<?xml version="1.0" encoding="utf-8"?>
<raweb xmlns:xlink="http://www.w3.org/1999/xlink" xml:lang="en" year="2017">
  <identification id="polsys" isproject="true">
    <shortname>POLSYS</shortname>
    <projectName>Polynomial Systems</projectName>
    <theme-de-recherche>Algorithmics, Computer Algebra and Cryptology</theme-de-recherche>
    <domaine-de-recherche>Algorithmics, Programming, Software and Architecture</domaine-de-recherche>
    <urlTeam>http://www-polsys.lip6.fr</urlTeam>
    <structure_exterieure type="Labs">
      <libelle>Laboratoire d'informatique de Paris 6 (LIP6)</libelle>
    </structure_exterieure>
    <structure_exterieure type="Organism">
      <libelle>CNRS</libelle>
    </structure_exterieure>
    <structure_exterieure type="Organism">
      <libelle>Université Pierre et Marie Curie (Paris 6)</libelle>
    </structure_exterieure>
    <header_dates_team>Creation of the Team: 2012 January 01, updated into Project-Team: 2013 January 01</header_dates_team>
    <LeTypeProjet>Project-Team</LeTypeProjet>
    <keywordsSdN>
      <term>A2.4. - Verification, reliability, certification</term>
      <term>A4.3. - Cryptography</term>
      <term>A4.3.1. - Public key cryptography</term>
      <term>A4.3.4. - Quantum Cryptography</term>
      <term>A5.10.1. - Design</term>
      <term>A6.1. - Mathematical Modeling</term>
      <term>A6.2.3. - Probabilistic methods</term>
      <term>A6.2.6. - Optimization</term>
      <term>A6.2.7. - High performance computing</term>
      <term>A6.4.3. - Observability and Controlability</term>
      <term>A8.1. - Discrete mathematics, combinatorics</term>
      <term>A8.2. - Optimization</term>
      <term>A8.3. - Geometry, Topology</term>
      <term>A8.4. - Computer Algebra</term>
    </keywordsSdN>
    <keywordsSecteurs>
      <term>B5. - Industry of the future</term>
      <term>B5.2. - Design and manufacturing</term>
      <term>B5.2.3. - Aviation</term>
      <term>B5.2.4. - Aerospace</term>
      <term>B6. - IT and telecom</term>
      <term>B6.3. - Network functions</term>
      <term>B6.5. - Information systems</term>
      <term>B9.4.1. - Computer science</term>
      <term>B9.4.2. - Mathematics</term>
      <term>B9.8. - Privacy</term>
    </keywordsSecteurs>
    <UR name="Paris"/>
  </identification>
  <team id="uid1">
    <person key="polsys-2014-idm27936">
      <firstname>Jean-Charles</firstname>
      <lastname>Faugère</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Team leader, Inria,
Senior Researcher</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="polsys-2014-idm26432">
      <firstname>Elias</firstname>
      <lastname>Tsigaridas</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, Researcher</moreinfo>
    </person>
    <person key="polsys-2014-idm25184">
      <firstname>Dongming</firstname>
      <lastname>Wang</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>CNRS, Senior
Researcher, on leave at Beihang University</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="polsys-2014-idp66592">
      <firstname>Jérémy</firstname>
      <lastname>Berthomieu</lastname>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>UPMC, Associate Professor</moreinfo>
    </person>
    <person key="polsys-2014-idp69456">
      <firstname>Daniel</firstname>
      <lastname>Lazard</lastname>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>UPMC, Emeritus
Professor</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="polsys-2014-idp70968">
      <firstname>Ludovic</firstname>
      <lastname>Perret</lastname>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>UPMC, Associate Professor</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="polsys-2014-idp72288">
      <firstname>Guénaël</firstname>
      <lastname>Renault</lastname>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>UPMC,
Associate Professor, on leave at ANSSI</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="polsys-2014-idp73616">
      <firstname>Mohab</firstname>
      <lastname>Safey El Din</lastname>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>UPMC, Professor</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="polsys-2015-idp92760">
      <firstname>Emmanuel</firstname>
      <lastname>Prouff</lastname>
      <categoryPro>CollaborateurExterieur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>ANSSI, Associate
Member</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="polsys-2017-idp176912">
      <firstname>Victor</firstname>
      <lastname>Magron</lastname>
      <categoryPro>CollaborateurExterieur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>CNRS, Researcher, from
Oct. 2017</moreinfo>
    </person>
    <person key="polsys-2017-idp179424">
      <firstname>Amine</firstname>
      <lastname>Mrabet</lastname>
      <categoryPro>PostDoc</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>UPMC, ATER, from Sept. 2017</moreinfo>
    </person>
    <person key="polsys-2015-idp72240">
      <firstname>Kaie</firstname>
      <lastname>Kubjas</lastname>
      <categoryPro>PostDoc</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>UPMC, Post-Doctoral
fellow, on leave at MIT, from Sept. 2017</moreinfo>
    </person>
    <person key="polsys-2017-idp184512">
      <firstname>Jocelyn</firstname>
      <lastname>Ryckeghem</lastname>
      <categoryPro>Technique</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>UPMC, from Apr. 2017 until
Dec. 2017</moreinfo>
    </person>
    <person key="polsys-2014-idp89656">
      <firstname>Ivan</firstname>
      <lastname>Bannwarth</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>UPMC, until Aug. 2017</moreinfo>
    </person>
    <person key="polsys-2014-idp101344">
      <firstname>Matías</firstname>
      <lastname>Bender</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
    <person key="vegas-2014-idp76336">
      <firstname>Olive</firstname>
      <lastname>Chakraborty</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>UPMC, from May 2017</moreinfo>
    </person>
    <person key="polsys-2017-idp194400">
      <firstname>Nagardjun</firstname>
      <lastname>Chinthamani Dwarakanath</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>UPMC, from Dec. 2017</moreinfo>
    </person>
    <person key="polsys-2017-idp196864">
      <firstname>Solane</firstname>
      <lastname>El Hirch</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>UPMC, from June 2017</moreinfo>
    </person>
    <person key="polsys-2017-idp199328">
      <firstname>Thi Xuan</firstname>
      <lastname>Vu</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>UPMC, from Oct. 2017</moreinfo>
    </person>
    <person key="matherials-2017-idp173824">
      <firstname>Kevin</firstname>
      <lastname>Bonny</lastname>
      <categoryPro>Assistant</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
    <person key="polsys-2016-idp155408">
      <firstname>Georgette</firstname>
      <lastname>Bonpapa</lastname>
      <categoryPro>Assistant</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>UPMC, Assistant, until July 2017</moreinfo>
    </person>
    <person key="lifeware-2014-idp73408">
      <firstname>Virginie</firstname>
      <lastname>Collette</lastname>
      <categoryPro>Assistant</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
    <person key="polsys-2015-idp96944">
      <firstname>Irphane</firstname>
      <lastname>Khan</lastname>
      <categoryPro>Assistant</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>UPMC, Assistant</moreinfo>
    </person>
    <person key="polsys-2017-idp211712">
      <firstname>Azzeddine</firstname>
      <lastname>Saidani</lastname>
      <categoryPro>Assistant</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
  </team>
  <presentation id="uid2">
    <bodyTitle>Overall Objectives</bodyTitle>
    <subsection id="uid3" level="1">
      <bodyTitle>Overall Objectives</bodyTitle>
      <p>The main focus of the <span class="smallcap" align="left">PolSys</span> project is to solve systems of
polynomial equations.</p>
      <p>Our main objectives are:</p>
      <simplelist>
        <li id="uid4">
          <p noindent="true"><b>Fundamental Algorithms and Structured Systems.</b> The
objective is to propose fast exponential exact algorithms for
solving polynomial equations and to identify large classes of
structured polynomial systems which can be solved in polynomial
time.</p>
        </li>
        <li id="uid5">
          <p noindent="true"><b>Solving Systems over the Reals and Applications.</b> For
positive dimensional systems basic questions over the reals may be
very difficult (for instance testing the existence of solutions)
but also very useful in applications (e.g. global optimization
problems). We plan to propose efficient algorithms and
implementations to address the most important issues: computing
sample points in the real solution sets, decide if two such sample
points can be path-connected and, as a long term objective,
perform quantifier elimination over the reals (computing a
quantifier-free formula which is equivalent to a given quantified
boolean formula of polynomial equations/inequalities).</p>
        </li>
        <li id="uid6">
          <p noindent="true"><b>Dedicated Algebraic Computation and Linear Algebra.</b>
While linear algebra is a key step in the computation of Gröbner
bases, the matrices generated by the algorithms <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><msub><mi>F</mi><mn>4</mn></msub><mo>/</mo><msub><mi>F</mi><mn>5</mn></msub></mrow></math></formula>
have specific structures (quasi block triangular). The objective
is to develop a dedicated efficient multi-core linear algebra
package as the basis of a future open source library for computing
Gröbner bases.</p>
        </li>
        <li id="uid7">
          <p noindent="true"><b>Solving Systems in Finite Fields, Applications in
Cryptology and Algebraic Number Theory.</b> We propose to develop a
systematic use of <i>structured systems</i> in Algebraic
Cryptanalysis. We want to improve the efficiency and to predict
the theoretical complexity of such attacks. We plan to demonstrate
the power of algebraic techniques in new areas of cryptography
such as Algebraic Number Theory (typically, in curve based
cryptography).</p>
        </li>
      </simplelist>
    </subsection>
  </presentation>
  <fondements id="uid8">
    <bodyTitle>Research Program</bodyTitle>
    <subsection id="uid9" level="1">
      <bodyTitle>Introduction</bodyTitle>
      <p>Polynomial system solving is a fundamental problem in Computer
Algebra with many applications in cryptography, robotics, biology,
error correcting codes, signal theory, ... Among all available
methods for solving polynomial systems, computation of Gröbner
bases remains one of the most powerful and versatile method since it
can be applied in the continuous case (rational coefficients) as
well as in the discrete case (finite fields). Gröbner bases are
also building blocks for higher level algorithms who compute real
sample points in the solution set of polynomial systems, decide
connectivity queries and quantifier elimination over the reals. The
major challenge facing the designer or the user of such algorithms
is the intrinsic exponential behaviour of the complexity for
computing Gröbner bases. The current proposal is an attempt to
tackle these issues in a number of different ways: improve the
efficiency of the fundamental algorithms (even when the complexity
is exponential), develop high performance implementation exploiting
parallel computers, and investigate new classes of structured
algebraic problems where the complexity drops to polynomial time.</p>
    </subsection>
    <subsection id="uid10" level="1">
      <bodyTitle>Fundamental Algorithms
and Structured Systems</bodyTitle>
      <participants>
        <person key="polsys-2014-idp66592">
          <firstname>Jérémy</firstname>
          <lastname>Berthomieu</lastname>
        </person>
        <person key="polsys-2014-idm27936">
          <firstname>Jean-Charles</firstname>
          <lastname>Faugère</lastname>
        </person>
        <person key="polsys-2014-idp72288">
          <firstname>Guénaël</firstname>
          <lastname>Renault</lastname>
        </person>
        <person key="polsys-2014-idp73616">
          <firstname>Mohab</firstname>
          <lastname>Safey El Din</lastname>
        </person>
        <person key="polsys-2014-idm26432">
          <firstname>Elias</firstname>
          <lastname>Tsigaridas</lastname>
        </person>
        <person key="polsys-2014-idm25184">
          <firstname>Dongming</firstname>
          <lastname>Wang</lastname>
        </person>
        <person key="polsys-2014-idp101344">
          <firstname>Matías</firstname>
          <lastname>Bender</lastname>
        </person>
        <person key="polsys-2017-idp199328">
          <firstname>Thi Xuan</firstname>
          <lastname>Vu</lastname>
        </person>
      </participants>
      <p>Efficient algorithms
<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><msub><mi>F</mi><mn>4</mn></msub><mo>/</mo><msub><mi>F</mi><mn>5</mn></msub></mrow></math></formula> <footnote id="uid11" id-text="1">J.-C.
