Constructing elliptic curves in almost polynomial time
Reinier Broker, Peter Stevenhagen
Abstract
We present an algorithm that, on input of a positive integer N together with its prime factorization, constructs a finite field F and an elliptic curve E over F for which E(F) has order N. Although it is unproved that this can be done for all N, a heuristic analysis shows that the algorithm has an expected run time that is polynomial in 2omega(N) log N, where omega(N) is the number of distinct prime factors of N. In the cryptographically relevant case where N is prime, an expected run time O((log N)4+epsilon) can be achieved. We illustrate the efficiency of the algorithm by constructing elliptic curves with point groups of order N=102004 and N=nextprime(102004)=102004+4863.
Create a lesson
Related papers
Value distribution of multiplicative functions along linear fractional sequences
Sun-Kai Leung
Delta theory of Anderson Modules II: Hodge-Pink structure
Sudip Pandit, Arnab Saha
Integers divisible by a shifted prime in a given interval
Rebecca Abi Abdallah, Valeriya Kovaleva, Jeremy Schlitt et al.
On Piatetski-Shapiro primes from almost primes
Yuhua Zhao, Jinjiang Li, Linji Long et al.
On Consecutive Non-primitive Elements over Finite Fields
Bidushi Sharma, Dhiren Kumar Basnet
Birch's theorem over function fields with quadratically many variables
Matthew Hase-Liu