arXiv ScienceSearch

arXiv subjects

Koji Nuida

Publications and source records attributed to Koji Nuida.

At least 19 recordsLinked to original sources

Ordinary 3-Isogeny Graphs and Improvement of Supersingularity Testing for Twisted Hessian Curves over Prime Fields

For any primes $p \neq \ell$, $\ell$-isogeny graphs of ordinary elliptic curves defined over $\mathbb{F}_{p^2}$ have a typical structure called $\ell$-volcanoes, and the structure is the core of Sutherland's supersingularity testing algorithm for elliptic curves. In this paper, by exploiting the properties of $3$-isogenies between twisted Hessian curves, we show that when $p \equiv 2 \pmod{3}$ and $\ell = 3$, every ordinary twisted Hessian curve defined over $\mathbb{F}_p$ lies on the surface of the $3$-volcano. As an application, we give an improved version of Sutherland's supersingularity testing algorithm specialized to twisted Hessian curves defined over $\mathbb{F}_p$ with $p \equiv 2 \pmod{3}$. We also give a generalization of the known fact that any supersingular $j$-invariant is a cube in $\mathbb{F}_{p^2}$; we show that for any twisted Hessian curve $H(a,d)$ defined over $\mathbb{F}_{p^2}$, its $j$-invariant is not a cube in $\mathbb{F}_{p^2}$ if and only if $H(a,d)$ is ordinary and lies on the floor of a $3$-volcano.

math.NT

Cyclic Equalizability of Words and Its Application to Card-Based Cryptography

Card-based cryptography is a research area to implement cryptographic procedures using a deck of physical cards. In recent years, it has been found to be related to finite group theory and algebraic combinatorics, and is becoming more and more closely connected to the field of mathematics. In this paper, we discuss the relationship between card-based cryptography and combinatorics on words for the first time. In particular, we focus on cyclic equality of words. We say that a set of words are cyclically equalizable if they can be transformed to be cyclically equal by repeated simultaneous insertion of letters. The main result of this paper is to show that two binary words of equal length and equal Hamming weight are cyclically equalizable. As applications of cyclic equalizability to card-based cryptography, we describe its applications to the information erasure problem and to single-cut full-open protocols.

cs.CR

A Note on Single-Cut Full-Open Protocols

Card-based cryptography is a research area that realizes cryptographic protocols such as secure computation by applying shuffles to sequences of cards that encode input values. A single-cut full-open protocol is one that obtains an output value by applying a random cut to an input sequence of cards, after which all cards are opened. In this paper, we propose three single-cut full-open protocols: two protocols for three-variable functions and one protocol for a four-variable function.

cs.CR

Bounds on Heights of $2$-isogeny Graphs in Ordinary Curves over $\mathbb{F}_p$ and $\mathbb{F}_{p^2}$ and Its Application

It is known that any isogeny graph consisting of ordinary elliptic curves over $\mathbb{F}_q$ with $q = p$ or $p^2$ has a special structure, called a volcano graph. We have a bound $h < \log_2 \sqrt{4q}$ of a height $h$ of the $2$-volcano graph. In this paper, we improve the bound on a height of $2$-volcano graphs over $\mathbb{F}_q$. In case $q = p^2$, we show a tighter bound $h \leq \left\lfloor \frac{ 1 }{ 2 } \lfloor \log_2 p \rfloor \right\rfloor + 2 $. In case $q = p$, we also show that a good bound for each prime $p$ can be computed by using our proposed techniques.

math.NT

Listing superspecial curves of genus three using Richelot isogeny graphs

In algebraic geometry, superspecial curves are important research objects. While the number of superspecial genus-3 curves in characteristic $p$ is known, the number of hyperelliptic ones among them has not been determined even for small $p$. In this paper, in order to compute the latter number, we give an explicit algorithm for computing the Richelot isogeny graph of superspecial principally polarized abelian varieties of dimension 3 using theta functions. In particular, one can determine whether a given vertex in the graph corresponds to the Jacobian of a genus-3 curve or not, and restore the defining equation of such a genus-3 curve from its theta constants. Our algorithm enables efficient enumeration of superspecial genus-3 curves, as all operations can be performed in $\mathbb{F}_{p^2}$. By implementing the algorithm in Magma, we successfully counted the number of hyperelliptic curves among them for all primes $11 \leq p < 100$.

math.AG

A Simple and Elementary Proof of Zorn's Lemma

Zorn's Lemma is a well-known equivalent of the Axiom of Choice. It is usually regarded as a topic in axiomatic set theory, and its historically standard proof (from the Axiom of Choice) relies on transfinite recursion, a non-elementary set-theoretic machinery. However, the statement of Zorn's Lemma itself uses only elementary terminology for partially ordered sets. Therefore, it is worthy to establish a proof using only such elementary terminology. Following this line of study, we give a new simple proof of Zorn's Lemma, which does not even use the notion of a well-ordered set.