Faugère. <i>A new efficient algorithm for computing
Gröbner bases without reduction to zero (F5).</i> In Proceedings of
ISSAC '02, pages 75-83, New York, NY, USA, 2002. ACM.</footnote> for
computing the Gröbner basis of a polynomial system rely heavily on
a connection with linear algebra. Indeed, these algorithms reduce
the Gröbner basis computation to a sequence of Gaussian
eliminations on several submatrices of the so-called Macaulay matrix
in some degree. Thus, we expect to improve the existing algorithms
by</p>
      <p noindent="true"><i>(i)</i> developing dedicated linear algebra routines
performing the Gaussian elimination steps: this is precisely the
objective 2 described below;</p>
      <p noindent="true"><i>(ii)</i> generating smaller or
simpler matrices to which we will apply Gaussian elimination.</p>
      <p noindent="true">We
describe here our goals for the latter problem. First, we focus on
algorithms for computing a Gröbner basis of <i>general
polynomial systems</i>. Next, we present our goals on the
development of dedicated algorithms for computing Gröbner bases of
<i>structured polynomial systems</i> which arise in various
applications.</p>
      <p noindent="true" spacebefore="6.0pt"><b>Algorithms for general systems.</b> Several
degrees of freedom are available to the designer of a Gröbner
basis algorithm to generate the matrices occurring during the
computation. For instance, it would be desirable to obtain matrices
which would be almost triangular or very sparse. Such a goal can be
achieved by considering various interpretations of the <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msub><mi>F</mi><mn>5</mn></msub></math></formula>
algorithm with respect to different monomial orderings. To address
this problem, the tight complexity results obtained for <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msub><mi>F</mi><mn>5</mn></msub></math></formula>
will be used to help in the design of such a general algorithm. To
illustrate this point, consider the important problem of solving
boolean polynomial systems; it might be interesting to preserve the
sparsity of the original equations and, at the same time, using the
fact that overdetermined systems are much easier to solve.</p>
      <p noindent="true" spacebefore="6.0pt"><b>Algorithms dedicated to </b><i><b>structured</b></i><b>
polynomial systems.</b> A complementary approach is to exploit the
structure of the input polynomials to design specific
algorithms. Very often, problems coming from applications are not
random but are highly structured. The specific nature of these
systems may vary a lot: some polynomial systems can be sparse (when
the number of terms in each equation is low), overdetermined (the
number of the equations is larger than the number of variables),
invariants by the action of some finite groups, multi-linear (each
equation is linear w.r.t. to one block of variables) or more
generally multihomogeneous. In each case, the ultimate goal is to
identify large classes of problems whose theoretical/practical
complexity drops and to propose in each case dedicated algorithms.</p>
    </subsection>
    <subsection id="uid12" level="1">
      <bodyTitle>Solving Systems over the Reals
and Applications.</bodyTitle>
      <participants>
        <person key="polsys-2014-idp73616">
          <firstname>Mohab</firstname>
          <lastname>Safey El Din</lastname>
        </person>
        <person key="polsys-2014-idm26432">
          <firstname>Elias</firstname>
          <lastname>Tsigaridas</lastname>
        </person>
        <person key="polsys-2014-idp69456">
          <firstname>Daniel</firstname>
          <lastname>Lazard</lastname>
        </person>
        <person key="polsys-2014-idp89656">
          <firstname>Ivan</firstname>
          <lastname>Bannwarth</lastname>
        </person>
        <person key="polsys-2017-idp199328">
          <firstname>Thi Xuan</firstname>
          <lastname>Vu</lastname>
        </person>
      </participants>
      <p>We shall develop algorithms for solving polynomial systems over
complex/real numbers. Again, the goal is to extend significantly
the range of reachable applications using algebraic techniques based
on Gröbner bases and dedicated linear algebra routines. Targeted
application domains are global optimization problems, stability of
dynamical systems (e.g. arising in biology or in control theory) and
theorem proving in computational geometry.</p>
      <p>The following functionalities shall be requested by the end-users:</p>
      <p noindent="true"><i>(i)</i> deciding the emptiness of the real solution set of systems
of polynomial equations and inequalities,</p>
      <p noindent="true"><i>(ii)</i> quantifier
elimination over the reals or complex numbers,</p>
      <p noindent="true"><i>(iii)</i>
answering
connectivity queries for such real solution sets.</p>
      <p noindent="true">We will focus on these functionalities.</p>
      <p>We will develop algorithms based on the so-called critical point
method to tackle systems of equations and inequalities (problem <i>(i)</i>) . These techniques are based on solving 0-dimensional
polynomial systems encoding "critical points" which are defined by
the vanishing of minors of jacobian matrices (with polynomial
entries). Since these systems are highly structured, the expected
results of Objective 1 and 2 may allow us to obtain dramatic
improvements in the computation of Gröbner bases of such
polynomial systems. This will be the foundation of practically fast
implementations (based on singly exponential algorithms)
outperforming the current ones based on the historical Cylindrical
Algebraic Decomposition (CAD) algorithm (whose complexity is doubly
exponential in the number of variables). We will also develop
algorithms and implementations that allow us to analyze, at least
locally, the topology of solution sets in some specific
situations. A long-term goal is obviously to obtain an analysis of
the global topology.</p>
    </subsection>
    <subsection id="uid13" level="1">
      <bodyTitle>Low level implementation and
Dedicated Algebraic Computation and Linear Algebra.</bodyTitle>
      <participants>
        <person key="polsys-2014-idm27936">
          <firstname>Jean-Charles</firstname>
          <lastname>Faugère</lastname>
        </person>
        <person key="polsys-2014-idm26432">
          <firstname>Elias</firstname>
          <lastname>Tsigaridas</lastname>
        </person>
        <person key="vegas-2014-idp76336">
          <firstname>Olive</firstname>
          <lastname>Chakraborty</lastname>
        </person>
        <person key="polsys-2017-idp184512">
          <firstname>Jocelyn</firstname>
          <lastname>Ryckeghem</lastname>
        </person>
      </participants>
      <p>Here, the primary objective is to focus on <i>dedicated</i>
algorithms and software for the linear algebra steps in Gröbner
bases computations and for problems arising in Number Theory. As
explained above, linear algebra is a key step in the process of
computing efficiently Gröbner bases. It is then natural to develop
specific linear algebra algorithms and implementations to further
strengthen the existing software. Conversely, Gröbner bases
computation is often a key ingredient in higher level algorithms
from Algebraic Number Theory. In these cases, the algebraic problems
are very particular and specific. Hence dedicated Gröbner bases
algorithms and implementations would provide a better efficiency.</p>
      <p noindent="true" spacebefore="6.0pt"><b>Dedicated linear algebra tools.</b>
The <span class="smallcap" align="left">FGb</span>library is
an efficient one for Gröbner bases computations which can be
used, for instance, via <span class="smallcap" align="left">Maple</span>. However, the library is
sequential. A goal of the project is to extend its efficiency to new
trend parallel architectures such as clusters of multi-processor
systems in order to tackle a broader class of problems for several
applications. Consequently, our first aim is to provide a durable,
long term software solution, which will be the successor of the
existing <span class="smallcap" align="left">FGb</span> library. To achieve this goal, we will first
develop a high performance linear algebra package (under the LGPL
license). This could be organized in the form of a collaborative
project between the members of the team. The objective is not to
develop a general library similar to the <span class="smallcap" align="left">Linbox</span> project but to
propose a dedicated linear algebra package taking into account the
specific properties of the matrices generated by the Gröbner bases
algorithms. Indeed these matrices are sparse (the actual sparsity
depends strongly on the application), almost block triangular and
not necessarily of full rank. Moreover, most of the pivots are known
at the beginning of the computation. In practice, such matrices are
huge (more than <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mn>10</mn><mn>6</mn></msup></math></formula>
columns) but taking into account their shape may allow us to speed
up the computations by one or several orders of magnitude. A variant
of a Gaussian elimination algorithm together with a corresponding C
implementation has been presented. The main peculiarity is the
order in which the operations are performed. This will be the kernel
of the new linear algebra library that will be developed.</p>
      <p>Fast linear algebra packages would also benefit to the
transformation of a Gröbner basis of a zero–dimensional ideal
with respect to a given monomial ordering into a Gröbner basis
with respect to another ordering. In the generic case at least, the
change of ordering is equivalent to the computation of the minimal
polynomial of a so-called multiplication matrix. By taking into
account the sparsity of this matrix, the computation of the
Gröbner basis can be done more efficiently using a variant of the
Wiedemann algorithm. Hence, our goal is also to obtain a dedicated
high performance library for transforming (i.e. change ordering)
Gröbner bases.</p>
      <p noindent="true" spacebefore="6.0pt"><b>Dedicated algebraic tools for Algebraic
Number Theory.</b> Recent results in Algebraic Number Theory tend to
show that the computation of Gröbner basis is a key step toward
the resolution of difficult problems in this domain
<footnote id="uid14" id-text="2"> P. Gaudry, <i>Index calculus for abelian
varieties of small dimension and the elliptic curve discrete
logarithm problem</i>, Journal of Symbolic Computation 44,12 (2009)
pp. 1690-1702</footnote>. Using existing resolution methods is simply not
enough to solve relevant problems. The main algorithmic bottleneck
to overcome is to adapt the Gröbner basis computation step to the
specific problems. Typically, problems coming from Algebraic Number
Theory usually have a lot of symmetries or the input systems are
very structured. This is the case in particular for problems coming
from the algorithmic theory of Abelian varieties over finite fields
<footnote id="uid15" id-text="3"> e.g. point counting, discrete logarithm, isogeny.</footnote>
where the objects are represented by polynomial system and are
endowed with intrinsic group actions. The main goal here is to
provide dedicated algebraic resolution algorithms and
implementations for solving such problems. We do not restrict our
focus on problems in positive characteristic. For instance, tower of
algebraic fields can be viewed as triangular sets; more generally,
related problems (e.g. effective Galois theory) which can be
represented by polynomial systems will receive our attention. This
is motivated by the fact that, for example, computing small integer
solutions of Diophantine polynomial systems in connection with
Coppersmith's method would also gain in efficiency by using a
dedicated Gröbner bases computations step.</p>
    </subsection>
    <subsection id="uid16" level="1">
      <bodyTitle>Solving Systems in Finite Fields,
Applications in Cryptology and Algebraic Number Theory.</bodyTitle>
      <participants>
        <person key="polsys-2014-idp66592">
          <firstname>Jérémy</firstname>
          <lastname>Berthomieu</lastname>
        </person>
        <person key="polsys-2014-idm27936">
          <firstname>Jean-Charles</firstname>
          <lastname>Faugère</lastname>
        </person>
        <person key="polsys-2014-idp70968">
          <firstname>Ludovic</firstname>
          <lastname>Perret</lastname>
        </person>
        <person key="polsys-2014-idp72288">
          <firstname>Guénaël</firstname>
          <lastname>Renault</lastname>
        </person>
        <person key="vegas-2014-idp76336">
          <firstname>Olive</firstname>
          <lastname>Chakraborty</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Nagardjun</firstname>
          <lastname>Chinthamani</lastname>
        </person>
        <person key="polsys-2017-idp196864">
          <firstname>Solane</firstname>
          <lastname>El Hirch</lastname>
        </person>
        <person key="polsys-2017-idp184512">
          <firstname>Jocelyn</firstname>
          <lastname>Ryckeghem</lastname>
        </person>
      </participants>
      <p>Here, we focus on solving polynomial systems over finite fields
(i.e. the discrete case) and the corresponding applications
(Cryptology, Error Correcting Codes, ...). Obviously this
objective can be seen as an application of the results of the two
previous objectives. However, we would like to emphasize that it is
also the source of new theoretical problems and practical
challenges. We propose to develop a systematic use of <i>structured systems</i> in <i>algebraic cryptanalysis</i>.</p>
      <p noindent="true"><i>(i)</i> So far, breaking a cryptosystem using algebraic
techniques could be summarized as modeling the problem by algebraic
equations and then computing a, usually, time consuming Gröbner
basis. A new trend in this field is to require a theoretical
complexity analysis. This is needed to explain the behavior of the
attack but also to help the designers of new cryptosystems to
propose actual secure parameters.</p>
      <p noindent="true"><i>(ii)</i> To assess the
security of several cryptosystems in symmetric cryptography (block
ciphers, hash functions, ...), a major difficulty is the size of
the systems involved for this type of attack. More specifically,
the bottleneck
is the size of the linear algebra problems generated during a
Gröbner basis computation.</p>
      <p>We propose to develop a systematic use of <i>structured systems</i>
in <i>algebraic cryptanalysis</i>.</p>
      <p>The first objective is to build on the recent breakthrough in
attacking McEliece's cryptosystem: it is the first structural
weakness observed on one of the oldest public key cryptosystem. We
plan to develop a well founded framework for assessing the security
of public key cryptosystems based on coding theory from the
algebraic cryptanalysis point of view. The answer to this issue is
strongly related to the complexity of solving bihomogeneous systems
(of bidegree <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mo>(</mo><mn>1</mn><mo>,</mo><mi>d</mi><mo>)</mo></mrow></math></formula>).
We also plan to use the recently gained understanding on the
complexity of structured systems in other areas of cryptography.
For instance, the MinRank problem – which can be modeled as an
overdetermined system of bilinear equations – is at the heart of
the structural attack proposed by Kipnis and Shamir against HFE (one of the most well known multivariate public cryptosystem). The
same family of structured systems arises in the algebraic
cryptanalysis of the Discrete Logarithmic Problem (DLP) over curves
(defined over some finite fields). More precisely, some bilinear
systems appear in the polynomial modeling the points decomposition
problem. Moreover, in this context, a natural group action can also
be used during the resolution of the considered polynomial system.</p>
      <p>Dedicated tools for linear algebra problems generated during the
Gröbner basis computation will be used in algebraic cryptanalysis.
The promise of considerable algebraic computing power beyond the
capability of any standard computer algebra system will enable us to
attack various cryptosystems or at least to propose accurate secure
parameters for several important cryptosystems. Dedicated linear
tools are thus needed to tackle these problems. From a theoretical
perspective, we plan to further improve the theoretical complexity
of the hybrid method and to investigate the problem of solving
polynomial systems with noise, i.e. some equations of the system are
incorrect. The hybrid method is a specific method for solving
polynomial systems over finite fields. The idea is to mix exhaustive
search and Gröbner basis computation to take advantage of the
over-determinacy of the resulting systems.</p>
      <p>Polynomial system with noise is currently emerging as a problem of
major interest in cryptography. This problem is a key to further
develop new applications of algebraic techniques; typically in
side-channel and statistical attacks. We also emphasize that
recently a connection has been established between several classical
lattice problems (such as the Shortest Vector Problem), polynomial
system solving and polynomial systems with noise. The main issue is
that there is no sound algorithmic and theoretical framework for
solving polynomial systems with noise. The development of such
framework is a long-term objective.
</p>
    </subsection>
  </fondements>
  <highlights id="uid17">
    <bodyTitle>Highlights of the Year</bodyTitle>
    <subsection id="uid18" level="1">
      <bodyTitle>Highlights of the Year</bodyTitle>
      <p>Dongming Wang has been elected as a Member of the Academia Europaea.</p>
      <p>Elias Tsigaridas was awarded an ANR “Jeune Chercheur Grant”.
