Paper 2026/560
High-Order Galois Automorphisms for TNFS Linear Algebra
Abstract
The Number Field Sieve and its variants are the best-known algorithms to solve the discrete logarithm problem in finite fields. When the extension degree is composite, the Tower variant, TNFS, is the most efficient. Looking at finite fields with composite extension degrees such as $6$ and $12$ is motivated by pairing-based cryptography, which does not yet have a good quantum-resistant equivalent. The two most costly steps in TNFS are the relation collection and linear algebra steps. Although the use of order-$k$ Galois automorphisms allows one to accelerate the relation collection step by a factor of $k$, their use to accelerate the linear algebra step remains an open problem. In previous work, this problem is solved for $k=2$, leveraging a quadratic acceleration factor equal to $4$. In this article, we provide a solution for $k=6$ and $k=12$. We propose a new construction that allows the use of a Galois automorphism of order $6$ (resp. $12$) in $\mathbb{F}_{p^6}$ (resp. $\mathbb{F}_{p^{12}}$), thus accelerating the linear algebra step by a factor of approximately $36$ (resp. $144$). Moreover, we provide a SageMath implementation of TNFS and our construction, and validate our findings on small examples.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Published by the IACR in CRYPTO 2026
- Keywords
- CryptanalysisPublic Key CryptographyDiscrete Log-arithmTower Number Field SieveAutomorphismsSchirokauer maps
- Contact author(s)
-
haetham al-aswad @ lirmm fr
cecile pierrot @ inria fr
emmanuel thome @ inria fr - History
- 2026-06-19: revised
- 2026-03-20: received
- See all versions
- Short URL
- https://ia.cr/2026/560
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/560,
author = {Haetham Al Aswad and Cécile Pierrot and Emmanuel Thomé},
title = {High-Order Galois Automorphisms for {TNFS} Linear Algebra},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/560},
year = {2026},
url = {https://eprint.iacr.org/2026/560}
}