2 Primality and Compositeness Tests

Save this PDF as:

Size: px
Start display at page:

Transcription

1 Int. J. Contemp. Math. Sciences, Vol. 3, 2008, no. 33, On Factoring R. A. Mollin Department of Mathematics and Statistics University of Calgary, Calgary, Alberta, Canada, T2N 1N4 ramollin/ Abstract This is a survey article on factoring. Given the importance of factoring, or rather the difficulty thereof, in the security of RSA and other cryptosystems, it is worth having an overview of the area. Mathematics Subject Classification: Primary: 11A41; Secondary: 11A51 Keywords: primality testing, factorization, cryptography 1 Introduction Primality testing is now one of the most dynamic areas of number-theoretic research. The power of modern computers and development of sophisticated algorithms have made the recognition of primes and factoring of composite integers highly efficient to the point that would have been thought infeasible only a generation ago. These algorithms are important in the modern day for ensuring that sensitive data is protected in electronic transmissions for government, industry, and the military. Much of what follows is adapted from [4]. 2 Primality and Compositeness Tests In general, factorization methods are quite time consuming, whereas deciding whether a given n is composite or prime is much more efficient. Part of the reason is that a test for recognizing primes, which are not attempts to factor n, and which determine n to be composite, do not provide the factors of n. Two tests for recognizing primes are given as follows.

2 1636 R. A. Mollin (1) The test has a condition for compositeness. If n satisfies the condition, then n must be composite. If n fails the condition, it might still be composite (with low probability). In other words, a successful completion of the test satisfying the condition always guarantees that n is composite; whereas an unsuccessful completion of the test failing to satisfy the condition does not prove that n is prime. (2) The test has a condition for primality. If n satisfies the condition, then n must must be prime. If it fails the condition, then n must be composite. We call (1) a compositeness test and (2) a primality test. Factorization methods may be used as compositeness tests, but quite expensive ones, as we discussed above. Thus, they may be used only as compositeness tests, and only to find very small factors. Primality tests, as we have defined them, are sometimes called primality proofs, which are typically either complicated to apply or else are applicable only to special numbers such as Fermat numbers, those of the form 2 2n +1. In other words, they sacrifice either speed or generality, but always provide a correct answer without failure. We look at one, which employs the converse of Fermat s little theorem. The following is attributable to D.H. Lehmer, M. Kraitchik, and others. Primality Test via the Converse of Fermat s Little Theorem Suppose that n N with n 3. Then n is prime if and only if there exists an m N such that m n 1 1 (mod n), but m (n 1)/q 1 (mod n) for any prime q (n 1). A major pitfall with the above primality test is that we must have knowleege of a factorization of n 1, so it works well on special numbers such as Fermat numbers, for instance. However, the above is a general proof that n is prime since the test finds an element of order n 1in(Z/nZ), namely a primitive root modulo n. Furthermore, it can be demonstrated that if we have a factorization of n 1 and n is prime, then the above primality test can be employed to prove that n is prime in polynomial time; but if n is composite the algorithm will run without bound, or diverge. Primality proofs sacrifice one of speed or generality. For instance, there is the Lucas-Lehmer test for Mersenne numbers, Pocklington s theorem, Proth s theorem, and Pepin s theorem, all of which the reader may see in detail by consulting [5], for instance. We will be concerned herein with tests that are used in practice. Usually, these are tests that are simple, generally applicable, and efficient, but unlike the aforementioned tests, they sometimes fail. These are the compositeness tests. Note that in a compositeness test, failure of the test means that n

3 On factoring 1637 does not satisfy the condition for compositeness and n is composite. In other words, failure results in a composite number being indicated as a prime, but never is a prime indicated as a composite number. The reason is that the condition is a proof of compositeness in the sense that if the condition is satisfied, n is forced to be composite. However, the converse is false. Composite numbers may fail to satisfy the condition. We may again employ the converse of Fermat s little theorem as an illustration. Fermat s Little Theorem as a Compositness Test If n N, a Z with gcd(a, n) = 1, and a n 1 1 (mod n), (2.1) then n is composite. Note that any n satisfying condition (2.1) must be composite by Fermat s little theorem. An application of the above is an interpretation of Lucas test as a compositeness test by letting n be odd and a = 2. See [2] for a recent article by John Brillhart on this famous test by Lucas. He argues that a primality test is an algorithm whose steps verify the hypothesis of a theorem whose conclusion is n is prime. which is consistent with our definition. If n fails condition (2.1), then this is not a proof that n is prime. For instance, (mod 341), yet 341 = Such numbers that fail condition (2.1), and are composite are called pseudoprimes In fact, there are composite numbers for which the choice of the base a is irrelevant in the sense that they will always fail the test. For instance, a 541 a (mod 541) for any a Z, yet 561 = This is an example of a Carmichael number. Moreover, there are known to be infinitely many Carmichael numbers (see [1]). This shows, in the extreme, that Fermat s little theorem may not be used as a primality test. However, the following is a well-known and utilized primality test. The Miller-Selfridge-Rabin Primality Test Let n 1=2 t m where m N is odd and t N. The value n is the input to be tested by executing the following steps. (1) Choose a random integer a with 2 a n 2. (2) Compute If then terminate the algorithm with x a m (mod n). x ±1 (mod n), n is probably prime.

