Article ID | Journal | Published Year | Pages | File Type |
---|---|---|---|---|
8895606 | Finite Fields and Their Applications | 2018 | 21 Pages |
Abstract
The discrete logarithm over finite fields of small characteristic can be solved much more efficiently than previously thought. This algorithmic breakthrough is based on pinpointing relations among the factor base discrete logarithms. In this paper, we concentrate on the Kummer extension Fq2(qâ1)=Fq2[x]/(xqâ1âA). It has been suggested that in this case, a small number of degenerate relations (from the Borel subgroup) are enough to solve the factor base discrete logarithms. We disprove the conjecture, and design a new heuristic algorithm with an improved bit complexity OË(q1+θ) (or algebraic complexity OË(qθ)) to compute discrete logarithms of all the elements in the factor base {x+α|αâFq2}, where θ<2.38 is the matrix multiplication exponent over rings. Given additional time OË(q4), we can compute discrete logarithms of at least Ω(q3) many monic irreducible quadratic polynomials. We reduce the correctness of the algorithm to a conjecture concerning the determinant of a simple (q+1)-dimensional lattice, rather than to elusive smoothness assumptions. We verify the conjecture numerically for all prime powers q such that log2â¡(q2(qâ1))â¤5134, and provide theoretical supporting evidences.
Related Topics
Physical Sciences and Engineering
Mathematics
Algebra and Number Theory
Authors
Dianyan Xiao, Jincheng Zhuang, Qi Cheng,