An object of the invention is to allow cipher strength evaluation when
available resources such as the complexity and the number of plaintext
available for decryption have conditions, and to allow comparison of
cipher strength under given conditions. The invention combines the
exhaustive search with an algebraic method, sets conditions for resources
such as the complexity and the number of plaintext available for
decryption beforehand, and utilizes the linear dependency of a decryption
equation for use in decryption to optimize a decryption method as the
maximum number of available plaintext is secured. Thus, it reduces the
complexity and allows efficient search of solutions for the decryption
equation.