On the discrete logarithm problem in elliptic curves
Claus Diem University of Leipzig
On the discrete logarithm problem in elliptic curves – p.1/37
On the discrete logarithm problem in elliptic curves Claus Diem - - PowerPoint PPT Presentation
On the discrete logarithm problem in elliptic curves Claus Diem University of Leipzig On the discrete logarithm problem in elliptic curves p.1/37 Some history At ECC 2004 in Bochum, Pierrick Gaudry presented an index calculus algorithm
Claus Diem University of Leipzig
On the discrete logarithm problem in elliptic curves – p.1/37
n) .
On the discrete logarithm problem in elliptic curves – p.2/37
n) .
On the discrete logarithm problem in elliptic curves – p.2/37
n) .
On the discrete logarithm problem in elliptic curves – p.2/37
On the discrete logarithm problem in elliptic curves – p.3/37
On the discrete logarithm problem in elliptic curves – p.4/37
On the discrete logarithm problem in elliptic curves – p.4/37
On the discrete logarithm problem in elliptic curves – p.5/37
On the discrete logarithm problem in elliptic curves – p.5/37
On the discrete logarithm problem in elliptic curves – p.5/37
K be as usual.
On the discrete logarithm problem in elliptic curves – p.6/37
On the discrete logarithm problem in elliptic curves – p.7/37
On the discrete logarithm problem in elliptic curves – p.7/37
k
On the discrete logarithm problem in elliptic curves – p.8/37
i γiαi
On the discrete logarithm problem in elliptic curves – p.9/37
On the discrete logarithm problem in elliptic curves – p.10/37
On the discrete logarithm problem in elliptic curves – p.11/37
On the discrete logarithm problem in elliptic curves – p.11/37
On the discrete logarithm problem in elliptic curves – p.11/37
m⌉ and δ := mc − n.
On the discrete logarithm problem in elliptic curves – p.12/37
k
On the discrete logarithm problem in elliptic curves – p.13/37
i γiαi
On the discrete logarithm problem in elliptic curves – p.14/37
On the discrete logarithm problem in elliptic curves – p.15/37
On the discrete logarithm problem in elliptic curves – p.16/37
On the discrete logarithm problem in elliptic curves – p.16/37
On the discrete logarithm problem in elliptic curves – p.16/37
On the discrete logarithm problem in elliptic curves – p.16/37
On the discrete logarithm problem in elliptic curves – p.16/37
ℓ αℓbℓ)(Pi) = 0
On the discrete logarithm problem in elliptic curves – p.17/37
On the discrete logarithm problem in elliptic curves – p.18/37
On the discrete logarithm problem in elliptic curves – p.18/37
On the discrete logarithm problem in elliptic curves – p.19/37
m·log(q)) .
On the discrete logarithm problem in elliptic curves – p.19/37
m·log(q)) .
m·log(q)) for the linear
log(q) , log(q))) .
On the discrete logarithm problem in elliptic curves – p.20/37
log(q) , log(q))) .
On the discrete logarithm problem in elliptic curves – p.21/37
log(q) , log(q))) .
log(q)·log(q))2/3 ≤ e( 1
an log(q))2/3
On the discrete logarithm problem in elliptic curves – p.21/37
log(q),log(q))) .
On the discrete logarithm problem in elliptic curves – p.22/37
On the discrete logarithm problem in elliptic curves – p.23/37
K) with
K)(k) ≃ K .
K)(k) ≃ An
On the discrete logarithm problem in elliptic curves – p.23/37
K) be the “affine part” of E.
K induces a covering
K)
On the discrete logarithm problem in elliptic curves – p.24/37
K) be the “affine part” of E.
K induces a covering
K)
K)
On the discrete logarithm problem in elliptic curves – p.24/37
K) be the “affine part” of E.
K induces a covering
K)
K)
On the discrete logarithm problem in elliptic curves – p.24/37
Res(x)
ResK|k(A1
K) .
On the discrete logarithm problem in elliptic curves – p.25/37
On the discrete logarithm problem in elliptic curves – p.26/37
On the discrete logarithm problem in elliptic curves – p.26/37
On the discrete logarithm problem in elliptic curves – p.26/37
On the discrete logarithm problem in elliptic curves – p.27/37
On the discrete logarithm problem in elliptic curves – p.27/37
On the discrete logarithm problem in elliptic curves – p.27/37
On the discrete logarithm problem in elliptic curves – p.27/37
On the discrete logarithm problem in elliptic curves – p.27/37
On the discrete logarithm problem in elliptic curves – p.28/37
m
m
On the discrete logarithm problem in elliptic curves – p.29/37
m
m
On the discrete logarithm problem in elliptic curves – p.29/37
m
k ≃ ResK|k(A1 K) = m
On the discrete logarithm problem in elliptic curves – p.30/37
K;
K) is unramified at
On the discrete logarithm problem in elliptic curves – p.31/37
K;
K) is unramified at
On the discrete logarithm problem in elliptic curves – p.31/37
K;
K) is unramified at
On the discrete logarithm problem in elliptic curves – p.31/37
On the discrete logarithm problem in elliptic curves – p.32/37
(am)∗
P
(τ((m−1)P0))∗
T0(ResK|k(A1
K))
P
K .
On the discrete logarithm problem in elliptic curves – p.33/37
m
On the discrete logarithm problem in elliptic curves – p.34/37
m
y and the holomorphic tangent vector field
On the discrete logarithm problem in elliptic curves – p.34/37
m
x
On the discrete logarithm problem in elliptic curves – p.34/37
m
On the discrete logarithm problem in elliptic curves – p.34/37
4 · qdim(Vi) elements.
On the discrete logarithm problem in elliptic curves – p.35/37
On the discrete logarithm problem in elliptic curves – p.36/37
On the discrete logarithm problem in elliptic curves – p.37/37