4 1638 R. A. Mollin If t = 1, terminate the algorithm with n is definitely composite. Otherwise, set j = 1 and go to step (3). (3) Compute x a 2jm (mod n). If x 1 (mod n), then terminate the algorithm with n is definitely composite. If x 1 (mod n), terminate the algorithm with n is probably prime. Otherwise set j = j + 1 and go to step (4). (4) If j = t 1, then go to step (5). Otherwise, go to step (3). (5) Compute x a 2t 1m (mod n). If x 1 (mod n), then terminate the algorithm with n is definitely composite. If x 1 (mod n), then terminate the algorithm with n is probably prime. If n is declared to be probably prime with base a by the Miller-Selfridge- Rabin test, then n is said to be a strong pseudoprime to base a. Thus, the above test is often called the strong pseudoprime test in the literature. The set of all pseudoprimes to base a is denoted by spsp(a). Let us look a little closer at the above test to see why it it is possible to declare that n is definitely composite in step (3). If x 1 (mod n) in step (3), then for some j with 1 j<t 1: a 2jm 1 (mod n), but a 2j 1m ±1 (mod n). Thus, it can be shown that gcd(a 2j 1m 1,n) is a nontrivial factor of n. Hence, if the Miller-Selfridge-Rabin test declares in step (3) that n is definitely composite, then indeed it is. Another way of saying this is that if n is prime, then

5 On factoring 1639 Miller-Selfridge-Rabin will declare it to be so. However, if n is composite, then it can be shown that the test fails to recognize n as composite with probability at most (1/4). This is why the most we can say is that n is probably prime. However, if we perform the test r times for r large enough, this probability (1/4) r can be brought arbitrarily close to zero. Moreover, at least in practice, using the test with a single choice of a base a is usually sufficient. Also, in step (5), notice that we have not mentioned the possibility that a 2t 1m 1 (mod n) specifically. However, if this did occur, then that means that in step (3), we would have determined that a 2t 2m ±1 (mod n), from which it follows that n cannot be prime. Furthermore, by the above method, we can factor n since gcd(a 2t 2m 1,n) is a nontrivial factor. This final step (4) is required since, if we get to j = t 1, with x ±1 (mod n) for any j<t 1, then simply invoking step (3) again would dismiss those values of x ±1 (mod n), and this would not allow us to claim that n is composite in those cases. Hence, it allows for more values of n to be deemed composite, with certainty, than if we merely performed step (3) as with previous values of j. 3 Generating Primes Selecting random primes for, say, the RSA cipher is important since bad choices can be made that compromise the algorithm. Safe primes are those primes p for which (p 1)/2 is also prime. Such primes are important in selecting an RSA modulus n = pq since, if p and q are safe primes, then RSA is not vulnerable to p 1 factoring method discovered by Pollard in [6] or the p+1 factoring method found by Williams in [7]. In general, having safe primes in the modulus makes it more difficult to factor. However, finding such primes is also more difficult. Algorithm for Generating (Probable) Safe Primes Let b be the input bitlength of the required prime. Execute the following steps. (1) Select a (b 1)-bit odd random n N and a smoothness bound B (determined experimentally). (2) Trial divide n by primes p B. Ifn is divisible by any such p, go to step (1). Otherwise, go to step (3).

6 1640 R. A. Mollin (3) Use the Miller-Selfridge-Rabin test to test n for primality. If it declares that n is probably prime, then go to step (4). Otherwise, go to step (1). (4) Compute 2n + 1 = q and use the Miller-Selfridge-Rabin test on q. If it declares q to be a probable prime, terminate the algorithm with q as a probable safe prime. Otherwise go to step (1). There are primes that have even more constraints to ensure security of the RSA modulus. They are given as follows. Definition 3.1 (Strong Primes) A prime p is called a strong prime if each of the following hold. (1) p 1 has a large prime factor q. (2) p +1has a large prime factor r. (3) q 1 has a large prime factor s. The following algorithm was initiated in [3]. Gordon s Algorithm for Generating (Probable) Strong Primes (1) Generate two large (probable) primes r s of roughly equal bitlength using the Miller-Selfridge-Rabin test. (2) Select the first prime in the sequence {2js +1} j Æ, and let be that prime. q =2js +1 (3) Compute p 0 r q 1 q r 1 (mod rq). (4) Find the first prime in the sequence {p 0 +2iqr} i Æ, and let p = p 0 +2iqr be that prime, which is a strong prime. Although it is possible to generate primes that are both safe and strong, the algorithms are not as efficient as Gordon s algorithm. Furthermore, choosing random primes large enough will generally thwart direct factoring attacks. The following provides a mechanism for generating large random primes. Large (Probable) Prime Generation We let b be the input bitlength of the desired prime and let B be the input smoothness bound (empirically determined). Execute the following steps.

