Mathematics Problem Archive
Conjecture 4.15
v1.3 research notesThere exists a positive absolute constant $C$ with the following property. Let $\alpha_1,\ldots,\alpha_n$ be nonzero algebraic numbers and $\log\alpha...
Conjecture 4.16 — Quantitative Refinement of Schanuel's Conjecture
v1.3 research notesLet $x_1,\ldots,x_n$ be $\mathbb{Q}$-linearly independent complex numbers. Assume that for any $\varepsilon>0$, there exists a positive number $H_0$ s...
Conjecture 4.18
v1.3 research notesLet $A$ be a simple abelian variety over $\mathbb{Q}$, $\exp_A:\mathbb{R}^g\rightarrow A(\mathbb{R})^0$ the exponential map of the Lie group $A(\mathb...
Conjecture 4.20
v1.3 research notesLet $m$, $n$, $k$ be positive integers and $a_{ij\kappa}$ rational integers ($1\le i\le n$, $1\le j\le m$, $1\le\kappa\le k$). For $\underline{x}=(x_1...
Conjecture 4.21
v1.3 research notesFor any $\varepsilon>0$ there exists $S_0>0$ (depending on $\varepsilon$, $\gamma_1,\ldots,\gamma_m$ and $\mathcal{K}$) such that, for any $S\ge S_0$ ...
Conjecture 5.3
v1.3 research notesLet $n$ be a positive integer. For almost all $n$-tuples $(x_1,\ldots,x_n)$, there are positive constants $c$ and $D_0$ (depending on $n$, $x_1,\ldots...
Computational realization of a second cohomology group
v1.3 research notesTurn $H^2(G_K,K_s^*)$ into an explicitly computational group....
Explicit cocycles and invariants for split local algebras
v1.3 research notesExplicitly describe the cocycle $c_u$, equivalently fast-compute invariants of local algebras split by the generalized-dihedral extensions specified i...
Schoof-type zeta computation without bad genus dependence
v1.3 research notesAdapt Schoof's method to compute zeta functions of curves without unfavorable dependence on the genus....
Polynomial-time curve zeta computation in genus and field size
v1.3 research notesIs computation of a curve's zeta function polynomial simultaneously in the genus $g$ and in $\log q$?...
Reducing guesses in factoring with known bits
v1.3 research notesReduce the number of guesses required by lattice attacks for factoring with partially known bits....
Learning from wrong guesses in partial-key factoring
v1.3 research notesExtract useful information from incorrect guesses in factoring attacks based on partially known bits....
Roots of x-squared minus one modulo a composite
v1.3 research notesEfficiently solve for, or characterize all relevant roots of, $x^2-1$ modulo a composite integer $N$ in the setting of the slides....
Faster Coppersmith root methods
v1.3 research notesImprove the running time of Coppersmith-type methods for finding small modular or integer roots....
Polynomial-shape dependence in small-root algorithms
v1.3 research notesUnderstand and control how the shape of a polynomial affects Coppersmith-type small-root algorithms....
Algebraic independence in multivariate elimination
v1.3 research notesGive conditions or constructions that ensure algebraic independence in multivariate elimination for small-root attacks....
Optimal polynomial collections for lattice attacks
v1.3 research notesFind an optimal collection of polynomials for multivariate lattice-based small-root attacks....
Dimension reduction in small-root lattices
v1.3 research notesDetermine whether the lattice dimension in the stated small-root constructions can be reduced....
Zero-constant-term Newton-polytope case
v1.3 research notesResolve the zero-constant-term case in the Newton-polytope formulation of multivariate small-root methods....
Cryptographic primitives from hard small roots
v1.3 research notesConstruct additional cryptographic primitives whose security follows from the hardness of finding small roots....
Quality of rotation-augmented cyclic-lattice reduction
v1.3 research notesAnalyze how effective rotation-augmented lattice reduction is on cyclic or NTRU lattices....
Faster cyclic-lattice reduction
v1.3 research notesSpeed up rotation-augmented reduction algorithms for cyclic or NTRU lattices....
Prime extension-degree quotients of elliptic-curve orders
v1.3 research notesFor a fixed $E/\mathbb{F}_q$, prove that $\#E(\mathbb{F}_{q^n})/\#E(\mathbb{F}_q)$ is prime for infinitely many $n$....
