Search arXivSearch

arXiv · math/0311120

On the Bounded Sum-of-digits Discrete Logarithm Problem in Kummer and Artin-Schreier Extensions

Abstract

In this paper, we study the discrete logarithm problem in the finite fields $\F_{q^n}$ where $n|q-1$. The field is called a Kummer field or a Kummer extension of $\F_q$. It plays an important role in improving the AKS primality proving algorithm. It is known that we can efficiently construct an element $g$ with order greater than $2^n$ in the fields. Let $S_q(\bullet)$ be the function from integers to the sum of digits in their $q$-ary expansions. We present an algorithm that given $g^e$ ($ 0\leq e < q^n $) finds $e$ in random polynomial time, provided that $S_q (e) < n$. We then show that the problem is solvable in random polynomial time for most of the exponent $e$ with $S_q (e) < 1.32 n $. The main tool for the latter result is the Guruswami-Sudan list decoding algorithm. Built on these results, we prove that in the field $\F_{q^{q-1}}$, the bounded sum-of-digits discrete logarithm with respect to $g$ can be computed in random time $O(f(w) \log^4 (q^{q-1}))$, where $f$ is a subexponential function and $w$ is the bound on the $q$-ary sum-of-digits of the exponent. Hence the problem is fixed parameter tractable. These results are shown to be extendible to Artin-Schreier extension $\F_{p^p}$ where $p$ is a prime. Since every finite field has an extension of reasonable degree which is a Kummer field, our result reveals an unexpected property of the discrete logarithm problem, namely, the bounded sum-of-digits discrete logarithm problem in any given finite field becomes polynomial time solvable in certain low degree extensions.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Qi Cheng. 2003-11-07. On the Bounded Sum-of-digits Discrete Logarithm Problem in Kummer and Artin-Schreier Extensions. https://arxiv.org/abs/math/0311120

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Asymptotic density of k-almost primes

Landau's well known asymptotic formula $$N_k(x):=\ \mid\{n\leq x : Ω(n)=k\}\mid \ \sim \left( \frac{x}{\log x} \right) \frac{(\log\log x)^{k-1}}{(k - 1)!}\ \ (x \rightarrow \infty),$$ which also holds for $$π_k(x):=\ \mid\{n\leq x : ω(n)=k\}\mid,$$ is known to be fairly poor for $k > 1$, and when $k$ is allowed to tend to infinity with $x$, the study of $N_k(x)$ and $π_k(x)$ becomes very technical [1, Chapter II.6, $§$ 6.1, p.200]. I hope to show that the method described below provides not only a more accurate approach, but rather increases in its asymptotic accuracy as $k$ tends to infinity.

math.NT

Real quadratic base changes for $\mathrm{GL}_3$ and integral periods relations

We prove a $p$-adic divisibility between the automorphic periods of a cuspidal automorphic representation of $\mathrm{GL}_3(\mathbb{Q})$ and the periods of its Arthur-Clozel's base change to some real quadratic field $E$. This generalizes earlier works of Tilouine-Urban and of Hida in the case of classical modular forms. The divisibility we prove involves a new kind of automorphic periods, defined using the middle degree of the cuspidal cohomology of $\mathrm{GL}_3(E)$, instead of the top or bottom degrees. We also investigate the Rogawski's stable base change from the quasi-split unitary group $U_E$ associated with $E$ to $\mathrm{GL}_3(E)$. In this situation, we also obtain some results toward a $p$-adic divisibility of automorphic periods.

math.NT