English

An $L (1/3 + \epsilon)$ Algorithm for the Discrete Logarithm Problem for Low Degree Curves

Cryptography and Security 2015-06-25 v1 Algebraic Geometry

Abstract

The discrete logarithm problem in Jacobians of curves of high genus gg over finite fields \FFq\FF_q is known to be computable with subexponential complexity Lqg(1/2,O(1))L_{q^g}(1/2, O(1)). We present an algorithm for a family of plane curves whose degrees in XX and YY are low with respect to the curve genus, and suitably unbalanced. The finite base fields are arbitrary, but their sizes should not grow too fast compared to the genus. For this family, the group structure can be computed in subexponential time of Lqg(1/3,O(1))L_{q^g}(1/3, O(1)), and a discrete logarithm computation takes subexponential time of Lqg(1/3+ϵ,o(1))L_{q^g}(1/3+\epsilon, o(1)) for any positive ϵ\epsilon. These runtime bounds rely on heuristics similar to the ones used in the number field sieve or the function field sieve algorithms.

Keywords

Cite

@article{arxiv.cs/0703032,
  title  = {An $L (1/3 + \epsilon)$ Algorithm for the Discrete Logarithm Problem for Low Degree Curves},
  author = {Andreas Enge and Pierrick Gaudry},
  journal= {arXiv preprint arXiv:cs/0703032},
  year   = {2015}
}
R2 v1 2026-07-22T12:28:14.117Z