# Short Programs for functions on Curves

Save this PDF as:

Size: px
Start display at page:

## Transcription

1 Short Programs for functions on Curves Victor S. Miller Exploratory Computer Science IBM, Thomas J. Watson Research Center Yorktown Heights, NY May 6, 1986 Abstract The problem of deducing a function on an algebraic curve having a given divisor is important in the field of indefinite integration. Indeed, it is the main computational step in determining whether an algebraic function posseses an indefinite integral. It has also become important recently in the study of discrete elliptic logarithms in cryptography, and in the construction of the new class of error-correcting codes which exceed the Varshamov-Gilbert bound. It can also be used to give a partial answer to a question raised by Schoof in his paper on computing the exact number of points on an elliptic curve over a finite field. Heretofore, the best known algorithm for calculating such functions was exponential in the size of the input. In this paper I give an algorithm which is linear in the size of the input (if arithmetic in the field under consideration takes constant time). For this algorithm it is necessary to represent the function as a straight-line program, for representation as a rational function may be exponential in the size of the input. 1 Introduction I recall some standard terminology from the theory of algebraic curves. There are many good references for this theory, for example [Ful69]. It contains all results quoted here. For simplicity in presentation I only work with plane curves, even though all of the results work for more general curves. Definition 1 Projective n-space over a field K: denoted by P n (K) is the set of equivalence classes {(a 0,..., a n ) 0 a i ɛk} where two vectors are equivalent if they are non-zero scalar multiples of one another. The equivalence class contataining (a 0,, a n ) is denoted by (a 0 : : a n ). The projective line is P 1, and the projective plane is P 2. 1

2 Definition 2 A plane (projective) algebraic curve is the set of solutions to a homogeneous polynomial f(x, Y, Z) considered as points in boldp 1. The curve is non-singular if the three partial derivatives of f never vanish simultaneously. Definition 3 The function field of the curve, C, is the set of functions from the curve to the projective line, which are given by rational functions of the coordinates and is denoted by k(c). Definition 4 A (geometric) point, P on C is a solution to the set of defining equations. Definition 5 At each point, P, of the curve one can define the :hp2order, v P (f), of the function f at P : it is n > 0 if the function has a zero of order n at P, and is n < 0 if the function has a pole of order n at P ( 1/f has a zero of order n). Definition 6 A divisor on a curve, C as being a formal sum of points on the curve with integral coefficients: P a P (P ), where only finitely many of the a P are 0. Divisors will normally be denoted by script letters such as A or B. Definition 7 The degree of a divisor is the sum of its coefficients: deg A = P a P. A function f has only a finite number of zeroes and poles. Therefore we may define Definition 8 The divisor of a function f 0, denoted by (f) is P v P (f)(p ). It is also true that deg(f) = 0. The set of divisors of degree 0 is denoted by D 0. A divisor of a function is also called principal. Definition 9 Linear equivalence. If A and B are divisors we write A B if there is a function f such that A = B + (f). Principal divisors are also called linearly equivalent to 0. The set of all such is denoted by D l. The group D 0 /D l is known as the Picard group of C and is denoted by Pic(C). Definition 10 Genus. The genus g of a curve C is an integer 0, which is a measure of the curve s complexity. It, for example, is the number of donut-holes in the Riemann-surface of the curve if we are working over the complex numbers. See [Ful69] for an exact definition. For our purposes, we only need to know that g (n 1)(n 2)/2 where n is the degree of the polynomial defining the curve. A curve whose genus is 1 is usually called an elliptic curve. Definition 11 Linear system. The linear system of a divisor A is L(A) = {0} {fɛk(c) (f) + A 0}. It is easily seen that L(A) is a vector space (in fact finite-dimensional). We denote l(a) = dim L(A). Definition 12 Support. The support supp A of a divisor A is the set {P A P 0}. 2

3 2 The main algorithm One of the fundamental problems in the theory of curves is to determine when a divisor of degree 0 is principal, and to construct a function whose divisor is the given divisor. In [Dav79]. Davenport gives an algorithm for this problem which does not always work for curves of genus > 1, and which is claimed to run in O(lg A where A is the largest multiplicity of a zero or a pole at any point. This claim seems to be unjustified. The construction below gives a straight-line program instead of a ratio of two polynomials. This is in keeping with the spirit of [Kal85]. Algorithm 1 Input: 1. An algebraic curve C of genus g 2. a fixed point Q on C 3. a divisor A = P a P (P ) of degree 0 Output: 1. A straight-line program for a function f on the curve 2. A divisor of the form C g(q) where deg C = g and C 0. The divisor C g(q) will = 0 if and only if A 0. We will further have A = (f) + C g(q). The length of this program is O(L) where L = P lg( a P + 1) and the running time of the algorithm is O(L) arithmetic operations in the field of definition. The program gives the value undefined on a set of points of size 2gL. We use the following fundamental theorem: Theorem 1 The Riemann Theorem: Given a non-singular curve C, and a divisor A, then l(a) deg A + 1 g with equality holding if deg A > 2g 2. Using the above we have Lemma 1 Any divisor A of degree 0 is equivalent to a divisor of the form C g(q), where deg C = g and C 0. Proof: Using the Riemann Theorem we find that l(a + g(q)) 1. Thus there is a function f 0, fɛl(a + g(q)). Now set C = (f) + A + g(q). It is readily seen that C has the desired properties. We use 1 to make calculations in the Picard Group, by representing each equivalence class by a divisor of the form C g(q). The fundamental point is that 3