math.LO

Uniform Cyclic Group Factorizations of Finite Groups

In this paper, we introduce a kind of decomposition of a finite group called a uniform group factorization, as a generalization of exact factorizations of a finite group. A group $G$ is said to admit a uniform group factorization if there exist subgroups $H_1, H_2, \ldots, H_k$ such that $G = H_1 H_2 \cdots H_k$ and the number of ways to represent any element $g \in G$ as $g = h_1 h_2 \cdots h_k$ ($h_i \in H_i$) does not depend on the choice of $g$. Moreover, a uniform group factorization consisting of cyclic subgroups is called a uniform cyclic group factorization. First, we show that any finite solvable group admits a uniform cyclic group factorization. Second, we show that whether all finite groups admit uniform cyclic group factorizations or not is equivalent to whether all finite simple groups admit uniform group factorizations or not. Lastly, we give some concrete examples of such factorizations.

math.GR

Private Simultaneous Messages Based on Quadratic Residues

Private Simultaneous Messages (PSM) model is a minimal model for secure multiparty computation. Feige, Kilian, and Naor (STOC 1994) and Ishai (Cryptology and Information Security Series 2013) constructed PSM protocols based on quadratic residues. In this paper, we define QR-PSM protocols as a generalization of these protocols. A QR-PSM protocol is a PSM protocol whose decoding function outputs the quadratic residuosity of what is computed from messages. We design a QR-PSM protocol for any symmetric function $f: \{0,1\}^n \rightarrow \{0,1\}$ of communication complexity $O(n^2)$. As far as we know, it is the most efficient PSM protocol since the previously known best PSM protocol was of $O(n^2\log n)$ (Beimel et al., CRYPTO 2014). We also study the sizes of the underlying finite fields $\mathbb{F}_p$ in the protocols since the communication complexity of a QR-PSM protocol is proportional to the bit length of the prime $p$. In particular, we show that the $N$-th Peralta prime $P_N$, which is used for general QR-PSM protocols, can be taken as at most $(1+o(1))N^2 2^{2N-2}$, which improves the Peralta's known result (Mathematics of Computation 1992) by a constant factor $(1+\sqrt{2})^2$.

cs.CR

On Compression Functions over Groups with Applications to Homomorphic Encryption

Fully homomorphic encryption (FHE) enables an entity to perform arbitrary computation on encrypted data without decrypting the ciphertexts. An ongoing group-theoretical approach to construct an FHE scheme uses a certain "compression" function $F(x)$ implemented by group operations on a given finite group $G$, which satisfies that $F(1) = 1$ and $F(\sigma) = F(\sigma^2) = \sigma$ where $\sigma \in G$ is some element of order $3$. The previous work gave an example of such a function over the symmetric group $G = S_5$ by just a heuristic approach. In this paper, we systematically study the possibilities of such a function over various groups. We show that such a function does not exist over any solvable group $G$ (such as an Abelian group and a smaller symmetric group $S_n$ with $n \leq 4$). We also construct such a function over the alternating group $G = A_5$ that has a shortest possible expression. Moreover, by using this new function, we give a reduction of a construction of an FHE scheme to a construction of a homomorphic encryption scheme over the group $A_5$, which is more efficient than the previously known reductions.

math.GR

An Improvement of a Key Exchange Protocol Relying on Polynomial Maps

Akiyama et al. (Int. J. Math. Indust., 2019) proposed a post-quantum key exchange protocol that is based on the hardness of solving a system of multivariate non-linear polynomial equations but has a design strategy different from ordinary multivariate cryptography. Their protocol has two versions, an original one and a modified one, where the modified one has a trade-off that its security is strengthened while it has non-zero error probability in establishing a common key. In fact, the evaluation in their paper suggests that the probability of failing to establish a common key by the modified protocol with the proposed parameter set is impractically high. In this paper, we improve the success probability of Akiyama et al.'s modified key exchange protocol significantly while keeping the security, by restricting each component of the correct common key from the whole of the coefficient field to its small subset. We give theoretical and experimental evaluations showing that our proposed parameter set for our protocol is expected to achieve both failure probability $2^{-120}$ and $128$-bit security level.

cs.CR

Halt Properties and Complexity Evaluations for Optimal DeepLLL Algorithm Families

DeepLLL algorithm (Schnorr, 1994) is a famous variant of LLL lattice basis reduction algorithm, and PotLLL algorithm (Fontein et al., 2014) and $S^2$LLL algorithm (Yasuda and Yamaguchi, 2019) are recent polynomial-time variants of DeepLLL algorithm developed from cryptographic applications. However, the known polynomial bounds for computational complexity are shown only for parameter $\delta < 1$; for "optimal" parameter $\delta = 1$ which ensures the best output quality, no polynomial bounds are known, and except for LLL algorithm, it is even not formally proved that the algorithm always halts within finitely many steps. In this paper, we prove that these four algorithms always halt also with optimal parameter $\delta = 1$, and furthermore give explicit upper bounds for the numbers of loops executed during the algorithms. Unlike the known bound (Akhavi, 2003) applicable to LLL algorithm only, our upper bounds are deduced in a unified way for all of the four algorithms.

