Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
Jean-S´ ebastien Coron
Gemplus Card International Issy-les-Moulineaux, France
Finding Small Roots of Bivariate Integer Polynomial Equations - - PowerPoint PPT Presentation
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited Jean-S ebastien Coron Gemplus Card International Issy-les-Moulineaux, France Solving polynomial equations Let p ( x ) be a polynomial and N an RSA modulus. Solving
Gemplus Card International Issy-les-Moulineaux, France
01/05/04 2/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 3/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 4/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 5/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 6/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
i.
X N 2N
01/05/04 7/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 8/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 9/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 10/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 11/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 12/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
00 p(x, y) mod n for some integer n.
01/05/04 13/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 14/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 15/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 16/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 17/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
00 · p(x, y) mod n
(i,j)=(0,0) aijxiyj
01/05/04 18/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
1 x y xy x2 x2y y2 xy2 x2y2 XY q XY a10X2Y a01XY 2 a11X2Y 2 Y xq XY a01XY 2 a10X2Y a11X2Y 2 Xyq XY a10X2Y a01XY 2 a11X2Y 2 xyq XY a10X2Y a01XY 2 a11X2Y 2 x2n X2n x2yn X2Y n y2n Y 2n xy2n XY 2n x2y2n X2Y 2n
01/05/04 19/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
n √ω.
01/05/04 20/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 21/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 22/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
3δ − 2 3·(k+1) and β = 4k2 δ + 13 · δ.
01/05/04 23/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 24/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 25/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
N bits of p given lattice dimension running time 512 bits 144 bits 25 35 sec 512 bits 141 bits 36 3 min 1024 bits 282 bits 36 20 min
N bits of p given lattice dimension running time 1024 bits 282 bits 11 1 sec 1024 bits 266 bits 25 1 min 1536 bits 396 bits 33 19 min
01/05/04 26/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited
01/05/04 27/27 Bull & Innovatron Patents
Finding Small Roots of Bivariate Integer Polynomial Equations Revisited