4 to calculate a representative for the sum of two such divisors takes O(g 3 ) field operations (basically the solution of a system of linear equations). We then write the divisor A = P a P (P ) as P a P ((P ) (Q)). We then can calculate a straight-line program of length 2 lg( a P + 1) and a divisor C g(q) as above by means of the binary method of addition (or any other addition chain). The program will be undefined at most at all points of the supports of the divisors occuring in the intermediate steps. We then finish off by adding up all of the individual pieces, while multiplying the functions (this concatenates the straight-line programs with a multiplication in between). In actual calculation one must proceed more explicitly: First calculate a basis for the space L(3g(Q)) in the form f 1,..., f d where ord Q (f 1 ) > ord Q (f 2 ) > > ord Q (f d ). When adding the two divisors A g(q) and B g(q) we first find fɛl(3g(q) A B). Define C = (f) + 3g(Q) A B then it is effective of degree g. Now find hɛl(2g(q) C), and set D = (h) + 2g(Q) C. This divisor is also effective of degree g and A g(q)+b g(q) = D g(q)+(f/h). We further exploit the fact that there is a one-to-one correspondence between effective divisors and integral ideals of the ring of functions whose only poles are at Q. We represent each ideal by means of it Grobner Basis. In this way we avoid the necessity for root finding and factorization. In the case of genus 1 we do not even need to do this. All zeroes and poles of intermediate divisors must be rational. If the curve is given in Weierstrass form y 2 = x 3 + ax + b then 1, x, y form a basis of L(3g(0)). Finding the function f above amounts to finding the coefficients of the line y = cx + d passing through the points A and B. 3 Applications In this section I discuss some applications of the above construction. The first is the calculation of the Weil e N pairing. Andre Weil [Wei46] introduced a pairing on points of finite order on elliptic curves in his first proof of the Riemann Hypothesis for curves over finite fields. Following are its definition and properties: Definition 13 Given an elliptic curve C and a non-negative integer N there is a unique function e N defined on points of exponent N (P is of exponent N if NP = 0, it is of order N if N is an exponent and no smaller integer is). It has the following properties: 1. e N (P, Q) is an N-th root of unity. 2. Skew-symmetry: e N (P, Q) = e N (Q, P )sup 1 3. Linearity: e N (P + R, Q) = e N (P, Q)e N (R, Q) 4. Non-degeneracy: Given a point P of order N there is a point Q of order N such that e N (P, Q) 1. 4

5 This pairing may be defined as follows (see [Lan73, pages ]): If A is a divisor of order N in the divisor class group D 0 /D l, then there is a function f A such that (f A ) = NA. This function is defined up to multiplication by a constant. If f is any function, and A = P a P (P ) is a divisor of degree 0, then we define f(a) = P f(p )ap. Note that this depends only on (f). If P and Q are points of exponent N, define f P and f Q as above. Then e N (P, Q) = f A (B)/f B (A) where A (P ) (0) and B (Q) (0) and whose support is disjoint. This is independent of the choice of A and B. This yields: Algorithm 2 Calculation of e N pairing Input: 1. An Elliptic Curve E 2. A natural number N 3. Two points P, Q on C of exponent N Output: 1. The value e N (P, Q) Method: First fix an addition chain 1 = a 1,..., a t = N. Now choose T, U points on C at random until T and T + P are distinct from a i U and a i (U + Q) and U and U + Q are distinct from a i T and a i (T + P ) for all i. This choice guarantees that the straight-line programs constructed below are defined at input values used. Set A = (T + P ) (T ) and B = (U + Q) (Q). Use 1 to construct straight-line programs for the functions f A and f B. Now the number of pairs (T, U) which do not satisfy the two conditions above is 8tN p where N p is the total number of points on the curve in GF (p). Because there always is an addition chain with t 2 lg N we see that when N 256 that the probability of success is gt1/2. We then set e N (P, Q) = f A(U + Q)f B (T ) f B (T + P )f A (U) If one is willing to work a little harder, a deterministic algorithm for the Weil pairing with the same running time as above may be obtained. The main idea is to modify the straight line program to give the value of the function at all points. The program will no longer be straight-line, but will be allowed to have case statements. One handles zeroes and poles by representing the value there by a pair (α, n) with the property that α 0 and that the Laurent series of the function at the point P starts with αu n where u is a uniformizer at P. Such functions may be multiplied without any problems: one multiplies their α s and adds their n s. If one uses this representation it is possible to dispense with the usual restriction that the divisors A and B above have disjoint supports. 5

