Discrete logarithm in GF(2) with FFS

نویسندگان

  • Razvan Barbulescu
  • Cyril Bouvier
  • Jérémie Detrey
  • Pierrick Gaudry
  • Hamza Jeljeli
  • Emmanuel Thomé
  • Marion Videau
  • Paul Zimmermann
چکیده

We give details on solving the discrete logarithm problem in the 202-bit prime order subgroup of F2809 using the Function Field Sieve algorithm (FFS). To our knowledge, this computation is the largest discrete logarithm computation so far in a binary field extension of prime degree. The Function Field Sieve is the traditional approach for solving these problems, and has been used in previous records for such fields, namely F2619 [3] and F2613 [8]. One should note that an adaptation of the newer L(1/4 + o(1), ·) algorithm by Joux [7] also applies to computations of this kind. Presently, the crossover point between the Function Field Sieve and this newer algorithm is not known, and the present computation contributes to giving an idea of the present state of the art of what may be computed using the Function Field Sieve. Most of the software used for this computation is freely available as part of the cado-nfs software suite [1] (although cado-nfs originally focuses on the Number Field Sieve, recent additions cover FFS as well). Various improvements over the different steps of the algorithm are covered in preprints by some of the authors of the present computation [2, 4, 5, 6]. We therefore keep this report very short and refer the interested reader to these articles for more detail.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Solving a 676-Bit Discrete Logarithm Problem in GF(36n)

Pairings on elliptic curves over finite fields are crucial for constructing various cryptographic schemes. The ηT pairing on supersingular curves over GF(3) is particularly popular since it is efficiently implementable. Taking into account the Menezes-Okamoto-Vanstone (MOV) attack, the discrete logarithm problem (DLP) in GF(3) becomes a concern for the security of cryptosystems using ηT pairing...

متن کامل

Breaking Pairing-Based Cryptosystems Using η T Pairing over GF(397)

There are many useful cryptographic schemes, such as ID-based encryption, short signature, keyword searchable encryption, attribute-based encryption, functional encryption, that use a bilinear pairing. It is important to estimate the security of such pairing-based cryptosystems in cryptography. The most essential number-theoretic problem in pairing-based cryptosystems is the discrete logarithm ...

متن کامل

Accelerating Iterative SpMV for Discrete Logarithm Problem using GPUs

In the context of cryptanalysis, computing discrete logarithms in large cyclic groups using index-calculus-based methods, such as the number field sieve or the function field sieve, requires solving large sparse systems of linear equations modulo the group order. Most of the fast algorithms used to solve such systems — e.g., the conjugate gradient or the Lanczos and Wiedemann algorithms — itera...

متن کامل

Faster individual discrete logarithms in non-prime finite fields with the NFS and FFS algorithms

Computing discrete logarithms in finite fields is a main concern in cryptography. The best algorithms known are the Number Field Sieve and its variants in large and medium characteristic fields (e.g. GF(p), GF(p)); the Function Field Sieve and the Quasi Polynomial-time Algorithm in small characteristic finite fields (e.g. GF(36·509)). The last step of the NFS and FFS algorithms is the individua...

متن کامل

Key Length Estimation of Pairing-Based Cryptosystems Using η T Pairing

The security of pairing-based cryptosystems depends on the difficulty of the discrete logarithm problem (DLP) over certain types of finite fields. One of the most efficient algorithms for computing a pairing is the ηT pairing over supersingular curves on finite fields whose characteristic is 3. Indeed many high-speed implementations of this pairing have been reported, and it is an attractive ca...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013