Abstract
The discrete logarithm problem in an interval of size N N in a group G G is: Given g , h ∈ G g, h \in G and an integer N N to find an integer 0 ≤ n ≤ N 0 \le n \le N , if it exists, such that h = g n h = g^n . Previously the best low-storage algorithm to solve this problem was the van Oorschot and Wiener version of the Pollard kangaroo method. The heuristic average case running time of this method is ( 2 + o ( 1 ) ) N (2 + o(1)) \sqrt {N} group operations. We present two new low-storage algorithms for the discrete logarithm problem in an interval of size N N . The first algorithm is based on the Pollard kangaroo method, but uses 4 kangaroos instead of the usual two. We explain why this algorithm has heuristic average case expected running time of ( 1.715 + o ( 1 ) ) N (1.715 + o(1)) \sqrt {N} group operations. The second algorithm is based on the Gaudry-Schost algorithm and the ideas of our first algorithm. We explain why this algorithm has heuristic average case expected running time of ( 1.661 + o ( 1 ) ) N (1.661 + o(1)) \sqrt {N} group operations. We give experimental results that show that the methods do work close to that predicted by the theoretical analysis.
Cite
CITATION STYLE
Galbraith, S., Pollard, J., & Ruprai, R. (2012). Computing discrete logarithms in an interval. Mathematics of Computation, 82(282), 1181–1195. https://doi.org/10.1090/s0025-5718-2012-02641-x
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.