English

Near Optimal Bounds for Collision in Pollard Rho for Discrete Log

Number Theory 2016-11-18 v3 Combinatorics Probability

Abstract

We analyze a fairly standard idealization of Pollard's Rho algorithm for finding the discrete logarithm in a cyclic group G. It is found that, with high probability, a collision occurs in O(GlogGloglogG)O(\sqrt{|G|\log |G| \log \log |G|}) steps, not far from the widely conjectured value of Θ(G)\Theta(\sqrt{|G|}). This improves upon a recent result of Miller--Venkatesan which showed an upper bound of O(Glog3G)O(\sqrt{|G|}\log^3 |G|). Our proof is based on analyzing an appropriate nonreversible, non-lazy random walk on a discrete cycle of (odd) length |G|, and showing that the mixing time of the corresponding walk is O(logGloglogG)O(\log |G| \log \log |G|).

Keywords

Cite

@article{arxiv.math/0611586,
  title  = {Near Optimal Bounds for Collision in Pollard Rho for Discrete Log},
  author = {Jeong Han Kim and Ravi Montenegro and Prasad Tetali},
  journal= {arXiv preprint arXiv:math/0611586},
  year   = {2016}
}