The relationship between breaking the Diffie-Hellman protocol and computing discrete logarithms
The relationship between breaking the Diffie-Hellman protocol and computing discrete logarithms
复制标题
DOI:
10.1137/s0097539796302749
复制
发表时间:
1999-05-26
影响因子:
1.6
通讯作者:
Wolf, S
中科院分区:
文献类型:
--
作者:
Maurer, UM;Wolf, S
Both uniform and nonuniform results concerning the security of the Diffie-Hellman key-exchange protocol are proved. First, it is shown that in a cyclic group G of order \G\ = Pi p(i)(ei), where all the multiple prime factors of \G\ are polynomial in log \G\, there exists an algorithm that reduces the computation of discrete logarithms in G to breaking the Diffie-Hellman protocol in G and has complexity root max{nu(p(i))}.(log\G\)(O(1)), where nu(p) stands for the minimum of the set of largest prime factors of all the numbers d in the interval [p - 2 root p + 1; p + 2 root p + 1]. Under the unproven but plausible assumption that nu(p) is polynomial in log p, this reduction implies that the Diffie-Hellman problem and the discrete logarithm problem are polynomial-time equivalent in G. Second, it is proved that the Diffie-Hellman problem and the discrete logarithm problem are equivalent in a uniform sense for groups whose orders belong to certain classes: there exists a polynomial-time reduction algorithm that works for all those groups. Moreover, it is shown that breaking the Diffie-Hellman protocol for a small but nonnegligible fraction of the instances is equally difficult as breaking it for all instances. Finally, efficient constructions of groups are described for which the algorithm reducing the discrete logarithm problem to the Diffie-Hellman problem is efficiently constructible.