Sciweavers

IACR
2016

On Splitting a Point with Summation Polynomials in Binary Elliptic Curves

8 years 8 months ago
On Splitting a Point with Summation Polynomials in Binary Elliptic Curves
Abstract. Recent research for efficient algorithms for solving the discrete logarithm (DL) problem on elliptic curves depends on the difficult question of the feasibility of index calculus which would consist of splitting EC points into sums of points lying in a certain subspace. A natural algebraic approach towards this goal is through solving systems of non linear multivariate equations derived from the so called summation polynomials which method have been proposed by Semaev in 2004 [12]. In this paper we consider simplified variants of this problem with splitting in two or three parts in binary curves. We propose three algorithms with running time of the order of 2n/3 for both problems. It is not clear how to interpret these results but they do in some sense violate the generic group model for these curves. Key Words: cryptanalysis, summation polynomials, algebraic attacks, block ciphers, Gr¨obner bases, DL problem, finite fields, elliptic curves, ECDSA, generic group model.
Nicolas T. Courtois
Added 03 Apr 2016
Updated 03 Apr 2016
Type Journal
Year 2016
Where IACR
Authors Nicolas T. Courtois
Comments (0)