10.12.2012 Views

Prime Numbers

Prime Numbers

Prime Numbers

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

7.8 Research problems 385<br />

is prime.<br />

For more information on “rapid” primality proofs, see [Pomerance 1987a]<br />

and the discussion in [Williams 1998, p. 366] in regard to numbers of certain<br />

ternary form.<br />

7.34. An interesting problem one may address after having found a factor<br />

via an ECM scheme such as Algorithm 7.4.4 is this: What is the actual group<br />

order that allowed the factor discovery?<br />

One approach, which has been used in [Brent et al. 2000], is simply to<br />

“backtrack” on the stage limits until the precise largest- and second-largest<br />

primes are found, and so on until the group order is completely factored.<br />

But another way is simply to obtain, via Algorithm 7.5.6, say, the actual<br />

order. To this end, work out the preparatory curve algebra as follows. First,<br />

show that if a curve is constructed according to Theorem 7.4.3, then the<br />

rational initial point x/z = u 3 /v 3 satisfies<br />

x 3 + Cx 2 z + xz 2 = σ 2 − 5 3 125 − 105σ 2 − 21σ 4 + σ 6 2<br />

in the ring. Then deduce that the order of the curve is either the order of<br />

y 2 = x 3 + ax + b,<br />

or the order of the twist, depending respectively on whether ( σ3−5σ p )=1or<br />

−1, where affine parameters a, b are computed from<br />

γ = (v − u)3 (3u + v)<br />

4u 3 v<br />

a =1− 1<br />

3 γ2 ,<br />

b = 2<br />

27 γ3 − 1<br />

3 γ.<br />

− 2,<br />

These machinations suggest a straightforward algorithm for finding the order<br />

of the curve that discovered a factor p. Namely, one uses the starting seed σ,<br />

calculates again if necessary the u, v field parameters, then applies the above<br />

formulae to get an affine curve parameter pair (a, b),whichinturncanbe<br />

used directly in the Schoof algorithm.<br />

Here is an explicit example of the workings of this method. The McIntosh–<br />

Tardif factor<br />

p = 81274690703860512587777<br />

of F18 was found with seed parameter σ = 16500076. One finds with the above<br />

formulae that<br />

a = 26882295688729303004012,<br />

b = 10541033639146374421403,

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!