cs.DS

An Elementary Linear-Algebraic Proof without Computer-Aided Arguments for the Group Law on Elliptic Curves

The group structure on the rational points of elliptic curves plays several important roles, in mathematics and recently also in other areas such as cryptography. However, the famous proofs for the group property (in particular, for its associative law) require somewhat advanced mathematics and therefore are not easily accessible by non-mathematician. On the other hand, there have been attempts in the literature to give an elementary proof, but those rely on computer-aided calculation for some part in their proofs. In this paper, we give a self-contained proof of the associative law for this operation, assuming mathematical knowledge only at the level of basic linear algebra and not requiring computer-aided arguments.

math.AG

Communication-Efficient (Client-Aided) Secure Two-Party Protocols and Its Application

Secure multi-party computation (MPC) allows a set of parties to compute a function jointly while keeping their inputs private. Compared with the MPC based on garbled circuits,some recent research results show that MPC based on secret sharing (SS) works at a very high speed. Moreover, SS-based MPC can be easily vectorized and achieve higher throughput. In SS-based MPC, however, we need many communication rounds for computing concrete protocols like equality check, less-than comparison, etc. This property is not suited for large-latency environments like the Internet (or WAN). In this paper, we construct semi-honest secure communication-efficient two-party protocols. The core technique is Beaver triple extension, which is a new tool for treating multi-fan-in gates, and we also show how to use it efficiently. We mainly focus on reducing the number of communication rounds, and our protocols also succeed in reducing the number of communication bits (in most cases). As an example, we propose a less-than comparison protocol (under practical parameters) with three communication rounds. Moreover, the number of communication bits is also $38.4\%$ fewer. As a result, total online execution time is $56.1\%$ shorter than the previous work adopting the same settings. Although the computation costs of our protocols are more expensive than those of previous work, we confirm via experiments that such a disadvantage has small effects on the whole online performance in the typical WAN environments.

cs.CR

Secure Grouping Protocol Using a Deck of Cards

We consider a problem, which we call secure grouping, of dividing a number of parties into some subsets (groups) in the following manner: Each party has to know the other members of his/her group, while he/she may not know anything about how the remaining parties are divided (except for certain public predetermined constraints, such as the number of parties in each group). In this paper, we construct an information-theoretically secure protocol using a deck of physical cards to solve the problem, which is jointly executable by the parties themselves without a trusted third party. Despite the non-triviality and the potential usefulness of the secure grouping, our proposed protocol is fairly simple to describe and execute. Our protocol is based on algebraic properties of conjugate permutations. A key ingredient of our protocol is our new techniques to apply multiplication and inverse operations to hidden permutations (i.e., those encoded by using face-down cards), which would be of independent interest and would have various potential applications.

cs.CR

Polynomial expressions of $p$-ary auction functions

Let $\mathbb{F}_p$ be the finite field of prime order $p$. For any function $f \colon \mathbb{F}_p{}^n \to \mathbb{F}_p$, there exists a unique polynomial over $\mathbb{F}_p$ having degree at most $p-1$ with respect to each variable which coincides with $f$. We call it the minimal polynomial of $f$. It is in general a non-trivial task to find a concrete expression of the minimal polynomial of a given function, which has only been worked out for limited classes of functions in the literature. In this paper, we study minimal polynomial expressions of several functions that are closely related to some practically important procedures such as auction and voting.

math.CO

Intrinsic reflections in Coxeter systems

Let $(W,S)$ be a Coxeter system and let $s \in S$. We call $s$ a right-angled generator of $(W,S)$ if $st = ts$ or $st$ has infinite order for each $t \in S$. We call $s$ an intrinsic reflection of $W$ if $s \in R^W$ for all Coxeter generating sets $R$ of $W$. We give necessary and sufficient conditions for a right-angled generator $s \in S$ of $(W,S)$ to be an intrinsic reflection of $W$.

math.GR

Polynomial Expressions of Carries in p-ary Arithmetics

It is known that any $n$-variable function on a finite prime field of characteristic $p$ can be expressed as a polynomial over the same field with at most $p^n$ monomials. However, it is not obvious to determine the polynomial for a given concrete function. In this paper, we study the concrete polynomial expressions of the carries in addition and multiplication of $p$-ary integers. For the case of addition, our result gives a new family of symmetric polynomials, which generalizes the known result for the binary case $p = 2$ where the carries are given by elementary symmetric polynomials. On the other hand, for the case of multiplication of $n$ single-digit integers, we give a simple formula of the polynomial expression for the carry to the next digit using the Bernoulli numbers, and show that it has only $(n+1)(p-1)/2 + 1$ monomials, which is significantly fewer than the worst-case number $p^n$ of monomials for general functions. We also discuss applications of our results to cryptographic computation on encrypted data.

math.CO