Search arXivSearch

arXiv · 2002.03811

Efficient ECM factorization in parallel with the Lyness map

Abstract

The Lyness map is a birational map in the plane which provides one of the simplest discrete analogues of a Hamiltonian system with one degree of freedom, having a conserved quantity and an invariant symplectic form. As an example of a symmetric Quispel-Roberts-Thompson (QRT) map, each generic orbit of the Lyness map lies on a curve of genus one, and corresponds to a sequence of points on an elliptic curve which is one of the fibres in a pencil of biquadratic curves in the plane. Here we present a version of the elliptic curve method (ECM) for integer factorization, which is based on iteration of the Lyness map with a particular choice of initial data. More precisely, we give an algorithm for scalar multiplication of a point on an elliptic curve, which is represented by one of the curves in the Lyness pencil. In order to avoid field inversion, and require only field multiplication (${\bf M}$), squaring (${\bf S}$) and addition, projective coordinates in $\mathbb{P}^1 \times \mathbb{P}^1$ are used. Neglecting multiplication by curve constants (assumed small), each addition of the chosen point uses $2{\bf M}$, while each doubling step requires $15{\bf M}$. We further show that the doubling step can be implemented efficiently in parallel with four processors, dropping the effective cost to $4{\bf M}$. Our scalar multiplication algorithm should require, on average, roughly twice as many multiplications per bit as the fastest state of the art methods using twisted Edwards curves with small constants, but it can be applied to any elliptic curve over $\mathbb{Q}$, whereas twisted Edwards curves (equivalent to Montgomery curves) correspond to only a subset of all elliptic curves. Hence, if implemented in parallel, our method may have potential advantages for integer factorization or elliptic curve cryptography.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Andrew N. W. Hone. 2020-02-05. Efficient ECM factorization in parallel with the Lyness map. https://arxiv.org/abs/2002.03811

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

On the factorisation of the $p$-adic Rankin-Selberg $L$-function in the supersingular case

Given a cusp form $f$ which is supersingular at a fixed prime $p$ away from the level, and a Coleman family $F$ through one of its $p$-stabilisations, we construct a $2$-variable meromorphic $p$-adic $L$-function for the symmetric square of $F$. We prove that this new $p$-adic $L$-function interpolates values of complex imprimitive symmetric square $L$-functions, for the various specialisations of the family $F$. We use this $p$-adic $L$-function to prove a $p$-adic factorisation formula, expressing the geometric $p$-adic $L$-function attached to the Rankin--Selberg convolution of $f$ with itself as a the product of the $p$-adic symmetric square $L$-function of $f$ and a Kubota-Leopoldt $L$-function. This extends a result of Dasgupta in the ordinary case.

math.NT

Exceptional poles of archimedean Rankin-Selberg L-functions for irreducible generic representations of GL(n,R)

For irreducible generic representations $π_1$ and $π_2$ of $\operatorname{GL}_n(\mathbb R)$, we prove that the notions of exceptional pole of type $1$ and type $2$ coincide at every level. When both representations are in general position, we use this identification to express the Rankin--Selberg $L$-function $L(s,π_1\timesπ_2)$ in terms of the exceptional $L$-factors attached to the irreducible constituents of their derivatives.

math.NT