The title of the project is <tt>GALOP</tt> (Games through the lens
of ALgebra and
OPptimization)</p>
    </subsection>
  </highlights>
  <logiciels id="uid19">
    <bodyTitle>New Software and Platforms</bodyTitle>
    <subsection id="uid20" level="1">
      <bodyTitle>Epsilon</bodyTitle>
      <p><span class="smallcap" align="left">Functional Description:</span> Epsilon is a library of functions implemented in Maple and Java for polynomial elimination and decomposition with (geometric) applications.</p>
      <simplelist>
        <li id="uid21">
          <p noindent="true">Contact: Dongming Wang</p>
        </li>
        <li id="uid22">
          <p noindent="true">URL: <ref xlink:href="http://wang.cc4cm.org/epsilon/index.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>wang.<allowbreak/>cc4cm.<allowbreak/>org/<allowbreak/>epsilon/<allowbreak/>index.<allowbreak/>html</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid23" level="1">
      <bodyTitle>FGb</bodyTitle>
      <p><span class="smallcap" align="left">Keywords:</span> Gröbner bases - Nonlinear system - Computer algebra</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> FGb is a powerful software for computing Gröbner bases. It includes the new generation of algorihms for computing Gröbner bases polynomial systems (mainly the F4, F5 and FGLM algorithms). It is implemented in C/C++ (approximately 250000 lines), standalone servers are available on demand. Since 2006, FGb is dynamically linked with Maple software (version 11 and higher) and is part of the official distribution of this software.</p>
      <simplelist>
        <li id="uid24">
          <p noindent="true">Participant: Jean Charles Faugere</p>
        </li>
        <li id="uid25">
          <p noindent="true">Contact: Jean-Charles Faugère</p>
        </li>
        <li id="uid26">
          <p noindent="true">URL: <ref xlink:href="http://www-polsys.lip6.fr/~jcf/FGb/index.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www-polsys.<allowbreak/>lip6.<allowbreak/>fr/<allowbreak/>~jcf/<allowbreak/>FGb/<allowbreak/>index.<allowbreak/>html</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid27" level="1">
      <bodyTitle>FGb Light</bodyTitle>
      <p><span class="smallcap" align="left">Functional Description:</span> Gröbner basis computation modulo p (p is a prime integer of 16 bits).</p>
      <simplelist>
        <li id="uid28">
          <p noindent="true">Participant: Jean-Charles Faugère</p>
        </li>
        <li id="uid29">
          <p noindent="true">Contact: Jean-Charles Faugère</p>
        </li>
        <li id="uid30">
          <p noindent="true">URL: <ref xlink:href="http://www-polsys.lip6.fr/~jcf/FGb/index.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www-polsys.<allowbreak/>lip6.<allowbreak/>fr/<allowbreak/>~jcf/<allowbreak/>FGb/<allowbreak/>index.<allowbreak/>html</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid31" level="1">
      <bodyTitle>GBLA</bodyTitle>
      <p><span class="smallcap" align="left">Functional Description:</span> GBLA is an open source C library for linear algebra specialized for eliminating matrices generated during Gröbner basis computations in algorithms like F4 or F5.</p>
      <simplelist>
        <li id="uid32">
          <p noindent="true">Contact: Jean-Charles Faugère</p>
        </li>
        <li id="uid33">
          <p noindent="true">URL: <ref xlink:href="http://www-polsys.lip6.fr/~jcf/GBLA/index.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www-polsys.<allowbreak/>lip6.<allowbreak/>fr/<allowbreak/>~jcf/<allowbreak/>GBLA/<allowbreak/>index.<allowbreak/>html</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid34" level="1">
      <bodyTitle>HFEBoost</bodyTitle>
      <p><span class="smallcap" align="left">Functional Description:</span> Public-key cryptography system enabling an authentification of dematerialized data.</p>
      <simplelist>
        <li id="uid35">
          <p noindent="true">Authors: Jean-Charles Faugère and Ludovic Perret</p>
        </li>
        <li id="uid36">
          <p noindent="true">Partner: UPMC</p>
        </li>
        <li id="uid37">
          <p noindent="true">Contact: Jean-Charles Faugère</p>
        </li>
        <li id="uid38">
          <p noindent="true">URL: <ref xlink:href="http://www-polsys.lip6.fr/Links/hfeboost.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www-polsys.<allowbreak/>lip6.<allowbreak/>fr/<allowbreak/>Links/<allowbreak/>hfeboost.<allowbreak/>html</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid39" level="1">
      <bodyTitle>RAGlib</bodyTitle>
      <p>
        <i>Real Algebraic Geometry library</i>
      </p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> RAGLib is a powerful library, written in Maple, dedicated to solving over the reals polynomial systems. It is based on the FGb library for computing Grobner bases. It provides functionalities for deciding the emptiness and/or computing sample points to real solution sets of polynomial systems of equations and inequalities. This library provides implementations of the state-of-the-art algorithms with the currently best known asymptotic complexity for those problems.</p>
      <simplelist>
        <li id="uid40">
          <p noindent="true">Contact: Mohab Safey El Din</p>
        </li>
        <li id="uid41">
          <p noindent="true">URL: <ref xlink:href="http://www-polsys.lip6.fr/~safey/RAGLib/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www-polsys.<allowbreak/>lip6.<allowbreak/>fr/<allowbreak/>~safey/<allowbreak/>RAGLib/</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid42" level="1">
      <bodyTitle>SLV</bodyTitle>
      <p><span class="smallcap" align="left">Functional Description:</span> SLV is a software package in C that provides routines for isolating (and subsequently refine) the real roots of univariate polynomials with integer or rational coefficients based on subdivision algorithms and on the continued fraction expansion of real numbers. Special attention is given so that the package can handle polynomials that have degree several thousands and size of coefficients hundrends of Megabytes. Currently the code consists of approx. 5000 lines.</p>
      <simplelist>
        <li id="uid43">
          <p noindent="true">Contact: Elias Tsigaridas</p>
        </li>
        <li id="uid44">
          <p noindent="true">URL: <ref xlink:href="http://www-polsys.lip6.fr/~elias/soft" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www-polsys.<allowbreak/>lip6.<allowbreak/>fr/<allowbreak/>~elias/<allowbreak/>soft</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid45" level="1">
      <bodyTitle>SPECTRA</bodyTitle>
      <p>
        <i>Semidefinite Programming solved Exactly with Computational Tools of Real Algebra</i>
      </p>
      <p noindent="true"><span class="smallcap" align="left">Keyword:</span> Linear Matrix Inequalities</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> SPECTRA is a Maple library devoted to solving exactly Semi-Definite Programs. It can handle rank constraints on the solution. It is based on the FGb library for computing Gröbner bases and provides either certified numerical approximations of the solutions or exact representations thereof.</p>
      <simplelist>
        <li id="uid46">
          <p noindent="true">Contact: Mohab Safey El Din</p>
        </li>
        <li id="uid47">
          <p noindent="true">URL: <ref xlink:href="http://homepages.laas.fr/henrion/software/spectra/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>homepages.<allowbreak/>laas.<allowbreak/>fr/<allowbreak/>henrion/<allowbreak/>software/<allowbreak/>spectra/</ref></p>
        </li>
      </simplelist>
    </subsection>
  </logiciels>
  <resultats id="uid48">
    <bodyTitle>New Results</bodyTitle>
    <subsection id="uid49" level="1">
      <bodyTitle>Fundamental algorithms and structured
polynomial systems</bodyTitle>
      <subsection id="cid1" level="2">
        <bodyTitle>Linear Algebra for Computing Gröbner Bases of Linear
Recursive Multidimensional Sequences</bodyTitle>
        <p>The so-called Berlekamp – Massey – Sakata algorithm computes a
Gröbner basis of a 0-dimensional ideal of relations satisfied by
an input table. It extends the Berlekamp – Massey algorithm to
<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>n</mi></math></formula>-dimensional tables, for <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mi>n</mi><mo>&gt;</mo><mn>1</mn></mrow></math></formula>.</p>
        <p>In <ref xlink:href="#polsys-2017-bid0" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we investigate this problem and
design several algorithms for computing such a Gröbner basis of an
ideal of relations using linear algebra techniques. The first one
performs a lot of table queries and is analogous to a change of
variables on the ideal of relations.</p>
        <p>As each query to the table can be expensive, we design a second
algorithm requiring fewer queries, in general. This
<span class="smallcap" align="left">FGLM</span>-like algorithm allows us to compute the relations of the
table by extracting a full rank submatrix of a <i>multi-Hankel</i>
matrix (a multivariate generalization of Hankel matrices).</p>
        <p>Under some additional assumptions, we make a third, adaptive,
algorithm and reduce further the number of table queries. Then, we
relate the number of queries of this third algorithm to the
<i>geometry</i> of the final staircase and we show that it is
essentially linear in the size of the output when the staircase is
convex. As a direct application to this, we decode <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>n</mi></math></formula>-cyclic codes,
a generalization in dimension <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>n</mi></math></formula> of Reed Solomon codes.</p>
        <p>We show that the multi-Hankel matrices are heavily structured when
using the <span class="smallcap" align="left">LEX</span> ordering and that we can speed up the
computations using fast algorithms for quasi-Hankel matrices.
Finally, we design algorithms for computing the generating series of a
linear recursive table.</p>
      </subsection>
      <subsection id="cid2" level="2">
        <bodyTitle>In-depth comparison of the Berlekamp – Massey – Sakata and
the Scalar-FGLM algorithms: the non adaptive variants</bodyTitle>
        <p>In <ref xlink:href="#polsys-2017-bid1" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we compare thoroughly the
<span class="smallcap" align="left">Berlekamp – Massey – Sakata</span> algorithm and the
<span class="smallcap" align="left">Scalar-FGLM</span> algorithm, which compute both the ideal of
relations of a multidimensional linear recurrent sequence.</p>
        <p>Suprisingly, their behaviors differ. We detail in which way they do
and prove that it is not possible to tweak one of the algorithms in
order to mimic exactly the behavior of the other.</p>
      </subsection>
      <subsection id="cid3" level="2">
        <bodyTitle>Resultants and Discriminants for Bivariate Tensor-product Polynomials</bodyTitle>
        <p>Optimal resultant formulas have been systematically constructed mostly
for <i>unmixed polynomial systems</i>, that is, systems of polynomials
which all have the same support. However, such a condition is
restrictive, since <i>mixed systems</i> of equations arise frequently
in practical problems.
In <ref xlink:href="#polsys-2017-bid2" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> we present a square,
<i>Koszul-type</i> matrix expressing the resultant of arbitrary
(mixed) bivariate <i>tensor-product systems</i>. The formula
generalizes the classical Sylvester matrix of two univariate
polynomials, since it expresses a map of <i>degree one</i>, that is,
the entries of the matrix are simply coefficients of the input
polynomials.
Interestingly, the matrix expresses a primal-dual multiplication map,
that is, the tensor product of a univariate multiplication map with a
map expressing derivation in a dual space. Moreover, for
tensor-product systems with more than two (affine) variables, we prove
an impossibility result: no universal degree-one formulas are
possible, unless the system is unmixed.
We also present applications of the new construction in the
computation of discriminants and mixed discriminants as well as in
solving systems of bivariate polynomials with tensor-product
structure.</p>
      </subsection>
      <subsection id="cid4" level="2">
        <bodyTitle>Sparse Rational Univariate Representation</bodyTitle>
        <p>In <ref xlink:href="#polsys-2017-bid3" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> we present explicit worst case
degree and height bounds for the rational univariate representation of
the isolated roots of polynomial systems based on mixed volume. We
base our estimations on height bounds of resultants and we consider
the case of 0-dimensional, positive dimensional, and parametric
polynomial systems.</p>
        <p>Multi-homogeneous polynomial systems arise in many applications. In
<ref xlink:href="#polsys-2017-bid4" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we provide bit complexity estimates
for representing the solutions of these systems. These are the best
currently known bounds. The assumptions essentially imply that the
Jacobian matrix of the system under study has maximal rank at the
solution set and that this solution set is finite.</p>
        <p>We do not only obtain bounds but an algorithm is also given for
solving such systems. We give bit complexity estimates which, up to a
few extra other factors, are quadratic in the number of solutions and
linear in the height of the input system, under some genericity
assumptions.</p>
        <p>The algorithm is probabilistic and a probability analysis is provided.
Next, we apply these results to the problem of optimizing a linear map
on the real trace of an algebraic set. Under some genericity
assumptions, we provide bit complexity estimates for solving this
polynomial minimization problem.</p>
      </subsection>
      <subsection id="cid5" level="2">
        <bodyTitle>Improving Root Separation Bounds</bodyTitle>
        <p>Let <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>f</mi></math></formula> be a polynomial (or polynomial system) with all simple
roots. The root separation of <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>f</mi></math></formula> is the minimum of the pair-wise
distances between the complex roots. A root separation bound is a
lower bound on the root separation. Finding a root separation bound is
a fundamental problem, arising in numerous disciplines. In
<ref xlink:href="#polsys-2017-bid5" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> we present two new root separation bounds:
one univariate bound, and one multivariate bound. The new bounds
improve on the old bounds in two ways: (1) The new bounds are usually
significantly bigger (hence better) than the previous bounds. (2) The
new bounds scale correctly, unlike the previous bounds. Crucially, the
new bounds are not harder to compute than the previous bounds.</p>
      </subsection>
      <subsection id="cid6" level="2">
        <bodyTitle>Accelerated Approximation of the Complex Roots and Factors of a Univariate Polynomial</bodyTitle>
        <p>The known algorithms approximate the roots of a complex univariate
polynomial in nearly optimal arithmetic and Boolean time. They are,
however, quite involved and require a high precision of computing when
the degree of the input polynomial is large, which causes numerical
stability problems. In <ref xlink:href="#polsys-2017-bid6" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> we observe that these
difficulties do not appear at the initial stages of the algorithms,
and in our present paper we extend one of these stages, analyze it,
and avoid the cited problems, still achieving the solution within a
nearly optimal complexity estimates, provided that some mild initial
isolation of the roots of the input polynomial has been ensured. The
resulting algorithms promise to be of some practical value for
root-finding and can be extended to the problem of polynomial
factorization, which is of interest on its own right. We conclude with
outlining such an extension, which enables us to cover the cases of
isolated multiple roots and root clusters.</p>
      </subsection>
      <subsection id="cid7" level="2">
        <bodyTitle>Nearly optimal computations with structured matrices</bodyTitle>
        <p>In <ref xlink:href="#polsys-2017-bid7" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> we estimate the Boolean complexity of
multiplication of structured matrices by a vector and the solution of
nonsingular linear systems of equations with these matrices. We study
four basic and most popular classes, that is, Toeplitz, Hankel, Cauchy
and Vandermonde matrices, for which the cited computational problems
are equivalent to the task of polynomial multiplication and division
and polynomial and rational multipoint evaluation and
interpolation. The Boolean cost estimates for the latter problems have
been obtained by Kirrinnis, except for rational interpolation. We
supply them now as well as the Boolean complexity estimates for the
important problems of multiplication of transposed Vandermonde matrix
and its inverse by a vector. All known Boolean cost estimates
for such problems rely on using Kronecker product. This implies
the d-fold precision increase for the <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>d</mi></math></formula>-th degree output, but we
avoid such an increase by relying on distinct techniques based on
employing FFT. Furthermore we simplify the analysis and make it more
transparent by combining the representations of our tasks and
algorithms both via structured matrices and via polynomials and
rational functions. This also enables further extensions of our
estimates to cover Trummer’s important problem and computations with
the popular classes of structured matrices that generalize the four
cited basic matrix classes, as well as the transposed Vandermonde
matrices. It is known that the solution of Toeplitz, Hankel, Cauchy,
Vandermonde, and transposed Vandermonde linear systems of equations is
generally prone to numerical stability problems, and numerical
problems arise even for multiplication of Cauchy, Vandermonde, and
transposed Vandermonde matrices by a vector. Thus our FFT-based
results on the Boolean complexity of these important computations
could be quite interesting because our estimates are reasonable even
for more general classes of structured matrices, showing rather
moderate growth of the complexity as the input size increases.</p>
      </subsection>
      <subsection id="cid8" level="2">
        <bodyTitle>Sliding solutions of second-order differential equations with
discontinuous right-hand side</bodyTitle>
        <p>In <ref xlink:href="#polsys-2017-bid8" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we consider second-order ordinary
differential equations with discontinuous right-hand side. We analyze
the concept of solution of this kind of equations and determine
analytical conditions that are satisfied by typical
solutions. Moreover, the existence and uniqueness of solutions and
sliding solutions are studied.</p>
      </subsection>
      <subsection id="cid9" level="2">
        <bodyTitle>Sparse <span class="smallcap" align="left">FGLM</span> algorithms</bodyTitle>
        <p>Given a zero-dimensional ideal <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mi>I</mi><mo>⊂</mo><mi>𝕂</mi><mo>[</mo><msub><mi>x</mi><mn>1</mn></msub><mo>,</mo><mo>...</mo><mo>,</mo><msub><mi>x</mi><mi>n</mi></msub><mo>]</mo></mrow></math></formula> of
degree <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>D</mi></math></formula>, the transformation of the ordering of its Gröbner basis
from <span class="smallcap" align="left">DRL</span> to <span class="smallcap" align="left">LEX</span> is a key step in polynomial system
solving and turns out to be the bottleneck of the whole solving
process. Thus it is of crucial importance to design efficient
algorithms to perform the change of ordering. The main contributions
of <ref xlink:href="#polsys-2017-bid9" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> are several efficient methods for the
change of ordering which take advantage of the sparsity of
multiplication matrices in the classical <i>FGLM</i>
algorithm. Combining all these methods, we propose a deterministic
top-level algorithm that automatically detects which method to use
depending on the input. As a by-product, we have a fast implementation
that is able to handle ideals of degree over <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mn>40</mn><mo>,</mo><mn>000</mn></mrow></math></formula>. Such an
implementation outperforms the <i>Magma</i> and <i>Singular</i> ones, as
shown by our experiments. First for the shape position case, two
methods are designed based on the Wiedemann algorithm: the first is
probabilistic and its complexity to complete the change of ordering is
<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mi>O</mi><mo>(</mo><mi>D</mi><mrow><mo>(</mo><msub><mi>N</mi><mn>1</mn></msub><mo>+</mo><mi>n</mi><mo form="prefix">log</mo><mi>D</mi><mo>)</mo></mrow><mo>)</mo></mrow></math></formula>, where <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msub><mi>N</mi><mn>1</mn></msub></math></formula> is the number of nonzero entries of a
multiplication matrix; the other is deterministic and computes the
<span class="smallcap" align="left">LEX</span> Gröbner basis of <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msqrt><mi>I</mi></msqrt></math></formula> via Chinese Remainder
Theorem. Then for the general case, the designed method is
characterized by the Berlekamp–Massey–Sakata algorithm from Coding
Theory to handle the multi-dimensional linearly recurring
relations. Complexity analyses of all proposed methods are also
provided. Furthermore, for generic polynomial systems, we present an
explicit formula for the estimation of the sparsity of one main
multiplication matrix, and prove its construction is free. With the
asymptotic analysis of such sparsity, we are able to show for generic
systems the complexity above becomes
<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mi>O</mi><mo>(</mo><msqrt><mrow><mn>6</mn><mo>/</mo><mi>n</mi><mi>π</mi></mrow></msqrt><msup><mi>D</mi><mrow><mn>2</mn><mo>+</mo><mfrac><mrow><mi>n</mi><mo>-</mo><mn>1</mn></mrow><mi>n</mi></mfrac></mrow></msup><mo>)</mo></mrow></math></formula>.