Prime reductions of elliptic curves over the rationals
v1.3 research notesFor a torsion-free elliptic curve $E/\mathbb{Q}$, prove that $\#E(\mathbb{F}_p)$ is prime for infinitely many primes $p$....
Effective representation of principally polarized abelian threefolds
v1.3 research notesGive an effective input representation for a principally polarized abelian threefold suitable for deciding whether it is a Jacobian....
Detecting Jacobians via criteria and Deligne modules
v1.3 research notesCombine the Meagher–Ritzenthaler criteria with Deligne modules to detect Jacobians in an ordinary absolutely simple abelian-threefold isogeny class....
Monotonicity of maximal curve point counts in genus
v1.3 research notesFor fixed $q$, is $N_q(g)=\max_C\#C(\mathbb{F}_q)$ increasing as a function of the genus $g$?...
Shortest vectors in Hermitian lattices
v1.3 research notesFind a sharp upper bound for the shortest-vector length in an $n$-dimensional positive-definite Hermitian space of determinant $d$ over an imaginary q...
Genus-four pairing speed-security tradeoff
v1.3 research notesDetermine the exact computational-speed and security tradeoff for genus-four curves used in pairing cryptography....
Breaking the pairing system
v1.3 research notesFind an attack that breaks the pairing-based cryptographic system discussed in the slides, or establish its resistance to known attacks....
Breaking weaker pairing assumptions
v1.3 research notesBreak, or determine the true hardness of, the weaker security assumptions used in pairing-based cryptography....
Taxonomy of pairing-related assumptions
v1.3 research notesUpdate Joux's 2002 work by developing a systematic taxonomy of pairing-related computational assumptions....
Decision Linear versus DDH
v1.3 research notesIs the Decision Linear problem strictly harder than the decisional Diffie–Hellman problem in the relevant pairing groups?...
Polynomial-factor hardness of general lattice problems
v1.3 research notesProve that general SVP and SIVP are hard in the worst case to approximate within small polynomial factors....
NP-hardness of minimum distance for cyclic codes
v1.3 research notesIs the minimum-distance problem for cyclic codes NP-hard?...
Worst-case security of quasi-cyclic cryptosystems
v1.3 research notesProve that quasi-cyclic lattice or code public-key constructions are secure based on worst-case hardness for quasi-cyclic structures....
Lattice reduction for algebraic-number-theory problems
v1.3 research notesUse lattice reduction together with average-case problems to solve computational problems in algebraic number theory....
Quantum algorithm for Smallest Conjugate
v1.3 research notesDevelop an efficient quantum algorithm for the Smallest Conjugate problem....
Non-malleability of real RSA key generators
v1.3 research notesUse number theory to prove non-malleability properties for real-world RSA key-generation algorithms....
Malleable RSA modulus generation
v1.3 research notesConstruct a malleable RSA generator producing publicly related moduli $n,n'$ such that factoring $n'$ makes $n$ easy to factor....
Practical trapdoor discrete-logarithm groups
v1.3 research notesConstruct practical groups in which discrete logarithms have an effective trapdoor....
Groups with infeasible inversion
v1.3 research notesConstruct groups in which inversion is infeasible under reasonable cryptographic assumptions....
Better trapdoor pairings
v1.3 research notesConstruct improved practical trapdoor pairings....
Security of the TGII directed-signature construction
v1.3 research notesProve the simple construction from trapdoor groups with infeasible inversion to directed transitive signatures secure, or repair the construction....
Finiteness of a Shafarevich–Tate group needed by the lifting method
v1.3 research notesProve finiteness of the Shafarevich–Tate group of the elliptic-curve lift required by the Huang–Raskind method, in the general cases where it is not k...
Necessity of the odd-class-number condition for Heegner bounds
v1.3 research notesIs the odd-class-number condition in the stated lower bound for Heegner points necessary?...
Necessity of the no-CM condition for Heegner bounds
v1.3 research notesIs the no-complex-multiplication condition in the stated lower bound for Heegner points necessary?...
Heegner points from nonmaximal orders
v1.3 research notesProve analogues of the stated Heegner-point results for points arising from nonmaximal orders....
Deuring lifting for Darmon–Heegner points
v1.3 research notesFind an analogue of the Deuring Lifting Theorem for Darmon–Heegner points....
Growing-degree improvements to the lifting attack
v1.3 research notesCan the lifting attack be improved by allowing the number-field degree $[K:\mathbb{Q}]$ to grow?...