Re: Do Gap-CDH groups exist?



jiangwu.m...@xxxxxxxxx wrote:
Can you give some evidence/intuition behind this conclusion?
No direct evidence. But all the papers I read on the relation between
DLP and CDH are trying to find equivalence, instead of gap.

If the security of protocols is based on CDH then it is reasonable to
*try* to reduce DL to CDH. On the other hand, for certain groups, it is
known that DL =/=> CDH so there is no point in trying to prove the
equivalence in those groups because there is none.

.



Relevant Pages

  • Re: Do Gap-CDH groups exist?
    ... DLP and CDH are trying to find equivalence, instead of gap. ...
    (sci.crypt)
  • Re: about a (possible) hard problem
    ... >> Your problem is equivalent to CDH. ... >Maybe you mean the Discrete Logorithm problem (DLP, given g, g^x to ... I refer to the paper "The Decision Diffie-Hellman Problem" by Dan ...
    (sci.crypt)
  • a problem combined with DLP and CDH
    ... g is a generator of Z^*_p where p is a prime, ... CDH: given g^x, g^y, it's intractable to compute g^; ... DLP: given g^z, ... Jiang ...
    (sci.crypt)

Quantcast