Conjecture 5.3
v1.3 research notesLet $n$ be a positive integer. For almost all $n$-tuples $(x_1,\ldots,x_n)$, there are positive constants $c$ and $D_0$ (depending on $n$, $x_1,\ldots...
Conjecture 5.4 — Loxton and van der Poorten
v1.3 research notesLet $(n_i)_{i\ge 0}$ be an increasing sequence of positive integers. Assume there is a prime number $p$ such that the power series $$ \sum_{i\ge 0}z^{...
Fast evaluation of high-degree elliptic-curve isogenies
v1.3 research notesGiven an elliptic curve $E/\mathbb{F}_q$ and $P\in E(\mathbb{F}_q)$, characterize maps or isogenies $\psi:E\to E'$ for which $\psi(P)$ can be evaluate...
Cryptographically useful bilinear structures
v1.3 research notesFind bilinear structures that are useful for cryptographic constructions....
Efficient class-group realizations of large cyclic groups
v1.3 research notesFind orders $\mathcal{O}$ whose Picard groups contain $\mathbb{Z}/\ell$, admit compact element representations, and allow group composition in $O(\log...
Explicit class-group realization of finite-field discrete logarithms
v1.3 research notesMake the proposed realization of existing finite-field discrete-logarithm systems inside class groups explicit for practical systems....
Security consequences of Weil descent for the class-group realization
v1.3 research notesDetermine whether Weil descent compromises the security of the proposed class-group realization of finite-field discrete-logarithm systems....
Fast Tate–Lichtenbaum pairing computation
v1.3 research notesDevelop a fast algorithm to compute the Tate–Lichtenbaum pairing $T_n$....
Computational realization of a second cohomology group
v1.3 research notesTurn $H^2(G_K,K_s^*)$ into an explicitly computational group....
Explicit cocycles and invariants for split local algebras
v1.3 research notesExplicitly describe the cocycle $c_u$, equivalently fast-compute invariants of local algebras split by the generalized-dihedral extensions specified i...
Globalizing prescribed local Brauer classes
v1.3 research notesExplicitly construct global algebras or Brauer classes with prescribed local data, especially when the local splitting fields are dihedral....
Schoof-type zeta computation without bad genus dependence
v1.3 research notesAdapt Schoof's method to compute zeta functions of curves without unfavorable dependence on the genus....
Polynomial-time curve zeta computation in genus and field size
v1.3 research notesIs computation of a curve's zeta function polynomial simultaneously in the genus $g$ and in $\log q$?...
Cup-product pairings in zeta computation
v1.3 research notesDetermine whether natural de Rham cup-product pairings can be used to improve zeta-function computations....
Removing restrictions from hyperelliptic zeta algorithms
v1.3 research notesRemove the imaginary-hyperelliptic and $p\ne2$ restrictions from the complexity bound stated in the slides....
Improved Frobenius lifts for nondegenerate curves
v1.3 research notesTest and analyze whether deleting extra points and fixing the lift $x\mapsto x^p$ improves Frobenius lifts for nondegenerate curves....
Higher-dimensional nondegenerate Frobenius algorithms
v1.3 research notesDevelop the higher-dimensional analogue of the nondegenerate-curve Frobenius-lift method....
Useful deformations for nondegenerate curves
v1.3 research notesFind useful deformations of nondegenerate curves together with easy starting matrices for Frobenius computation....
Nondegenerate surfaces in toric threefolds
v1.3 research notesWork out effective zeta-function computations for nondegenerate surfaces in toric threefolds....
Factoring structured semiprimes from fewer known bits
v1.3 research notesFactor $N=p^rq^s$ with $r\approx s$ using fewer known bits of the factors than existing methods require....
Factoring a three-prime integer from fewer known bits
v1.3 research notesFactor $N=pqr$ from fewer known bits of its prime factors....
Factoring from nonconsecutive known bits
v1.3 research notesDevelop methods to factor an integer when the known bits of its factors are nonconsecutive....
Reducing guesses in factoring with known bits
v1.3 research notesReduce the number of guesses required by lattice attacks for factoring with partially known bits....
Learning from wrong guesses in partial-key factoring
v1.3 research notesExtract useful information from incorrect guesses in factoring attacks based on partially known bits....
Roots of x-squared minus one modulo a composite
v1.3 research notesEfficiently solve for, or characterize all relevant roots of, $x^2-1$ modulo a composite integer $N$ in the setting of the slides....
