The traditional approach for the individual logarithm step can be extremely slow, and it is too slow especially for $n$ greater than 3. Its asymptotic complexity is $L_Q[1/3, c]$ with $c \geq 1.44$. We present a new preimage computation that provides a dramatic improvement for individual logarithm computations for small $n$, both in practice and in asymptotic running-time: we have $L_Q[1/3, c]$ with $c = 1.14$ for $n=2,4$, $c = 1.26$ for $n=3,6$ and $c = 1.34$ for $n=5$. Our method generalizes to any $n$; in particular $c < 1.44$ for the two state-of-the-art variants of NFS for extension fields.
Category / Keywords: public-key cryptography / discrete logarithm, finite field, number field sieve, NFS, individual logarithm Date: received 27 May 2015, last revised 27 May 2015 Contact author: guillevic at lix polytechnique fr Available format(s): PDF | BibTeX Citation Version: 20150529:075412 (All versions of this report) Short URL: ia.cr/2015/513 Discussion forum: Show discussion | Start new discussion