Computing discrete logarithms in subfields of residue class rings

Abstract

Recent breakthrough methods gggz,joux,bgjt on computing discrete logarithms in small characteristic finite fields share an interesting feature in common with the earlier medium prime function field sieve method jl. To solve discrete logarithms in a finite extension of a finite field , a polynomial h(x) ∈ [x] of a special form is constructed with an irreducible factor g(x) ∈ [x] of the desired degree. The special form of h(x) is then exploited in generating multiplicative relations that hold in the residue class ring [x]/h(x)[x] hence also in the target residue class field [x]/g(x)[x]. An interesting question in this context and addressed in this paper is: when and how does a set of relations on the residue class ring determine the discrete logarithms in the finite fields contained in it? We give necessary and sufficient conditions for a set of relations on the residue class ring to determine discrete logarithms in the finite fields contained in it. We also present efficient algorithms to derive discrete logarithms from the relations when the conditions are met. The derived necessary conditions allow us to clearly identify structural obstructions intrinsic to the special polynomial h(x) in each of the aforementioned methods, and propose modifications to the selection of h(x) so as to avoid obstructions.

0

Turn this paper into a lesson

ArcXiv compiles a structured reading guide from this paper's metadata: plain-English importance, contributions, prerequisite concepts, which sections to read first, flashcards, and a quiz. Grounded in the abstract, never invented.

Discussion (0)

Sign in to join the discussion.

Loading comments…