Hard Instances of the Constrained Discrete Logarithm Problem
Ilya Mironov, Anton Mityagin, Kobbi Nissim
Abstract
The discrete logarithm problem (DLP) generalizes to the constrained DLP, where the secret exponent x belongs to a set known to the attacker. The complexity of generic algorithms for solving the constrained DLP depends on the choice of the set. Motivated by cryptographic applications, we study sets with succinct representation for which the constrained DLP is hard. We draw on earlier results due to Erd\"os et al. and Schnorr, develop geometric tools such as generalized Menelaus' theorem for proving lower bounds on the complexity of the constrained DLP, and construct sets with succinct representation with provable non-trivial lower bounds.
Create a lesson
Related papers
Value distribution of multiplicative functions along linear fractional sequences
Sun-Kai Leung
Delta theory of Anderson Modules II: Hodge-Pink structure
Sudip Pandit, Arnab Saha
Integers divisible by a shifted prime in a given interval
Rebecca Abi Abdallah, Valeriya Kovaleva, Jeremy Schlitt et al.
On Piatetski-Shapiro primes from almost primes
Yuhua Zhao, Jinjiang Li, Linji Long et al.
On Consecutive Non-primitive Elements over Finite Fields
Bidushi Sharma, Dhiren Kumar Basnet
Birch's theorem over function fields with quadratically many variables
Matthew Hase-Liu