</p>
      </subsection>
    </subsection>
    <subsection id="uid50" level="1">
      <bodyTitle>Solving Systems over the Reals and
Applications</bodyTitle>
      <subsection id="cid10" level="2">
        <bodyTitle>Answering connectivity queries in real algebraic sets</bodyTitle>
        <p>A roadmap for a semi-algebraic set <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>S</mi></math></formula> is a curve which has a
non-empty and connected intersection with all connected components
of <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>S</mi></math></formula>. Hence, this kind of object, introduced by Canny, can be used
to answer connectivity queries (with applications, for instance, to
motion planning) but has also become of central importance in
effective real algebraic geometry, since it is used in higher-level
algorithms. In <ref xlink:href="#polsys-2017-bid10" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we provide a
probabilistic algorithm which computes roadmaps for smooth and
bounded real algebraic sets. Its output size and running time are
polynomial in <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mrow><mo>(</mo><mi>n</mi><mi>D</mi><mo>)</mo></mrow><mrow><mi>n</mi><mo form="prefix">log</mo><mi>d</mi></mrow></msup></math></formula>, where <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>D</mi></math></formula> is the maximum of the
degrees of the input polynomials, <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>d</mi></math></formula> is the dimension of the set
under consideration and n is the number of variables. More
precisely, the running time of the algorithm is essentially
subquadratic in the output size. Even under our assumptions, it is
the first roadmap algorithm with output size and running time
polynomial in <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mrow><mo>(</mo><mi>n</mi><mi>D</mi><mo>)</mo></mrow><mrow><mi>n</mi><mo form="prefix">log</mo><mi>d</mi></mrow></msup></math></formula>.</p>
      </subsection>
      <subsection id="cid11" level="2">
        <bodyTitle>Polynomial optimization and semi-definite programming</bodyTitle>
        <p>In <ref xlink:href="#polsys-2017-bid11" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we describe our freely distributed Maple
library spectra, for Semidefinite Programming solved Exactly with
Computational Tools of Real Algebra. It solves linear matrix
inequalities, a fundamental object in effective real algebraic
geometry and polynomial optimization, with symbolic computation in
exact arithmetic and it is targeted to small-size, possibly
degenerate problems for which symbolic infeasibility or feasibility
certificates are required.</p>
        <p>The positive semidefinite rank of a convex body <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>C</mi></math></formula> is the size of
its smallest positive semi-definite formulation. In
<ref xlink:href="#polsys-2017-bid12" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we show that the positive semidefinite
rank of any convex body <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>C</mi></math></formula> is at least <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msqrt><mrow><mo form="prefix">log</mo><mo>(</mo><mi>d</mi><mo>)</mo></mrow></msqrt></math></formula> where <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>d</mi></math></formula>
is the smallest degree of a polynomial that vanishes on the boundary
of the polar of <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>C</mi></math></formula>. This improves on the existing bound which
relies on results from quantifier elimination. Our proof relies on
the Bézout bound applied to the Karush-Kuhn-Tucker conditions of
optimality. We discuss the connection with the algebraic degree of
semidefinite programming and show that the bound is tight (up to
constant factor) for random spectrahedra of suitable dimension.</p>
      </subsection>
      <subsection id="cid12" level="2">
        <bodyTitle>The Complexity of an Adaptive Subdivision Method for
Approximating Real Curves</bodyTitle>
        <p>In <ref xlink:href="#polsys-2017-bid13" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> we present the first complexity analysis
of the algorithm by Plantinga and Vegter for approximating real
implicit curves and surfaces. This approximation algorithm
certifies the topological correctness of the output using both
subdivision and interval arithmetic. In practice, it has been seen
to be quite efficient; our goal is to quantify this efficiency. We
focus on the subdivision step (and not the approximation step) of
the Plantinga and Vegter algorithm. We begin by extending the
subdivision step to arbitrary dimensions. We provide <i>a priori</i>
worst-case bounds on the complexity of this algorithm both in terms
of the number of subregions constructed and the bit complexity for
the construction. Then, we use continuous amortization to derive
adaptive bounds on the complexity of the subdivided region. We also
provide examples showing our bounds are tight.</p>
      </subsection>
    </subsection>
    <subsection id="uid51" level="1">
      <bodyTitle>Solving Systems in Finite Fields,
Applications in Cryptology and Algebraic Number Theory.</bodyTitle>
      <subsection id="cid13" level="2">
        <bodyTitle>Private Multiplication over Finite Fields</bodyTitle>
        <p>The notion of privacy in the probing model, introduced by Ishai,
Sahai, and Wagner in 2003, is nowadays frequently involved to assess
the security of circuits manipulating sensitive
information. However, provable security in this model still comes at
the cost of a significant overhead both in terms of arithmetic
complexity and randomness complexity. In <ref xlink:href="#polsys-2017-bid14" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>,
we deal with this issue for circuits processing multiplication over
finite fields. Our contributions are manifold. Extending the work of
Belaïd, Benhamouda, Passelègue, Prouff, Thillard, and Vergnaud at
Eurocrypt 2016, we introduce an algebraic characterization of the
privacy for multiplication in any finite field and we propose a
novel algebraic characterization for non-interference (a stronger
security notion in this setting). Then, we present two generic
constructions of multiplication circuits in finite fields that
achieve non-interference in the probing model. The second proposal
achieves a linear complexity in terms of randomness
consumption. This complexity is proved to be almost
optimal. Eventually, we show that our constructions can always be
instantiated in large enough finite fields.</p>
      </subsection>
      <subsection id="cid14" level="2">
        <bodyTitle>Convolutional Neural Networks with Data Augmentation Against
Jitter-Based Countermeasures - Profiling Attacks Without
Pre-processing</bodyTitle>
        <p>In the context of the security evaluation of cryptographic
implementations, profiling attacks (aka Template Attacks) play a
fundamental role. Nowadays the most popular Template Attack strategy
consists in approximating the information leakages by Gaussian
distributions. Nevertheless this approach suffers from the difficulty
to deal with both the traces misalignment and the high dimensionality
of the data. This forces the attacker to perform critical
preprocessing phases, such as the selection of the points of interest
and the temporal realignment of measurements. Some software and
hardware countermeasures have been conceived exactly to create such a
misalignment. In <ref xlink:href="#polsys-2017-bid15" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we propose an end-to-end
profiling attack strategy based on Deep Learning algorithms combined
with Data Augmentation strategies.</p>
      </subsection>
      <subsection id="cid15" level="2">
        <bodyTitle>Submissions to the <tt>NIST</tt> Post-Quantum Standardization Process</bodyTitle>
        <p>We have submitted three cryptosystems to the current process leads by
<tt>NIST</tt> for standardizing post-quantum public-key algorithms.</p>
        <subsection id="uid52" level="3">
          <bodyTitle><i>G</i>e<i>MSS</i></bodyTitle>
          <p>The acronym stands for a Gr<i>e</i>at Multivariate Signature Scheme <ref xlink:href="#polsys-2017-bid16" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. As suggested by its name, <i>G</i>e<i>MSS</i> is a multivariate-based signature scheme producing small signatures. It has a fast verification process, and a medium/large public-key. <i>G</i>e<i>MSS</i> is in direct lineage from <tt>QUARTZ</tt> and borrows some design rationale of the <tt>Gui</tt> multivariate
signature scheme.
The former schemes are built from the <i>Hidden Field Equations</i> crypotsystem (<tt>HFE</tt>) by using the so-called minus and vinegar modifiers.
It is fair to say that <tt>HFE</tt> and its variants, are the most studied schemes in multivariate cryptography. <tt>QUARTZ</tt> produces signatures of 128 bits for a security level of 80 bits and was submitted to the <i>Nessie Ecrypt</i> competition for public-key signatures. In contrast to many multivariate schemes, no practical attack has been reported against <tt>QUARTZ</tt>.
This is remarkable knowing the intense activity in the cryptanalysis of multivariate schemes.</p>
          <p><i>G</i>e<i>MSS</i> is a faster variant of <tt>QUARTZ</tt> that incorporates the
latest results in multivariate cryptography to reach higher security
levels than <tt>QUARTZ</tt> whilst improving efficiency.</p>
        </subsection>
        <subsection id="uid53" level="3">
          <bodyTitle>
            <i>DualModeMS</i>
          </bodyTitle>
          <p><i>DualModeMS</i>  <ref xlink:href="#polsys-2017-bid17" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>
is a multivariate-based signature scheme with a rather
peculiar property. Its public-key is small whilst the signature is
large. This is in sharp contrast with traditional multivariate
signature schemes based on the so-called <i>Matsumoto and Imai</i>
(<tt>MI</tt>) principle, such as <tt>QUARTZ</tt> or <tt>Gui</tt>, that produce
short signatures but have larger public-keys.</p>
          <p><i>DualModeMS</i> is based on the method proposed by A. Szepieniec,
W. Beullens, and B. Preneel at PQC'17 where they present a generic
technique permitting to transform any (<tt>MI</tt>-based multivariate
signature scheme into a new scheme with much shorter public-key but
larger signatures. This technique can be viewed as a <i>mode of
operations</i> that offers a new flexibility for <tt>MI</tt>-like
signature schemes. Thus, we believe that <i>DualModeMS</i> could also be
useful for others multivariate-based signature candidates proposed to
<tt>NIST</tt>.</p>
        </subsection>
        <subsection id="uid54" level="3">
          <bodyTitle>
            <i>CPFKM</i>
          </bodyTitle>
          <p><i>CPFKM</i> <ref xlink:href="#polsys-2017-bid18" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> is a based on the
problem of solving a system of noisy
non-linear polynomials, also known as the PoSSo with Noise
Problem. Our scheme largely borrows its design rationale from key
encapsulation schemes based on the Learning With Errors (LWE) problem
and its derivatives. The main motivation of building this scheme is to
have a key exchange and encapsulation scheme based on the hardness of
solving system of noisy polynomials.</p>
        </subsection>
      </subsection>
      <subsection id="cid16" level="2">
        <bodyTitle>The Point Decomposition Problem over Hyperelliptic Curves: toward efficient computations of Discrete Logarithms in even characteristic</bodyTitle>
        <p>Computing discrete logarithms is generically a difficult problem. For
divisor class groups of curves defined over extension fields, a
variant of the Index-Calculus called Decomposition attack is used, and
it can be faster than generic approaches. In this situation,
collecting the relations is done by solving multiple instances of the
Point <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>m</mi></math></formula>-Decomposition Problem (<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msub><mrow><mi>P</mi><mi>D</mi><mi>P</mi></mrow><mi>m</mi></msub></math></formula>). An instance of
this problem can be modelled as a zero-dimensional polynomial
system. Solving is done with Gröbner bases algorithms, where the
number of solutions of the system is a good indicator for the time
complexity of the solving process. For systems arising from a
<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msub><mrow><mi>P</mi><mi>D</mi><mi>P</mi></mrow><mi>m</mi></msub></math></formula> context, this number grows exponentially fast with
the extension degree. To achieve an efficient harvesting, this number
must be reduced as much as possible. Extending the elliptic case,
we introduce in <ref xlink:href="#polsys-2017-bid19" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> a notion of Summation
Ideals to describe <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msub><mrow><mi>P</mi><mi>D</mi><mi>P</mi></mrow><mi>m</mi></msub></math></formula> instances over higher genus
curves, and compare to Nagao's general approach to
<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msub><mrow><mi>P</mi><mi>D</mi><mi>P</mi></mrow><mi>m</mi></msub></math></formula>. In even characteristic we obtain reductions of the
number of solutions for both approaches, depending on the curve's
equation. In the best cases, for a hyperelliptic curve of genus <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>g</mi></math></formula>,
we can divide the number of solutions by <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mn>2</mn><mrow><mo>(</mo><mi>n</mi><mo>-</mo><mn>1</mn><mo>)</mo><mo>(</mo><mi>g</mi><mo>+</mo><mn>1</mn><mo>)</mo></mrow></msup></math></formula>. For
instance, for a type II genus 2 curve defined over
<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msub><mi>𝔽</mi><mn>293</mn></msub></math></formula> whose divisor class group has cardinality a
near-prime 184 bits integer, the number of solutions is reduced from
4096 to 64. This is enough to build the matrix of relations in
around 7 days with 8000 cores using a dedicated implementation.</p>
      </subsection>
    </subsection>
  </resultats>
  <contrats id="uid55">
    <bodyTitle>Bilateral Contracts and Grants with Industry</bodyTitle>
    <subsection id="uid56" level="1">
      <bodyTitle>Bilateral Grants with Industry</bodyTitle>
      <p>Until the mid 2000’s, multivariate cryptography was developing very
rapidly, producing many interesting and versatile public-key
schemes. However, many of them were soon successfully cryptanalysed
(a lot have been done in this group). As a consequence, the
confidence in multivariate cryptography cryptosystems declined. It
seems that there have emerged new important reasons for renewal of
the interest in a new generation of multivariate schemes. In the
past two years, the algorithms for solving the Discrete Logarithm
Problem over small characteristic fields underwent an extraordinary
development. This clearly illustrates the risk to not consider
alternatives to classical assumptions based on number theory. In
parallel, two of the most important standardization bodies in the
world, NIST and ETSI have recently started initiatives for
developing cryptographic standards not based on number theory, with
a particular focus on primitives resistant to quantum algorithms.
