SLIDE 5 Problem statement: an example (1)
Discrete Logarithm Problem on Edwards elliptic curves (Faugère, Gaudry, Huot, Renault 2013)
0 = 7871 18574 14294 32775 20289 e16 5 + 53362 50900 36407 58813 20802 ˜ e8 1 + 26257 128 3037 38424 41456 ˜ e7 1 ˜ e2 + 25203 23117 28918 29298 56353 ˜ e6 1 ˜ e2 2 + 19817 29737 52187 36574 46683 ˜ e5 1 ˜ e3 2 + 9843 3752 27006 64195 63059 ˜ e4 1 ˜ e4 2 + 11204 25459 58263 17964 57146 ˜ e3 1 ˜ e5 2 + 46217 5478 45631 13171 42548 ˜ e2 1 ˜ e6 2 + 63811 50777 48809 1858 55751 ˜ e1 ˜ e7 2 + 40524 6881 1238 8056 54831 ˜ e8 2 + 4522 1728 18652 54885 8241 ˜ e7 1 ˜ e3 + 27518 32176 31159 28424 5276 ˜ e6 1 ˜ e2 ˜ e3 + 2067 smaller monomials
Description of the system
◮ Ideal invariant under the group
(Z/2Z)n−1 ⋊ Sn, rewritten with the invariants:
ei := ei(x2
1 , . . . , x2 n ) (1 ≤ i ≤ n − 1)
en(x1, . . . , xn)
◮ n equations of degree 2n−1
in Fq[˜ e1, . . . , ˜ en−1, en]
◮ 1 DLP = thousands of such systems
Goal: compute a Gröbner basis
◮ Normal strategy (total degree)
→ difficult → non regular
◮ Weighted degree strategy
Weight(˜ ei) = 2 · Weight(ei) → easier → regular