Repository logo

Infoscience

  • English
  • French
Log In
Logo EPFL, École polytechnique fédérale de Lausanne

Infoscience

  • English
  • French
Log In
  1. Home
  2. Academic and Research Output
  3. Conferences, Workshops, Symposiums, and Seminars
  4. Breaking `128-bit Secure' Supersingular Binary Curves (or how to solve discrete logarithms in $\mathbb{F}_{2^{4 \cdot 1223}}$ and $\mathbb{F}_{2^{12 \cdot 367}}$)
 
conference paper

Breaking `128-bit Secure' Supersingular Binary Curves (or how to solve discrete logarithms in $\mathbb{F}{2^{4 \cdot 1223}}$ and $\mathbb{F}{2^{12 \cdot 367}}$)

Granger, Robert  
•
Kleinjung, Thorsten  
•
Zumbrägel, Jens  
Garay, Juan A.
•
Gennaro, Rosario
2014
Advances in Cryptology – CRYPTO 2014, 34th Annual Cryptology Conference, Santa Barbara, CA, USA, August 17-21, 2014, Proceedings, Part II
Advances in Cryptology – CRYPTO 2014

In late 2012 and early 2013 the discrete logarithm problem (DLP) in finite fields of small characteristic underwent a dramatic series of breakthroughs, culminating in a heuristic quasi-polynomial time algorithm, due to Barbulescu, Gaudry, Joux and Thomé. Using these developments, Adj, Menezes, Oliveira and Rodríguez-Henríquez analysed the concrete security of the DLP, as it arises from pairings on (the Jacobians of) various genus one and two supersingular curves in the literature, which were originally thought to be 128-bit secure. In particular, they suggested that the new algorithms have no impact on the security of a genus one curve over $\mathbb{F}{2^{1223}}$, and reduce the security of a genus two curve over $\mathbb{F}{2^{367}}$ to 94.6 bits. In this paper we propose a new field representation and efficient general descent principles which together make the new techniques far more practical. Indeed, at the ‘128-bit security level’ our analysis shows that the aforementioned genus one curve has approximately 59 bits of security, and we report a total break of the genus two curve.

  • Details
  • Metrics
Type
conference paper
DOI
10.1007/978-3-662-44381-1_8
Author(s)
Granger, Robert  
Kleinjung, Thorsten  
Zumbrägel, Jens  
Editors
Garay, Juan A.
•
Gennaro, Rosario
Date Issued

2014

Publisher

Springer Berlin Heidelberg

Published in
Advances in Cryptology – CRYPTO 2014, 34th Annual Cryptology Conference, Santa Barbara, CA, USA, August 17-21, 2014, Proceedings, Part II
Series title/Series vol.

Lecture Notes in Computer Science; 8617

Start page

126

End page

145

Subjects

Discrete logarithm problem

•

Supersingular binary curves

•

Pairings

•

Finite fields

Editorial or Peer reviewed

REVIEWED

Written at

EPFL

EPFL units
LACAL  
Event nameEvent placeEvent date
Advances in Cryptology – CRYPTO 2014

Santa Barbara, CA, USA

August 17-21, 2014

Available on Infoscience
January 19, 2016
Use this identifier to reference this record
https://infoscience.epfl.ch/handle/20.500.14299/122365
Logo EPFL, École polytechnique fédérale de Lausanne
  • Contact
  • infoscience@epfl.ch

  • Follow us on Facebook
  • Follow us on Instagram
  • Follow us on LinkedIn
  • Follow us on X
  • Follow us on Youtube
AccessibilityLegal noticePrivacy policyCookie settingsEnd User AgreementGet helpFeedback

Infoscience is a service managed and provided by the Library and IT Services of EPFL. © EPFL, tous droits réservés