An objective here is then to focus on the design of multivariate
schemes.</p>
      <p>The team is involved in the industrial transfer of post-quantum
cryptography. The maturation project, called <span class="smallcap" align="left">HFEBoost</span>, is supervised by
SATT-LUTECH.</p>
      <p>SATT-LUTECH specializes in the processing and transfer of technologies from
research laboratories of its shareholders: Inria, CNRS, University
of Technology of Compiègne, National Museum of Natural History,
Institute Curie, Université Panthéon-Assas, Paris Sorbonne
University and National School of Industrial Creation).</p>
      <p>The team has recently developed, in partnership with a mobile
application development company (WASSA), an Android app for
smartphones (Samsung S5 type) that uses multivariate
cryptography. The application has been tested mid-November in a
series of experiments supervised by DGA and French Ministry of
Defense. The experiment gathered a total of hundred participants
from various operational units. This is a first milestone in the
maturation project whose goal is to create a start-up.
</p>
    </subsection>
    <subsection id="uid57" level="1">
      <bodyTitle>Public Contracts</bodyTitle>
      <p>CEA LETI / DSYS / CESTI</p>
      <p>In smart card domain, the emanations of a component during a
cryptographic computation may compromise the information that is
directly or not linked to the secret keys. The most part of the side
channel attacks are based on statistical tools that exploit relations
between the handled data and the signals. However these methods do not
take advantage of all the signal information. The goal is to study the
existing algorithms in pattern and speech recognition and to apply
them to signals related to cryptographic computations. The objective
will be to improve the attacks efficiency and resolve more complex
problems.
</p>
    </subsection>
  </contrats>
  <partenariat id="uid58">
    <bodyTitle>Partnerships and Cooperations</bodyTitle>
    <subsection id="uid59" level="1">
      <bodyTitle>Regional Initiatives</bodyTitle>
      <descriptionlist>
        <li id="uid60">
          <p noindent="true">
            <b>French Ministry of Armies</b>
          </p>
          <p><span class="smallcap" align="left">PolSys</span> has a collaboration with the French Ministry of Armies.</p>
        </li>
      </descriptionlist>
      <descriptionlist>
        <li id="uid61">
          <p noindent="true"><b>Grant GAMMA</b> (funded by PGMO).</p>
          <p>
            <span class="smallcap" align="left">Global Algebraic Shooting Method in OptiMal Control and
Applications</span>
          </p>
          <p>Optimal control consists in steering a system from an initial
configuration
to a final one, while minimizing some given cost
criterion. One of the current main challenges is to develop
innovative methods for computing global solutions. This is crucial
for applications where validating the global control laws is a
crucial but a highly time consuming and expensive phase. GAMMA
focuses on the wide range of optimal control problems having an
algebraic structure, involving for instance polynomial or
semi-algebraic dynamics and costs, or switches between polynomial
models. In this case, GAMMA aims at designing methods relying on
algebraic computations to the mainstream shooting method in order
to yield optimal solutions that purely numerical techniques cannot
provide.</p>
        </li>
      </descriptionlist>
    </subsection>
    <subsection id="uid62" level="1">
      <bodyTitle>National
Initiatives</bodyTitle>
      <subsection id="uid63" level="2">
        <bodyTitle>ANR</bodyTitle>
        <descriptionlist>
          <li id="uid64">
            <p noindent="true">
              <b>ANR Jeunes Chercheurs GALOP
(Games through the lens of ALgebra and OPptimization)</b>
            </p>
            <p><tt>Duration:</tt> 2018–2022</p>
            <p>GALOP is a Young Researchers (JCJC) project with the
purpose of extending the limits of the state-of-the-art algebraic
tools in computer science, especially in stochastic games. It brings original
and innovative algebraic tools, based on symbolic-numeric computing,
that exploit the geometry and the structure and complement the state-of-the-art.
We support our theoretical tools with a highly efficient open-source software
for solving polynomials. Using our algebraic tools we study the geometry of
the central curve of (semi-definite) optimization problems. The algebraic tools
and our results from the geometry of optimization pave the way to introduce
algorithms and precise bounds for stochastic games.</p>
            <p><tt>Participants:</tt> E. Tsigaridas [contact], F. Johansson, H. Gimbert, J.-C. Faugère, M. Safey El Din.</p>
          </li>
        </descriptionlist>
      </subsection>
      <subsection id="uid65" level="2">
        <bodyTitle>Programme d'investissements d'avenir (PIA)</bodyTitle>
        <descriptionlist>
          <li id="uid66">
            <p noindent="true"><b>PIA grant RISQ: Regroupement of the Security Industry for
Quantum-Safe security (2017-2020).</b> The goal of the RISQ
project is to prepare the security industry to the upcoming shift
of classical cryptography to quantum-safe cryptography.
(J.-C. Faugère [contact], and L. Perret).</p>
            <p>The RISQ project is certainly the biggest industrial project ever
organized in quantum-safe cryptography. RISQ is one of few projects
accepted in the call Grands Défis du Numérique which is managed by BPI
France, and will be funded thanks to the so-called Plan
d'Investissements d'Avenir.</p>
            <p>The RISQ project is a natural continuation of <span class="smallcap" align="left">PolSys</span>
commitment to the industrial transfert of quantum-safe
cryptography. RISQ is a large scale version of the HFEBoost project;
which demonstrated the potential of quantum-safe cryptography.</p>
            <p><span class="smallcap" align="left">PolSys</span> actively participated to shape the RISQ project. <span class="smallcap" align="left">PolSys</span> is
now a member of the strategic board of RISQ, and is leading the task
of designing and analyzing quantum-safe algorithms. In particular, a
first milestone of this task was to prepare submissions to NIST's
quantum-safe standardisation process.</p>
          </li>
        </descriptionlist>
      </subsection>
    </subsection>
    <subsection id="uid67" level="1">
      <bodyTitle>European Initiatives</bodyTitle>
      <subsection id="uid68" level="2">
        <bodyTitle>FP7 &amp; H2020 Projects</bodyTitle>
        <subsection id="uid69" level="3">
          <bodyTitle>A3</bodyTitle>
          <sanspuceslist>
            <li id="uid70">
              <p noindent="true">Type: PEOPLE</p>
            </li>
            <li id="uid71">
              <p noindent="true">Instrument: Career Integration Grant</p>
            </li>
            <li id="uid72">
              <p noindent="true">Duration: May 2013 - Apr. 2017</p>
            </li>
            <li id="uid73">
              <p noindent="true">Coordinator: Jean-Charles Faugère</p>
            </li>
            <li id="uid74">
              <p noindent="true">Partner: Institut National de Recherche en Informatique et en
Automatique (Inria), France</p>
            </li>
            <li id="uid75">
              <p noindent="true">Inria contact: Elias Tsigaridas</p>
            </li>
            <li id="uid76">
              <p noindent="true">Abstract: The project Algebraic Algorithms and Applications
(A3) is an interdisciplinary and multidisciplinary project, with
strong international synergy. It consists of four work packages
The first (Algebraic Algorithms) focuses on fundamental problems
of computational (real) algebraic geometry: effective zero bounds,
that is estimations for the minimum distance of the roots of a
polynomial system from zero, algorithms for solving polynomials
and polynomial systems, derivation of non-asymptotic bounds for
basic algorithms of real algebraic geometry and application of
polynomial system solving techniques in optimization. We propose a
novel approach that exploits structure and symmetry, combinatorial
properties of high dimensional polytopes and tools from
mathematical physics. Despite the great potential of the modern
tools from algebraic algorithms, their use requires a combined
effort to transfer this technology to specific problems. In the
second package (Stochastic Games) we aim to derive optimal
algorithms for computing the values of stochastic games, using
techniques from real algebraic geometry, and to introduce a whole
new arsenal of algebraic tools to computational game theory. The
third work package (Non-linear Computational Geometry), we focus
on exact computations with implicitly defined plane and space
curves. These are challenging problems that commonly arise in
geometric modeling and computer aided design, but they also have
applications in polynomial optimization. The final work package
(Efficient Implementations) describes our plans for complete,
robust and efficient implementations of algebraic algorithms.</p>
            </li>
          </sanspuceslist>
        </subsection>
      </subsection>
      <subsection id="uid77" level="2">
        <bodyTitle>Collaborations in European Programs, Except FP7 &amp;
H2020</bodyTitle>
        <sanspuceslist>
          <li id="uid78">
            <p noindent="true">Program: COST</p>
          </li>
          <li id="uid79">
            <p noindent="true">Project acronym: CryptoAction</p>
          </li>
          <li id="uid80">
            <p noindent="true">Project title: Cryptography for Secure Digital Interaction</p>
          </li>
          <li id="uid81">
            <p noindent="true">Duration: Apr. 2014 - Apr. 2018</p>
          </li>
          <li id="uid82">
            <p noindent="true">Coordinator: Claudio ORLANDI</p>
          </li>
          <li id="uid83">
            <p noindent="true">Abstract: As increasing amounts of sensitive data are
exchanged and processed every day on the Internet, the need for
security is paramount. Cryptography is the fundamental tool for
securing digital interactions, and allows much more than secure
communication: recent breakthroughs in cryptography enable the
protection - at least from a theoretical point of view - of any
interactive data processing task. This includes electronic voting,
outsourcing of storage and computation, e-payments, electronic
auctions, etc. However, as cryptography advances and becomes more
complex, single research groups become specialized and lose
contact with "the big picture". Fragmentation in this field can be
dangerous, as a chain is only as strong as its weakest link. To
ensure that the ideas produced in Europe's many excellent research
groups will have a practical impact, coordination among national
efforts and different skills is needed. The aim of this COST
Action is to stimulate interaction between the different national
efforts in order to develop new cryptographic solutions and to
evaluate the security of deployed algorithms with applications to
the secure digital interactions between citizens, companies and
governments. The Action will foster a network of European research
centers thus promoting movement of ideas and people between
partners.</p>
          </li>
        </sanspuceslist>
        <sanspuceslist>
          <li id="uid84">
            <p noindent="true">Program: COST</p>
          </li>
          <li id="uid85">
            <p noindent="true">Project acronym: CRYPTACUS</p>
          </li>
          <li id="uid86">
            <p noindent="true">Project title: Cryptanalysis of ubiquitous computing systems</p>
          </li>
          <li id="uid87">
            <p noindent="true">Duration: Dec. 2014 - Dec. 2018</p>
          </li>
          <li id="uid88">
            <p noindent="true">Coordinator: Gildas AVOINE</p>
          </li>
          <li id="uid89">
            <p noindent="true">Abstract: Recent technological advances in hardware and software
have irrevocably affected the classical picture of computing
systems. Today, these no longer consist only of connected servers,
but involve a wide range of pervasive and embedded devices, leading
to the concept of “ubiquitous computing systems”. The objective
of the Action is to improve and adapt the existent cryptanalysis
methodologies and tools to the ubiquitous computing
framework. Cryptanalysis, which is the assessment of theoretical and
practical cryptographic mechanisms designed to ensure security and
privacy, will be implemented along four axes: cryptographic models,
cryptanalysis of building blocks, hardware and software security
engineering, and security assessment of real-world systems.
