Solving a 676-Bit Discrete Logarithm Problem in GF(36n)

被引:3
作者
Hayashi, Takuya [1 ]
Shinohara, Naoyuki [2 ]
Wang, Lihua [2 ]
Matsuo, Shin'ichiro [2 ]
Shirase, Masaaki [3 ]
Takagi, Tsuyoshi [4 ]
机构
[1] Kyushu Univ, Grad Sch Math, Fukuoka 8190395, Japan
[2] Natl Inst Informat & Commun Technol, Network Secur Res Inst, Koganei, Tokyo 1849795, Japan
[3] Future Univ Hakodate, Sch Syst Informat Sci, Hakodate, Hokkaido 0410806, Japan
[4] Kyushu Univ, Inst Math Ind, Fukuoka 8190395, Japan
关键词
function field sieve; discrete logarithm problem; pairing-based cryptosystems; FUNCTION-FIELD SIEVE; ENCRYPTION; CURVES;
D O I
10.1587/transfun.E95.A.204
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Pairings on elliptic curves over finite fields are crucial for constructing various cryptographic schemes. The eta(T) pairing on supersingular curves over GF(3(n)) is particularly popular since it is efficiently implementable. Taking into account the Menezes-Okamoto-Vanstone attack, the discrete logarithm problem (DLP) in GF(3(6n)) becomes a concern for the security of cryptosystems using eta(T) pairings in this case. In 2006, Joux and Lercier proposed a new variant of the function field sieve in the medium prime case, named JL06-FFS. We have, however, not yet found any practical implementations on JL06-FFS over GF(3(6n)). Therefore, we first fulfill such an implementation and we successfully set a new record for solving the DLP in GF(3(6n)), the DLP in GF(3(6.71)) of 676-bit size. In addition, we also compare JL06-FFS and an earlier version, named JL02-FFS, with practical experiments. Our results confirm that the former is several times faster than the latter under certain conditions.
引用
收藏
页码:204 / 212
页数:9
相关论文
共 8 条
  • [1] Solving a 676-Bit Discrete Logarithm Problem in GF(36n)
    Hayashi, Takuya
    Shinohara, Naoyuki
    Wang, Lihua
    Matsuo, Shin'ichiro
    Shirase, Masaaki
    Takagi, Tsuyoshi
    PUBLIC KEY CRYPTOGRAPHY - PKC 2010, PROCEEDINGS, 2010, 6056 : 351 - +
  • [2] Quantum algorithm for solving hyperelliptic curve discrete logarithm problem
    Huang, Yan
    Su, Zhaofeng
    Zhang, Fangguo
    Ding, Yong
    Cheng, Rong
    QUANTUM INFORMATION PROCESSING, 2020, 19 (02)
  • [3] Quantum algorithm for solving hyperelliptic curve discrete logarithm problem
    Yan Huang
    Zhaofeng Su
    Fangguo Zhang
    Yong Ding
    Rong Cheng
    Quantum Information Processing, 2020, 19
  • [4] Solving Discrete Logarithm Problem in an Interval Using Periodic Iterates
    Liu, Jianing
    Lv, Kewei
    INFORMATION AND COMMUNICATIONS SECURITY, ICICS 2017, 2018, 10631 : 75 - 80
  • [5] Solving the Discrete Logarithm of a 113-bit Koblitz Curve with an FPGA Cluster
    Wenger, Erich
    Wolfger, Paul
    SELECTED AREAS IN CRYPTOGRAPHY - SAC 2014, 2014, 8781 : 363 - 379
  • [6] Using Equivalence Classes to Accelerate Solving the Discrete Logarithm Problem in a Short Interval
    Galbraith, Steven D.
    Ruprai, Raminder S.
    PUBLIC KEY CRYPTOGRAPHY - PKC 2010, PROCEEDINGS, 2010, 6056 : 368 - +
  • [7] Cryptanalysing the critical group: efficiently solving Biggs's discrete logarithm problem
    Blackburn, Simon R.
    JOURNAL OF MATHEMATICAL CRYPTOLOGY, 2009, 3 (03) : 199 - 203
  • [8] Practical Solving of Discrete Logarithm Problem over Prime Fields Using Quantum Annealing
    Wronski, Michal
    COMPUTATIONAL SCIENCE, ICCS 2022, PT IV, 2022, : 93 - 106