Orders of CM elliptic curves modulo p with at most two primes

نویسندگان

  • Henryk Iwaniec
  • Jorge Jiménez Urroz
چکیده

Nowadays the generation of cryptosystems requires two main aspects. First the security, and then the size of the keys involved in the construction and comunication process. About the former one needs a difficult mathematical assumption which ensures your system will not be broken unless a well known difficult problem is solved. In this context one of the most famous assumption underlying a wide variety of cryptosystems is the computation of logarithms in finite fields and the Diffie Hellman assumption. However it is also well known that elliptic curves provide good examples of representation of abelian groups reducing the size of keys needed to guarantee the same level of security as in the finite field case. The first thing one needs to perform elliptic logarithms which are computationaly secure is to fix a finite field, Fp, and one curve, E/Fp defined over the field, such that |E(Fp)| has a prime factor as large as possible. In practice the problem of finding such a pair, of curve and field, seems simple, just take a curve with integer coefficients and a prime p of good reduction at random and see if |E(Fp)| has a big prime factor. However the theory that makes the previous algorithm useful is by no means obvious, neither clear or complete. For example it is well known that supersingular elliptic curves have to be avoided in the previous process since they reduce the security of any cryptosystem based on the Diffie Hellman assumption on the elliptic logarithm. But more importantly, the process will be feasible whenever the probability to find a pair, (E, p), with a big prime factor q| |E(Fp)| is big enough. One problem arises naturally from the above.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Gross-Zagier formula for quaternion algebras over totally real fields

We prove a higher dimensional generalization of Gross and Zagier’s theorem on the factorization of differences of singular moduli. Their result is proved by giving a counting formula for the number of isomorphisms between elliptic curves with complex multiplication by two different imaginary quadratic fields K and K′, when the curves are reduced modulo a supersingular prime and its powers. Equi...

متن کامل

Square-free orders for CM elliptic curves modulo p

Let E be an elliptic curve defined over Q, of conductor N , and with complex multiplication. We prove unconditional and conditional asymptotic formulae for the number of ordinary primes p ! N , p ≤ x , for which the group of points of the reduction of E modulo p has square-free order. These results are related to the problem of finding an asymptotic formula for the number of primes p for which ...

متن کامل

Evil Primes and Superspecial Moduli

For a quartic primitive CM field K, we say that a rational prime p is evil if at least one of the abelian varieties with CM by K reduces modulo a prime ideal p|p to a product of supersingular elliptic curves with the product polarization. We call such primes evil primes for K. In [GL], we showed that for fixed K, such primes are bounded by a quantity related to the discriminant of the field K. ...

متن کامل

Reductions of an elliptic curve with almost prime orders

1 Let E be an elliptic curve over Q. For a prime p of good reduction, let Ep be the reduction of E modulo p. We investigate Koblitz’s Conjecture about the number of primes p for which Ep(Fp) has prime order. More precisely, our main result is that if E is with Complex Multiplication, then there exist infinitely many primes p for which #Ep(Fp) has at most 5 prime factors. We also obtain upper bo...

متن کامل

On Silverman's conjecture for a family of elliptic curves

Let $E$ be an elliptic curve over $Bbb{Q}$ with the given Weierstrass equation $ y^2=x^3+ax+b$. If $D$ is a squarefree integer, then let $E^{(D)}$ denote the $D$-quadratic twist of $E$ that is given by $E^{(D)}: y^2=x^3+aD^2x+bD^3$. Let $E^{(D)}(Bbb{Q})$ be the group of $Bbb{Q}$-rational points of $E^{(D)}$. It is conjectured by J. Silverman that there are infinitely many primes $p$ for which $...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006