Researchers have only recently started to focus on the security of
ubiquitous computing systems. Despite the critical flaws found, the
required highly-specialized skills and the isolation of the involved
disciplines are a true barrier for identifying additional
issues. The Action will establish a network of complementary skills,
so that expertise in cryptography, information security, privacy,
and embedded systems can be put to work together. The outcome will
directly help industry stakeholders and regulatory bodies to
increase security and privacy in ubiquitous computing systems, in
order to eventually make citizens better protected in their everyday
life.</p>
          </li>
        </sanspuceslist>
      </subsection>
    </subsection>
    <subsection id="uid90" level="1">
      <bodyTitle>International
Initiatives</bodyTitle>
      <subsection id="uid91" level="2">
        <bodyTitle>Inria Associate Teams Not Involved in an Inria
International Labs</bodyTitle>
        <subsection id="uid92" level="3">
          <bodyTitle>
            <ref xlink:href="http://www-polsys.lip6.fr/GOAL/index.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">GOAL
</ref>
          </bodyTitle>
          <sanspuceslist>
            <li id="uid93">
              <p noindent="true">Title: Geometry and Optimization with ALgebraic methods.</p>
            </li>
            <li id="uid94">
              <p noindent="true">International Partner (Institution - Laboratory - Researcher):</p>
              <sanspuceslist>
                <li id="uid95">
                  <p noindent="true">University of California Berkeley (United States) - Dept. of
Mathematics - Bernd Sturmfels</p>
                </li>
              </sanspuceslist>
            </li>
            <li id="uid96">
              <p noindent="true">Start year: 2015</p>
            </li>
            <li id="uid97">
              <p noindent="true">See also:
<ref xlink:href="http://www-polsys.lip6.fr/GOAL/index.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www-polsys.<allowbreak/>lip6.<allowbreak/>fr/<allowbreak/>GOAL/<allowbreak/>index.<allowbreak/>html</ref></p>
            </li>
            <li id="uid98">
              <p noindent="true">Polynomial optimization problems form a subclass of general
global optimization problems, which have received a lot of
attention from the research community recently; various solution
techniques have been designed. One reason for the spectacular
success of these methods is the potential impact in many fields:
data mining, big data, energy savings, etc. More generally, many
areas in mathematics, as well as applications in engineering,
biology, statistics, robotics etc. require a deeper understanding
of the algebraic structure of their underlying objects.</p>
              <p>A new trend in the polynomial optimization community is the
combination of algebraic and numerical methods. Understanding and
characterizing the algebraic properties of the objects occurring
in numerical algorithms can play an important role in improving
the efficiency of exact methods. Moreover, this knowledge can be
used to estimate the quality (for example the number of
significant digits) of numerical algorithms. In many situations
each coordinate of the optimum is an algebraic number. The degree
of the minimal polynomials of these algebraic numbers is the
Algebraic Degree of the problem. From a methodological point of
view, this notion of Algebraic Degree emerges as an important
complexity parameter for both numerical and the exact
algorithms. However, algebraic systems occurring in applications
often have special algebraic structures that deeply influence the
geometry of the solution set. Therefore, the (true) algebraic
degree could be much less than what is predicted by general worst
case bounds (using Bézout bounds, mixed volume, etc.), and would
be very worthwhile to understand it more precisely.</p>
              <p>The goal of this proposal is to develop algorithms and
mathematical tools to solve geometric and optimization problems
through algebraic techniques. As a long-term goal, we plan to
develop new software to solve these problems more
efficiently. These objectives encompass the challenge of
identifying instances of these problems that can be solved in
polynomial time with respect to the number of solutions and
modeling these problems with polynomial equations.</p>
            </li>
          </sanspuceslist>
        </subsection>
      </subsection>
    </subsection>
    <subsection id="uid99" level="1">
      <bodyTitle>International
Research Visitors</bodyTitle>
      <subsection id="uid100" level="2">
        <bodyTitle>Visits of International Scientists</bodyTitle>
        <simplelist>
          <li id="uid101">
            <p noindent="true">May – July 2017, Delaram Kahrobaei, Professor, CUNY, NYC, USA</p>
          </li>
        </simplelist>
        <subsection id="uid102" level="3">
          <bodyTitle>Internships</bodyTitle>
          <simplelist>
            <li id="uid103">
              <p noindent="true">May – July 2017, Kelsey Horan, PhD student, CUNY, NYC, USA.</p>
            </li>
            <li id="uid104">
              <p noindent="true">Apr. – Nov. 2017, Eliane Koussa, Université de Versailles</p>
            </li>
            <li id="uid105">
              <p noindent="true">Apr. – Aug. 2017, Pascal Fong, Université de Versailles</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
    </subsection>
  </partenariat>
  <diffusion id="uid106">
    <bodyTitle>Dissemination</bodyTitle>
    <subsection id="uid107" level="1">
      <bodyTitle>Promoting Scientific Activities</bodyTitle>
      <subsection id="uid108" level="2">
        <bodyTitle>Scientific Events Organisation</bodyTitle>
        <subsection id="uid109" level="3">
          <bodyTitle>Member of the Organizing Committees</bodyTitle>
          <p>Emmanuel Prouff was a member of the organization committee of
Eurocrypt 2017 (Paris, France, 2017, April 30 - May 4).</p>
          <p>Jean-Charles Faugère and Ludovic Perret were members of the
organization committee of the Quantum-Safe Cryptography for Industry
(Paris, France, 2017, April 30).</p>
        </subsection>
      </subsection>
      <subsection id="uid110" level="2">
        <bodyTitle>Scientific Events Selection</bodyTitle>
        <subsection id="uid111" level="3">
          <bodyTitle>Chair of Conference Program Committees</bodyTitle>
          <p>Mohab Safey El Din was PC Chair of the International Symposium on
Symbolic and Algebraic Computation (ISSAC), Kaiserslautern, Germany,
2017.</p>
          <p>Jean-Charles Faugère was PC co-Chair of the International workshop
on Parallel Symbolic Computation (PASCO), Kaiserslautern, Germany,
2017.</p>
        </subsection>
        <subsection id="uid112" level="3">
          <bodyTitle>Member of the Conference Program Committees</bodyTitle>
          <p>Ludovic Perret was a member of the program-committee of</p>
          <simplelist>
            <li id="uid113">
              <p noindent="true">20th IACR International Conference on Practice and Theory of
Public-Key Cryptography (PKC'17), Amsterdam, 28-31 March 2017</p>
            </li>
          </simplelist>
          <p>Emmanuel Prouff was a member of the steering committees of the
following conferences</p>
          <simplelist>
            <li id="uid114">
              <p noindent="true">Conference on Cryptographic Hardware and Embedded Systems 2017
(CHES 2017) (Taipei, Taiwan, 2017, Sept. 25-28);</p>
            </li>
            <li id="uid115">
              <p noindent="true">Smart Card Research and Advanced Application Conference
(CARDIS 2017) (Lugano, Switzerland, 2017, Nov. 13-17).</p>
            </li>
          </simplelist>
          <p>Guénaël Renault was a member of the program committee of</p>
          <simplelist>
            <li id="uid116">
              <p noindent="true">7th Int’l Conference on Mathematical Aspects of Computer and
Information Sciences (MACIS) 2017;</p>
            </li>
          </simplelist>
          <p>Elias Tsigaridas was a member of the program committees of the
following conferences</p>
          <simplelist>
            <li id="uid117">
              <p noindent="true">7th Int’l Conference on Mathematical Aspects of Computer and
Information Sciences (MACIS) 2017;</p>
            </li>
            <li id="uid118">
              <p noindent="true">19th International Workshop on Computer Algebra in Scientific
Computing (CASC) 2017.</p>
            </li>
          </simplelist>
          <p>Dongming Wang was a member of the program committees of the
following conferences</p>
          <simplelist>
            <li id="uid119">
              <p noindent="true">11th International Workshop on Automated Deduction in Geometry
(ADG 2016) (Strasbourg, France, June 27-29, 2016);</p>
            </li>
            <li id="uid120">
              <p noindent="true">8th International Symposium on Symbolic Computation in
Software Science (SCSS 2017) (Gammarth, Tunisia, 2017, April 6-9).</p>
            </li>
          </simplelist>
          <p>Dongming Wang was a member of the steering committees of the
following conferences</p>
          <simplelist>
            <li id="uid121">
              <p noindent="true">International Conference on Mathematical Aspects of Computer
and Information Sciences (MACIS),</p>
            </li>
            <li id="uid122">
              <p noindent="true">International Symposium on Symbolic Computation in Software
Science (SCSS).</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
      <subsection id="uid123" level="2">
        <bodyTitle>Journal</bodyTitle>
        <subsection id="uid124" level="3">
          <bodyTitle>Member of the Editorial Boards</bodyTitle>
          <p>Ludovic Perret is an Associate Editor for:</p>
          <simplelist>
            <li id="uid125">
              <p noindent="true">Designs, Codes and Cryptography (Springer, Berlin).</p>
            </li>
            <li id="uid126">
              <p noindent="true">The Computer Journal (Oxford University Press)</p>
            </li>
            <li id="uid127">
              <p noindent="true">Groups, Complexity, Cryptology (De Gruyter)</p>
            </li>
          </simplelist>
          <p>Emmanuel Prouff is an Associate Editor of the Journal of
Cryptographic Engineering (Springer, Berlin).</p>
          <p>Mohab Safey El Din is an Associate Editor of the Journal of Symbolic
Computation.</p>
          <p>Dongming Wang has the following editorial activities:</p>
          <simplelist>
            <li id="uid128">
              <p noindent="true">Editor-in-Chief and Managing Editor for the journal</p>
              <p noindent="true">Mathematics in Computer Science (published by
Birkhäuser/Springer, Basel).</p>
            </li>
            <li id="uid129">
              <p noindent="true">Executive Associate Editor-in-Chief for the journal</p>
              <p noindent="true">SCIENCE CHINA Information Sciences (published by Science China
Press, Beijing and Springer, Berlin).</p>
            </li>
            <li id="uid130">
              <p noindent="true">Member of the Editorial Boards for the</p>
              <simplelist>
                <li id="uid131">
                  <p noindent="true">Journal of Symbolic Computation (published by Academic
Press/Elsevier, London),</p>
                </li>
                <li id="uid132">
                  <p noindent="true">Frontiers of Computer Science (published by Higher Education
Press, Beijing and Springer, Berlin),</p>
                </li>
                <li id="uid133">
                  <p noindent="true">Texts and Monographs in Symbolic Computation (published by
Springer, Wien New York),</p>
                </li>
              </simplelist>
            </li>
            <li id="uid134">
              <p noindent="true">Member of the International Advisory Board for the
Communications of JSSAC (Japan Society for Symbolic and Algebraic
Computation) (published by JSSAC).</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
      <subsection id="uid135" level="2">
        <bodyTitle>Invited Talks</bodyTitle>
        <p>Jean-Charles Faugère was a plenary invited speaker at the</p>
        <simplelist>
          <li id="uid136">
            <p noindent="true">SIAM Conference on Applied Algebraic Geometry, Atlanta (August
2017).</p>
          </li>
        </simplelist>
        <p>Ludovic Perret was invited speaker at the</p>
        <simplelist>
          <li id="uid137">
            <p noindent="true">HEXATRUST Summer school 2017 (Paris, September 2017)</p>
          </li>
        </simplelist>
        <p>Emmanuel Prouff was invited speaker at the</p>
        <simplelist>
          <li id="uid138">
            <p noindent="true">Journées du <span class="smallcap" align="left">GDR-IM</span> (Montpellier, France, 2017,
Mar. 14-16).</p>
          </li>
          <li id="uid139">
            <p noindent="true">Aix-Marseille Cyber Security Forum (AMUSEC) (Marseille,
France, 2017, Oct. 12-13).</p>
          </li>
        </simplelist>
        <p>Guénaël Renault was invited speaker at the</p>
        <simplelist>
          <li id="uid140">
            <p noindent="true">Third French-Japanese Meeting on Cybersecurity (Tokyo, Japan,
April 2017)</p>
          </li>
        </simplelist>
        <p>Mohab Safey El Din was invited speaker at:</p>
        <simplelist>
          <li id="uid141">
            <p noindent="true">The mini-symposium on Euclidean Distance Degree at the 2017
SIAM Conference on Applied Algebraic Geometry, Atlanta, USA 2017;</p>
          </li>
          <li id="uid142">
            <p noindent="true">The math. seminar of the University of Dortmund, Germany;</p>
          </li>
          <li id="uid143">
            <p noindent="true">The Berlin-Leipzig Seminar on Algebra, Geometry and
Combinatorics, Germany;</p>
          </li>
          <li id="uid144">
            <p noindent="true">The mini-symposium on Numeric and Symbolic Convex Programming
for Polynomial Optimization, at the PGMO days, Saclay, France.</p>
          </li>
        </simplelist>
        <p>Dongming Wang invited speaker at the</p>
        <simplelist>
          <li id="uid145">
            <p noindent="true">7th International Conference on Mathematical Aspects of
Computer and Information Sciences (Vienna, Austria, 2017,
Nov. 15-17).</p>
          </li>
          <li id="uid146">
            <p noindent="true">19th International Symposium on Symbolic and Numeric
Algorithms for Scientific Computing (Timisoara, Romania, 2017,
Sept. 21-24).</p>
          </li>
          <li id="uid147">
            <p noindent="true">5th Summer School in Symbolic Computation (Nanning, China,
2017, July 16-22).</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid148" level="2">
        <bodyTitle>Scientific Expertise</bodyTitle>
        <p>Mohab Safey El Din was evaluator for the FWF International Program
(Austrian funding agency).</p>
        <p>Jean-Charles Faugère was the head of the hiring Committee for an associate professor in Grenoble.</p>
      </subsection>
    </subsection>
    <subsection id="uid149" level="1">
      <bodyTitle>Teaching - Supervision -
Juries</bodyTitle>
      <subsection id="uid150" level="2">
        <bodyTitle>Teaching</bodyTitle>
        <p>Jérémy Berthomieu had the following teaching activities:</p>
        <sanspuceslist>
          <li id="uid151">
            <p noindent="true">Master : Computation Modeling, 35 hours, M1, Université
Pierre-et-Marie-Curie, France.</p>
          </li>
          <li id="uid152">
            <p noindent="true">Master : In charge of Basics of Algebraic Algorithms, 73
hours, M1, Université Pierre-et-Marie-Curie &amp; Polytech'
<span class="smallcap" align="left">UPMC</span>, France.</p>
          </li>
          <li id="uid153">
            <p noindent="true">Master : Introduction to Security, 20 hours, M1, Université
Pierre-et-Marie-Curie, France.</p>
          </li>
          <li id="uid154">
            <p noindent="true">Master : Projects supervision, 8 hours, M1, Université
Pierre-et-Marie-Curie, France.</p>
          </li>
          <li id="uid155">
            <p noindent="true">Licence : Introduction to Algorithmics, 40,5 hours, L2,
Université Pierre-et-Marie-Curie, France.</p>
          </li>
          <li id="uid156">
            <p noindent="true">Licence : Representations and Numerical Methods, 38,5 hours,
L2, Université Pierre-et-Marie-Curie, France.</p>
          </li>
          <li id="uid157">
            <p noindent="true">Licence : Projects supervision, 10 hours, L2, Université
Pierre-et-Marie-Curie, France.</p>
          </li>
        </sanspuceslist>
        <p>Jean-Charles Faugère had the following teaching activities:</p>
        <sanspuceslist>
          <li id="uid158">
            <p noindent="true">Master: Fundamental Algorithms in Real Algebraic Geometry,
13,5 hours, M2, ENS de Lyon, France.</p>
          </li>
          <li id="uid159">
            <p noindent="true">Master : Polynomial Systems solving, 12 hours, M2, MPRI,
France.</p>
          </li>
        </sanspuceslist>
        <p>Ludovic Perret is teaching a full service (192 hours), balanced
between master and licence in cryptography, complexity and
introduction to algorithms.</p>
        <p>Mohab Safey El Din had the following teaching activities:</p>
        <sanspuceslist>
          <li id="uid160">
            <p noindent="true">Master : In charge of Modeling and problems numerical and
symbolic solving through <span class="smallcap" align="left">Maple</span> and <span class="smallcap" align="left">MATLAB</span>
software, 36 hours, M1, Université Pierre-et-Marie-Curie, France</p>
          </li>
          <li id="uid161">
            <p noindent="true">Master : In charge of Introduction to polynomial system
solving, 48 hours, M2, Université Pierre-et-Marie-Curie, France</p>
          </li>
          <li id="uid162">
            <p noindent="true">Master : In charge of the Security, Reliability and Numerical
Efficiency Program in Master, 40 hours, M1 and M2, Université
Pierre-et-Marie-Curie, France</p>
          </li>
          <li id="uid163">
            <p noindent="true">Licence : Introduction to Cryptology, 20 hours, L3, Université
Pierre-et-Marie-Curie, France</p>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid164" level="2">
        <bodyTitle>Supervision</bodyTitle>
        <sanspuceslist>
          <li id="uid165">
            <p noindent="true">PhD in progress : Ivan Bannwarth, Fast algorithms for studying
real algebraic sets, started in Sept. 2014, Mohab Safey El Din.</p>
          </li>
          <li id="uid166">
            <p noindent="true">PhD in progress : Matías Bender, Algorithms for Sparse Gröbner
basis and applications, started in Dec. 2015, Jean-Charles Faugère
and Elias Tsigaridas.</p>
          </li>
          <li id="uid167">
            <p noindent="true">PhD in progress : Eleonora Cagli, Analysis and interest points
research in the attacks by observation context, Emmanuel Prouff.</p>
          </li>
          <li id="uid168">
            <p noindent="true">PhD in progress : Loïc Masure, Recognition and Side Channel
Analysis, Emmanuel Prouff.</p>
          </li>
          <li id="uid169">
            <p noindent="true">PhD in progress, Olive Chakraborty, Design and Analysis of
Post-Quantum Schemes, started in May 2017, Jean-Charles Faugère
and Ludovic Perret.</p>
          </li>
          <li id="uid170">
            <p noindent="true">PhD in progress, Nagardjun Chinthamani Dwarakanath, Design and
Analysis of Fully Homomorphic Schemes, started in Dec.  2017,
Jean-Charles Faugère and Ludovic Perret.</p>
          </li>
          <li id="uid171">
            <p noindent="true">PhD in progress, Solane El Hirch Design and Analysis of
Post-Quantum Schemes, started in June  2017, Jean-Charles Faugère
and Ludovic Perret.</p>
          </li>
          <li id="uid172">
            <p noindent="true">PhD in progress, Xuan Vu. Algorithms for solving structured
semi-algebraic systems, started in October  2017, Jean-Charles
Faugère and Mohab Safey El Din.</p>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid173" level="2">
        <bodyTitle>Juries</bodyTitle>
        <p>Emmanuel Prouff was examiner in the PhD committee of N. Bruneau and
M. Dugardin and in the HDR committees of J.-M. Dutertre and N.  El
Mrabet.</p>
        <p>Guénaël Renault was referee in the Phd committee of T. Mefenza.</p>
      </subsection>
    </subsection>
    <subsection id="uid174" level="1">
      <bodyTitle>Popularization</bodyTitle>
      <p>The activity of <span class="smallcap" align="left">PolSys</span> in post-quantum cryptography has been covered in several large audience magazines:</p>
      <simplelist>
        <li id="uid175">
          <p noindent="true">“Enfin! La révolution quantique”, L'Usine Nouvelle, November 2017.</p>
        </li>
        <li id="uid176">
          <p noindent="true">“QUANTIQUE : THE NEXT BIG THING(K)”, L'Informaticien, November 2017.</p>
        </li>
        <li id="uid177">
          <p noindent="true">“L'ORDINATEUR QUANTIQUE VA-T-IL METTRE À MAL LA CYBERSÉCURITÉ MONDIALE?”, Bouygues Blog, October 2017.</p>
        </li>
      </simplelist>
      <p>Ludovic Perret is member of the Cloud Security Alliance (CSA) quantum-safe security working group.