Faster Coppersmith root methods
v1.3 research notesImprove the running time of Coppersmith-type methods for finding small modular or integer roots....
Polynomial-shape dependence in small-root algorithms
v1.3 research notesUnderstand and control how the shape of a polynomial affects Coppersmith-type small-root algorithms....
Algebraic independence in multivariate elimination
v1.3 research notesGive conditions or constructions that ensure algebraic independence in multivariate elimination for small-root attacks....
Optimal polynomial collections for lattice attacks
v1.3 research notesFind an optimal collection of polynomials for multivariate lattice-based small-root attacks....
Dimension reduction in small-root lattices
v1.3 research notesDetermine whether the lattice dimension in the stated small-root constructions can be reduced....
Zero-constant-term Newton-polytope case
v1.3 research notesResolve the zero-constant-term case in the Newton-polytope formulation of multivariate small-root methods....
Cryptographic primitives from hard small roots
v1.3 research notesConstruct additional cryptographic primitives whose security follows from the hardness of finding small roots....
Quality of rotation-augmented cyclic-lattice reduction
v1.3 research notesAnalyze how effective rotation-augmented lattice reduction is on cyclic or NTRU lattices....
Faster cyclic-lattice reduction
v1.3 research notesSpeed up rotation-augmented reduction algorithms for cyclic or NTRU lattices....
Fast construction of five-term geometric progressions for NFS
v1.3 research notesFor large $N$, efficiently find the required short five-term geometric progressions modulo $N$ that avoid first- and second-order recurrence, thereby ...
Distribution of elliptic-curve group structures
v1.3 research notesStudy the distribution of group structures $E(\mathbb{F}_q)$ as elliptic curves $E/\mathbb{F}_q$ vary; in particular, determine the correct nonuniform...
Typical exponent of an elliptic-curve group
v1.3 research notesIs the exponent $e_q(E)$ of $E(\mathbb{F}_q)$ typically close to $q$?...
Frequency of cyclic elliptic-curve groups
v1.3 research notesHow often is the group of a random elliptic curve over $\mathbb{F}_q$ cyclic?...
Typical arithmetic structure of elliptic-curve orders
v1.3 research notesCharacterize the typical arithmetic structure of $\#E(\mathbb{F}_q)$ for elliptic curves over finite fields....
Prime-order curves over every finite field
v1.3 research notesProve that there are sufficiently many prime-order elliptic curves over every finite field $\mathbb{F}_q$....
Prime extension-degree quotients of elliptic-curve orders
v1.3 research notesFor a fixed $E/\mathbb{F}_q$, prove that $\#E(\mathbb{F}_{q^n})/\#E(\mathbb{F}_q)$ is prime for infinitely many $n$....
Prime reductions of elliptic curves over the rationals
v1.3 research notesFor a torsion-free elliptic curve $E/\mathbb{Q}$, prove that $\#E(\mathbb{F}_p)$ is prime for infinitely many primes $p$....
Elliptic curves with smooth group order
v1.3 research notesProve that sufficiently many elliptic curves $E/\mathbb{F}_p$ have smooth group order $\#E(\mathbb{F}_p)$....
Elliptic-curve orders with a large prime divisor
v1.3 research notesQuantify elliptic curves over finite fields whose group order has a large prime divisor....
Distribution of elliptic-curve pseudorandom sequences
v1.3 research notesProve the conjecture that the EC-LCG, EC-PG, and EC-NRG sequences defined in the slides are very well distributed....
Constructing an elliptic curve of prescribed order over a fixed field
v1.3 research notesGiven integers $n$ and a prime power $q$, construct, when possible, an elliptic curve $E/\mathbb{F}_q$ with $\#E(\mathbb{F}_q)=n$....
Choosing a field for an elliptic curve of prescribed order
v1.3 research notesGiven $n$, efficiently choose a prime power $q$ and construct an elliptic curve $E/\mathbb{F}_q$ with $\#E(\mathbb{F}_q)=n$....
Jacobians in abelian-threefold isogeny classes
v1.3 research notesGiven the Weil polynomial of an abelian-threefold isogeny class over a finite field, determine whether the class contains a Jacobian....
Recognizing genus-three Jacobians over the base field
v1.3 research notesDecide whether a given principally polarized abelian threefold over a field $k$ is the Jacobian of a curve over $k$....
Effective representation of principally polarized abelian threefolds
v1.3 research notesGive an effective input representation for a principally polarized abelian threefold suitable for deciding whether it is a Jacobian....