Re: Multiplicative Homomorphic Mapping
- From: "Aldar C-F. Chan" <aldar@xxxxxxxxxxxxxxxx>
- Date: Mon, 22 Aug 2005 11:08:51 GMT
"Gerry Myerson" <gerry@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:gerry-E32158.14204822082005@xxxxxxxxxxxxxxxxxxxxx
> g generates G, h generates H, a is in G, so a = g^x for some (very
> hard to calculate) x, you want to know h^x; I don't see how you're
> going to get it without getting x first, or anyway doing as much
> work as it would take to get x. Do you have any reason to think
> otherwise?
>
> --
> Gerry Myerson (gerry@xxxxxxxxxxxxxxx) (i -> u for email)
I am not sure if I understand the difficulty of this problem well enough.
Given g^x for unknown x, I don't see why finding h^x has to be as
difficult as finding x. At the very least, given an algorithm doing so,
it appears that the DL problem cannot be solved.
I am not sure if the following could be possible counterexample:
Suppose G is a supersingular elliptic over F_p with a non-degenerate
pairing to F_p^l, let P in G be a subgroup of order q (call it S_1), then
the pairing e(P,P) is a generator of a subgroup in F_p^l (call it S_2)
of the same order.
Given xP in S_1, we can find e(P,P)^x = e(xP,P).
This is a very special instance and what I want to find is other more
general
instances.
.
- Follow-Ups:
- Re: Multiplicative Homomorphic Mapping
- From: Jyrki Lahtonen
- Re: Multiplicative Homomorphic Mapping
- From: Gerry Myerson
- Re: Multiplicative Homomorphic Mapping
- References:
- Multiplicative Homomorphic Mapping
- From: Aldar C-F. Chan
- Re: Multiplicative Homomorphic Mapping
- From: Gerry Myerson
- Re: Multiplicative Homomorphic Mapping
- From: Aldar C-F. Chan
- Re: Multiplicative Homomorphic Mapping
- From: Gerry Myerson
- Multiplicative Homomorphic Mapping
- Prev by Date: Re: infinity
- Next by Date: Re: Field Norm
- Previous by thread: Re: Multiplicative Homomorphic Mapping
- Next by thread: Re: Multiplicative Homomorphic Mapping
- Index(es):
Relevant Pages
|