SearcharxivSearch

arXiv subjects

Erik Mulder

Publications and source records attributed to Erik Mulder.

3 recordsLinked to original sources

Multi-target hyperbolic sieves and elliptic trace obstructions

Let $N=pq$ be a semiprime and let $\ell\nmid Na$ be an odd prime. The hyperbolic sieve set $H_a(N;\ell)=\{ax+Nx^{-1}:x\in\mathbb F_\ell^*\}$ contains the residue of the linear form $ap+q$ modulo $\ell$ and has exact cardinality $(\ell+\chi(aN))/2$, where $\chi$ is the Legendre symbol modulo $\ell$. We study simultaneous sieving for several linear forms and give a complete local analysis of the two-target primitive-root case proposed in connection with deterministic integer factorization. For two distinct coefficients $a,b$, with $A=4aN$ and $B=4bN$, we prove an exact formula for $|H_a(N;\ell)\cup H_b(N;\ell)|$ in terms of the degree-four character sum \[ K(A,B)=\sum_{z\in\mathbb F_\ell}\chi((z^2-A)(z^2-B)).\] For a smooth projective genus-one curve $E/\mathbb{F}_\ell$, we write $t_E=\ell+1-\#E(\mathbb{F}_\ell)$ for its Frobenius trace. With this convention, $K(A,B)$ is the Frobenius trace, up to sign and an additive constant, of the genus-one curve $Y^2=(X^2-A)(X^2-B)$. Hence Hasse--Weil gives a uniform $O(\sqrt\ell)$ error from the main term $3\ell/4$, and negative traces explain the counterexamples to the pointwise bound $3\ell/4+1$. We also prove a multi-target estimate \[\left|\left|\bigcup_{j=1}^k H_{a_j}(N;\ell)\right|-\ell(1-2^{-k})\right|\le (k-1+2^{-k})\sqrt\ell+k\] for distinct coefficients $a_1,\ldots,a_k$, together with the corresponding CRT product bound. Finally, for special-shape inputs $N=u^rv$, we study the $r$-power-constrained image $H_{a,r}(N;\ell)$ and determine its exact size by an elementary involution argument. These results recast the proposed local sieve questions as explicit finite-field statements with verified local tests.

math.NT

Large smooth twins from short lattice vectors

Finding the largest pair of consecutive $B$-smooth integers is computationally challenging. Current algorithms to find such pairs have an exponential runtime -- which has only be provably done for $B \leq 100$ and heuristically for $100 < B \leq 113$. We improve this by detailing a new algorithm to find such large pairs. The core idea is to solve the shortest vector problem (SVP) in a well constructed lattice. With this we are able to significantly increase $B$ and notably report the heuristically largest pair with $B = 751$ which has $196$-bits. By slightly modifying the lattice, we are able to find larger pairs for which one cannot conclusively say whether it is the largest or not for a given $B$. This notably includes a $213$-bit pair with $B = 997$ which is the largest pair found in this work.

math.NT

Fast square-free decomposition of integers using class groups

Let $n=a^2b$, where $b$ is square-free. In this paper we present an algorithm based on class groups of binary quadratic forms that finds the square-free decomposition of $n$, i.e. $a$ and $b$, in heuristic expected time: $$ \widetilde{\mathcal{O}}(L_{b}[1/2,1] \ln(n) + L_{b}[1/2,1/2] \ln(n)^2). $$ If $a,b$ are both primes of roughly the same cryptographic size, then our method is currently the fastest known method to factor $n$. This has applications in cryptography, since some cryptosystems rely on the hardness of factoring integers of this form.

math.NT