6 One application of the e N pairing is to give a partial answer to a question raised by Schoof [Sch85]. In that paper, Schoof gives a determinstic algorithm, polynomial in lg p for calculating the exact order of the group of points on an elliptic curve mod p. He points out that he does not determine the structure of the underlying group. It is known that this group is always either cyclic, or the product of two cyclic groups of orders d and e where d e. I give a random algorithm which runs in expected time polynomial in lg p if the factorization of gcd(p 1, N) is known, where N is the order computed by Schoof s algorithm. Algorithm 3 1. Calculate N p = N 0 N 1 where gcd(n 0, N 1 ) = 1, and the set of prime divisors of N 0 is the same as the set of prime divisors of gcd(p 1, N p ). 2. Using the Euclidean Algorithm find α and β such that αn 0 + βn 1 = Pick two points P, Q on the curve C, and set P = βn 1 P, Q = βn 1 Q. 4. Find the exact order of P and Q (this is where we need the factorization). Say they are m and n. 5. Set r = lcm(m, n). 6. Set a = e r (P, Q) 7. Find the exact order of a. Say it s s. 8. If rs = N then stop, the orders of the two groups are r and s. 9. If not go to step 3. The analysis of the algorithm depends on the non-degeneracy of e N, and its skew-symmetry. The probability of failure in the last step is O(lg lg 1 p). References [Dav79] James H. Davenport. On the Integration of Algebraic Functions, volume 102 of Lecture Notes in Computer Science. Springer-Verlag, Berlin, [Ful69] William Fulton. Algebraic Curves. W. A. Benjamin, Inc., New York, [Kal85] Erich Kaltofen. Computing with polynomials given by straight-line programs i; greatest common divisors. In Proc. 17th ACM Symp. Theory Comp., pages ACM Press, [Lan73] Serge Lang. Elliptic Functions. Addison-Wesley, Reading,

7 [Sch85] R. Schoof. Elliptic curves over finite fields and the computation of square roots mod p. Math. Comp., pages , [Wei46] Andre Weil. Sur les fonctions algebriques a corps de constantes fini. C. R. Academie des Sciences,

### Breaking The Code. Ryan Lowe. Ryan Lowe is currently a Ball State senior with a double major in Computer Science and Mathematics and

Breaking The Code Ryan Lowe Ryan Lowe is currently a Ball State senior with a double major in Computer Science and Mathematics and a minor in Applied Physics. As a sophomore, he took an independent study

### 7. Some irreducible polynomials

7. Some irreducible polynomials 7.1 Irreducibles over a finite field 7.2 Worked examples Linear factors x α of a polynomial P (x) with coefficients in a field k correspond precisely to roots α k [1] of

### Faster Cryptographic Key Exchange on Hyperelliptic Curves

Faster Cryptographic Key Exchange on Hyperelliptic Curves No Author Given No Institute Given Abstract. We present a key exchange procedure based on divisor arithmetic for the real model of a hyperelliptic

### CHAPTER SIX IRREDUCIBILITY AND FACTORIZATION 1. BASIC DIVISIBILITY THEORY

January 10, 2010 CHAPTER SIX IRREDUCIBILITY AND FACTORIZATION 1. BASIC DIVISIBILITY THEORY The set of polynomials over a field F is a ring, whose structure shares with the ring of integers many characteristics.

### Quotient Rings and Field Extensions

Chapter 5 Quotient Rings and Field Extensions In this chapter we describe a method for producing field extension of a given field. If F is a field, then a field extension is a field K that contains F.

### minimal polyonomial Example

Minimal Polynomials Definition Let α be an element in GF(p e ). We call the monic polynomial of smallest degree which has coefficients in GF(p) and α as a root, the minimal polyonomial of α. Example: We

### Introduction to Finite Fields (cont.)

Chapter 6 Introduction to Finite Fields (cont.) 6.1 Recall Theorem. Z m is a field m is a prime number. Theorem (Subfield Isomorphic to Z p ). Every finite field has the order of a power of a prime number

### Mathematics Course 111: Algebra I Part IV: Vector Spaces

Mathematics Course 111: Algebra I Part IV: Vector Spaces D. R. Wilkins Academic Year 1996-7 9 Vector Spaces A vector space over some field K is an algebraic structure consisting of a set V on which are

### LOW-DEGREE PLANAR MONOMIALS IN CHARACTERISTIC TWO

LOW-DEGREE PLANAR MONOMIALS IN CHARACTERISTIC TWO PETER MÜLLER AND MICHAEL E. ZIEVE Abstract. Planar functions over finite fields give rise to finite projective planes and other combinatorial objects.

