SearcharxivSearch

arXiv subjects

Felix Fontein

Publications and source records attributed to Felix Fontein.

11 recordsLinked to original sources

PotLLL: A Polynomial Time Version of LLL With Deep Insertions

Lattice reduction algorithms have numerous applications in number theory, algebra, as well as in cryptanalysis. The most famous algorithm for lattice reduction is the LLL algorithm. In polynomial time it computes a reduced basis with provable output quality. One early improvement of the LLL algorithm was LLL with deep insertions (DeepLLL). The output of this version of LLL has higher quality in practice but the running time seems to explode. Weaker variants of DeepLLL, where the insertions are restricted to blocks, behave nicely in practice concerning the running time. However no proof of polynomial running time is known. In this paper PotLLL, a new variant of DeepLLL with provably polynomial running time, is presented. We compare the practical behavior of the new algorithm to classical LLL, BKZ as well as blockwise variants of DeepLLL regarding both the output quality and running time.

cs.CR

On the Probability of Generating a Lattice

We study the problem of determining the probability that m vectors selected uniformly at random from the intersection of the full-rank lattice L in R^n and the window [0,B)^n generate $Λ$ when B is chosen to be appropriately large. This problem plays an important role in the analysis of the success probability of quantum algorithms for solving the Discrete Logarithm Problem in infrastructures obtained from number fields and also for computing fundamental units of number fields. We provide the first complete and rigorous proof that 2n+1 vectors suffice to generate L with constant probability (provided that B is chosen to be sufficiently large in terms of n and the covering radius of L and the last n+1 vectors are sampled from a slightly larger window). Based on extensive computer simulations, we conjecture that only n+1 vectors sampled from one window suffice to generate L with constant success probability. If this conjecture is true, then a significantly better success probability of the above quantum algorithms can be guaranteed.

math.CO

A Polynomial Time Version of LLL With Deep Insertions

Lattice reduction algorithms have numerous applications in number theory, algebra, as well as in cryptanalysis. The most famous algorithm for lattice reduction is the LLL algorithm. In polynomial time it computes a reduced basis with provable output quality. One early improvement of the LLL algorithm was LLL with deep insertions (DeepLLL). The output of this version of LLL has higher quality in practice but the running time seems to explode. Weaker variants of DeepLLL, where the insertions are restricted to blocks, behave nicely in practice concerning the running time. However no proof of polynomial running time is known. In this paper a new variant of DeepLLL with provably polynomial running time is presented. We compare the practical behavior of the new algorithm to classical LLL, BKZ as well as blockwise variants of DeepLLL regarding both the output quality and running time.

cs.CR

Quantum Algorithm for Computing the Period Lattice of an Infrastructure

We present a quantum algorithm for computing the period lattice of infrastructures of fixed dimension. The algorithm applies to infrastructures that satisfy certain conditions. The latter are always fulfilled for infrastructures obtained from global fields, i.e., algebraic number fields and function fields with finite constant fields. The first of our main contributions is an exponentially better method for sampling approximations of vectors of the dual lattice of the period lattice than the methods outlined in the works of Hallgren and Schmidt and Vollmer. This new method improves the success probability by a factor of at least 2^{n^2-1} where n is the dimension. The second main contribution is a rigorous and complete proof that the running time of the algorithm is polynomial in the logarithm of the determinant of the period lattice and exponential in n. The third contribution is the determination of an explicit lower bound on the success probability of our algorithm which greatly improves on the bounds given in the above works. The exponential scaling seems inevitable because the best currently known methods for carrying out fundamental arithmetic operations in infrastructures obtained from algebraic number fields take exponential time. In contrast, the problem of computing the period lattice of infrastructures arising from function fields can be solved without the exponential dependence on the dimension n since this problem reduces efficiently to the abelian hidden subgroup problem. This is also true for other important computational problems in algebraic geometry. The running time of the best classical algorithms for infrastructures arising from global fields increases subexponentially with the determinant of the period lattice.

quant-ph

The Infrastructure of a Global Field of Arbitrary Unit Rank

In this paper, we show a general way to interpret the infrastructure of a global field of arbitrary unit rank. This interpretation generalizes the prior concepts of the giant step operation and f-representations, and makes it possible to relate the infrastructure to the (Arakelov) divisor class group of the global field. In the case of global function fields, we present results that establish that effective implementation of the presented methods is indeed possible, and we show how Shanks' baby-step giant-step method can be generalized to this situation.

