Symmetrized summation polynomials: Using small order torsion points to speed up elliptic curve index calculus

  • Jean Charles Faugère
  • , Louise Huot
  • , Antoine Joux
  • , Guénaël Renault
  • , Vanessa Vitse

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Decomposition-based index calculus methods are currently efficient only for elliptic curves E defined over non-prime finite fields of very small extension degree n. This corresponds to the fact that the Semaev summation polynomials, which encode the relation search (or "sieving"), grow over-exponentially with n. Actually, even their computation is a first stumbling block and the largest Semaev polynomial ever computed is the 6-th. Following ideas from Faugère, Gaudry, Huot and Renault, our goal is to use the existence of small order torsion points on E to define new summation polynomials whose symmetrized expressions are much more compact and easier to compute. This setting allows to consider smaller factor bases, and the high sparsity of the new summation polynomials provides a very efficient decomposition step. In this paper the focus is on 2-torsion points, as it is the most important case in practice. We obtain records of two kinds: we successfully compute up to the 8-th symmetrized summation polynomial and give new timings for the computation of relations with degree 5 extension fields.

Original languageEnglish
Title of host publicationAdvances in Cryptology, EUROCRYPT 2014 - 33rd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Proceedings
PublisherSpringer Verlag
Pages40-57
Number of pages18
ISBN (Print)9783642552199
DOIs
Publication statusPublished - 1 Jan 2014
Externally publishedYes
Event33rd Annual International Conference on the Theory and Applications of Cryptographic Techniques, EUROCRYPT 2014 - Copenhagen, Denmark
Duration: 11 May 201415 May 2014

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume8441 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference33rd Annual International Conference on the Theory and Applications of Cryptographic Techniques, EUROCRYPT 2014
Country/TerritoryDenmark
CityCopenhagen
Period11/05/1415/05/14

Keywords

  • ECDLP
  • Semaev polynomials
  • decomposition method
  • elliptic curves
  • index calculus
  • invariant theory
  • multivariate polynomial systems

Fingerprint

Dive into the research topics of 'Symmetrized summation polynomials: Using small order torsion points to speed up elliptic curve index calculus'. Together they form a unique fingerprint.

Cite this