7 On factoring 1641 (1) Randomly generate an odd b-bit integer n. (2) Use trial division to test for divisibility of n by all odd primes no bigger than B. Ifn is so divisible, go to step (1). Otherwise go to step (3). (3) Use the Miller-Selfridge-Rabin to test n for primality. If it is declared to be a probable prime, then output n as such. Otherwise, go to step (1). Large (Provable) Prime Generation Begin with a prime p 1, and execute the following steps until you have a prime of the desired size. Initialize the variable counter j = 1. (1) Randomly generate a small odd integer m and form n =2mp j +1. (2) If 2 n 1 1 (mod n), then go to step (1). Otherwise, go to step (3). (3) Using the primality test on page 1636, with prime bases 2 a 23, if for any such a, a (n 1)/p 1 (mod n) for any prime p dividing n 1, then n is prime. If n is large enough, terminate the algorithm with output n as the provable prime. Otherwise, set n = p j+1, j = j + 1, and go to step (1). If the test fails go to step (1). Note that since we have a known factorization of n 1 in the above algorithm, and a small value of m to check, then the test is simple and efficient. 4 Decision Problem or Primality Test? Earlier we discussed Lucas test as an application of Fermat s compositeness criterion (2.1) (contrapositively speaking). There is, however, a brand of opinion that Lucas test is really a decision problem. Here is the reasoning. Lucas test tells us to compute 2 n 1 (mod n). If 2 n 1 1 (mod n), then we know that n is not prime and send it off to some factoring routine. If 2 n 1 1 (mod n), then we send it off for primality testing. Hence, the Lucas test may be viewed as a decision problem on whether to send n for primality testing or factoring. Since decision problems are yes-no issues, we phrase the question as Do we send n for primality testing?

8 1642 R. A. Mollin If the answer is yes, we do so, and if the answer is no, we send it to a factoring algorithm. There is merit to the above argument. Attendant with the above viewpoint is the opinion that assigning probabilities or improving such estimates has nothing to do with primality testing. Thus, this school of thought would not consider the Miller-Selfridge-Rabin algorithm to be a test that in any way assists with practical primality testing. Given that MSR does not satisfy our criterion (2) given above this viewpoint also has some merit. That said, this does not prevent the use of such algorithms in practice. The aforementioned point of view is presented for mental fodder and general interest in what is often a contentious topic. Acknowledgements: The author s research is supported by NSERC Canada grant # A8484. References [1] W.R. Alford, A. Granville, and C. Pomerance, There are infinitely many Carmichael numbers, Ann. Math. 140 (1994), [2] J. Brillhart, Commentary on Lucas Test, Fields Inst. Comm. 41 (2004), [3] J. Gordon, Strong primes are easy to find, inadvances in Cryptology, EUROCRYPT 84, Springer-Verlag, Berlin, LNCS 209 (1985), [4] R.A. Mollin, Codes The Guide to Secrecy from Ancient to Modern Times, Chapman and Hall/CRC Press, Boca Raton, New York, London, Tokyo (2005). [5] R.A. Mollin, An Introduction to Cryptography, Second Edition, Chapman and Hall/CRC Press, Boca Raton, New York, London, Tokyo (2006). [6] J.M. Pollard, An algorithm for testing the primality of any integer, Bull. London Math. Soc. 3 (1971), [7] H.C. Williams, A p +1 method of factoring, Math. Comp. 39 (1982), Received: September 3, 2008

International Journal of Information Technology, Modeling and Computing (IJITMC) Vol.1, No.3,August 2013

FACTORING CRYPTOSYSTEM MODULI WHEN THE CO-FACTORS DIFFERENCE IS BOUNDED Omar Akchiche 1 and Omar Khadir 2 1,2 Laboratory of Mathematics, Cryptography and Mechanics, Fstm, University of Hassan II Mohammedia-Casablanca,

On Generalized Fermat Numbers 3 2n +1

Applied Mathematics & Information Sciences 4(3) (010), 307 313 An International Journal c 010 Dixie W Publishing Corporation, U. S. A. On Generalized Fermat Numbers 3 n +1 Amin Witno Department of Basic

Primality - Factorization

Primality - Factorization Christophe Ritzenthaler November 9, 2009 1 Prime and factorization Definition 1.1. An integer p > 1 is called a prime number (nombre premier) if it has only 1 and p as divisors.

Factoring & Primality

Factoring & Primality Lecturer: Dimitris Papadopoulos In this lecture we will discuss the problem of integer factorization and primality testing, two problems that have been the focus of a great amount

FACTORING. n = 2 25 + 1. fall in the arithmetic sequence

FACTORING The claim that factorization is harder than primality testing (or primality certification) is not currently substantiated rigorously. As some sort of backward evidence that factoring is hard,

NEW DIGITAL SIGNATURE PROTOCOL BASED ON ELLIPTIC CURVES

NEW DIGITAL SIGNATURE PROTOCOL BASED ON ELLIPTIC CURVES Ounasser Abid 1, Jaouad Ettanfouhi 2 and Omar Khadir 3 1,2,3 Laboratory of Mathematics, Cryptography and Mechanics, Department of Mathematics, Fstm,

Integer Factorization using the Quadratic Sieve

Integer Factorization using the Quadratic Sieve Chad Seibert* Division of Science and Mathematics University of Minnesota, Morris Morris, MN 56567 seib0060@morris.umn.edu March 16, 2011 Abstract We give