### FACTORING POLYNOMIALS IN THE RING OF FORMAL POWER SERIES OVER Z

FACTORING POLYNOMIALS IN THE RING OF FORMAL POWER SERIES OVER Z DANIEL BIRMAJER, JUAN B GIL, AND MICHAEL WEINER Abstract We consider polynomials with integer coefficients and discuss their factorization

### Integer Factorization using the Quadratic Sieve

Integer Factorization using the Quadratic Sieve Chad Seibert* Division of Science and Mathematics University of Minnesota, Morris Morris, MN 56567 seib0060@morris.umn.edu March 16, 2011 Abstract We give

### Continued Fractions and the Euclidean Algorithm

Continued Fractions and the Euclidean Algorithm Lecture notes prepared for MATH 326, Spring 997 Department of Mathematics and Statistics University at Albany William F Hammond Table of Contents Introduction

### JUST THE MATHS UNIT NUMBER 1.8. ALGEBRA 8 (Polynomials) A.J.Hobson

JUST THE MATHS UNIT NUMBER 1.8 ALGEBRA 8 (Polynomials) by A.J.Hobson 1.8.1 The factor theorem 1.8.2 Application to quadratic and cubic expressions 1.8.3 Cubic equations 1.8.4 Long division of polynomials

### Galois Fields and Hardware Design

Galois Fields and Hardware Design Construction of Galois Fields, Basic Properties, Uniqueness, Containment, Closure, Polynomial Functions over Galois Fields Priyank Kalla Associate Professor Electrical

### International Journal of Information Technology, Modeling and Computing (IJITMC) Vol.1, No.3,August 2013

FACTORING CRYPTOSYSTEM MODULI WHEN THE CO-FACTORS DIFFERENCE IS BOUNDED Omar Akchiche 1 and Omar Khadir 2 1,2 Laboratory of Mathematics, Cryptography and Mechanics, Fstm, University of Hassan II Mohammedia-Casablanca,

### U.C. Berkeley CS276: Cryptography Handout 0.1 Luca Trevisan January, 2009. Notes on Algebra

U.C. Berkeley CS276: Cryptography Handout 0.1 Luca Trevisan January, 2009 Notes on Algebra These notes contain as little theory as possible, and most results are stated without proof. Any introductory

### Chapter 4, Arithmetic in F [x] Polynomial arithmetic and the division algorithm.

Chapter 4, Arithmetic in F [x] Polynomial arithmetic and the division algorithm. We begin by defining the ring of polynomials with coefficients in a ring R. After some preliminary results, we specialize

### An Overview of Integer Factoring Algorithms. The Problem

An Overview of Integer Factoring Algorithms Manindra Agrawal IITK / NUS The Problem Given an integer n, find all its prime divisors as efficiently as possible. 1 A Difficult Problem No efficient algorithm

### OSTROWSKI FOR NUMBER FIELDS

OSTROWSKI FOR NUMBER FIELDS KEITH CONRAD Ostrowski classified the nontrivial absolute values on Q: up to equivalence, they are the usual (archimedean) absolute value and the p-adic absolute values for

### Mathematics Review for MS Finance Students

Mathematics Review for MS Finance Students Anthony M. Marino Department of Finance and Business Economics Marshall School of Business Lecture 1: Introductory Material Sets The Real Number System Functions,

### Copy in your notebook: Add an example of each term with the symbols used in algebra 2 if there are any.

Algebra 2 - Chapter Prerequisites Vocabulary Copy in your notebook: Add an example of each term with the symbols used in algebra 2 if there are any. P1 p. 1 1. counting(natural) numbers - {1,2,3,4,...}

### Math Review. for the Quantitative Reasoning Measure of the GRE revised General Test

Math Review for the Quantitative Reasoning Measure of the GRE revised General Test www.ets.org Overview This Math Review will familiarize you with the mathematical skills and concepts that are important

### a 1 x + a 0 =0. (3) ax 2 + bx + c =0. (4)

ROOTS OF POLYNOMIAL EQUATIONS In this unit we discuss polynomial equations. A polynomial in x of degree n, where n 0 is an integer, is an expression of the form P n (x) =a n x n + a n 1 x n 1 + + a 1 x

### Elementary Number Theory We begin with a bit of elementary number theory, which is concerned

CONSTRUCTION OF THE FINITE FIELDS Z p S. R. DOTY Elementary Number Theory We begin with a bit of elementary number theory, which is concerned solely with questions about the set of integers Z = {0, ±1,

PYTHAGOREAN TRIPLES KEITH CONRAD 1. Introduction A Pythagorean triple is a triple of positive integers (a, b, c) where a + b = c. Examples include (3, 4, 5), (5, 1, 13), and (8, 15, 17). Below is an ancient

### 4. Factor polynomials over complex numbers, describe geometrically, and apply to real-world situations. 5. Determine and apply relationships among syn

I The Real and Complex Number Systems 1. Identify subsets of complex numbers, and compare their structural characteristics. 2. Compare and contrast the properties of real numbers with the properties of

### Appendix A. Appendix. A.1 Algebra. Fields and Rings

Appendix A Appendix A.1 Algebra Algebra is the foundation of algebraic geometry; here we collect some of the basic algebra on which we rely. We develop some algebraic background that is needed in the text.

