Search arXivSearch

arXiv · 2008.02717

Computation of a 30750-Bit Binary Field Discrete Logarithm

Abstract

This paper reports on the computation of a discrete logarithm in the finite field $\mathbb F_{2^{30750}}$, breaking by a large margin the previous record, which was set in January 2014 by a computation in $\mathbb F_{2^{9234}}$. The present computation made essential use of the elimination step of the quasi-polynomial algorithm due to Granger, Kleinjung and Zumbrägel, and is the first large-scale experiment to truly test and successfully demonstrate its potential when applied recursively, which is when it leads to the stated complexity. It required the equivalent of about 2900 core years on a single core of an Intel Xeon Ivy Bridge processor running at 2.6 GHz, which is comparable to the approximately 3100 core years expended for the discrete logarithm record for prime fields, set in a field of bit-length 795, and demonstrates just how much easier the problem is for this level of computational effort. In order to make the computation feasible we introduced several innovative techniques for the elimination of small degree irreducible elements, which meant that we avoided performing any costly Gröbner basis computations, in contrast to all previous records since early 2013. While such computations are crucial to the $L(\frac 1 4 + o(1))$ complexity algorithms, they were simply too slow for our purposes. Finally, this computation should serve as a serious deterrent to cryptographers who are still proposing to rely on the discrete logarithm security of such finite fields in applications, despite the existence of two quasi-polynomial algorithms and the prospect of even faster algorithms being developed.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Robert Granger, Thorsten Kleinjung, Arjen K. Lenstra, Benjamin Wesolowski, Jens Zumbrägel. 2020-08-06. Computation of a 30750-Bit Binary Field Discrete Logarithm. https://arxiv.org/abs/2008.02717

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

On single-variable Witten zeta functions of rank two and three

By introducing a novel integration kernel for the Mellin transform, we uncover many previously unknown and intriguing properties of the Witten zeta functions of rank two and three. Detailed results concerning their pole locations, residues, and special values are obtained. We propose a non-trivial conjecture regarding their derivatives at the origin, which seems to encode deep information about the root system. We also discuss their behavior at negative integers, highlighting a connection with Eisenstein series and a $p$-adic observation.

math.NT

On graded Lie algebras associated to once-punctured elliptic curves with complex multiplication

We study a graded Lie algebra arising from the Galois action on the pro-$p$ fundamental group of a once-punctured elliptic curve with complex multiplication. Among other things, we provide a minimal generating set of the rationalized Lie algebra under suitable assumptions. The proof is based on a slight variant of the theory of weighted completion of profinite groups developed by Hain and Matsumoto.

math.NT

Burgess-type volume dependent bounds for character sums over $\mathbb{F}_{p^n}$

We establish a Burgess-type bound for short multiplicative character sums over finite fields $\mathbb{F}_{p^n}$. Let \[ B=\left\{\sum_{i=1}^{n}x_iω_i: N_i+1\le x_i\le N_i+H_i,1\le i\le n\right\}\subseteq\mathbb{F}_{p^n}, \] where $1\le H_i\le p$ for all $1\le i\le n$, and the side lengths satisfy $H_1\le H_2\le\cdots\le H_n.$ We prove that if the side lengths satisfy certain lower bounds in terms of the two largest side lengths, then a nontrivial cancellation occurs in the character sum over the boxes. This generalizes the work of Gabdullin \cite{GB} in dimensions $n=2,3$ to arbitrary dimension. This also generalizes the character sum estimate of Konyagin \cite{Kon} where each of the side lengths of the boxes are greater than $p^{1/4}$. The proof combines techniques from the geometry of numbers, multiplicative energy estimates, and Katz's bounds for multiplicative character sums.

math.NT