SearcharxivSearch

arXiv subjects

Federico Pintore

Publications and source records attributed to Federico Pintore.

4 recordsLinked to original sources

The Hessian of elliptic curves as a Latt\`es map

We prove that the Hessian transformation of elliptic curves, both as an action on $j$-invariants and on the Hesse pencil, is a rigid Latt\`es map fitting into a reduced diagram, hence it lifts to a degree-$3$ endomorphism $\psi$ of a prescribed elliptic curve $E$. This result provides an effective tool to investigate the dynamics of the Hessian transformation, whose symmetries are inherited from those of $\psi$, which we characterize. In particular, over arbitrary fields of characteristic different from $2$ and $3$, the functional graphs of the Hessian and, more generally, of Latt\`es maps fitting into analogous reduced diagrams, are completely determined by the action of $\psi$ on the twists of $E$. When the underlying field is finite, we specialize these results to obtain a complete classification of Hessian functional graphs and derive an efficient method for computing iterated Hessians.

math.NT

A multistep strategy for polynomial system solving over finite fields and a new algebraic attack on the stream cipher Trivium

In this paper we introduce a multistep generalization of the guess-and-determine or hybrid strategy for solving a system of multivariate polynomial equations over a finite field. In particular, we propose performing the exhaustive evaluation of a subset of variables stepwise, that is, by incrementing the size of such subset each time that an evaluation leads to a polynomial system which is possibly unfeasible to solve. The decision about which evaluation to extend is based on a preprocessing consisting in computing an incomplete Grobner basis after the current evaluation, which possibly generates linear polynomials that are used to eliminate further variables. If the number of remaining variables in the system is deemed still too high, the evaluation is extended and the preprocessing is iterated. Otherwise, we solve the system by a complete Grobner basis computation. Having in mind cryptanalytic applications, we present an implementation of this strategy in an algorithm called MultiSolve which is designed for polynomial systems having at most one solution. We prove explicit formulas for its complexity which are based on probability distributions that can be easily estimated by performing the proposed preprocessing on a testset of evaluations for different subsets of variables. We prove that an optimal complexity of MultiSolve is achieved by using a full multistep strategy with a maximum number of steps and in turn the standard guess-and-determine strategy, which essentially is a strategy consisting of a single step, is the worst choice. Finally, we extensively study the behaviour of MultiSolve when performing an algebraic attack on the well-known stream cipher Trivium.

cs.SC

On the security of the Blockchain Bix Protocol and Certificates

The BIX protocol is a blockchain-based protocol that allows distribution of certificates linking a subject with his public key, hence providing a service similar to that of a PKI but without the need of a CA. In this paper we analyze the security of the BIX protocol in a formal way, in four steps. First, we identify formal security assumptions which are well-suited to this protocol. Second, we present some attack scenarios against the BIX protocol. Third, we provide a formal security proof that some of these attacks are not feasible under our previously established assumptions. Finally, we show how another attack may be carried on.

cs.CR

On the Representation of Primes by Binary Quadratic Forms, and Elliptic Curves

It is shown that, under some mild technical conditions, representations of prime numbers by binary quadratic forms can be computed in polynomial complexity by exploiting Schoof's algorithm, which counts the number of $\mathbb F_q$-points of an elliptic curve over a finite field $\mathbb F_q$. Further, a method is described which computes representations of primes from reduced quadratic forms by means of the integral roots of polynomials over $\mathbb Z$. Lastly, some progress is made on the still-unsettled general problem of deciding which primes are represented by which classes of quadratic forms of given discriminant.

math.NT