Elliptic Congruence Function Fields

نویسنده

  • Andreas Stein
چکیده

Recently, the well-known Diie-Hellman key exchange protocol was extended to real quadratic congruence function elds in a non-group based setting. Here, the underlying key space was the set of reduced principal ideals. This set does not possess a group structure, but instead exhibits a so-called infrastructure. The techniques are the same as in the protocol based on real quadratic number elds. As always, the security of the protocol depends on a certain discrete logarithm problem (DLP). It can be shown that for elliptic congruence function elds this DLP is equivalent to the DLP for elliptic curves over nite elds. In this paper, we present the arithmetic of reduced principal ideals in elliptic congruence function elds, which is the base for the equivalence, and prove some properties which have no analogies for real quadratic number elds. 1 Background and Motivation In 7], a new key exchange system is proposed, similar in concept to that of Diie-Hellman, which is based on the infrastructure (see Shanks 9]) of the principal ideal class of a real quadratic congruence function eld. It uses the same techniques as in the protocol based on real quadratic number elds (see 6]). The security of both protocols depends on the diiculty of the so-called discrete logarithm problem (DLP). In 1], Abel shows that the DLP in a real quadratic number eld Q(p) can be solved subexponentially in log. It can be seen from 12], that the DLP for elliptic curves is equivalent to the DLP in real quadratic congruence function elds of genus 1, which we call (real) elliptic congruence function elds. In this paper, we explain the main properties of the set of reduced principal ideals in elliptic congruence function elds based on the infrastructure ideas of 9] which are extended in 11]. The underlying structure of the key exchange protocols in 6] and 7] is the set of reduced principal ideals. In either case, this set does not form a group, however, it is \almost" a group. For elliptic congruence function elds, we will prove (Theorem 8) that the set of reduced principal ideals is even \closer" to a group, but it still fails to be a group (Theorem 9). Furthermore, for real quadratic congruence function elds of arbitrary genus and for real quadratic number elds, we know (see 16], 3], 11]) that the distance function is asymptotically linear in almost all cases, i.e., there is a …

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Equivalences between Elliptic Curves and Real Quadratic Congruence Function Fields

In 1994, the well-known Diie-Hellman key exchange protocol was for the rst time implemented in a non-group based setting. Here, the underlying key space was the set of reduced principal ideals of a real quadratic number eld. This set does not possess a group structure, but instead exhibits a so-called infrastructure. More recently, the scheme was extended to real quadratic congruence function e...

متن کامل

ASPECTS OF COMPLEX MULTIPLICATION Contents

1. Preview 2 Complex multiplication on elliptic curves over C 2 Traces of singular moduli 3 Class field theory 3 The Kronecker limit formula and Kronecker’s solution of Pell’s equation 4 Application to Diophantine equations (Villegas) 4 L-series and CM modular forms 5 Other topics 6 2. Complex Multiplication on Elliptic Curves over C 6 Elliptic Curves over C 6 Elliptic functions 7 Complex multi...

متن کامل

On the transfer congruence between p-adic Hecke L-functions

We prove the transfer congruence between p-adic Hecke L-functions for CM fields over cyclotomic extensions, which is a non-abelian generalization of the Kummer’s congruence. The ingredients of the proof include the comparison between Hilbert modular varieties, the q-expansion principle, and some modification of Hsieh’s Whittaker model for Katz’ Eisenstein series. As a first application, we prov...

متن کامل

Explicit Infrastructure for Real Quadratic Function Fields and Real Hyperelliptic Curves

In 1989, Koblitz first proposed the Jacobian of a an imaginary hyperelliptic curve for use in public-key cryptographic protocols. This concept is a generalization of elliptic curve cryptography. It can be used with the same assumed key-per-bit strength for small genus. More recently, real hyperelliptic curves of small genus have been introduced as another source for cryptographic protocols. The...

متن کامل

Bounds for traces of Hecke operators and applications to modular and elliptic curves over a finite field

Abstract. We give an upper bound for the trace of a Hecke operator acting on the space of holomorphic cusp forms with respect to a congruence subgroup. Such an estimate has applications to the analytic theory of elliptic curves over a finite field, going beyond the Riemann hypothesis over finite fields. As the main tool to prove our bound on traces of Hecke operators, we develop a Petersson for...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 1996