### On the floor and the ceiling of a divisor

On the floor and the ceiling of a divisor Hiren Maharaj and Gretchen L. Matthews 1 Department of Mathematical Sciences Clemson University Clemson, SC 29634-0975 USA Abstract Given a divisor A of a function

### Integer roots of quadratic and cubic polynomials with integer coefficients

Integer roots of quadratic and cubic polynomials with integer coefficients Konstantine Zelator Mathematics, Computer Science and Statistics 212 Ben Franklin Hall Bloomsburg University 400 East Second Street

### Math 345-60 Abstract Algebra I Questions for Section 23: Factoring Polynomials over a Field

Math 345-60 Abstract Algebra I Questions for Section 23: Factoring Polynomials over a Field 1. Throughout this section, F is a field and F [x] is the ring of polynomials with coefficients in F. We will

### The Dirichlet Unit Theorem

Chapter 6 The Dirichlet Unit Theorem As usual, we will be working in the ring B of algebraic integers of a number field L. Two factorizations of an element of B are regarded as essentially the same if

### Factoring Polynomials

Factoring Polynomials Sue Geller June 19, 2006 Factoring polynomials over the rational numbers, real numbers, and complex numbers has long been a standard topic of high school algebra. With the advent

### Interpolating Polynomials Handout March 7, 2012

Interpolating Polynomials Handout March 7, 212 Again we work over our favorite field F (such as R, Q, C or F p ) We wish to find a polynomial y = f(x) passing through n specified data points (x 1,y 1 ),

### ABSTRACT ALGEBRA: A STUDY GUIDE FOR BEGINNERS

ABSTRACT ALGEBRA: A STUDY GUIDE FOR BEGINNERS John A. Beachy Northern Illinois University 2014 ii J.A.Beachy This is a supplement to Abstract Algebra, Third Edition by John A. Beachy and William D. Blair

### Unique Factorization

Unique Factorization Waffle Mathcamp 2010 Throughout these notes, all rings will be assumed to be commutative. 1 Factorization in domains: definitions and examples In this class, we will study the phenomenon

### CONTINUED FRACTIONS AND PELL S EQUATION. Contents 1. Continued Fractions 1 2. Solution to Pell s Equation 9 References 12

CONTINUED FRACTIONS AND PELL S EQUATION SEUNG HYUN YANG Abstract. In this REU paper, I will use some important characteristics of continued fractions to give the complete set of solutions to Pell s equation.

### Algebra Unpacked Content For the new Common Core standards that will be effective in all North Carolina schools in the 2012-13 school year.

This document is designed to help North Carolina educators teach the Common Core (Standard Course of Study). NCDPI staff are continually updating and improving these tools to better serve teachers. Algebra

### Computer Aided Geometric Design. Axial moving planes and singularities of rational space curves

Computer Aided Geometric Design 26 (2009) 300 316 Contents lists available at ScienceDirect Computer Aided Geometric Design www.elsevier.com/locate/cagd Axial moving planes and singularities of rational

### Computer Algebra for Computer Engineers

p.1/14 Computer Algebra for Computer Engineers Preliminaries Priyank Kalla Department of Electrical and Computer Engineering University of Utah, Salt Lake City p.2/14 Notation R: Real Numbers Q: Fractions

### Math 4310 Handout - Quotient Vector Spaces

Math 4310 Handout - Quotient Vector Spaces Dan Collins The textbook defines a subspace of a vector space in Chapter 4, but it avoids ever discussing the notion of a quotient space. This is understandable

### ALGORITHMS FOR ALGEBRAIC CURVES

ALGORITHMS FOR ALGEBRAIC CURVES SUMMARY OF LECTURE 4 1. SCHOOF S ALGORITHM Let K be a finite field with q elements. Let p be its characteristic. Let X be an elliptic curve over K. To simplify we assume

### On the representability of the bi-uniform matroid

On the representability of the bi-uniform matroid Simeon Ball, Carles Padró, Zsuzsa Weiner and Chaoping Xing August 3, 2012 Abstract Every bi-uniform matroid is representable over all sufficiently large

### MOP 2007 Black Group Integer Polynomials Yufei Zhao. Integer Polynomials. June 29, 2007 Yufei Zhao yufeiz@mit.edu

Integer Polynomials June 9, 007 Yufei Zhao yufeiz@mit.edu We will use Z[x] to denote the ring of polynomials with integer coefficients. We begin by summarizing some of the common approaches used in dealing

### Introduction to finite fields

Introduction to finite fields Topics in Finite Fields (Fall 2013) Rutgers University Swastik Kopparty Last modified: Monday 16 th September, 2013 Welcome to the course on finite fields! This is aimed at

### ARITHMETIC PROGRESSIONS OF FOUR SQUARES

ARITHMETIC PROGRESSIONS OF FOUR SQUARES KEITH CONRAD 1. Introduction Suppose a, b, c, and d are rational numbers such that a 2, b 2, c 2, and d 2 form an arithmetic progression: the differences b 2 a 2,

### Computing divisors and common multiples of quasi-linear ordinary differential equations

Computing divisors and common multiples of quasi-linear ordinary differential equations Dima Grigoriev CNRS, Mathématiques, Université de Lille Villeneuve d Ascq, 59655, France Dmitry.Grigoryev@math.univ-lille1.fr

