inria-00135324, version 1
An $L (1/3 + \varepsilon)$ Algorithm for the Discrete Logarithm Problem for Low Degree Curves
Andreas Enge
1Pierrick Gaudry
2
Eurocrypt 2007 4515 (2007) 379-393
Résumé : The discrete logarithm problem in Jacobians of curves of high genus $g$ over finite fields $\FF_q$ is known to be computable with subexponential complexity $L_{q^g}(1/2, O(1))$. We present an algorithm for a family of plane curves whose degrees in $X$ and $Y$ are low with respect to the curve genus, and suitably unbalanced. The finite base fields are arbitrary, but their sizes should not grow too fast compared to the genus. For this family, the group structure can be computed in subexponential time of $L_{q^g}(1/3, O(1))$, and a discrete logarithm computation takes subexponential time of $L_{q^g}(1/3+\varepsilon, o(1))$ for any positive~$\varepsilon$. These runtime bounds rely on heuristics similar to the ones used in the number field sieve or the function field sieve algorithms.
- 1 : TANC (INRIA Futurs)
- CNRS : UMR7161 – INRIA – Polytechnique - X
- 2 : CACAO (Courbes, Algèbre, Calculs, Arithmétique des Ordinateurs) (INRIA Lorraine - LORIA)
- CNRS : UMR7503 – INRIA – Université Henri Poincaré - Nancy I – Université Nancy II – Institut National Polytechnique de Lorraine
- Domaine : Informatique/Cryptographie et sécurité
Mathématiques/Géométrie algébrique
- inria-00135324, version 1
- http://hal.inria.fr/inria-00135324
- oai:hal.inria.fr:inria-00135324
- Contributeur : Andreas Enge
- Soumis le : Mercredi 7 Mars 2007, 13:46:50
- Dernière modification le : Mardi 17 Mai 2011, 07:06:36






Documents associés

Exporter