In particular, he contributed to the following documents:</p>
      <simplelist>
        <li id="uid178">
          <p noindent="true">B. Huttner, J. Melia, G. Carter, L. Perret and L. Wilson. “<ref xlink:href="https://cloudsecurityalliance.org/download/applied-quantum-safe-security/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Applied Quantum-Safe Security”</ref>, Feb. 2017.</p>
        </li>
        <li id="uid179">
          <p noindent="true">B. Huttner, J. Melia, G. Carter, L. Perret and L. Wilson. “<ref xlink:href="https://cloudsecurityalliance.org/download/quantum-safe-security-glossary/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Quantum Safe Security Glossary”</ref>, January 2017.</p>
        </li>
      </simplelist>
      <p>Ludovic Perret is also member of the quantum-safe cryptography specification group of the European Telecommunications Standards Institute (ETSI) where is the referee for a document on quantum-safe signatures.</p>
      <p>Since May 2010, Daniel Lazard is engaged in a strong edition work on
the English Wikipedia (more than <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mn>6</mn><mspace width="0.166667em"/><mn>000</mn></mrow></math></formula> contributions, including
vandalism revert and talk pages). Initially focused on the themes of
<span class="smallcap" align="left">PolSys</span>, these contributions were later enlarged to general
algebra and algebraic geometry, because many elementary articles
require to be expanded to be useful as a background for computer
algebra. Examples of articles that have been subject of major
editing: “System of polynomial equations” (created), “Computer
algebra”, “Algebra”, “Algebraic geometry”, “Polynomial
greatest common divisor”, “Polynomial factorization”, “Finite
field”, “Hilbert series and Hilbert polynomial”,...</p>
      <p>For the year 2017, this contribution amounts to about <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mn>2</mn><mo>,</mo><mn>000</mn></mrow></math></formula> edits
on the English Wikipedia.</p>
      <p>Mohab Safey El Din was invited by FMJH to present and popularize
symbolic and algebraic computation to Master students in Mathematics
following the curricula proposed by Univ. Paris-Saclay.</p>
    </subsection>
  </diffusion>
  <biblio id="bibliography" html="bibliography" numero="10" titre="Bibliography">
    
    <biblStruct id="polsys-2017-bid0" type="article" rend="year" n="cite:berthomieu:hal-01253934">
      <identifiant type="doi" value="10.1016/j.jsc.2016.11.005"/>
      <identifiant type="hal" value="hal-01253934"/>
      <analytic>
        <title level="a">Linear Algebra for Computing Gröbner Bases of Linear Recursive Multidimensional Sequences</title>
        <author>
          <persName key="polsys-2014-idp66592">
            <foreName>Jérémy</foreName>
            <surname>Berthomieu</surname>
            <initial>J.</initial>
          </persName>
          <persName key="polsys-2014-idp75112">
            <foreName>Brice</foreName>
            <surname>Boyer</surname>
            <initial>B.</initial>
          </persName>
          <persName key="polsys-2014-idm27936">
            <foreName>Jean-Charles</foreName>
            <surname>Faugère</surname>
            <initial>J.-C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01272">
        <idno type="issn">0747-7171</idno>
        <title level="j">Journal of Symbolic Computation</title>
        <imprint>
          <biblScope type="volume">83</biblScope>
          <biblScope type="number">Supplement C</biblScope>
          <dateStruct>
            <month>November</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">36-67</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01253934" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01253934</ref>
        </imprint>
      </monogr>
      <note type="bnote">Special issue on the conference ISSAC 2015: Symbolic computation and computer algebra</note>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid8" type="article" rend="year" n="cite:dasilva:hal-01609363">
      <identifiant type="doi" value="10.1002/mma.4387"/>
      <identifiant type="hal" value="hal-01609363"/>
      <analytic>
        <title level="a">Sliding solutions of second-order differential equations with discontinuous right-hand side</title>
        <author>
          <persName>
            <foreName>Clayton E. L.</foreName>
            <surname>Da Silva</surname>
            <initial>C. E. L.</initial>
          </persName>
          <persName>
            <foreName>Paulo R.</foreName>
            <surname>Da Silva</surname>
            <initial>P. R.</initial>
          </persName>
          <persName key="polsys-2014-idp67920">
            <foreName>Alain</foreName>
            <surname>Jacquemard</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01386">
        <idno type="issn">0170-4214</idno>
        <title level="j">Mathematical Methods in the Applied Sciences</title>
        <imprint>
          <biblScope type="volume">40</biblScope>
          <biblScope type="number">14</biblScope>
          <dateStruct>
            <month>September</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">5295 - 5306</biblScope>
          <ref xlink:href="https://hal-univ-bourgogne.archives-ouvertes.fr/hal-01609363" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal-univ-bourgogne.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01609363</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid9" type="article" rend="year" n="cite:faugere:hal-00807540">
      <identifiant type="doi" value="10.1016/j.jsc.2016.07.025"/>
      <identifiant type="hal" value="hal-00807540"/>
      <analytic>
        <title level="a">Sparse FGLM algorithms</title>
        <author>
          <persName key="polsys-2014-idm27936">
            <foreName>Jean-Charles</foreName>
            <surname>Faugère</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName>
            <foreName>Chenqi</foreName>
            <surname>Mou</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01272">
        <idno type="issn">0747-7171</idno>
        <title level="j">Journal of Symbolic Computation</title>
        <imprint>
          <biblScope type="volume">80</biblScope>
          <biblScope type="number">3</biblScope>
          <dateStruct>
            <month>May</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">538 - 569</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-00807540" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00807540</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid19" subtype="nonparu-d" type="article" rend="year" n="cite:faugere:hal-01658573">
      <identifiant type="doi" value="10.1007/s10623-017-0449-y"/>
      <identifiant type="hal" value="hal-01658573"/>
      <analytic>
        <title level="a">The Point Decomposition Problem over Hyperelliptic Curves: toward efficient computations of Discrete Logarithms in even characteristic</title>
        <author>
          <persName key="polsys-2014-idm27936">
            <foreName>Jean-Charles</foreName>
            <surname>Faugère</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName key="polsys-2014-idp97400">
            <foreName>Alexandre</foreName>
            <surname>Wallet</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid00462">
        <idno type="issn">0925-1022</idno>
        <title level="j">Designs, Codes and Cryptography</title>
        <imprint>
          <dateStruct>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01658573" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01658573</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid12" subtype="nonparu-d" type="article" rend="year" n="cite:fawzi:hal-01657849">
      <identifiant type="hal" value="hal-01657849"/>
      <analytic>
        <title level="a">A lower bound on the positive semidefinite rank of convex bodies</title>
        <author>
          <persName>
            <foreName>Hamza</foreName>
            <surname>Fawzi</surname>
            <initial>H.</initial>
          </persName>
          <persName key="polsys-2014-idp73616">
            <foreName>Mohab</foreName>
            <surname>Safey El Din</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid03181">
        <idno type="issn">2470-6566</idno>
        <title level="j">SIAM Journal on Applied Algebra and Geometry</title>
        <imprint>
          <dateStruct>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">1-14</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01657849" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01657849</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid11" type="article" rend="year" n="cite:henrion:hal-01393022">
      <identifiant type="hal" value="hal-01393022"/>
      <analytic>
        <title level="a">SPECTRA -a Maple library for solving linear matrix inequalities in exact arithmetic</title>
        <author>
          <persName>
            <foreName>Didier</foreName>
            <surname>Henrion</surname>
            <initial>D.</initial>
          </persName>
          <persName key="polsys-2014-idp90952">
            <foreName>Simone</foreName>
            <surname>Naldi</surname>
            <initial>S.</initial>
          </persName>
          <persName key="polsys-2014-idp73616">
            <foreName>Mohab</foreName>
            <surname>Safey El Din</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01548">
        <idno type="issn">1055-6788</idno>
        <title level="j">Optimization, Methods and Software</title>
        <imprint>
          <dateStruct>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.laas.fr/hal-01393022" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>laas.<allowbreak/>fr/<allowbreak/>hal-01393022</ref>
        </imprint>
      </monogr>
      <note type="bnote"><ref xlink:href="https://arxiv.org/abs/1611.01947" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>arxiv.<allowbreak/>org/<allowbreak/>abs/<allowbreak/>1611.<allowbreak/>01947</ref> - Significantly extended version</note>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid5" type="article" rend="year" n="cite:herman:hal-01456686">
      <identifiant type="hal" value="hal-01456686"/>
      <analytic>
        <title level="a">Improving Root Separation Bounds</title>
        <author>
          <persName key="polsys-2014-idp81856">
            <foreName>Aaron</foreName>
            <surname>Herman</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Hoon</foreName>
            <surname>Hong</surname>
            <initial>H.</initial>
          </persName>
          <persName key="polsys-2014-idm26432">
            <foreName>Elias</foreName>
            <surname>Tsigaridas</surname>
            <initial>E.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01272">
        <idno type="issn">0747-7171</idno>
        <title level="j">Journal of Symbolic Computation</title>
        <imprint>
          <dateStruct>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01456686" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01456686</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct subtype="nonparu-n" id="polsys-2017-bid6" type="article" rend="year" n="cite:pan:hal-01105267">
      <identifiant type="hal" value="hal-01105267"/>
      <analytic>
        <title level="a">Accelerated Approximation of the Complex Roots and Factors of a Univariate Polynomial</title>
        <author>
          <persName>
            <foreName>Victor Y.</foreName>
            <surname>Pan</surname>
            <initial>V. Y.</initial>
          </persName>
          <persName key="polsys-2014-idm26432">
            <foreName>Elias</foreName>
            <surname>Tsigaridas</surname>
            <initial>E.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01855">
        <idno type="issn">0304-3975</idno>
        <title level="j">Theoretical Computer Science</title>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01105267" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01105267</ref>
        </imprint>
      </monogr>
      <note type="bnote">To appear</note>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid7" type="article" rend="year" n="cite:pan:hal-01105263">
      <identifiant type="hal" value="hal-01105263"/>
      <analytic>
        <title level="a">Nearly optimal computations with structured matrices</title>
        <author>
          <persName>
            <foreName>Victor Y.</foreName>
            <surname>Pan</surname>
            <initial>V. Y.</initial>
          </persName>
          <persName key="polsys-2014-idm26432">
            <foreName>Elias</foreName>
            <surname>Tsigaridas</surname>
            <initial>E.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01855">
        <idno type="issn">0304-3975</idno>
        <title level="j">Theoretical Computer Science</title>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01105263" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01105263</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid10" type="article" rend="year" n="cite:safeyeldin:hal-00849057">
      <identifiant type="doi" value="10.1145/2996450"/>
      <identifiant type="hal" value="hal-00849057"/>
      <analytic>
        <title level="a">A nearly optimal algorithm for deciding connectivity queries in smooth and bounded real algebraic sets</title>
        <author>
          <persName key="polsys-2014-idp73616">
            <foreName>Mohab</foreName>
            <surname>Safey El Din</surname>
            <initial>M.</initial>
          </persName>
          <persName key="polsys-2014-idp84576">
            <foreName>Éric</foreName>
            <surname>Schost</surname>
            <initial>É.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01303">
        <idno type="issn">0004-5411</idno>
        <title level="j">Journal of the ACM (JACM)</title>
        <imprint>
          <biblScope type="volume">63</biblScope>
          <biblScope type="number">6</biblScope>
          <dateStruct>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">48:1–48:37</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-00849057" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00849057</ref>
        </imprint>
      </monogr>
      <note type="bnote"><ref xlink:href="https://arxiv.org/abs/1307.7836v2" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>arxiv.<allowbreak/>org/<allowbreak/>abs/<allowbreak/>1307.<allowbreak/>7836v2</ref> - Major revision, accepted for publication to Journal of the ACM</note>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid4" subtype="nonparu-d" type="article" rend="year" n="cite:safeyeldin:hal-01319729">
      <identifiant type="doi" value="10.1016/j.jsc.2017.08.001"/>
      <identifiant type="hal" value="hal-01319729"/>
      <analytic>
        <title level="a">Bit complexity for multi-homogeneous polynomial system solving Application to polynomial minimization</title>
        <author>
          <persName key="polsys-2014-idp73616">
            <foreName>Mohab</foreName>
            <surname>Safey El Din</surname>
            <initial>M.</initial>
          </persName>
          <persName key="polsys-2014-idp84576">
            <foreName>Éric</foreName>
            <surname>Schost</surname>
            <initial>É.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01272">
        <idno type="issn">0747-7171</idno>
        <title level="j">Journal of Symbolic Computation</title>
        <imprint>
          <dateStruct>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">1-32</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01319729" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01319729</ref>
        </imprint>
      </monogr>
      <note type="bnote">
        <ref xlink:href="https://arxiv.org/abs/1605.07433" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>arxiv.<allowbreak/>org/<allowbreak/>abs/<allowbreak/>1605.<allowbreak/>07433</ref>
      </note>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid26" subtype="nonparu-d" type="article" rend="year" n="cite:strzebonski:hal-01248390">
      <identifiant type="hal" value="hal-01248390"/>
      <analytic>
        <title level="a">Univariate real root isolation in an extension field and applications</title>
        <author>
          <persName>
            <foreName>Adam</foreName>
            <surname>Strzebonski</surname>
            <initial>A.</initial>
          </persName>
          <persName key="polsys-2014-idm26432">
            <foreName>Elias</foreName>
            <surname>Tsigaridas</surname>
            <initial>E.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01272">
        <idno type="issn">0747-7171</idno>
        <title level="j">Journal of Symbolic Computation</title>
        <imprint>
          <dateStruct>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01248390" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01248390</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid14" type="inproceedings" rend="year" n="cite:belaid:hal-01613773">
      <identifiant type="doi" value="10.1007/978-3-319-63697-9_14"/>
      <identifiant type="hal" value="hal-01613773"/>
      <analytic>
        <title level="a">Private Multiplication over Finite Fields</title>
        <author>
          <persName key="cascade-2014-idp73576">
            <foreName>Sonia</foreName>
            <surname>Belaid</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Fabrice</foreName>
            <surname>Benhamouda</surname>
            <initial>F.</initial>
          </persName>
          <persName key="cascade-2014-idp91040">
            <foreName>Alain</foreName>
            <surname>Passelègue</surname>
            <initial>A.</initial>
          </persName>
          <persName key="polsys-2015-idp92760">
            <foreName>Emmanuel</foreName>
            <surname>Prouff</surname>
            <initial>E.</initial>
          </persName>
          <persName key="cascade-2014-idp95984">
            <foreName>Adrian</foreName>
            <surname>Thillard</surname>
            <initial>A.</initial>
          </persName>
          <persName key="cascade-2014-idp67136">
            <foreName>Damien</foreName>
            <surname>Vergnaud</surname>
            <initial>D.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <editor role="editor">
          <persName>
            <foreName>Jonathan</foreName>
            <surname>Katz</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Hovav</foreName>
            <surname>Shacham</surname>