A Factoring and Discrete Logarithm based Cryptosystem

Int. J. Contemp. Math. Sciences, Vol. 8, 2013, no. 11, 511-517 HIKARI Ltd, www.m-hikari.com A Factoring and Discrete Logarithm based Cryptosystem Abdoul Aziz Ciss and Ahmed Youssef Ecole doctorale de Mathematiques

Factoring Algorithms

Factoring Algorithms The p 1 Method and Quadratic Sieve November 17, 2008 () Factoring Algorithms November 17, 2008 1 / 12 Fermat s factoring method Fermat made the observation that if n has two factors

Determining the Optimal Combination of Trial Division and Fermat s Factorization Method

Determining the Optimal Combination of Trial Division and Fermat s Factorization Method Joseph C. Woodson Home School P. O. Box 55005 Tulsa, OK 74155 Abstract The process of finding the prime factorization

Is n a Prime Number? Manindra Agrawal. March 27, 2006, Delft. IIT Kanpur

Is n a Prime Number? Manindra Agrawal IIT Kanpur March 27, 2006, Delft Manindra Agrawal (IIT Kanpur) Is n a Prime Number? March 27, 2006, Delft 1 / 47 Overview 1 The Problem 2 Two Simple, and Slow, Methods

Primality Testing and Factorization Methods

Primality Testing and Factorization Methods Eli Howey May 27, 2014 Abstract Since the days of Euclid and Eratosthenes, mathematicians have taken a keen interest in finding the nontrivial factors of integers,

MATHEMATICS OF COMPUTATION VOLUME, NUMBER 0 JULY 99, PAGES -0 AMBIGUOUS CLASSES IN QUADRATIC FIELDS R. A. MOLLIN Dedicated to the memory ofd. H. Lehmer Abstract. We provide sufficient conditions for the

PRIME FACTORS OF CONSECUTIVE INTEGERS

PRIME FACTORS OF CONSECUTIVE INTEGERS MARK BAUER AND MICHAEL A. BENNETT Abstract. This note contains a new algorithm for computing a function f(k) introduced by Erdős to measure the minimal gap size in

U.C. Berkeley CS276: Cryptography Handout 0.1 Luca Trevisan January, 2009. Notes on Algebra

U.C. Berkeley CS276: Cryptography Handout 0.1 Luca Trevisan January, 2009 Notes on Algebra These notes contain as little theory as possible, and most results are stated without proof. Any introductory

Primes in Sequences. Lee 1. By: Jae Young Lee. Project for MA 341 (Number Theory) Boston University Summer Term I 2009 Instructor: Kalin Kostadinov

Lee 1 Primes in Sequences By: Jae Young Lee Project for MA 341 (Number Theory) Boston University Summer Term I 2009 Instructor: Kalin Kostadinov Lee 2 Jae Young Lee MA341 Number Theory PRIMES IN SEQUENCES

An Overview of Integer Factoring Algorithms. The Problem

An Overview of Integer Factoring Algorithms Manindra Agrawal IITK / NUS The Problem Given an integer n, find all its prime divisors as efficiently as possible. 1 A Difficult Problem No efficient algorithm

Public Key Cryptography: RSA and Lots of Number Theory

Public Key Cryptography: RSA and Lots of Number Theory Public vs. Private-Key Cryptography We have just discussed traditional symmetric cryptography: Uses a single key shared between sender and receiver

Breaking The Code. Ryan Lowe. Ryan Lowe is currently a Ball State senior with a double major in Computer Science and Mathematics and

Breaking The Code Ryan Lowe Ryan Lowe is currently a Ball State senior with a double major in Computer Science and Mathematics and a minor in Applied Physics. As a sophomore, he took an independent study

Factoring Algorithms

Institutionen för Informationsteknologi Lunds Tekniska Högskola Department of Information Technology Lund University Cryptology - Project 1 Factoring Algorithms The purpose of this project is to understand

Breaking Generalized Diffie-Hellman Modulo a Composite is no Easier than Factoring

Breaking Generalized Diffie-Hellman Modulo a Composite is no Easier than Factoring Eli Biham Dan Boneh Omer Reingold Abstract The Diffie-Hellman key-exchange protocol may naturally be extended to k > 2

Cryptography and Network Security Chapter 8

Cryptography and Network Security Chapter 8 Fifth Edition by William Stallings Lecture slides by Lawrie Brown (with edits by RHB) Chapter 8 Introduction to Number Theory The Devil said to Daniel Webster:

CONTRIBUTIONS TO ZERO SUM PROBLEMS

CONTRIBUTIONS TO ZERO SUM PROBLEMS S. D. ADHIKARI, Y. G. CHEN, J. B. FRIEDLANDER, S. V. KONYAGIN AND F. PAPPALARDI Abstract. A prototype of zero sum theorems, the well known theorem of Erdős, Ginzburg

Outline. Computer Science 418. Digital Signatures: Observations. Digital Signatures: Definition. Definition 1 (Digital signature) Digital Signatures

Outline Computer Science 418 Digital Signatures Mike Jacobson Department of Computer Science University of Calgary Week 12 1 Digital Signatures 2 Signatures via Public Key Cryptosystems 3 Provable 4 Mike

Discrete Mathematics Lecture 3 Elementary Number Theory and Methods of Proof. Harper Langston New York University

