Re: DR Reductions

From: Benjamin Goldberg (goldbb2@earthlink.net)
Date: 03/23/03


From: Benjamin Goldberg <goldbb2@earthlink.net>
Date: Sat, 22 Mar 2003 21:39:15 -0500

Tom St Denis wrote:
[snip]
> That is it takes less than half the time to compute!!!
[snip]
> I wonder why DR primes are virtually ignored in crypto though?
> Obviously they're useless for RSA, but they would be ideal for ECC
> and DH....

For primes of certain types of special forms, discrete logarithms are
easier than for arbitrary primes.

Perhaps the form of p needed for DR reduction is such a type?

-- 
$a=24;split//,240513;s/\B/ => /for@@=qw(ac ab bc ba cb ca
);{push(@b,$a),($a-=6)^=1 for 2..$a/6x--$|;print "$@[$a%6
]\n";((6<=($a-=6))?$a+=$_[$a%6]-$a%6:($a=pop @b))&&redo;}


Relevant Pages