SearcharxivSearch

arXiv · math/0311120

On the Bounded Sum-of-digits Discrete Logarithm Problem in Kummer and Artin-Schreier Extensions

Abstract

In this paper, we study the discrete logarithm problem in the finite fields $\F_{q^n}$ where $n|q-1$. The field is called a Kummer field or a Kummer extension of $\F_q$. It plays an important role in improving the AKS primality proving algorithm. It is known that we can efficiently construct an element $g$ with order greater than $2^n$ in the fields. Let $S_q(\bullet)$ be the function from integers to the sum of digits in their $q$-ary expansions. We present an algorithm that given $g^e$ ($ 0\leq e < q^n $) finds $e$ in random polynomial time, provided that $S_q (e) < n$. We then show that the problem is solvable in random polynomial time for most of the exponent $e$ with $S_q (e) < 1.32 n $. The main tool for the latter result is the Guruswami-Sudan list decoding algorithm. Built on these results, we prove that in the field $\F_{q^{q-1}}$, the bounded sum-of-digits discrete logarithm with respect to $g$ can be computed in random time $O(f(w) \log^4 (q^{q-1}))$, where $f$ is a subexponential function and $w$ is the bound on the $q$-ary sum-of-digits of the exponent. Hence the problem is fixed parameter tractable. These results are shown to be extendible to Artin-Schreier extension $\F_{p^p}$ where $p$ is a prime. Since every finite field has an extension of reasonable degree which is a Kummer field, our result reveals an unexpected property of the discrete logarithm problem, namely, the bounded sum-of-digits discrete logarithm problem in any given finite field becomes polynomial time solvable in certain low degree extensions.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Qi Cheng. 2003-11-07. On the Bounded Sum-of-digits Discrete Logarithm Problem in Kummer and Artin-Schreier Extensions. https://arxiv.org/abs/math/0311120

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Ordinary 3-Isogeny Graphs and Improvement of Supersingularity Testing for Twisted Hessian Curves over Prime Fields

For any primes $p \neq \ell$, $\ell$-isogeny graphs of ordinary elliptic curves defined over $\mathbb{F}_{p^2}$ have a typical structure called $\ell$-volcanoes, and the structure is the core of Sutherland's supersingularity testing algorithm for elliptic curves. In this paper, by exploiting the properties of $3$-isogenies between twisted Hessian curves, we show that when $p \equiv 2 \pmod{3}$ and $\ell = 3$, every ordinary twisted Hessian curve defined over $\mathbb{F}_p$ lies on the surface of the $3$-volcano. As an application, we give an improved version of Sutherland's supersingularity testing algorithm specialized to twisted Hessian curves defined over $\mathbb{F}_p$ with $p \equiv 2 \pmod{3}$. We also give a generalization of the known fact that any supersingular $j$-invariant is a cube in $\mathbb{F}_{p^2}$; we show that for any twisted Hessian curve $H(a,d)$ defined over $\mathbb{F}_{p^2}$, its $j$-invariant is not a cube in $\mathbb{F}_{p^2}$ if and only if $H(a,d)$ is ordinary and lies on the floor of a $3$-volcano.

math.NT

Effective estimates for exponential sums with multiplicative coefficients

Let $f$ be multiplicative, with $|f(p)|\le A$ at primes and $\sum_{n\le x}|f(n)|^2\le A^2x$ for every $x\ge1$. If $|\alpha-a/q|\le q^{-2}$, $(a,q)=1$, and $3\le R\le q\le N/R$, we prove \[ \sum_{n\le N}f(n)\operatorname{e}(n\alpha) \ll_A \frac{N}{\log N} +\frac{N}{\sqrt R}\sqrt{\log\log(3R)} \] with effective implied constants. Montgomery and Vaughan proved this with second term $NR^{-1/2}(\log R)^{3/2}$, and, for $1$-bounded functions, Bachman replaced it by $NR^{-1/2}\sqrt{\log R\log\log R}$. We remove the factor $\sqrt{\log R}$ from Bachman's second term while retaining the original coefficient hypotheses of Montgomery and Vaughan. A more precise estimate records the distance from a rational number. The proof combines the Brun-Titchmarsh inequality on short intervals with maximal Fourier estimates derived from the Carleson-Hunt theorem; the local bounds permit arbitrary prime-dependent prefixes. We also prove sharpness of the square-root displacement dependence.

math.NT

Rational Approximations for Reciprocals of Multiple Zeta Values and Trivariate Cauchy Numbers

In this paper, we will study a trivariate extension of the Cauchy numbers of both the first kind (also called Gregory coefficients) and the second kind (also called N\"orlund numbers) via the Laurent expansion of the reciprocal of any positive integer power (which is called the order) of multiple polylogarithms. In the case of logarithm, we will show by the WZ method that for each order $\ell>1$ some Gregory coefficient of order $\ell$ must vanish, in contrast to the fact that all classical Gregory coefficients are nonzero. We also prove in this higher order logarithm case that the sequence is eventually alternating for each fixed order, a property enjoyed by the classical Gregory coefficients. In the most general setting, we conjecture that these new sequences are all eventually positive, which is supported by strong numerical evidence. Finally, we confirm this conjecture in the special case of polylogarithms and double polylogarithms. As a by product, for each zeta value and double zeta value, we find an infinite family of identities expressing its reciprocal as a sum of a rational number and an improper integral.

math.NT