Discrete Mathematics Lecture 3 Elementary Number Theory and Methods of Proof Harper Langston New York University Proof and Counterexample Discovery and proof Even and odd numbers number n from Z is called

ALGEBRAIC APPROACH TO COMPOSITE INTEGER FACTORIZATION

ALGEBRAIC APPROACH TO COMPOSITE INTEGER FACTORIZATION Aldrin W. Wanambisi 1* School of Pure and Applied Science, Mount Kenya University, P.O box 553-50100, Kakamega, Kenya. Shem Aywa 2 Department of Mathematics,

LUC: A New Public Key System

LUC: A New Public Key System Peter J. Smith a and Michael J. J. Lennon b a LUC Partners, Auckland UniServices Ltd, The University of Auckland, Private Bag 92019, Auckland, New Zealand. b Department of

Lecture 13 - Basic Number Theory.

Lecture 13 - Basic Number Theory. Boaz Barak March 22, 2010 Divisibility and primes Unless mentioned otherwise throughout this lecture all numbers are non-negative integers. We say that A divides B, denoted

Finding Carmichael numbers

Finding Carmichael numbers Notes by G.J.O. Jameson Introduction Recall that Fermat s little theorem says that if p is prime and a is not a multiple of p, then a p 1 1 mod p. This theorem gives a possible

1 Digital Signatures. 1.1 The RSA Function: The eth Power Map on Z n. Crypto: Primitives and Protocols Lecture 6.

1 Digital Signatures A digital signature is a fundamental cryptographic primitive, technologically equivalent to a handwritten signature. In many applications, digital signatures are used as building blocks

3. Applications of Number Theory

3. APPLICATIONS OF NUMBER THEORY 163 3. Applications of Number Theory 3.1. Representation of Integers. Theorem 3.1.1. Given an integer b > 1, every positive integer n can be expresses uniquely as n = a

Computer and Network Security

MIT 6.857 Computer and Networ Security Class Notes 1 File: http://theory.lcs.mit.edu/ rivest/notes/notes.pdf Revision: December 2, 2002 Computer and Networ Security MIT 6.857 Class Notes by Ronald L. Rivest

MATH 168: FINAL PROJECT Troels Eriksen. 1 Introduction

MATH 168: FINAL PROJECT Troels Eriksen 1 Introduction In the later years cryptosystems using elliptic curves have shown up and are claimed to be just as secure as a system like RSA with much smaller key

2.1 Complexity Classes

15-859(M): Randomized Algorithms Lecturer: Shuchi Chawla Topic: Complexity classes, Identity checking Date: September 15, 2004 Scribe: Andrew Gilpin 2.1 Complexity Classes In this lecture we will look

(x + a) n = x n + a Z n [x]. Proof. If n is prime then the map

22. A quick primality test Prime numbers are one of the most basic objects in mathematics and one of the most basic questions is to decide which numbers are prime (a clearly related problem is to find

Recent Breakthrough in Primality Testing

Nonlinear Analysis: Modelling and Control, 2004, Vol. 9, No. 2, 171 184 Recent Breakthrough in Primality Testing R. Šleževičienė, J. Steuding, S. Turskienė Department of Computer Science, Faculty of Physics

Cryptography and Network Security

Cryptography and Network Security Spring 2012 http://users.abo.fi/ipetre/crypto/ Lecture 7: Public-key cryptography and RSA Ion Petre Department of IT, Åbo Akademi University 1 Some unanswered questions

The Mathematics of the RSA Public-Key Cryptosystem

The Mathematics of the RSA Public-Key Cryptosystem Burt Kaliski RSA Laboratories ABOUT THE AUTHOR: Dr Burt Kaliski is a computer scientist whose involvement with the security industry has been through

The Mathematics of RSA

The Mathematics of RSA Dimitri Papaioannou May 24, 2007 1 Introduction Cryptographic systems come in two flavors. Symmetric or Private key encryption and Asymmetric or Public key encryption. Strictly speaking,

Announcements. CS243: Discrete Structures. More on Cryptography and Mathematical Induction. Agenda for Today. Cryptography

Announcements CS43: Discrete Structures More on Cryptography and Mathematical Induction Işıl Dillig Class canceled next Thursday I am out of town Homework 4 due Oct instead of next Thursday (Oct 18) Işıl

An Approach to Shorten Digital Signature Length

Computer Science Journal of Moldova, vol.14, no.342, 2006 An Approach to Shorten Digital Signature Length Nikolay A. Moldovyan Abstract A new method is proposed to design short signature schemes based

The mathematics of cryptology

The mathematics of cryptology Paul E. Gunnells Department of Mathematics and Statistics University of Massachusetts, Amherst Amherst, MA 01003 www.math.umass.edu/ gunnells April 27, 2004 What is Cryptology?

9 Modular Exponentiation and Cryptography

9 Modular Exponentiation and Cryptography 9.1 Modular Exponentiation Modular arithmetic is used in cryptography. In particular, modular exponentiation is the cornerstone of what is called the RSA system.

