## Question: Attack against Matsumoto-Imai

Xelord
### Question: Attack against Matsumoto-Imai

I don't understand, how the $$A(x,y)=x^{q^{2\alpha}}y-xy^{q\alpha}$$ is computed ? Can anybody explain it ?

Thanks

Patr0rc
### Re: Question: Attack against Matsumoto-Imai

I'm sorry, I read your question several times and still don't understand it. What do you mean by "computed"? (It's, by the way, $$A(x,y)=x^{q^{2\alpha}}y - x y^{q^{\alpha}}$$, not $$A(x,y)=x^{q^{2\alpha}}y - x y^{q\alpha}$$.)
The only thing I at this moment can say is that this $$A(x,y)$$ is a bilinear relation that fulfills the equation stated in claim 11.6.2 (whose last sentence btw is NOT THAT correct as written down at the moment, but don't think about at this time). So we can find the mentioned field elements $$a_{ij}, b_i, c_j, d$$ and after this reconstruct the message $$w$$ for given ciphertext $$z$$.