Detecting Jacobians via criteria and Deligne modules
v1.3 research notesCombine the Meagher–Ritzenthaler criteria with Deligne modules to detect Jacobians in an ordinary absolutely simple abelian-threefold isogeny class....
Monotonicity of maximal curve point counts in genus
v1.3 research notesFor fixed $q$, is $N_q(g)=\max_C\#C(\mathbb{F}_q)$ increasing as a function of the genus $g$?...
Shortest vectors in Hermitian lattices
v1.3 research notesFind a sharp upper bound for the shortest-vector length in an $n$-dimensional positive-definite Hermitian space of determinant $d$ over an imaginary q...
Faster pairing computation
v1.3 research notesSpeed up the computation of cryptographic pairings....
More MNT and pairing-friendly elliptic curves
v1.3 research notesFind more MNT curves, including usable larger embedding degrees, more curve families, and smaller cofactors....
Pairing-friendly hyperelliptic curves
v1.3 research notesConstruct pairing-friendly hyperelliptic curves suitable for cryptography....
Genus-four pairing speed-security tradeoff
v1.3 research notesDetermine the exact computational-speed and security tradeoff for genus-four curves used in pairing cryptography....
Breaking the pairing system
v1.3 research notesFind an attack that breaks the pairing-based cryptographic system discussed in the slides, or establish its resistance to known attacks....
Breaking weaker pairing assumptions
v1.3 research notesBreak, or determine the true hardness of, the weaker security assumptions used in pairing-based cryptography....
Taxonomy of pairing-related assumptions
v1.3 research notesUpdate Joux's 2002 work by developing a systematic taxonomy of pairing-related computational assumptions....
Decision Linear versus DDH
v1.3 research notesIs the Decision Linear problem strictly harder than the decisional Diffie–Hellman problem in the relevant pairing groups?...
Pairing signatures without distortion maps
v1.3 research notesGive the cited pairing-based signature constructions and their security proofs without relying on distortion maps....
Hardness of the Pairing Inversion Problem
v1.3 research notesDetermine the computational hardness of the Pairing Inversion Problem....
Polynomial-factor hardness of general lattice problems
v1.3 research notesProve that general SVP and SIVP are hard in the worst case to approximate within small polynomial factors....
Polynomial-factor hardness of ideal-lattice problems
v1.3 research notesProve an analogous small-polynomial-factor worst-case hardness result for SVP and SIVP on ideal lattices....
NP-hardness of ideal-lattice SVP
v1.3 research notesIs the shortest vector problem on ideal or cyclic lattices NP-hard, either exactly or under approximation?...
NP-hardness of minimum distance for cyclic codes
v1.3 research notesIs the minimum-distance problem for cyclic codes NP-hard?...
Reducing arbitrary lattices to ideal lattices
v1.3 research notesReduce computational problems on arbitrary lattices to corresponding problems on cyclic or ideal lattices....
SVP-to-CVP reduction within ideal lattices
v1.3 research notesDoes SVP reduce to CVP while remaining inside the class of cyclic or ideal lattices?...
Worst cases for LLL on ideal lattices
v1.3 research notesExhibit cyclic or ideal lattices on which LLL achieves its worst-case approximation factor....
An algebraic LLL algorithm
v1.3 research notesDevelop an algebraic analogue of the LLL lattice-reduction algorithm that exploits ideal-lattice structure....
Ideal-lattice pseudorandom generators
v1.3 research notesConstruct efficient pseudorandom generators from ideal-lattice problems....
Ideal-lattice pseudorandom functions
v1.3 research notesConstruct efficient pseudorandom functions from ideal-lattice problems....
Ideal-lattice digital signatures
v1.3 research notesConstruct efficient digital-signature schemes from ideal-lattice problems....
Worst-case security of quasi-cyclic cryptosystems
v1.3 research notesProve that quasi-cyclic lattice or code public-key constructions are secure based on worst-case hardness for quasi-cyclic structures....
Algebraic algorithms for ideal-lattice problems
v1.3 research notesUse algebraic tools to solve computational problems on ideal lattices efficiently....