            <initial>H.</initial>
          </persName>
        </editor>
        <title level="m">Advances in Cryptology - CRYPTO 2017</title>
        <loc>Santa Barbara, United States</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">10403</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>August</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">397-426</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01613773" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01613773</ref>
        </imprint>
        <meeting id="cid306210">
          <title>International Cryptology Conference</title>
          <num>37</num>
          <abbr type="sigle">CRYPTO</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid13" type="inproceedings" rend="year" n="cite:burr:hal-01528392">
      <identifiant type="doi" value="10.1145/3087604.3087654"/>
      <identifiant type="hal" value="hal-01528392"/>
      <analytic>
        <title level="a">The Complexity of an Adaptive Subdivision Method for Approximating Real Curves</title>
        <author>
          <persName>
            <foreName>Michael</foreName>
            <surname>Burr</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Shuhong</foreName>
            <surname>Gao</surname>
            <initial>S.</initial>
          </persName>
          <persName key="polsys-2014-idm26432">
            <foreName>Elias</foreName>
            <surname>Tsigaridas</surname>
            <initial>E.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">ISSAC 2017 - International Symposium on Symbolic and Algebraic Computation</title>
        <loc>Kaiserslautern, Germany</loc>
        <imprint>
          <dateStruct>
            <month>July</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">8</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01528392" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01528392</ref>
        </imprint>
        <meeting id="cid318495">
          <title>International Symposium on Symbolic and Algebraic Computation</title>
          <num>2017</num>
          <abbr type="sigle">ISSAC</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid15" type="inproceedings" rend="year" n="cite:cagli:hal-01661212">
      <identifiant type="hal" value="hal-01661212"/>
      <analytic>
        <title level="a">Convolutional Neural Networks with Data Augmentation against Jitter-Based Countermeasures</title>
        <author>
          <persName>
            <foreName>Eleonora</foreName>
            <surname>Cagli</surname>
            <initial>E.</initial>
          </persName>
          <persName>
            <foreName>Cécile</foreName>
            <surname>Dumas</surname>
            <initial>C.</initial>
          </persName>
          <persName key="polsys-2015-idp92760">
            <foreName>Emmanuel</foreName>
            <surname>Prouff</surname>
            <initial>E.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">Cryptographic Hardware and Embedded Systems - CHES 2017 - 19th International Conference</title>
        <loc>Taipei, Taiwan</loc>
        <imprint>
          <dateStruct>
            <month>September</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01661212" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01661212</ref>
        </imprint>
        <meeting id="cid375810">
          <title>Workshop on Cryptographic Hardware and Embedded Systems</title>
          <num>19</num>
          <abbr type="sigle">CHES</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid3" type="inproceedings" rend="year" n="cite:mantzaflaris:hal-01528377">
      <identifiant type="doi" value="10.1145/3087604.3087653"/>
      <identifiant type="hal" value="hal-01528377"/>
      <analytic>
        <title level="a">Sparse Rational Univariate Representation</title>
        <author>
          <persName>
            <foreName>Angelos</foreName>
            <surname>Mantzaflaris</surname>
            <initial>A.</initial>
          </persName>
          <persName key="polsys-2014-idp84576">
            <foreName>Éric</foreName>
            <surname>Schost</surname>
            <initial>É.</initial>
          </persName>
          <persName key="polsys-2014-idm26432">
            <foreName>Elias</foreName>
            <surname>Tsigaridas</surname>
            <initial>E.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">ISSAC 2017 - International Symposium on Symbolic and Algebraic Computation</title>
        <loc>Kaiserslautern, Germany</loc>
        <imprint>
          <dateStruct>
            <month>July</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">8</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01528377" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01528377</ref>
        </imprint>
        <meeting id="cid318495">
          <title>International Symposium on Symbolic and Algebraic Computation</title>
          <num>2017</num>
          <abbr type="sigle">ISSAC</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid2" type="inproceedings" rend="year" n="cite:mantzaflaris:hal-01525560">
      <identifiant type="doi" value="10.1145/3087604.3087646"/>
      <identifiant type="hal" value="hal-01525560"/>
      <analytic>
        <title level="a">Resultants and Discriminants for Bivariate Tensor-product Polynomials</title>
        <author>
          <persName>
            <foreName>Angelos</foreName>
            <surname>Mantzaflaris</surname>
            <initial>A.</initial>
          </persName>
          <persName key="polsys-2014-idm26432">
            <foreName>Elias</foreName>
            <surname>Tsigaridas</surname>
            <initial>E.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">ISSAC 2017 - International Symposium on Symbolic and Algebraic Computation</title>
        <loc>Kaiserslautern, Germany</loc>
        <imprint>
          <publisher>
            <orgName type="organisation">Mohab Safey El Din</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">8</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01525560" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01525560</ref>
        </imprint>
        <meeting id="cid318495">
          <title>International Symposium on Symbolic and Algebraic Computation</title>
          <num>2017</num>
          <abbr type="sigle">ISSAC</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid16" type="techreport" rend="year" n="cite:casanova:hal-01662158">
      <identifiant type="hal" value="hal-01662158"/>
      <monogr>
        <title level="m">GeMSS: A Great Multivariate Short Signature</title>
        <author>
          <persName>
            <foreName>Antoine</foreName>
            <surname>Casanova</surname>
            <initial>A.</initial>
          </persName>
          <persName key="polsys-2014-idm27936">
            <foreName>Jean-Charles</foreName>
            <surname>Faugère</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName>
            <foreName>Gilles</foreName>
            <surname>Macario-Rat</surname>
            <initial>G.</initial>
          </persName>
          <persName>
            <foreName>Jacques</foreName>
            <surname>Patarin</surname>
            <initial>J.</initial>
          </persName>
          <persName key="polsys-2014-idp70968">
            <foreName>Ludovic</foreName>
            <surname>Perret</surname>
            <initial>L.</initial>
          </persName>
          <persName key="polsys-2017-idp184512">
            <foreName>Jocelyn</foreName>
            <surname>Ryckeghem</surname>
            <initial>J.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="institution">UPMC - Paris 6 Sorbonne Universités ; Inria Paris Research Centre, MAMBA Team, F-75012, Paris, France ; LIP6 - Laboratoire d'Informatique de Paris 6</orgName>
          </publisher>
          <dateStruct>
            <month>December</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">1-4</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01662158" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01662158</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Research Report</note>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid18" type="techreport" rend="year" n="cite:chakraborty:hal-01662175">
      <identifiant type="hal" value="hal-01662175"/>
      <monogr>
        <title level="m">CFPKM : A Key Encapsulation Mechanism based on Solving System of non-linear multivariate Polynomials 20171129</title>
        <author>
          <persName key="vegas-2014-idp76336">
            <foreName>Olive</foreName>
            <surname>Chakraborty</surname>
            <initial>O.</initial>
          </persName>
          <persName key="polsys-2014-idm27936">
            <foreName>Jean-Charles</foreName>
            <surname>Faugère</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName key="polsys-2014-idp70968">
            <foreName>Ludovic</foreName>
            <surname>Perret</surname>
            <initial>L.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="institution">UPMC - Paris 6 Sorbonne Universités ; Inria Paris ; CNRS</orgName>
          </publisher>
          <dateStruct>
            <month>December</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01662175" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01662175</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Research Report</note>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid17" type="techreport" rend="year" n="cite:faugere:hal-01662165">
      <identifiant type="hal" value="hal-01662165"/>
      <monogr>
        <title level="m">DualModeMS: A Dual Mode for Multivariate-based Signature 20170918 draft</title>
        <author>
          <persName key="polsys-2014-idm27936">
            <foreName>Jean-Charles</foreName>
            <surname>Faugère</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName key="polsys-2014-idp70968">
            <foreName>Ludovic</foreName>
            <surname>Perret</surname>
            <initial>L.</initial>
          </persName>
          <persName key="polsys-2017-idp184512">
            <foreName>Jocelyn</foreName>
            <surname>Ryckeghem</surname>
            <initial>J.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="institution">UPMC - Paris 6 Sorbonne Universités ; Inria Paris ; CNRS</orgName>
          </publisher>
          <dateStruct>
            <month>December</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01662165" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01662165</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Research Report</note>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid1" type="unpublished" rend="year" n="cite:berthomieu:hal-01516708">
      <identifiant type="hal" value="hal-01516708"/>
      <monogr>
        <title level="m">In-depth comparison of the Berlekamp – Massey – Sakata and the Scalar-FGLM algorithms: the non adaptive variants</title>
        <author>
          <persName key="polsys-2014-idp66592">
            <foreName>Jérémy</foreName>
            <surname>Berthomieu</surname>
            <initial>J.</initial>
          </persName>
          <persName key="polsys-2014-idm27936">
            <foreName>Jean-Charles</foreName>
            <surname>Faugère</surname>
            <initial>J.-C.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>May</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01516708" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01516708</ref>
        </imprint>
      </monogr>
      <note type="bnote">working paper or preprint</note>
    </biblStruct>
    
    <biblStruct subtype="nonparu-n" id="polsys-2017-bid23" type="unpublished" rend="year" n="cite:bonnard:hal-01556806">
      <identifiant type="hal" value="hal-01556806"/>
      <monogr>
        <title level="m">Algebraic-geometric techniques for the feedback classification and robustness of the optimal control of a pair of Bloch equations with application to Magnetic Resonance Imaging</title>
        <author>
          <persName key="mctao-2014-idp60264">
            <foreName>Bernard</foreName>
            <surname>Bonnard</surname>
            <initial>B.</initial>
          </persName>
          <persName key="mctao-2014-idp72488">
            <foreName>Olivier</foreName>
            <surname>Cots</surname>
            <initial>O.</initial>
          </persName>
          <persName key="polsys-2014-idm27936">
            <foreName>Jean-Charles</foreName>
            <surname>Faugère</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName key="polsys-2014-idp67920">
            <foreName>Alain</foreName>
            <surname>Jacquemard</surname>
            <initial>A.</initial>
          </persName>
          <persName key="mctao-2014-idp67016">
            <foreName>Jérémy</foreName>
            <surname>Rouot</surname>
            <initial>J.</initial>
          </persName>
          <persName key="polsys-2014-idp73616">
            <foreName>Mohab</foreName>
            <surname>Safey El Din</surname>
            <initial>M.</initial>
          </persName>
          <persName key="polsys-2014-idp96144">
            <foreName>Thibaut</foreName>
            <surname>Verron</surname>
            <initial>T.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01556806" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01556806</ref>
        </imprint>
      </monogr>
      <note type="bnote">submitted</note>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid25" type="unpublished" rend="year" n="cite:buse:hal-01654263">
      <identifiant type="hal" value="hal-01654263"/>
      <monogr>
        <title level="m">Matrix formulae for Resultants and Discriminants of Bivariate Tensor-product Polynomials</title>
        <author>
          <persName key="galaad2-2014-idm29072">
            <foreName>Laurent</foreName>
            <surname>Busé</surname>
            <initial>L.</initial>
          </persName>
          <persName>
            <foreName>Angelos</foreName>
            <surname>Mantzaflaris</surname>
            <initial>A.</initial>
          </persName>
          <persName key="polsys-2014-idm26432">
            <foreName>Elias</foreName>
            <surname>Tsigaridas</surname>
            <initial>E.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>December</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01654263" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01654263</ref>
        </imprint>
      </monogr>
      <note type="bnote">working paper or preprint</note>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid22" type="unpublished" rend="year" n="cite:emiris:hal-01105276">
      <identifiant type="hal" value="hal-01105276"/>
      <monogr>
        <title level="m">Separation bounds for polynomial systems</title>
        <author>
          <persName key="aromath-2016-idp117968">
            <foreName>Ioannis Z.</foreName>
            <surname>Emiris</surname>
            <initial>I. Z.</initial>
          </persName>
          <persName key="galaad2-2014-idm30552">
            <foreName>Bernard</foreName>
            <surname>Mourrain</surname>
            <initial>B.</initial>
          </persName>
          <persName key="polsys-2014-idm26432">
            <foreName>Elias</foreName>
            <surname>Tsigaridas</surname>
            <initial>E.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>February</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01105276" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01105276</ref>
        </imprint>
      </monogr>
      <note type="bnote">working paper or preprint</note>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid20" type="unpublished" rend="year" n="cite:henrion:hal-01159210">
      <identifiant type="hal" value="hal-01159210"/>
      <monogr>
        <title level="m">Real root finding for low rank linear matrices</title>
        <author>
          <persName>
            <foreName>Didier</foreName>
            <surname>Henrion</surname>
            <initial>D.</initial>
          </persName>
          <persName key="polsys-2014-idp90952">
            <foreName>Simone</foreName>
            <surname>Naldi</surname>
            <initial>S.</initial>
          </persName>
          <persName key="polsys-2014-idp73616">
            <foreName>Mohab</foreName>
            <surname>Safey El Din</surname>
            <initial>M.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01159210" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01159210</ref>
        </imprint>
      </monogr>
      <note type="bnote">working paper or preprint</note>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid21" type="unpublished" rend="year" n="cite:magron:hal-01538729">
      <identifiant type="hal" value="hal-01538729"/>
      <monogr>
        <title level="m">Algorithms for Weighted Sums of Squares Decomposition of Non-negative Univariate Polynomials</title>
        <author>
          <persName key="polsys-2017-idp176912">
            <foreName>Victor</foreName>
            <surname>Magron</surname>
            <initial>V.</initial>
          </persName>
          <persName key="polsys-2014-idp73616">
            <foreName>Mohab</foreName>
            <surname>Safey El Din</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Markus</foreName>
            <surname>Schweighofer</surname>
            <initial>M.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01538729" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01538729</ref>
        </imprint>
      </monogr>
      <note type="bnote">working paper or preprint</note>
    </biblStruct>
    
    <biblStruct id="polsys-2017-bid24" type="patent" rend="year" n="cite:perret:hal-01668254">
      <identifiant type="hal" value="hal-01668254"/>
      <monogr>
        <title level="m">Mise en Oeuvre Optimisée du HFE</title>
        <author>
          <persName key="polsys-2014-idp70968">
            <foreName>Ludovic</foreName>
            <surname>Perret</surname>
            <initial>L.</initial>
          </persName>
          <persName key="polsys-2014-idm27936">
            <foreName>Jean-Charles</foreName>
            <surname>Faugère</surname>
            <initial>J.-C.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="number">WO 2017001809 A1</biblScope>
          <dateStruct>
            <month>January</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01668254" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01668254</ref>
        </imprint>
      </monogr>
    </biblStruct>
  </biblio>
</raweb>