### MATH 423 Linear Algebra II Lecture 38: Generalized eigenvectors. Jordan canonical form (continued).

MATH 423 Linear Algebra II Lecture 38: Generalized eigenvectors Jordan canonical form (continued) Jordan canonical form A Jordan block is a square matrix of the form λ 1 0 0 0 0 λ 1 0 0 0 0 λ 0 0 J = 0

MA 134 Lecture Notes August 20, 2012 Introduction The purpose of this lecture is to... Introduction The purpose of this lecture is to... Learn about different types of equations Introduction The purpose

### MATH 304 Linear Algebra Lecture 16: Basis and dimension.

MATH 304 Linear Algebra Lecture 16: Basis and dimension. Basis Definition. Let V be a vector space. A linearly independent spanning set for V is called a basis. Equivalently, a subset S V is a basis for

### Factorization Methods: Very Quick Overview

Factorization Methods: Very Quick Overview Yuval Filmus October 17, 2012 1 Introduction In this lecture we introduce modern factorization methods. We will assume several facts from analytic number theory.

### ECE 842 Report Implementation of Elliptic Curve Cryptography

ECE 842 Report Implementation of Elliptic Curve Cryptography Wei-Yang Lin December 15, 2004 Abstract The aim of this report is to illustrate the issues in implementing a practical elliptic curve cryptographic

### IRREDUCIBLE OPERATOR SEMIGROUPS SUCH THAT AB AND BA ARE PROPORTIONAL. 1. Introduction

IRREDUCIBLE OPERATOR SEMIGROUPS SUCH THAT AB AND BA ARE PROPORTIONAL R. DRNOVŠEK, T. KOŠIR Dedicated to Prof. Heydar Radjavi on the occasion of his seventieth birthday. Abstract. Let S be an irreducible

### On the generation of elliptic curves with 16 rational torsion points by Pythagorean triples

On the generation of elliptic curves with 16 rational torsion points by Pythagorean triples Brian Hilley Boston College MT695 Honors Seminar March 3, 2006 1 Introduction 1.1 Mazur s Theorem Let C be a

### Some facts about polynomials modulo m (Full proof of the Fingerprinting Theorem)

Some facts about polynomials modulo m (Full proof of the Fingerprinting Theorem) In order to understand the details of the Fingerprinting Theorem on fingerprints of different texts from Chapter 19 of the

### Factoring & Primality

Factoring & Primality Lecturer: Dimitris Papadopoulos In this lecture we will discuss the problem of integer factorization and primality testing, two problems that have been the focus of a great amount

### HOMEWORK 5 SOLUTIONS. n!f n (1) lim. ln x n! + xn x. 1 = G n 1 (x). (2) k + 1 n. (n 1)!

Math 7 Fall 205 HOMEWORK 5 SOLUTIONS Problem. 2008 B2 Let F 0 x = ln x. For n 0 and x > 0, let F n+ x = 0 F ntdt. Evaluate n!f n lim n ln n. By directly computing F n x for small n s, we obtain the following

### 1 VECTOR SPACES AND SUBSPACES

1 VECTOR SPACES AND SUBSPACES What is a vector? Many are familiar with the concept of a vector as: Something which has magnitude and direction. an ordered pair or triple. a description for quantities such

### ON THE FIBONACCI NUMBERS

ON THE FIBONACCI NUMBERS Prepared by Kei Nakamura The Fibonacci numbers are terms of the sequence defined in a quite simple recursive fashion. However, despite its simplicity, they have some curious properties

### Factoring Algorithms

Factoring Algorithms The p 1 Method and Quadratic Sieve November 17, 2008 () Factoring Algorithms November 17, 2008 1 / 12 Fermat s factoring method Fermat made the observation that if n has two factors

### Module MA3411: Abstract Algebra Galois Theory Appendix Michaelmas Term 2013

Module MA3411: Abstract Algebra Galois Theory Appendix Michaelmas Term 2013 D. R. Wilkins Copyright c David R. Wilkins 1997 2013 Contents A Cyclotomic Polynomials 79 A.1 Minimum Polynomials of Roots of

### MATH10040 Chapter 2: Prime and relatively prime numbers

MATH10040 Chapter 2: Prime and relatively prime numbers Recall the basic definition: 1. Prime numbers Definition 1.1. Recall that a positive integer is said to be prime if it has precisely two positive

### Basics of Polynomial Theory

3 Basics of Polynomial Theory 3.1 Polynomial Equations In geodesy and geoinformatics, most observations are related to unknowns parameters through equations of algebraic (polynomial) type. In cases where

### SOLVING POLYNOMIAL EQUATIONS

C SOLVING POLYNOMIAL EQUATIONS We will assume in this appendix that you know how to divide polynomials using long division and synthetic division. If you need to review those techniques, refer to an algebra

