestamp>2024-03-06T11:07:16Z</datestamp>
        <setSpec>ddc:004</setSpec>
        <setSpec>open_access</setSpec>
      </header>
      <metadata>
        <oai_dc:dc xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd">
          <dc:title>QUAD: Overview and Recent Developments</dc:title>
          <dc:creator>Arditti, David</dc:creator>
          <dc:creator>Berbain, Côme</dc:creator>
          <dc:creator>Billet, Olivier</dc:creator>
          <dc:creator>Gilbert, Henri</dc:creator>
          <dc:creator>Patarin, Jacques</dc:creator>
          <dc:subject>MQ problem</dc:subject>
          <dc:subject>stream cipher</dc:subject>
          <dc:subject>provable security</dc:subject>
          <dc:subject>GrÃƒÂ¶bner basis</dc:subject>
          <dc:description>We give an outline of the specification and provable security&#13;
features of the QUAD stream cipher proposed at Eurocrypt 2006.&#13;
The cipher relies on the iteration of a multivariate system of quadratic&#13;
equations over a finite field, typically GF(2) or a small extension. In the&#13;
binary case, the security of the keystream generation can be related, in&#13;
the concrete security model, to the conjectured intractability of the MQ&#13;
problem of solving a random system of m equations in n unknowns. We&#13;
show that this security reduction can be extended to incorporate the key&#13;
and IV setup and provide a security argument related to the whole stream&#13;
cipher.We also briefly address software and hardware performance issues&#13;
and show that if one is willing to pseudorandomly generate the systems&#13;
of quadratic polynomials underlying the cipher, this leads to suprisingly&#13;
inexpensive hardware implementations of QUAD.</dc:description>
          <dc:publisher>Schloss Dagstuhl – Leibniz-Zentrum für Informatik</dc:publisher>
          <dc:contributor>David Arditti and Côme Berbain and Olivier Billet and Henri Gilbert and Jacques Patarin</dc:contributor>
          <dc:date>2007</dc:date>
          <dc:relation>Is Part Of Dagstuhl Seminar Proceedings, Volume 7021, Symmetric Cryptography (2007)</dc:relation>
          <dc:type>InProceedings</dc:type>
          <dc:type>Text</dc:type>
          <dc:type>doc-type:ResearchArticle</dc:type>
          <dc:type>publishedVersion</dc:type>
          <dc:format>application/pdf</dc:format>
          <dc:identifier>doi:10.4230/DagSemProc.07021.9</dc:identifier>
          <dc:identifier>urn:nbn:de:0030-drops-10155</dc:identifier>
          <dc:identifier>https://drops.dagstuhl.de/entities/document/10.4230/DagSemProc.07021.9</dc:identifier>
          <dc:language>eng</dc:language>
          <dc:rights>https://creativecommons.org/licenses/by/4.0/legalcode</dc:rights>
        </oai_dc:dc>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