math.NT

Rigorous Computation of Fundamental Units in Algebraic Number Fields

We present an algorithm that unconditionally computes a representation of the unit group of a number field of discriminant $Δ_K$, given a full-rank subgroup as input, in asymptotically fewer bit operations than the baby-step giant-step algorithm. If the input is assumed to represent the full unit group, for example, under the assumption of the Generalized Riemann Hypothesis, then our algorithm can unconditionally certify its correctness in expected time $O(Δ_K^{n/(4n + 2) + ε}) = O(Δ_K^{1/4 - 1/(8n+4) + ε})$ where $n$ is the unit rank.

math.NT

Class Number and Regulator Computation in Purely Cubic Function Fields of Unit Rank Two

We describe and give computational results of a procedure to compute the divisor class number and regulator of most purely cubic function fields of unit rank 2. Our implementation is an improvement to Pollard's Kangaroo method in infrastructures, using distribution results of class numbers as well as information on the congruence class of the divisor class number, and an adaptation that efficiently navigates these torus-shaped infrastructures. Moreover, this is the first time that an efficient "square-root" algorithm has been applied to the infrastructure of a global field of unit rank 2. With the exception of certain function fields defined by Picard curves, our examples are the largest known divisor class numbers and regulators ever computed for a function field of genus 3.

math.NT

Explicit Methods for Radical Function Fields over Finite Fields

We develop explicit formulas and algorithms for arithmetic in radical function fields K/k(x) over finite constant fields. First, we classify which places of k(x) whose local integral bases have an easy monogenic form, and give explicit formulas for these bases. Then, for a fixed place p of k(x), we give formulas for functions whose valuation is zero for all places P | p except one, for which it is one. We extend a result by Q. Wu on a k[x]-basis of its integral closure in K, show how to compute certain Riemann-Roch spaces and how to compute the exact constant field, resulting in explicit formulas for the exact constant field together with easy to evaluate formulas for the genus of K. Finally, we show how to approximate the Euler product to obtain the class number using ideas of R. Scheidler and A. Stein and give an algorithm. We give bounds on the running time for all algorithms.

math.NT

Holes in the Infrastructure of Global Hyperelliptic Function Fields

We prove that the number of "hole elements" $H(K)$ in the infrastructure of a hyperelliptic function field $K$ of genus $g$ with finite constant field $\F_q$ with $n + 1$ places at infinity, of whom $n' + 1$ are of degree one, satisfies $|\frac{H(K)}{\abs{\Pic^0(K)}} - \frac{n'}{q}| = O(16^g n q^{-3/2}).$ We obtain an explicit formula for the number of holes using only information on the infinite places and the coefficients of the $L$-polynomial of the hyperelliptic function field. This proves a special case of a conjecture by E. Landquist and the author on the number of holes of an infrastructure of a global function field. Moreover, we investigate the size of a hole in case $n = n'$, and show that asymptotically for $n \to \infty$, the size of a hole next to a reduced divisor $D$ behaves like the function $\frac{n^{g - °D}}{(g - °D)!}$.

math.NT

Groups from Cyclic Infrastructures and Pohlig-Hellman in Certain Infrastructures

In discrete logarithm based cryptography, a method by Pohlig and Hellman allows solving the discrete logarithm problem efficiently if the group order is known and has no large prime factors. The consequence is that such groups are avoided. In the past, there have been proposals for cryptography based on cyclic infrastructures. We will show that the Pohlig-Hellman method can be adapted to certain cyclic infrastructures, which similarly implies that certain infrastructures should not be used for cryptography. This generalizes a result by Müller, Vanstone and Zuccherato for infrastructures obtained from hyperelliptic function fields. We recall the Pohlig-Hellman method, define the concept of a cyclic infrastructure and briefly describe how to obtain such infrastructures from certain function fields of unit rank one. Then, we describe how to obtain cyclic groups from discrete cyclic infrastructures and how to apply the Pohlig-Hellman method to compute absolute distances, which is in general a computationally hard problem for cyclic infrastructures. Moreover, we give an algorithm which allows to test whether an infrastructure satisfies certain requirements needed for applying the Pohlig-Hellman method, and discuss whether the Pohlig-Hellman method is applicable in infrastructures obtained from number fields. Finally, we discuss how this influences cryptography based on cyclic infrastructures.

cs.CR