Zero-constant-term Newton-polytope case
v1.3 research notesResolve the zero-constant-term case in the Newton-polytope formulation of multivariate small-root methods....
Cryptographic primitives from hard small roots
v1.3 research notesConstruct additional cryptographic primitives whose security follows from the hardness of finding small roots....
Quality of rotation-augmented cyclic-lattice reduction
v1.3 research notesAnalyze how effective rotation-augmented lattice reduction is on cyclic or NTRU lattices....
Faster cyclic-lattice reduction
v1.3 research notesSpeed up rotation-augmented reduction algorithms for cyclic or NTRU lattices....
Prime extension-degree quotients of elliptic-curve orders
v1.3 research notesFor a fixed $E/\mathbb{F}_q$, prove that $\#E(\mathbb{F}_{q^n})/\#E(\mathbb{F}_q)$ is prime for infinitely many $n$....
Prime reductions of elliptic curves over the rationals
v1.3 research notesFor a torsion-free elliptic curve $E/\mathbb{Q}$, prove that $\#E(\mathbb{F}_p)$ is prime for infinitely many primes $p$....
Effective representation of principally polarized abelian threefolds
v1.3 research notesGive an effective input representation for a principally polarized abelian threefold suitable for deciding whether it is a Jacobian....
Detecting Jacobians via criteria and Deligne modules
v1.3 research notesCombine the Meagher–Ritzenthaler criteria with Deligne modules to detect Jacobians in an ordinary absolutely simple abelian-threefold isogeny class....
Monotonicity of maximal curve point counts in genus
v1.3 research notesFor fixed $q$, is $N_q(g)=\max_C\#C(\mathbb{F}_q)$ increasing as a function of the genus $g$?...
Shortest vectors in Hermitian lattices
v1.3 research notesFind a sharp upper bound for the shortest-vector length in an $n$-dimensional positive-definite Hermitian space of determinant $d$ over an imaginary q...
Genus-four pairing speed-security tradeoff
v1.3 research notesDetermine the exact computational-speed and security tradeoff for genus-four curves used in pairing cryptography....
Breaking the pairing system
v1.3 research notesFind an attack that breaks the pairing-based cryptographic system discussed in the slides, or establish its resistance to known attacks....
Breaking weaker pairing assumptions
v1.3 research notesBreak, or determine the true hardness of, the weaker security assumptions used in pairing-based cryptography....
Taxonomy of pairing-related assumptions
v1.3 research notesUpdate Joux's 2002 work by developing a systematic taxonomy of pairing-related computational assumptions....
Decision Linear versus DDH
v1.3 research notesIs the Decision Linear problem strictly harder than the decisional Diffie–Hellman problem in the relevant pairing groups?...
Polynomial-factor hardness of general lattice problems
v1.3 research notesProve that general SVP and SIVP are hard in the worst case to approximate within small polynomial factors....
NP-hardness of minimum distance for cyclic codes
v1.3 research notesIs the minimum-distance problem for cyclic codes NP-hard?...
Worst-case security of quasi-cyclic cryptosystems
v1.3 research notesProve that quasi-cyclic lattice or code public-key constructions are secure based on worst-case hardness for quasi-cyclic structures....
Lattice reduction for algebraic-number-theory problems
v1.3 research notesUse lattice reduction together with average-case problems to solve computational problems in algebraic number theory....
Quantum algorithm for Smallest Conjugate
v1.3 research notesDevelop an efficient quantum algorithm for the Smallest Conjugate problem....
Non-malleability of real RSA key generators
v1.3 research notesUse number theory to prove non-malleability properties for real-world RSA key-generation algorithms....
Malleable RSA modulus generation
v1.3 research notesConstruct a malleable RSA generator producing publicly related moduli $n,n'$ such that factoring $n'$ makes $n$ easy to factor....
Practical trapdoor discrete-logarithm groups
v1.3 research notesConstruct practical groups in which discrete logarithms have an effective trapdoor....
Groups with infeasible inversion
v1.3 research notesConstruct groups in which inversion is infeasible under reasonable cryptographic assumptions....
Better trapdoor pairings
v1.3 research notesConstruct improved practical trapdoor pairings....
Security of the TGII directed-signature construction
v1.3 research notesProve the simple construction from trapdoor groups with infeasible inversion to directed transitive signatures secure, or repair the construction....
Finiteness of a Shafarevich–Tate group needed by the lifting method
v1.3 research notesProve finiteness of the Shafarevich–Tate group of the elliptic-curve lift required by the Huang–Raskind method, in the general cases where it is not k...
