Search arXivSearch

arXiv · math/0411378

Do All Elliptic Curves of the Same Order Have the Same Difficulty of Discrete Log?

Abstract

The aim of this paper is to justify the common cryptographic practice of selecting elliptic curves using their order as the primary criterion. We can formalize this issue by asking whether the discrete log problem (DLOG) has the same difficulty for all curves over a given finite field with the same order. We prove that this is essentially true by showing polynomial time random reducibility of DLOG among such curves, assuming the Generalized Riemann Hypothesis (GRH). We do so by constructing certain expander graphs, similar to Ramanujan graphs, with elliptic curves as nodes and low degree isogenies as edges. The result is obtained from the rapid mixing of random walks on this graph. Our proof works only for curves with (nearly) the same endomorphism rings. Without this technical restriction such a DLOG equivalence might be false; however, in practice the restriction may be moot, because all known polynomial time techniques for constructing equal order curves produce only curves with nearly equal endomorphism rings.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

David Jao, Stephen D. Miller, Ramarathnam Venkatesan. 2005-09-02. Do All Elliptic Curves of the Same Order Have the Same Difficulty of Discrete Log?. https://doi.org/10.1007/11593447_2

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Asymptotic density of k-almost primes

Landau's well known asymptotic formula $$N_k(x):=\ \mid\{n\leq x : Ω(n)=k\}\mid \ \sim \left( \frac{x}{\log x} \right) \frac{(\log\log x)^{k-1}}{(k - 1)!}\ \ (x \rightarrow \infty),$$ which also holds for $$π_k(x):=\ \mid\{n\leq x : ω(n)=k\}\mid,$$ is known to be fairly poor for $k > 1$, and when $k$ is allowed to tend to infinity with $x$, the study of $N_k(x)$ and $π_k(x)$ becomes very technical [1, Chapter II.6, $§$ 6.1, p.200]. I hope to show that the method described below provides not only a more accurate approach, but rather increases in its asymptotic accuracy as $k$ tends to infinity.

math.NT

Real quadratic base changes for $\mathrm{GL}_3$ and integral periods relations

We prove a $p$-adic divisibility between the automorphic periods of a cuspidal automorphic representation of $\mathrm{GL}_3(\mathbb{Q})$ and the periods of its Arthur-Clozel's base change to some real quadratic field $E$. This generalizes earlier works of Tilouine-Urban and of Hida in the case of classical modular forms. The divisibility we prove involves a new kind of automorphic periods, defined using the middle degree of the cuspidal cohomology of $\mathrm{GL}_3(E)$, instead of the top or bottom degrees. We also investigate the Rogawski's stable base change from the quasi-split unitary group $U_E$ associated with $E$ to $\mathrm{GL}_3(E)$. In this situation, we also obtain some results toward a $p$-adic divisibility of automorphic periods.

math.NT