### Basic Algorithms In Computer Algebra

Basic Algorithms In Computer Algebra Kaiserslautern SS 2011 Prof. Dr. Wolfram Decker 2. Mai 2011 References Cohen, H.: A Course in Computational Algebraic Number Theory. Springer, 1993. Cox, D.; Little,

### Factorization Algorithms for Polynomials over Finite Fields

Degree Project Factorization Algorithms for Polynomials over Finite Fields Sajid Hanif, Muhammad Imran 2011-05-03 Subject: Mathematics Level: Master Course code: 4MA11E Abstract Integer factorization is

### MATH 289 PROBLEM SET 4: NUMBER THEORY

MATH 289 PROBLEM SET 4: NUMBER THEORY 1. The greatest common divisor If d and n are integers, then we say that d divides n if and only if there exists an integer q such that n = qd. Notice that if d divides

### Infinite Algebra 1 supports the teaching of the Common Core State Standards listed below.

Infinite Algebra 1 Kuta Software LLC Common Core Alignment Software version 2.05 Last revised July 2015 Infinite Algebra 1 supports the teaching of the Common Core State Standards listed below. High School

### APPLICATIONS OF THE ORDER FUNCTION

APPLICATIONS OF THE ORDER FUNCTION LECTURE NOTES: MATH 432, CSUSM, SPRING 2009. PROF. WAYNE AITKEN In this lecture we will explore several applications of order functions including formulas for GCDs and

### Lecture 13 - Basic Number Theory.

Lecture 13 - Basic Number Theory. Boaz Barak March 22, 2010 Divisibility and primes Unless mentioned otherwise throughout this lecture all numbers are non-negative integers. We say that A divides B, denoted

### Algebra 2 Chapter 1 Vocabulary. identity - A statement that equates two equivalent expressions.

Chapter 1 Vocabulary identity - A statement that equates two equivalent expressions. verbal model- A word equation that represents a real-life problem. algebraic expression - An expression with variables.

### THE NUMBER OF REPRESENTATIONS OF n OF THE FORM n = x 2 2 y, x > 0, y 0

THE NUMBER OF REPRESENTATIONS OF n OF THE FORM n = x 2 2 y, x > 0, y 0 RICHARD J. MATHAR Abstract. We count solutions to the Ramanujan-Nagell equation 2 y +n = x 2 for fixed positive n. The computational

### SECRET sharing schemes were introduced by Blakley [5]

206 IEEE TRANSACTIONS ON INFORMATION THEORY, VOL. 52, NO. 1, JANUARY 2006 Secret Sharing Schemes From Three Classes of Linear Codes Jin Yuan Cunsheng Ding, Senior Member, IEEE Abstract Secret sharing has

### Copyrighted Material. Chapter 1 DEGREE OF A CURVE

Chapter 1 DEGREE OF A CURVE Road Map The idea of degree is a fundamental concept, which will take us several chapters to explore in depth. We begin by explaining what an algebraic curve is, and offer two

### FOUNDATIONS OF ALGEBRAIC GEOMETRY CLASS 22

FOUNDATIONS OF ALGEBRAIC GEOMETRY CLASS 22 RAVI VAKIL CONTENTS 1. Discrete valuation rings: Dimension 1 Noetherian regular local rings 1 Last day, we discussed the Zariski tangent space, and saw that it

### ARITHMETICAL FUNCTIONS II: CONVOLUTION AND INVERSION

ARITHMETICAL FUNCTIONS II: CONVOLUTION AND INVERSION PETE L. CLARK 1. Sums over divisors, convolution and Möbius Inversion The proof of the multiplicativity of the functions σ k, easy though it was, actually

### Notes 11: List Decoding Folded Reed-Solomon Codes

Introduction to Coding Theory CMU: Spring 2010 Notes 11: List Decoding Folded Reed-Solomon Codes April 2010 Lecturer: Venkatesan Guruswami Scribe: Venkatesan Guruswami At the end of the previous notes,

### MTH 06 LECTURE NOTES (Ojakian) Topic 2: Functions

MTH 06 LECTURE NOTES (Ojakian) Topic 2: Functions OUTLINE (References: Iyer Textbook - pages 4,6,17,18,40,79,80,81,82,103,104,109,110) 1. Definition of Function and Function Notation 2. Domain and Range

### Elliptic Curve Cryptography

Elliptic Curve Cryptography Elaine Brow, December 2010 Math 189A: Algebraic Geometry 1. Introduction to Public Key Cryptography To understand the motivation for elliptic curve cryptography, we must first

### Polynomials can be added or subtracted simply by adding or subtracting the corresponding terms, e.g., if

1. Polynomials 1.1. Definitions A polynomial in x is an expression obtained by taking powers of x, multiplying them by constants, and adding them. It can be written in the form c 0 x n + c 1 x n 1 + c

### PROBLEM SET 6: POLYNOMIALS

PROBLEM SET 6: POLYNOMIALS 1. introduction In this problem set we will consider polynomials with coefficients in K, where K is the real numbers R, the complex numbers C, the rational numbers Q or any other