USING LUCAS SEQUENCES TO FACTOR LARGE INTEGERS NEAR GROUP ORDERS

USING LUCAS SEQUENCES TO FACTOR LARGE INTEGERS NEAR GROUP ORDERS Zhenxiang Zhang* Dept. of Math., Anhui Normal University, 241000 Wuhu, Anhui, P.R. China e-mail: zhangzhx@mail.ahwhptt.net.cn (Submitted

8 Primes and Modular Arithmetic

8 Primes and Modular Arithmetic 8.1 Primes and Factors Over two millennia ago already, people all over the world were considering the properties of numbers. One of the simplest concepts is prime numbers.

Faster deterministic integer factorisation

David Harvey (joint work with Edgar Costa, NYU) University of New South Wales 25th October 2011 The obvious mathematical breakthrough would be the development of an easy way to factor large prime numbers

CRC Press has granted the following specific permissions for the electronic version of this book:

This is a Chapter from the Handbook of Applied Cryptography, by A. Menezes, P. van Oorschot, and S. Vanstone, CRC Press, 1996. For further information, see www.cacr.math.uwaterloo.ca/hac CRC Press has

Number Theory and Cryptography using PARI/GP

Number Theory and Cryptography using Minh Van Nguyen nguyenminh2@gmail.com 25 November 2008 This article uses to study elementary number theory and the RSA public key cryptosystem. Various commands will

Factoring pq 2 with Quadratic Forms: Nice Cryptanalyses

Factoring pq 2 with Quadratic Forms: Nice Cryptanalyses Phong Nguyễn http://www.di.ens.fr/~pnguyen & ASIACRYPT 2009 Joint work with G. Castagnos, A. Joux and F. Laguillaumie Summary Factoring A New Factoring

Number Theory Learning Module 2 Prime Numbers and Integer Factorization in Sage 1

Learning Module 2 Prime Numbers and Integer Factorization in Sage 1 1 Objectives. Learn how to test for primality and generate prime numbers and in Sage. Learn how to work with factorizations in Sage.

FACTORING LARGE NUMBERS, A GREAT WAY TO SPEND A BIRTHDAY

FACTORING LARGE NUMBERS, A GREAT WAY TO SPEND A BIRTHDAY LINDSEY R. BOSKO I would like to acknowledge the assistance of Dr. Michael Singer. His guidance and feedback were instrumental in completing this

Revised Version of Chapter 23. We learned long ago how to solve linear congruences. ax c (mod m)

Chapter 23 Squares Modulo p Revised Version of Chapter 23 We learned long ago how to solve linear congruences ax c (mod m) (see Chapter 8). It s now time to take the plunge and move on to quadratic equations.

Elements of Applied Cryptography Public key encryption

Network Security Elements of Applied Cryptography Public key encryption Public key cryptosystem RSA and the factorization problem RSA in practice Other asymmetric ciphers Asymmetric Encryption Scheme Let

Runtime and Implementation of Factoring Algorithms: A Comparison

Runtime and Implementation of Factoring Algorithms: A Comparison Justin Moore CSC290 Cryptology December 20, 2003 Abstract Factoring composite numbers is not an easy task. It is classified as a hard algorithm,

Elementary factoring algorithms

Math 5330 Spring 013 Elementary factoring algorithms The RSA cryptosystem is founded on the idea that, in general, factoring is hard. Where as with Fermat s Little Theorem and some related ideas, one can

Elementary Number Theory We begin with a bit of elementary number theory, which is concerned

CONSTRUCTION OF THE FINITE FIELDS Z p S. R. DOTY Elementary Number Theory We begin with a bit of elementary number theory, which is concerned solely with questions about the set of integers Z = {0, ±1,

Today s Topics. Primes & Greatest Common Divisors

Today s Topics Primes & Greatest Common Divisors Prime representations Important theorems about primality Greatest Common Divisors Least Common Multiples Euclid s algorithm Once and for all, what are prime

STUDY ON ELLIPTIC AND HYPERELLIPTIC CURVE METHODS FOR INTEGER FACTORIZATION. Takayuki Yato. A Senior Thesis. Submitted to

STUDY ON ELLIPTIC AND HYPERELLIPTIC CURVE METHODS FOR INTEGER FACTORIZATION by Takayuki Yato A Senior Thesis Submitted to Department of Information Science Faculty of Science The University of Tokyo on

CIS 5371 Cryptography. 8. Encryption --

CIS 5371 Cryptography p y 8. Encryption -- Asymmetric Techniques Textbook encryption algorithms In this chapter, security (confidentiality) is considered in the following sense: All-or-nothing secrecy.

The Quadratic Sieve Factoring Algorithm Eric Landquist MATH 488: Cryptographic Algorithms December 14, 2001 1 Introduction Mathematicians have been attempting to find better and faster ways to factor composite

Characterizing the Sum of Two Cubes

1 3 47 6 3 11 Journal of Integer Sequences, Vol. 6 (003), Article 03.4.6 Characterizing the Sum of Two Cubes Kevin A. Broughan University of Waikato Hamilton 001 New Zealand kab@waikato.ac.nz Abstract

EMBEDDING DEGREE OF HYPERELLIPTIC CURVES WITH COMPLEX MULTIPLICATION

EMBEDDING DEGREE OF HYPERELLIPTIC CURVES WITH COMPLEX MULTIPLICATION CHRISTIAN ROBENHAGEN RAVNSHØJ Abstract. Consider the Jacobian of a genus two curve defined over a finite field and with complex multiplication.

