Using Symmetries and Fast Change of Ordering in the Index Calculus for Elliptic Curves Discrete Logarithm

نویسندگان

  • Jean-Charles Faugère
  • Pierrick Gaudry
  • Louise Huot
  • Guénaël Renault
چکیده

This abstract presents results on polynomial systems involved in an algebraic attack on elliptic curves cryptosystems. The security of these cryptosystems is based on the difficulty to solve the elliptic curves discrete logarithm problem (ECDLP): let E be an elliptic curve defined over a finite field K. The set of its rational points forms a commutative group, E(K). Given two points P and Q of E(K) the ECDLP is to find if it exists, an integer x such that Q = [x]P . The notation [x]P denotes, as usual, the multiplication of P by x. Except for few weak curves (as curves with small enough embedding degree or curves defined over Fp of order p), the best known algorithms to solve the ECDLP are generic algorithms. A generic algorithm is an algorithm to solve the DLP in any group. A result from Shoup [18] shows that these algorithms are exponential in general. Among this algorithms, the Pollard rho method [17] is the most optimal and its complexity is given, up to a constant factor, by the square root of the order of the curve. In [11], it is proposed an index calculus attack to solve the ECDLP defined over a non prime finite field Fqn where n > 1. Later on, Diem [2,1] obtained rigorous proofs that for some particular families of curves the discrete logarithm problem can be solved in subexponential time. Let us recall the principle of the algorithm: given P and Q, two points of E(Fqn), we look for x, if it exists, such that Q = [x]P 1. Compute the factor base F = {(x, y) ∈ E(Fqn) | x ∈ Fq}. 2. Look for at least #F +1 relations of the form: [aj ]P ⊕ [bj ]Q = P1⊕· · ·⊕Pn, where P1, · · · , Pn ∈ F and aj and bj are randomly picked up in Z. 3. Finally, by using linear algebra, recover the discrete logarithm x.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Generalized Jacobian and Discrete Logarithm Problem on Elliptic Curves

Let E be an elliptic curve over the finite field F_{q}, P a point in E(F_{q}) of order n, and Q a point in the group generated by P. The discrete logarithm problem on E is to find the number k such that Q = kP. In this paper we reduce the discrete logarithm problem on E[n] to the discrete logarithm on the group F*_{q} , the multiplicative group of nonzero elements of Fq, in the case where n | q...

متن کامل

An Efficient Threshold Verifiable Multi-Secret Sharing Scheme Using Generalized Jacobian of Elliptic Curves

‎In a (t,n)-threshold secret sharing scheme‎, ‎a secret s is distributed among n participants such that any group of t or more participants can reconstruct the secret together‎, ‎but no group of fewer than t participants can do‎. In this paper, we propose a verifiable (t,n)-threshold multi-secret sharing scheme based on Shao and Cao‎, ‎and the intractability of the elliptic curve discrete logar...

متن کامل

Polynomial systems solving and elliptic curve cryptography. (Résolution de systèmes polynomiaux et cryptologie sur les courbes elliptiques)

Since the last decade, attacks on the elliptic curve discrete logarithm problem (ECDLP) whichrequires to solve polynomial systems have been quite successful. This thesis takes place in this contextand the contributions are twofold.On the one hand, we present new tools for solving polynomial systems by using Gröbner bases.First, we investigate polynomial systems with symmetries. ...

متن کامل

An efficient blind signature scheme based on the elliptic curve discrete logarithm problem

Elliptic Curve Cryptosystems (ECC) have recently received significant attention by researchers due to their high performance such as low computational cost and small key size. In this paper a novel untraceable blind signature scheme is presented. Since the security of proposed method is based on difficulty of solving discrete logarithm over an elliptic curve, performance of the proposed scheme ...

متن کامل

Elliptic Curve Discrete Logarithms and the Index Calculus

The discrete logarithm problem forms the basis of numerous cryptographic systems. The most eeective attack on the discrete logarithm problem in the multiplicative group of a nite eld is via the index calculus, but no such method is known for elliptic curve discrete logarithms. Indeed, Miller 23] has given a brief heuristic argument as to why no such method can exist. IN this note we give a deta...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012