10.12.2012 Views

Prime Numbers

Prime Numbers

Prime Numbers

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

7.7 Exercises 377<br />

(some Bj equals Ai). Give the computational complexity of this polynomial<br />

method for finding A ∩ B. How does one handle duplicate matches in this<br />

polynomial setting? Note the related material in Sections 5.5, 9.6.3.<br />

7.14. By analyzing the trend of “record” ECM factorizations, estimate in<br />

what calendar year we shall be able to discover 70-digit factors via ECM.<br />

([Zimmermann 2000] has projected the year 2010, for example.)<br />

7.15. Verify claims made in reference to Algorithm 7.5.10, as follows. First,<br />

show how the tabulated parameters r, s were obtained. For this, one uses the<br />

fact of the class polynomial being at most quadratic, and notes also that a<br />

defining cubic y 2 = x 3 + Rx/S + T/S can be cleared of denominator S by<br />

multiplying through by S 6 . Second, use quadratic reciprocity to prove that<br />

every explicit square root in the tabulated parameters does, in fact, exist. For<br />

this, one presumes that a representation 4p = u 2 +|D|v 2 has been found for p.<br />

Third, show that 4a 3 +27b 2 cannot vanish (mod p). This could be done case<br />

by case, but it is easier to go back to Algorithm 7.5.9 and see how the final a, b<br />

parameters actually arise. Finally, factor the s values of the tabulated data<br />

to verify that they tend to be highly smooth. How can this smoothness be<br />

explained?<br />

7.16. Recall that for elliptic curve Ea,b(Fp) atwistcurveE ′ of E is governed<br />

by a cubic<br />

y 2 = x 3 + g 2 ax + g 3 b,<br />

where g<br />

p = −1. Show that the curve orders are related thus:<br />

#E +#E ′ =2p +2.<br />

7.17. Suppose the largest order of an element in a finite abelian group G is<br />

m. Show there is an absolute constant c>0 (that is, c does not depend on<br />

m or G) such that the proportion of elements of G with order m is at least<br />

c/ ln ln(3m). (The presence of the factor 3 is only to ensure that the double<br />

log is positive.) This result is relevant to the comments following Theorem<br />

7.5.2 and also to some results in Chapter 3.<br />

7.18. Consider, for p = 229, the curves E,E ′ over Fp governed respectively<br />

by<br />

y 2 = x 3 − 1,<br />

y 2 = x 3 − 8,<br />

the latter being a twist curve of the former. Show that #E = 252, #E ′ = 208<br />

with respective group structures<br />

E ∼ = Z42 × Z6,<br />

E ′ ∼ = Z52 × Z4.<br />

Argue thus that every point P ∈ E has [252]P = [210]P = O, and similarly<br />

every point P ∈ E ′ has [208]P = [260]P = O, and therefore that for any point

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!