Lattice reduction for algebraic-number-theory problems
v1.3 research notesUse lattice reduction together with average-case problems to solve computational problems in algebraic number theory....
Cryptography from worst-case algebraic-number-theory hardness
v1.3 research notesBase cryptographic constructions directly on worst-case hardness assumptions from algebraic number theory....
Quantum algorithm for Smallest Conjugate
v1.3 research notesDevelop an efficient quantum algorithm for the Smallest Conjugate problem....
Quantum algorithm for ideal-lattice SVP
v1.3 research notesDevelop an efficient quantum algorithm for the shortest vector problem on ideal lattices....
Ideal-lattice Regev cryptosystem
v1.3 research notesConstruct an efficient ideal-lattice version of Regev's quantum-SVP-based cryptosystem....
Non-malleability of real RSA key generators
v1.3 research notesUse number theory to prove non-malleability properties for real-world RSA key-generation algorithms....
Malleable RSA modulus generation
v1.3 research notesConstruct a malleable RSA generator producing publicly related moduli $n,n'$ such that factoring $n'$ makes $n$ easy to factor....
Practical trapdoor discrete-logarithm groups
v1.3 research notesConstruct practical groups in which discrete logarithms have an effective trapdoor....
Groups with infeasible inversion
v1.3 research notesConstruct groups in which inversion is infeasible under reasonable cryptographic assumptions....
Better trapdoor pairings
v1.3 research notesConstruct improved practical trapdoor pairings....
Security of the TGII directed-signature construction
v1.3 research notesProve the simple construction from trapdoor groups with infeasible inversion to directed transitive signatures secure, or repair the construction....
Finiteness of a Shafarevich–Tate group needed by the lifting method
v1.3 research notesProve finiteness of the Shafarevich–Tate group of the elliptic-curve lift required by the Huang–Raskind method, in the general cases where it is not k...
Faster infrastructure discrete logarithms and point counting
v1.3 research notesUse a baby-step/giant-step infrastructure framework to speed infrastructure discrete logarithms or point counting by a polynomial factor....
Converting between divisor-class and infrastructure discrete logarithms
v1.3 research notesGive efficient reductions in both directions between the degree-zero divisor-class-group discrete logarithm problem and the infrastructure discrete lo...
Necessity of the odd-class-number condition for Heegner bounds
v1.3 research notesIs the odd-class-number condition in the stated lower bound for Heegner points necessary?...
Necessity of the no-CM condition for Heegner bounds
v1.3 research notesIs the no-complex-multiplication condition in the stated lower bound for Heegner points necessary?...
Heegner points from nonmaximal orders
v1.3 research notesProve analogues of the stated Heegner-point results for points arising from nonmaximal orders....
Deuring lifting for Darmon–Heegner points
v1.3 research notesFind an analogue of the Deuring Lifting Theorem for Darmon–Heegner points....
Growing-degree improvements to the lifting attack
v1.3 research notesCan the lifting attack be improved by allowing the number-field degree $[K:\mathbb{Q}]$ to grow?...
Explicit test homogeneous spaces of prescribed ramification
v1.3 research notesExplicitly construct test elements or principal homogeneous spaces having prescribed ramification and a prescribed large prime order $\ell$....
Implicit computation with testing characters and homogeneous spaces
v1.3 research notesWork efficiently with the testing characters and principal homogeneous spaces without constructing them explicitly....
Tractable special cases of the signature problem
v1.3 research notesIdentify and solve tractable special cases of the signature problem described in the slides....
Trapdoor-free security from multiple nearby RSA moduli
v1.3 research notesFor nearby moduli $n_i=n_1+d_i$ and maps $f_i(r)=r^{e_i}\bmod n_i$, prove the conjecture that with sufficiently many components at least one $f_i$ is ...
Vandiver's conjecture
v1.3 research notesFor a prime $p$, conjecturally $p$ does not divide the class number of the maximal real subfield $\mathbb{Q}(\zeta_p+\overline{\zeta_p})$ of the $p$th...