Faster cofactorization with ECM using mixed representations
Cyril Bouvier Laurent Imbert
LIRMM, CNRS, Univ. Montpellier, France
Faster cofactorization with ECM using mixed representations Laurent - - PowerPoint PPT Presentation
Faster cofactorization with ECM using mixed representations Laurent Imbert Cyril Bouvier LIRMM, CNRS, Univ. Montpellier, France Sminaire CARAMBA November 29th, 2018 Context The Elliptic Curve Method (ECM) is the fastest known method for
LIRMM, CNRS, Univ. Montpellier, France
1 / 33
2 / 33
3 / 33
4 / 33
5 / 33
A,B : BY 2Z = X 3 + AX 2Z + XZ 2.
6 / 33
a,d : aX 2Z 2 + Y 2Z 2 = Z 4 + dX 2Y 2.
7 / 33
8 / 33
9 / 33
9 / 33
9 / 33
9 / 33
10 / 33
11 / 33
12 / 33
13 / 33
14 / 33
m
15 / 33
16 / 33
m
17 / 33
18 / 33
19 / 33
20 / 33
21 / 33
p∈MB1 p.
b∈S Mb = MB1, i.e., b∈S n(b) = k, which
22 / 33
⌈log2(max(M))⌉
aℓ(M)=0
23 / 33
24 / 33
25 / 33
26 / 33
b∈S0 Mb MB1.
27 / 33
1Bos and Kleinjung 2Ishii et al.
28 / 33
7.5 7.6 7.7 7.8 7.9 8 8.1 8.2 8.3 8.4 8.5 8.6 8.7 8.8 128 192 256 320 384 448 512 576 640 704 768 832 896 960 1024 Arithmetic cost per bit B1 cado-nfs 2.3.0 EECM-MPFQ ECM at Work no storage ECM for Kalray ECM at Work low storage Our work
29 / 33
1same as ECM at Work for stage 2; it is based on Miele’s thesis
30 / 33
31 / 33
32 / 33
33 / 33
1 / 8
2 / 8
3 / 8
u∈U\{u}
u]Q ×
v∈V
vω]Q
u∈U
u]Q ×
v∈V \{v}
vω]Q
4 / 8
6
5 / 8
6
5 / 8
6
5 / 8
6
5 / 8
6 / 8
6 / 8
6 / 8
6 / 8
7 / 8
8 / 8
8 / 8
8 / 8