Equivalence of Counting the Number of Points on Elliptic Curve over the Ring Zn and Factoring n

نویسندگان

  • Noboru Kunihiro
  • Kenji Koyama
چکیده

1 I n t r o d u c t i o n Elliptic curves can be applied to public-key cryptosystems, and as such several schemes have been proposed [3, 4, 5, 6, 9, 11]. There are two typical elliptic curve cryptosystems: E1Gamal-type scheme [4, 11] and RSA-type schemes [3, 5, 6]. The security of the EIGamal-type elliptic curve cryptosystem is based on the difficulty of solving a discrete logarithm over elliptic curve modulo a prime. However, the security of an RSA-type elliptic curve cryptosystem is based on the difficulty of factoring a large composite. It has been conjectured that completely breaking the original RSA is computationally equivalent to the factoring the used composite, although this has NOT been proved yet. In a certain RSA-type elliptic curve (or cubic curve) cryptosystem proposed in [6], however, this equivalence between the two problems was proved. In general RSA-type elliptic curve cryptosystems, including RSA-type cubic curve cryptosystems, the equivalence has not been proved. As the order r of Z* for a composite n have played a significant role in analyzing the security of the original RSA scheme, it is important to evaluate the complexity of counting the number of points on an elliptic curve over the ring Z,~ for RSA-type elliptic curve cryptosystems. We are interested in reductions of factoring to other problems in elliptic curve theory over Z~. In this paper, we will consider the following problems. F C T ( n ) : Given composite n, find the complete prime factorization of n. C O M P ( r : Given composite n, compute the Euler phi function r -IZ*I, which is the number of integers in the interval [1, n], each of which are relatively prime to n. C O M P ( ~ E , . , ( a , b ) ) : Given composite n and integers a and b, compute # E n ( a , b), which is the number of points over an elliptic curve E,~ : y2 _x 3 + ax + b (mod n).

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Efficient elliptic curve cryptosystems

Elliptic curve cryptosystems (ECC) are new generations of public key cryptosystems that have a smaller key size for the same level of security. The exponentiation on elliptic curve is the most important operation in ECC, so when the ECC is put into practice, the major problem is how to enhance the speed of the exponentiation. It is thus of great interest to develop algorithms for exponentiation...

متن کامل

On the elliptic curves of the form $ y^2=x^3-3px $

By the Mordell-Weil theorem‎, ‎the group of rational points on an elliptic curve over a number field is a finitely generated abelian group‎. ‎There is no known algorithm for finding the rank of this group‎. ‎This paper computes the rank of the family $ E_p:y^2=x^3-3px $ of elliptic curves‎, ‎where p is a prime‎.

متن کامل

Diffie-Hellman type key exchange protocols based on isogenies

‎In this paper‎, ‎we propose some Diffie-Hellman type key exchange protocols using isogenies of elliptic curves‎. ‎The first method which uses the endomorphism ring of an ordinary elliptic curve $ E $‎, ‎is a straightforward generalization of elliptic curve Diffie-Hellman key exchange‎. ‎The method uses commutativity of the endomorphism ring $ End(E) $‎. ‎Then using dual isogenies‎, ‎we propose...

متن کامل

On Silverman's conjecture for a family of elliptic curves

Let $E$ be an elliptic curve over $Bbb{Q}$ with the given Weierstrass equation $ y^2=x^3+ax+b$. If $D$ is a squarefree integer, then let $E^{(D)}$ denote the $D$-quadratic twist of $E$ that is given by $E^{(D)}: y^2=x^3+aD^2x+bD^3$. Let $E^{(D)}(Bbb{Q})$ be the group of $Bbb{Q}$-rational points of $E^{(D)}$. It is conjectured by J. Silverman that there are infinitely many primes $p$ for which $...

متن کامل

On the Elliptic Curves of the Form $y^2 = x^3 − pqx$

‎By the Mordell‎- ‎Weil theorem‎, ‎the group of rational points on an elliptic curve over a number field is a finitely generated abelian group‎. ‎This paper studies the rank of the family Epq:y2=x3-pqx of elliptic curves‎, ‎where p and q are distinct primes‎. ‎We give infinite families of elliptic curves of the form y2=x3-pqx with rank two‎, ‎three and four‎, ‎assuming a conjecture of Schinzel ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 1998