Necessity of the odd-class-number condition for Heegner bounds
v1.3 research notesIs the odd-class-number condition in the stated lower bound for Heegner points necessary?...
Necessity of the no-CM condition for Heegner bounds
v1.3 research notesIs the no-complex-multiplication condition in the stated lower bound for Heegner points necessary?...
Heegner points from nonmaximal orders
v1.3 research notesProve analogues of the stated Heegner-point results for points arising from nonmaximal orders....
Deuring lifting for Darmon–Heegner points
v1.3 research notesFind an analogue of the Deuring Lifting Theorem for Darmon–Heegner points....
Growing-degree improvements to the lifting attack
v1.3 research notesCan the lifting attack be improved by allowing the number-field degree $[K:\mathbb{Q}]$ to grow?...
Explicit test homogeneous spaces of prescribed ramification
v1.3 research notesExplicitly construct test elements or principal homogeneous spaces having prescribed ramification and a prescribed large prime order $\ell$....
Implicit computation with testing characters and homogeneous spaces
v1.3 research notesWork efficiently with the testing characters and principal homogeneous spaces without constructing them explicitly....
Tractable special cases of the signature problem
v1.3 research notesIdentify and solve tractable special cases of the signature problem described in the slides....
Trapdoor-free security from multiple nearby RSA moduli
v1.3 research notesFor nearby moduli $n_i=n_1+d_i$ and maps $f_i(r)=r^{e_i}\bmod n_i$, prove the conjecture that with sufficiently many components at least one $f_i$ is ...
Vandiver's conjecture
v1.3 research notesFor a prime $p$, conjecturally $p$ does not divide the class number of the maximal real subfield $\mathbb{Q}(\zeta_p+\overline{\zeta_p})$ of the $p$th...
Nonvanishing of the p-adic zeta function at even integers
v1.3 research notesLet $\zeta_p:\mathbb{Z}_p\to\mathbb{Q}_p$ be the $p$-adic zeta function. Is $\zeta_p(k)\ne0$ for every even integer $k$?...
Congruent number decision problem
v1.3 research notesGiven an integer $n$, determine whether there are rational numbers $x,y,z$ satisfying $x^2+y^2=z^2$ and $xy=2n$; equivalently, determine whether $n$ i...
Congruent numbers in residue classes 5, 6, and 7 modulo 8
v1.3 research notesIs every integer $n\equiv5,6,$ or $7\pmod 8$ a congruent number?...
L-value criterion for congruent numbers
v1.3 research notesFor $E_n:y^2=x^3-n^2x$, is $n$ a congruent number if and only if $L(E_n,1)=0$?...
Infinitude of rational points on an elliptic curve
v1.3 research notesGiven an elliptic curve $E:y^2=x^3+Ax+B$ over $\mathbb{Q}$, determine whether $E$ has infinitely many rational points....
Bounded prime-sum criterion for rational points
v1.3 research notesFor an elliptic curve $E/\mathbb{Q}$, let $N_p$ be its number of solutions modulo $p$ plus one and put $f(X)=\sum_{p\le X}\log(N_p/p)$. Is $f(X)$ boun...
Prime-sum growth and elliptic-curve rank
v1.3 research notesFor an elliptic curve $E/\mathbb{Q}$ of rank $r$, does $f(X)=\sum_{p\le X}\log(N_p/p)$ grow asymptotically like $r\log\log X$?...
Higher-dimensional cropping formula
v1.3 research notesFind a higher-dimensional analogue of the paper's cropping and summation argument; in dimension three the expected sum ranges over quadruples $v_1,v_2...
Complex continuation of the associated zeta function
v1.3 research notesFor $Z(s)=\sum f(a,b,c,d)^s$, which is known to converge for real $s>1/2$, extend $Z$ to complex values of $s$....
Modular extension and analogous lattice series
v1.3 research notesCan the function $f$ on $SL(2,\mathbb{Z})$ be extended naturally to $\mathbb{C}/SL(2,\mathbb{Z})$? Can analogous series be constructed for other latti...
Odd-prime-power periodicity conjecture
v1.3 research notesFor every odd prime $p$ and $k\ge1$, is $s(p^k)=k$? For $k\ge2$, is $d(p^k)=p^{k-1}d(p)$?...
Power-of-two periodicity conjecture
v1.3 research notesFor every $k\ge1$, is $s(2^k)=u_k$? Is $d(2^k)=2^k$ for $k\ne2$, with $d(4)=2$?...
Arnold sequence as an f-transform
v1.3 research notesIs Arnold's sequence $(u_k)_{k\ge1}$ the $f$-transform of the quadruple $(2,4,4,4)$?...