Reconstructing points of superelliptic curves over a prime finite field

Let p be a prime and Fp the finite field with p elements. We show how, when given an superelliptic curve Y n + f(X) ∈ Fp[X, Y ] and an approximation to (v0, v1) ∈ F2 p such that vn 1 = −f(v0), one can recover (v0, v1) efficiently, if the approximation is good enough. As consequence we provide an upp...

Descripción completa

Detalles Bibliográficos
Autor: Gutiérrez Gutiérrez, Jaime
Tipo de recurso: artículo
Fecha de publicación:2024
País:España
Institución:Universidad de Cantabria (UC)
Repositorio:UCrea Repositorio Abierto de la Universidad de Cantabria
Idioma:inglés
OAI Identifier:oai:repositorio.unican.es:10902/31261
Acceso en línea:https://hdl.handle.net/10902/31261
Access Level:acceso abierto
Palabra clave:Superelliptic curves
Lattice techniques
Prime finite fields
Cryptography
Descripción
Sumario:Let p be a prime and Fp the finite field with p elements. We show how, when given an superelliptic curve Y n + f(X) ∈ Fp[X, Y ] and an approximation to (v0, v1) ∈ F2 p such that vn 1 = −f(v0), one can recover (v0, v1) efficiently, if the approximation is good enough. As consequence we provide an upper bound on the number of roots of such bivariate polynomials where the roots have certain restrictions. The results has been motivated by the predictability problem for non-linear pseudorandom number generators and, other potential applications to cryptography.