By Manjul Bhargava (auth.), Claus Fieker, David R. Kohel (eds.)

ISBN-10: 3540438637

ISBN-13: 9783540438632

From the reviews:

"The ebook comprises 39 articles approximately computational algebraic quantity concept, mathematics geometry and cryptography. … The articles during this booklet mirror the vast curiosity of the organizing committee and the contributors. The emphasis lies at the mathematical idea in addition to on computational effects. we suggest the ebook to scholars and researchers who are looking to examine present study in quantity idea and mathematics geometry and its applications." (R. Carls, Nieuw Archief voor Wiskunde, Vol. 6 (3), 2005)

Additional info for Algorithmic Number Theory: 5th International Symposium, ANTS-V Sydney, Australia, July 7–12, 2002 Proceedings

Example text

Williams, editor, Advances in Cryptology — CRYPTO’85, volume 218 of Lecture Notes in Comput. , pages 417–428. Springer, 1986. 30. T. Okamoto and D. Pointcheval. The gap problems: a new class of problems for the security of cryptographic primitives. In Public Key Cryptography, PKC 2001, volume 1992 of Lecture Notes in Comput. , pages 104–118. Springer, 2001. 31. K. Paterson. ID–based signatures from pairings on elliptic curves. org, 2002. Number 2002/004. 32. K. Rubin and A. Silverberg. The best and worst of supersingular abelian varieties in cryptology.

E. when G1 can be generated by a single point P , such that P, P = 1). In [4], Boneh and Franklin introduced a new assumption: the hardness of the Weil Diffie–Hellman (WDH) problem. Similarly, one can define the (modified) Tate Diffie–Hellman (TDH) problem as follows: – Given (P, aP, bP, cP ) for random a, b, c compute tˆ(P, P )abc . As noted in [4], the TDH assumption implies that CDH is hard in the group of points G1 , it also implies that CDH is hard in G2 where pairings are taking their values. The security of the IBE scheme from [4] is based on TDH in the random oracle model, thanks to the use of the function H.

It can be written as a finite formal sum: D = i ai (Pi ), where the Pi ’s are points on E and the ai ’s are integers. e. such that i ai = 0. Weil and Tate Pairings as Building Blocks for Public Key Cryptosystems 23 Given any function f in K(E), we can build a degree 0 divisor div(f ) from the zeros and poles of f simply by forming the formal sum of the zeros (with multiplicity) minus the formal sum of the poles (with multiplicity). All divisors of the form D = div(f ) will be called principal divisors.

