Removing restrictions from hyperelliptic zeta algorithms
v1.3 research notesRemove the imaginary-hyperelliptic and $p\ne2$ restrictions from the complexity bound stated in the slides....
Improved Frobenius lifts for nondegenerate curves
v1.3 research notesTest and analyze whether deleting extra points and fixing the lift $x\mapsto x^p$ improves Frobenius lifts for nondegenerate curves....
Higher-dimensional nondegenerate Frobenius algorithms
v1.3 research notesDevelop the higher-dimensional analogue of the nondegenerate-curve Frobenius-lift method....
Useful deformations for nondegenerate curves
v1.3 research notesFind useful deformations of nondegenerate curves together with easy starting matrices for Frobenius computation....
Nondegenerate surfaces in toric threefolds
v1.3 research notesWork out effective zeta-function computations for nondegenerate surfaces in toric threefolds....
Factoring structured semiprimes from fewer known bits
v1.3 research notesFactor $N=p^rq^s$ with $r\approx s$ using fewer known bits of the factors than existing methods require....
Factoring from nonconsecutive known bits
v1.3 research notesDevelop methods to factor an integer when the known bits of its factors are nonconsecutive....
Fast construction of five-term geometric progressions for NFS
v1.3 research notesFor large $N$, efficiently find the required short five-term geometric progressions modulo $N$ that avoid first- and second-order recurrence, thereby ...
Distribution of elliptic-curve group structures
v1.3 research notesStudy the distribution of group structures $E(\mathbb{F}_q)$ as elliptic curves $E/\mathbb{F}_q$ vary; in particular, determine the correct nonuniform...
Typical exponent of an elliptic-curve group
v1.3 research notesIs the exponent $e_q(E)$ of $E(\mathbb{F}_q)$ typically close to $q$?...
Frequency of cyclic elliptic-curve groups
v1.3 research notesHow often is the group of a random elliptic curve over $\mathbb{F}_q$ cyclic?...
Typical arithmetic structure of elliptic-curve orders
v1.3 research notesCharacterize the typical arithmetic structure of $\#E(\mathbb{F}_q)$ for elliptic curves over finite fields....
Prime-order curves over every finite field
v1.3 research notesProve that there are sufficiently many prime-order elliptic curves over every finite field $\mathbb{F}_q$....
Elliptic curves with smooth group order
v1.3 research notesProve that sufficiently many elliptic curves $E/\mathbb{F}_p$ have smooth group order $\#E(\mathbb{F}_p)$....
Elliptic-curve orders with a large prime divisor
v1.3 research notesQuantify elliptic curves over finite fields whose group order has a large prime divisor....
Distribution of elliptic-curve pseudorandom sequences
v1.3 research notesProve the conjecture that the EC-LCG, EC-PG, and EC-NRG sequences defined in the slides are very well distributed....
Choosing a field for an elliptic curve of prescribed order
v1.3 research notesGiven $n$, efficiently choose a prime power $q$ and construct an elliptic curve $E/\mathbb{F}_q$ with $\#E(\mathbb{F}_q)=n$....
Jacobians in abelian-threefold isogeny classes
v1.3 research notesGiven the Weil polynomial of an abelian-threefold isogeny class over a finite field, determine whether the class contains a Jacobian....
Recognizing genus-three Jacobians over the base field
v1.3 research notesDecide whether a given principally polarized abelian threefold over a field $k$ is the Jacobian of a curve over $k$....
More MNT and pairing-friendly elliptic curves
v1.3 research notesFind more MNT curves, including usable larger embedding degrees, more curve families, and smaller cofactors....
Pairing-friendly hyperelliptic curves
v1.3 research notesConstruct pairing-friendly hyperelliptic curves suitable for cryptography....
Hardness of the Pairing Inversion Problem
v1.3 research notesDetermine the computational hardness of the Pairing Inversion Problem....
Polynomial-factor hardness of ideal-lattice problems
v1.3 research notesProve an analogous small-polynomial-factor worst-case hardness result for SVP and SIVP on ideal lattices....
NP-hardness of ideal-lattice SVP
v1.3 research notesIs the shortest vector problem on ideal or cyclic lattices NP-hard, either exactly or under approximation?...
Reducing arbitrary lattices to ideal lattices
v1.3 research notesReduce computational problems on arbitrary lattices to corresponding problems on cyclic or ideal lattices....
SVP-to-CVP reduction within ideal lattices
v1.3 research notesDoes SVP reduce to CVP while remaining inside the class of cyclic or ideal lattices?...
Worst cases for LLL on ideal lattices
v1.3 research notesExhibit cyclic or ideal lattices on which LLL achieves its worst-case approximation factor....
An algebraic LLL algorithm
v1.3 research notesDevelop an algebraic analogue of the LLL lattice-reduction algorithm that exploits ideal-lattice structure....
Ideal-lattice pseudorandom functions
v1.3 research notesConstruct efficient pseudorandom functions from ideal-lattice problems....
Algebraic algorithms for ideal-lattice problems
v1.3 research notesUse algebraic tools to solve computational problems on ideal lattices efficiently....
Quantum algorithm for ideal-lattice SVP
v1.3 research notesDevelop an efficient quantum algorithm for the shortest vector problem on ideal lattices....
Faster infrastructure discrete logarithms and point counting
v1.3 research notesUse a baby-step/giant-step infrastructure framework to speed infrastructure discrete logarithms or point counting by a polynomial factor....
Converting between divisor-class and infrastructure discrete logarithms
v1.3 research notesGive efficient reductions in both directions between the degree-zero divisor-class-group discrete logarithm problem and the infrastructure discrete lo...
Coordinates on convex domains
v1.3 research notesFor a compact convex domain $\Omega$, the values of $F_\Omega$ at the vertices of its corner locus $C_\Omega$ give complete coordinates. How are these...
Alternative and arithmetic proofs of the pi identities
v1.3 research notesGive another proof of the paper's identities (Ж) and (ж) using the methods for identity (1). Can $f(a,b,c,d)$ be interpreted as a residue at $(a+b)+(c...
Liouville property under rough isometry to nonamenable Cayley graphs
v1.3 research notesProve that every bounded-degree graph roughly isometric to a nonamenable Cayley graph is non-Liouville....