Math 319 Problem Set #3 Solution 21 February 2002

Math 319 Problem Set #3 Solution 21 February 2002 1. ( 2.1, problem 15) Find integers a 1, a 2, a 3, a 4, a 5 such that every integer x satisfies at least one of the congruences x a 1 (mod 2), x a 2 (mod

Handout #1: Mathematical Reasoning

Math 101 Rumbos Spring 2010 1 Handout #1: Mathematical Reasoning 1 Propositional Logic A proposition is a mathematical statement that it is either true or false; that is, a statement whose certainty or

Lecture 13: Factoring Integers

CS 880: Quantum Information Processing 0/4/0 Lecture 3: Factoring Integers Instructor: Dieter van Melkebeek Scribe: Mark Wellons In this lecture, we review order finding and use this to develop a method

SECURITY IMPROVMENTS TO THE DIFFIE-HELLMAN SCHEMES

www.arpapress.com/volumes/vol8issue1/ijrras_8_1_10.pdf SECURITY IMPROVMENTS TO THE DIFFIE-HELLMAN SCHEMES Malek Jakob Kakish Amman Arab University, Department of Computer Information Systems, P.O.Box 2234,

Applications of Fermat s Little Theorem and Congruences

Applications of Fermat s Little Theorem and Congruences Definition: Let m be a positive integer. Then integers a and b are congruent modulo m, denoted by a b mod m, if m (a b). Example: 3 1 mod 2, 6 4

RSA Attacks. By Abdulaziz Alrasheed and Fatima

RSA Attacks By Abdulaziz Alrasheed and Fatima 1 Introduction Invented by Ron Rivest, Adi Shamir, and Len Adleman [1], the RSA cryptosystem was first revealed in the August 1977 issue of Scientific American.

Notes on Factoring. MA 206 Kurt Bryan

The General Approach Notes on Factoring MA 26 Kurt Bryan Suppose I hand you n, a 2 digit integer and tell you that n is composite, with smallest prime factor around 5 digits. Finding a nontrivial factor

The application of prime numbers to RSA encryption

The application of prime numbers to RSA encryption Prime number definition: Let us begin with the definition of a prime number p The number p, which is a member of the set of natural numbers N, is considered

Doug Ravenel. October 15, 2008

Doug Ravenel University of Rochester October 15, 2008 s about Euclid s Some s about primes that every mathematician should know (Euclid, 300 BC) There are infinitely numbers. is very elementary, and we

Smooth numbers and the quadratic sieve

Algorithmic Number Theory MSRI Publications Volume 44, 2008 Smooth numbers and the quadratic sieve CARL POMERANCE ABSTRACT. This article gives a gentle introduction to factoring large integers via the

IRREDUCIBLE OPERATOR SEMIGROUPS SUCH THAT AB AND BA ARE PROPORTIONAL. 1. Introduction

IRREDUCIBLE OPERATOR SEMIGROUPS SUCH THAT AB AND BA ARE PROPORTIONAL R. DRNOVŠEK, T. KOŠIR Dedicated to Prof. Heydar Radjavi on the occasion of his seventieth birthday. Abstract. Let S be an irreducible

Number Theory. Proof. Suppose otherwise. Then there would be a finite number n of primes, which we may

Number Theory Divisibility and Primes Definition. If a and b are integers and there is some integer c such that a = b c, then we say that b divides a or is a factor or divisor of a and write b a. Definition

CHAPTER 5. Number Theory. 1. Integers and Division. Discussion

CHAPTER 5 Number Theory 1. Integers and Division 1.1. Divisibility. Definition 1.1.1. Given two integers a and b we say a divides b if there is an integer c such that b = ac. If a divides b, we write a

MA2C03 Mathematics School of Mathematics, Trinity College Hilary Term 2016 Lecture 59 (April 1, 2016) David R. Wilkins

MA2C03 Mathematics School of Mathematics, Trinity College Hilary Term 2016 Lecture 59 (April 1, 2016) David R. Wilkins The RSA encryption scheme works as follows. In order to establish the necessary public

Factoring a semiprime n by estimating φ(n)

Factoring a semiprime n by estimating φ(n) Kyle Kloster May 7, 2010 Abstract A factoring algorithm, called the Phi-Finder algorithm, is presented that factors a product of two primes, n = pq, by determining

Family Name:... First Name:... Section:... Advanced Cryptography Final Exam July 18 th, 2006 Start at 9:15, End at 12:00 This document consists of 12 pages. Instructions Electronic devices are not allowed.

