• DocumentCode
    1476108
  • Title

    Parameterized Splitting Systems for the Discrete Logarithm

  • Author

    Kim, Sungwook ; Cheon, Jung Hee

  • Author_Institution
    Dept. of Math. Sci., Seoul Nat. Univ. (SNU), Seoul, South Korea
  • Volume
    56
  • Issue
    5
  • fYear
    2010
  • fDate
    5/1/2010 12:00:00 AM
  • Firstpage
    2528
  • Lastpage
    2535
  • Abstract
    Hoffstein and Silverman suggested the use of low Hamming weight product (LHWP) exponents to accelerate group exponentiation while maintaining the security level. With LHWP exponents, the computation costs on GF(2 n) or Koblitz elliptic curves can be reduced significantly, where the cost of squaring and elliptic curve doubling is much lower than that of multiplication and elliptic curve addition, respectively. In this paper, we present a parameterized splitting system with an additional property, which is a refinement version of the system introduced in PKC´08. We show that it yields an algorithm for the discrete logarithm problem (DLP) with LHWP exponents with lower complexity than that of any previously known algorithms. To demonstrate its application, we attack the GPS identification scheme modified by Coron, Lefranc, and Poupard in CHES´05 and the DLP with Hoffstein and Silverman´s (2,2,11)-exponent. The time complexity of our key recovery attack against the GPS scheme is 2 61.82 , which was expected to be 2 78. Hoffstein and Silverman´s (2,2,11)-exponent can be recovered with a time complexity of 2 53.02 , which is the lowest among the known attacks.
  • Keywords
    computational complexity; public key cryptography; GPS identification; Koblitz elliptic curves; LHWP exponent; computation cost; discrete logarithm problem; elliptic curve doubling; group exponentiation; low Hamming weight product; parameterized splitting system; recovery attack; security level; time complexity; Acceleration; Computational efficiency; Costs; Cryptographic protocols; Elliptic curve cryptography; Elliptic curves; Global Positioning System; Government; Hamming weight; Security; Discrete logarithm problem with low Hamming weight product (LHWP) exponents; parameterized splitting systems;
  • fLanguage
    English
  • Journal_Title
    Information Theory, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    0018-9448
  • Type

    jour

  • DOI
    10.1109/TIT.2010.2044071
  • Filename
    5452195