Hidden Monomial Cryptosystems

Let K be an extension of degree n of the finite field F q , where q is a power of 2, and let β1, β2,..., β n ∈ K be a basis of K as an F q -vector space. Alice will be using the Imai-Matsumoto system in K. She regards each element of K as an n-tuple over F q . Alice may choose to keep her basis secret, in which case we cannot assume that a cryptanalyst (whom we shall name “Catherine”) knows what basis she is using.