### 3 Congruence arithmetic

3 Congruence arithmetic 3.1 Congruence mod n As we said before, one of the most basic tasks in number theory is to factor a number a. How do we do this? We start with smaller numbers and see if they divide

### STUDY GUIDE FOR SOME BASIC INTERMEDIATE ALGEBRA SKILLS

STUDY GUIDE FOR SOME BASIC INTERMEDIATE ALGEBRA SKILLS The intermediate algebra skills illustrated here will be used extensively and regularly throughout the semester Thus, mastering these skills is an

### Introduction to Algebraic Geometry. Bézout s Theorem and Inflection Points

Introduction to Algebraic Geometry Bézout s Theorem and Inflection Points 1. The resultant. Let K be a field. Then the polynomial ring K[x] is a unique factorisation domain (UFD). Another example of a

### A One Round Protocol for Tripartite

A One Round Protocol for Tripartite Diffie Hellman Antoine Joux SCSSI, 18, rue du Dr. Zamenhoff F-92131 Issy-les-Mx Cedex, France Antoine.Joux@ens.fr Abstract. In this paper, we propose a three participants

### Math 115 Spring 2014 Written Homework 3 Due Wednesday, February 19

Math 11 Spring 01 Written Homework 3 Due Wednesday, February 19 Instructions: Write complete solutions on separate paper (not spiral bound). If multiple pieces of paper are used, they must be stapled with

### Factorization in Polynomial Rings

Factorization in Polynomial Rings These notes are a summary of some of the important points on divisibility in polynomial rings from 17 and 18 of Gallian s Contemporary Abstract Algebra. Most of the important

### Text: A Graphical Approach to College Algebra (Hornsby, Lial, Rockswold)

Students will take Self Tests covering the topics found in Chapter R (Reference: Basic Algebraic Concepts) and Chapter 1 (Linear Functions, Equations, and Inequalities). If any deficiencies are revealed,

### The degree of a polynomial function is equal to the highest exponent found on the independent variables.

DETAILED SOLUTIONS AND CONCEPTS - POLYNOMIAL FUNCTIONS Prepared by Ingrid Stewart, Ph.D., College of Southern Nevada Please Send Questions and Comments to ingrid.stewart@csn.edu. Thank you! PLEASE NOTE

### ELLIPTIC CURVES AND LENSTRA S FACTORIZATION ALGORITHM

ELLIPTIC CURVES AND LENSTRA S FACTORIZATION ALGORITHM DANIEL PARKER Abstract. This paper provides a foundation for understanding Lenstra s Elliptic Curve Algorithm for factoring large numbers. We give

### Lecture 14: Section 3.3

Lecture 14: Section 3.3 Shuanglin Shao October 23, 2013 Definition. Two nonzero vectors u and v in R n are said to be orthogonal (or perpendicular) if u v = 0. We will also agree that the zero vector in

### Review: Vector space

Math 2F Linear Algebra Lecture 13 1 Basis and dimensions Slide 1 Review: Subspace of a vector space. (Sec. 4.1) Linear combinations, l.d., l.i. vectors. (Sec. 4.3) Dimension and Base of a vector space.

### 3 1. Note that all cubes solve it; therefore, there are no more

Math 13 Problem set 5 Artin 11.4.7 Factor the following polynomials into irreducible factors in Q[x]: (a) x 3 3x (b) x 3 3x + (c) x 9 6x 6 + 9x 3 3 Solution: The first two polynomials are cubics, so if

### arxiv: v1 [math.ag] 12 Sep 2009

arxiv:0909.2304v1 [math.ag] 12 Sep 2009 A Few More Functions That Are Not APN Infinitely Often Yves Aubry Institut de Mathématiques de Toulon Université du Sud Toulon-Var France Gary McGuire School of

### 2.5 Complex Eigenvalues

1 25 Complex Eigenvalues Real Canonical Form A semisimple matrix with complex conjugate eigenvalues can be diagonalized using the procedure previously described However, the eigenvectors corresponding

### Math 319 Problem Set #3 Solution 21 February 2002

Math 319 Problem Set #3 Solution 21 February 2002 1. ( 2.1, problem 15) Find integers a 1, a 2, a 3, a 4, a 5 such that every integer x satisfies at least one of the congruences x a 1 (mod 2), x a 2 (mod

### 9 More on differentiation

Tel Aviv University, 2013 Measure and category 75 9 More on differentiation 9a Finite Taylor expansion............... 75 9b Continuous and nowhere differentiable..... 78 9c Differentiable and nowhere monotone......

### Monogenic Fields and Power Bases Michael Decker 12/07/07

Monogenic Fields and Power Bases Michael Decker 12/07/07 1 Introduction Let K be a number field of degree k and O K its ring of integers Then considering O K as a Z-module, the nicest possible case is

### Subsets of Euclidean domains possessing a unique division algorithm

Subsets of Euclidean domains possessing a unique division algorithm Andrew D. Lewis 2009/03/16 Abstract Subsets of a Euclidean domain are characterised with the following objectives: (1) ensuring uniqueness