On the Use of the Legendre Symbol in Symmetric Cipher Design

Alan Szepieniec


This paper proposes the use of Legendre symbols as component gates in the design of ciphers tailored for use in cryptographic proof systems. Legendre symbols correspond to high-degree maps, but can be evaluated much faster. As a result, a cipher that uses Legendre symbols can offer the same security as one that uses high-degree maps but without incurring the penalty of a comparatively slow evaluation time. After discussing the design considerations induced by the use of Legendre symbol gates, we present a concrete design that follows this strategy, along with an elaborate security analysis thereof. This cipher is called Grendel.

Note: add root finding attack to security analysis

Secret-key cryptography
Preprint. MINOR revision.
arithmetization-orientedhash functionszero knowledge
alan szepieniec @ gmail com
2021-11-29: revised
2021-07-23: received
Creative Commons Attribution