Paillier Threshold Encryption Toolbox

Paillier Threshold Encryption Toolbox October 23, 2010 1 Introduction Following a desire for secure (encrypted) multiparty computation, the University of Texas at Dallas Data Security and Privacy Lab created

PRIME PYTHAGOREAN TRIANGLES

PRIME PYTHAGOREAN TRIANGLES HARVEY DUBNER AND TONY FORBES Abstract. A prime Pythagorean triangle has three integer sides of which the hypotenuse and one leg are primes. In this article we investigate their

Factoring. Factoring 1

Factoring Factoring 1 Factoring Security of RSA algorithm depends on (presumed) difficulty of factoring o Given N = pq, find p or q and RSA is broken o Rabin cipher also based on factoring Factoring like

MOP 2007 Black Group Integer Polynomials Yufei Zhao. Integer Polynomials. June 29, 2007 Yufei Zhao yufeiz@mit.edu

Integer Polynomials June 9, 007 Yufei Zhao yufeiz@mit.edu We will use Z[x] to denote the ring of polynomials with integer coefficients. We begin by summarizing some of the common approaches used in dealing

Cryptography and Network Security Chapter 9

Cryptography and Network Security Chapter 9 Fifth Edition by William Stallings Lecture slides by Lawrie Brown (with edits by RHB) Chapter 9 Public Key Cryptography and RSA Every Egyptian received two names,

Computational Number Theory

Computational Number Theory C. Pomerance 1 Introduction Historically, computation has been a driving force in the development of mathematics. To help measure the sizes of their fields, the Egyptians invented

FACTORING POLYNOMIALS IN THE RING OF FORMAL POWER SERIES OVER Z

FACTORING POLYNOMIALS IN THE RING OF FORMAL POWER SERIES OVER Z DANIEL BIRMAJER, JUAN B GIL, AND MICHAEL WEINER Abstract We consider polynomials with integer coefficients and discuss their factorization

ON FIBONACCI NUMBERS WITH FEW PRIME DIVISORS

ON FIBONACCI NUMBERS WITH FEW PRIME DIVISORS YANN BUGEAUD, FLORIAN LUCA, MAURICE MIGNOTTE, SAMIR SIKSEK Abstract If n is a positive integer, write F n for the nth Fibonacci number, and ω(n) for the number

Consequently, for the remainder of this discussion we will assume that a is a quadratic residue mod p.

Computing square roots mod p We now have very effective ways to determine whether the quadratic congruence x a (mod p), p an odd prime, is solvable. What we need to complete this discussion is an effective

Factorization Methods: Very Quick Overview

Factorization Methods: Very Quick Overview Yuval Filmus October 17, 2012 1 Introduction In this lecture we introduce modern factorization methods. We will assume several facts from analytic number theory.

Factoring integers, Producing primes and the RSA cryptosystem Harish-Chandra Research Institute

RSA cryptosystem HRI, Allahabad, February, 2005 0 Factoring integers, Producing primes and the RSA cryptosystem Harish-Chandra Research Institute Allahabad (UP), INDIA February, 2005 RSA cryptosystem HRI,

Notes on Network Security Prof. Hemant K. Soni

Chapter 9 Public Key Cryptography and RSA Private-Key Cryptography traditional private/secret/single key cryptography uses one key shared by both sender and receiver if this key is disclosed communications

HOMEWORK 5 SOLUTIONS. n!f n (1) lim. ln x n! + xn x. 1 = G n 1 (x). (2) k + 1 n. (n 1)!

Math 7 Fall 205 HOMEWORK 5 SOLUTIONS Problem. 2008 B2 Let F 0 x = ln x. For n 0 and x > 0, let F n+ x = 0 F ntdt. Evaluate n!f n lim n ln n. By directly computing F n x for small n s, we obtain the following

Introduction. Digital Signature

Introduction Electronic transactions and activities taken place over Internet need to be protected against all kinds of interference, accidental or malicious. The general task of the information technology

Carmichael numbers and pseudoprimes

Carmichael numbers and pseudoprimes Notes by G.J.O. Jameson Introduction Recall that Fermat s little theorem says that if p is prime and a is not a multiple of p, then a p 1 1 mod p. This theorem gives

MATH 537 (Number Theory) FALL 2016 TENTATIVE SYLLABUS

MATH 537 (Number Theory) FALL 2016 TENTATIVE SYLLABUS Class Meetings: MW 2:00-3:15 pm in Physics 144, September 7 to December 14 [Thanksgiving break November 23 27; final exam December 21] Instructor:

RSA and Primality Testing

and Primality Testing Joan Boyar, IMADA, University of Southern Denmark Studieretningsprojekter 2010 1 / 81 Correctness of cryptography cryptography Introduction to number theory Correctness of with 2

Integer Factorization

Integer Factorization Lecture given at the Joh. Gutenberg-Universität, Mainz, July 23, 1992 by ÖYSTEIN J. RÖDSETH University of Bergen, Department of Mathematics, Allégt. 55, N-5007 Bergen, Norway 1 Introduction

COMMUTATIVITY DEGREES OF WREATH PRODUCTS OF FINITE ABELIAN GROUPS

Bull Austral Math Soc 77 (2008), 31 36 doi: 101017/S0004972708000038 COMMUTATIVITY DEGREES OF WREATH PRODUCTS OF FINITE ABELIAN GROUPS IGOR V EROVENKO and B SURY (Received 12 April 2007) Abstract We compute

Alex, I will take congruent numbers for one million dollars please

Alex, I will take congruent numbers for one million dollars please Jim L. Brown The Ohio State University Columbus, OH 4310 jimlb@math.ohio-state.edu One of the most alluring aspectives of number theory