Search arXivSearch

arXiv · math/0505487

Thompson's group and public key cryptography

Abstract

Recently, several public key exchange protocols based on symbolic computation in non-commutative (semi)groups were proposed as a more efficient alternative to well established protocols based on numeric computation. Notably, the protocols due to Anshel-Anshel-Goldfeld and Ko-Lee et al. exploited the conjugacy search problem in groups, which is a ramification of the discrete logarithm problem. However, it is a prevalent opinion now that the conjugacy search problem alone is unlikely to provide sufficient level of security no matter what particular group is chosen as a platform. In this paper we employ another problem (we call it the decomposition problem), which is more general than the conjugacy search problem, and we suggest to use R. Thompson's group as a platform. This group is well known in many areas of mathematics, including algebra, geometry, and analysis. It also has several properties that make it fit for cryptographic purposes. In particular, we show here that the word problem in Thompson's group is solvable in almost linear time.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Vladimir Shpilrain, Alexander Ushakov. 2005-05-24. Thompson's group and public key cryptography. https://arxiv.org/abs/math/0505487

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Hyperfiniteness of boundary actions via tree decompositions

We study conditions for a countable group acting on a connected locally finite hyperbolic graph to induce a hyperfinite orbit equivalence relation on the Gromov boundary of the graph in terms of tree-decompositions of the graph. We prove that for a connected locally finite hyperbolic graph $X$ equipped with an action of a countable group $G$, if $(T, β)$ is a $G$-invariant tree-decomposition of $X$ such that each bag induces a connected subgraph $X_t$ of $X$ for each $t \in V(T)$, each adhesion set is finite and such that there are only finitely many $G$-orbits of edges of $T$, then the orbit equivalence relation of $G$ acting on the Gromov boundary $\partial X$ is hyperfinite provided the orbit equivalence relation of $G$ acting on $\partial T$ is hyperfinite and the orbit equivalence relations of the bag stabilizers acting on $\partial X_t$ are all hyperfinite. We show that the converse also holds if $(T, β)$ satisfies the additional property that each adhesion set distinguishes at least two ends of $X$.

math.GR

Compatible additions on a six-element commutative semigroup: equational bases and subvariety lattices

Let $M$ be the six-element commutative semigroup occurring as the common multiplicative reduct of the semirings $SR_6$ and $TR_6$. The closing paragraph of Shao, Ren, and Gao~\cite{ShaoRenGao2026} asks for the finite-basis and subvariety questions for the four remaining compatible additions on $M$. We answer these questions for the four isomorphism types $R_{01},R_{02},R_{11},R_{12}$. First, we classify all compatible additions on $M$: there are nine labelled additions and six isomorphism types, parametrized by $R_{ij}$ with $0\leq i\leq j\leq 2$. For each of the four new types we give a graph-theoretic criterion for every identity, an explicit infinite basis, and a proof of nonfinite basability. The generated varieties $\V(R_{01})$ and $\V(R_{02})$ have eleven subvarieties each, while $\V(R_{11})$ has sixty-six. The lattice $\Sub(\V(R_{12}))$ is countably infinite. Every identity in this variety reduces to a subset of twenty-five fixed identities together with two monotone path families $γ_n$ and $\gammaD_n$. This yields a canonical signature $(H,p,q)$, complete normal forms, explicit meet and join operations, and a formula for all covers. There are 153 fixed nodes, 43 one-parameter families, and 9 two-parameter families; exactly eighteen subvarieties are finitely based, and the unique limit subvariety is $\V(SR_6)$. The strong nonfinite-basis status of the four finite semirings remains open.

math.GR