8 citations found. Retrieving documents...
K. Sakrai and H. Shizuya, Relationships among the computational powers of breaking discrete log cryptosystems, Advances in Cryptology -- EUROCRYPT '95 , L.C. Guillou and J.-J. Quiswater (Eds.), Springer-Verlag Berlin, 1995.

 Home/Search   Document Not in Database   Summary   Related Articles   Check  

This paper is cited in the following contexts:
On the Difficulty of Breaking the Diffie-Hellman Protocol - Maurer, Wolf (1995)   (Correct)

....for G. The complete equivalence holds for groups such that S is easily constructable. We will also show how to construct DH groups with the property that S is either easily constructable, known to the group designer or at least provably exists. Considerations on related topics can be found in [34] and [21] In the latter, the notion of a black box field is introduced, what makes explicit our concept of hidden computation, presented in [24] 2 The index search problem and methods for computing discrete logarithms Let A be a set with n elements, and let an enumeration of the elements of A, ....

K. Sakrai and H. Shizuya, Relationships among the computational powers of breaking discrete log cryptosystems, Advances in Cryptology -- EUROCRYPT '95 , L.C. Guillou and J.-J. Quiswater (Eds.), Springer-Verlag Berlin, 1995.


On the Complexity of Breaking the Diffie-Hellman Protocol - Maurer, Wolf (1996)   (1 citation)  (Correct)

....Section 6 we show how to construct DH groups with provable equivalence of the DH problem and the discrete logarithm problem, and in Appendix D we obtain a stronger equivalence result under the assumption of DH oracle algorithms for certain groups. Considerations on related topics can be found in [34] and [4] In the latter, the notion of a black box field is introduced which makes more explicit our concept of computation with implicitly represented elements, presented already in [24] 2 The index search problem and methods for computing discrete logarithms Let A = fa 0 ; a n Gamma1 g ....

K. Sakrai and H. Shizuya, Relationships among the computational powers of breaking discrete log cryptosystems, Advances in Cryptology -- EUROCRYPT '95 , L.C. Guillou and J.-J. Quiswater (Eds.), Springer-Verlag Berlin, 1995.


The Relationship Between Breaking the Diffie-Hellman Protocol.. - Maurer, Wolf (1998)   (2 citations)  (Correct)

....that efficient algorithms exist for solving the DH problem in certain groups, and in Appendix D, we show how to construct DH groups for which the DH and DL problems are provably equivalent. 1. 4 Related work Considerations on related topics can be found in [4] 3] 45] 28] 11] 10] and [42]. In [4] the notion of a black box field is introduced which makes more explicit the concept of computation with implicitly represented elements presented in [26] Furthermore, the existence of a uniform reduction of the DL problem to the DH problem of subexponential complexity was proved in [4] ....

....example it was shown that the DH function cannot be interpolated by a low degree polynomial. An alternative construction to that of Section 5 for correcting a faulty oracle solving the DH problem is described in [45] Finally, a comparison of the security of different DL based systems is given in [42]. 2 The index search problem and algorithms for computing discrete logarithms 2.1 The index search and DL problems Let A = a i ) i=1; n Gamma1 be a list of elements of some set S such that for a given i it is easy to compute a i . We call the problem of computing for a given b 2 S an ....

K. Sakurai and H. Shizuya, Relationships among the computational powers of breaking discrete log cryptosystems, Advances in Cryptology - EUROCRYPT '95 , Lecture Notes in Computer Science, Vol. 921, pp. 341--355, Springer-Verlag, 1995.


Rounding in Lattices and Its Cryptographic Applications - Boneh, Venkatesan (1997)   (12 citations)  (Correct)

....a random r and sends y r ; mg r . Bob can decode the message by computing mg r = y r ) x 01 . To break the scheme one has to compute the function EL 0 g (g x ; g xr ; mg r ) m. The equivalence of computing the first three functions above to breaking Diffie Hellman was studied in [9]. The methods of [9] can also be used to show that breaking the modified ElGamal public key system is equivalent to breaking the original ElGamal system. Our non uniform results can be applied to the modified ElGamal public key system and Okamoto s conference key scheme. It is still an open ....

....y r ; mg r . Bob can decode the message by computing mg r = y r ) x 01 . To break the scheme one has to compute the function EL 0 g (g x ; g xr ; mg r ) m. The equivalence of computing the first three functions above to breaking Diffie Hellman was studied in [9] The methods of [9] can also be used to show that breaking the modified ElGamal public key system is equivalent to breaking the original ElGamal system. Our non uniform results can be applied to the modified ElGamal public key system and Okamoto s conference key scheme. It is still an open problem whether the same ....

K. Sakurai, Shizuya H, "Relationships among Computational powers of Breaking Discrete Log Cryptosystems", Eurocrypt 95, pp 341-351.


Searching for Elements in Black Box Fields and Applications - Boneh, Lipton (1996)   (3 citations)  (Correct)

....of the Diffie Hellman function we note that many other cryptographic protocols rely on it for their security. Some examples are the ElGamal public key cryptosystem [15] Shamir s three pass protocol [17, pp. 96 97] and the Bellare Micali non interactive oblivious transfer scheme [6] See [32] for proofs of the equivalence of breaking these protocols and computing the Diffie Hellman function. A long standing open problem in cryptography is the question of whether computing DH g (x; y) is as hard as computing discrete log for the group G. The discrete log function is defined as Dlog g ....

K. Sakurai and H Shizuya. Relationships among the computational powers of breaking discrete log cryptosystems. In Proc. EUROCRYPT 95, pages 341--355, May 1995.


On the Security of ElGamal based Encryption - Tsiounis, Yung (1998)   (76 citations)  (Correct)

....to more natural and widely used assumptions by showing that the semantic security of the ElGamal encryption [ElG85] is equivalent to the decision Diffie Hellman assumption. Note that obtaining the full plaintext of an ElGamal encrypted ciphertext is equivalent to the Diffie Hellman assumption [ElG85,SS98]; thus the fact that the semantic security [GM84] of ElGamal encryption is equivalent to the decision Diffie Hellman problem provides a natural analogy. In fact, ElGamal has stated this result as a conjecture in his earlier work [ElG98] We also discuss efficiency (security degradation) of our ....

K. Sakurai and H. Shizuya. Relationships among the computational powers of breaking discrete log cryptosystems. Journal of Cryptology, 1998. To appear.


The Diffie-Hellman Protocol - Maurer, Wolf (1999)   (1 citation)  (Correct)

No context found.

K. Sakrai and H. Shizuya, Relationships among the computational powers of breaking discrete log cryptosystems, Advances in Cryptology - EUROCRYPT '95 , Lecture Notes in Computer Science, Vol. 921, pp. 341--355, SpringerVerlag, 1995.


Hardness Computing Bits of Secret Keys in Diffie-Hellman and .. - Boneh, Venkatesan (1996)   (Correct)

No context found.

K. Sakurai, Shizuya H, "Relationships among Computational powers of Breaking Discrete Log Cryptosystems", Eurocrypt 95, pp 341-351. 13

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC