{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,27]],"date-time":"2026-03-27T08:40:34Z","timestamp":1774600834654,"version":"3.50.1"},"publisher-location":"Cham","reference-count":80,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319783741","type":"print"},{"value":"9783319783758","type":"electronic"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-78375-8_14","type":"book-chapter","created":{"date-parts":[[2018,3,30]],"date-time":"2018-03-30T06:12:59Z","timestamp":1522390379000},"page":"415-447","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":42,"title":["The Discrete-Logarithm Problem with\u00a0Preprocessing"],"prefix":"10.1007","author":[{"given":"Henry","family":"Corrigan-Gibbs","sequence":"first","affiliation":[]},{"given":"Dmitry","family":"Kogan","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2018,3,31]]},"reference":[{"key":"14_CR1","doi-asserted-by":"publisher","unstructured":"Abadi, M., Feigenbaum, J., Kilian, J.: On hiding information from an oracle. In: STOC (1987). https:\/\/doi.org\/10.1145\/28395.28417","DOI":"10.1145\/28395.28417"},{"key":"14_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1007\/978-3-319-70697-9_13","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2017","author":"H Abusalah","year":"2017","unstructured":"Abusalah, H., Alwen, J., Cohen, B., Khilko, D., Pietrzak, K., Reyzin, L.: Beyond Hellman\u2019s time-memory trade-offs with applications to proofs of space. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017. LNCS, vol. 10625, pp. 357\u2013379. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70697-9_13"},{"key":"14_CR3","doi-asserted-by":"publisher","unstructured":"Adrian, D., Bhargavan, K., Durumeric, Z., Gaudry, P., Green, M., Halderman, J.A., Heninger, N., Springall, D., Thom\u00e9, E., Valenta, L., et al.: Imperfect forward secrecy: how Diffie-Hellman fails in practice. In: CCS (2015). https:\/\/doi.org\/10.1145\/2810103.2813707","DOI":"10.1145\/2810103.2813707"},{"key":"14_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1007\/978-3-642-01001-9_2","volume-title":"Advances in Cryptology - EUROCRYPT 2009","author":"D Aggarwal","year":"2009","unstructured":"Aggarwal, D., Maurer, U.: Breaking RSA generically is equivalent to factoring. In: Joux, A. (ed.) EUROCRYPT 2009. LNCS, vol. 5479, pp. 36\u201353. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-01001-9_2"},{"key":"14_CR5","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511804090","volume-title":"Computational Complexity: A Modern Approach","author":"S Arora","year":"2009","unstructured":"Arora, S., Barak, B.: Computational Complexity: A Modern Approach. Cambridge University Press, Cambridge (2009)"},{"key":"14_CR6","doi-asserted-by":"publisher","unstructured":"Babai, L., Szemeredi, E.: On the complexity of matrix group problems I. In: FOCS (1984). https:\/\/doi.org\/10.1109\/sfcs.1984.715919","DOI":"10.1109\/sfcs.1984.715919"},{"key":"14_CR7","unstructured":"B\u0103rbulescu, R.: Improvements on the Discrete Logarithm Problem in GF$$(p)$$. Master\u2019s thesis, \u00c8cole Normale Sup\u00e9rieure de Lyon (2011). https:\/\/hal.inria.fr\/inria-00588713"},{"key":"14_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-55220-5_1","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2014","author":"R Barbulescu","year":"2014","unstructured":"Barbulescu, R., Gaudry, P., Joux, A., Thom\u00e9, E.: A heuristic quasi-polynomial algorithm for discrete logarithm in finite fields of small characteristic. In: Nguyen, P.Q., Oswald, E. (eds.) EUROCRYPT 2014. LNCS, vol. 8441, pp. 1\u201316. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-642-55220-5_1"},{"key":"14_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11818175_1","volume-title":"Advances in Cryptology - CRYPTO 2006","author":"E Barkan","year":"2006","unstructured":"Barkan, E., Biham, E., Shamir, A.: Rigorous bounds on cryptanalytic time\/memory tradeoffs. In: Dwork, C. (ed.) CRYPTO 2006. LNCS, vol. 4117, pp. 1\u201321. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11818175_1"},{"key":"14_CR10","doi-asserted-by":"publisher","unstructured":"Bellare, M., Rogaway, P.: Random oracles are practical: a paradigm for designing efficient protocols. In: CCS (1993). https:\/\/doi.org\/10.1145\/168588.168596","DOI":"10.1145\/168588.168596"},{"key":"14_CR11","doi-asserted-by":"publisher","unstructured":"Bernstein, D., Lange, T.: Two grumpy giants and a baby. In: The Open Book Series, vol. 1, no. 1, pp. 87\u2013111 (2013). https:\/\/doi.org\/10.2140\/obs.2013.1.87","DOI":"10.2140\/obs.2013.1.87"},{"key":"14_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/11745853_14","volume-title":"Public Key Cryptography - PKC 2006","author":"DJ Bernstein","year":"2006","unstructured":"Bernstein, D.J.: Curve25519: new Diffie-Hellman speed records. In: Yung, M., Dodis, Y., Kiayias, A., Malkin, T. (eds.) PKC 2006. LNCS, vol. 3958, pp. 207\u2013228. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11745853_14"},{"key":"14_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"321","DOI":"10.1007\/978-3-642-42045-0_17","volume-title":"Advances in Cryptology - ASIACRYPT 2013","author":"DJ Bernstein","year":"2013","unstructured":"Bernstein, D.J., Lange, T.: Non-uniform cracks in the concrete: the power of free precomputation. In: Sako, K., Sarkar, P. (eds.) ASIACRYPT 2013. LNCS, vol. 8270, pp. 321\u2013340. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-42045-0_17"},{"key":"14_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"48","DOI":"10.1007\/BFb0054851","volume-title":"Algorithmic Number Theory","author":"D Boneh","year":"1998","unstructured":"Boneh, D.: The decision Diffie-Hellman problem. In: Buhler, J.P. (ed.) ANTS 1998. LNCS, vol. 1423, pp. 48\u201363. Springer, Heidelberg (1998). https:\/\/doi.org\/10.1007\/BFb0054851"},{"key":"14_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1007\/978-3-540-24676-3_4","volume-title":"Advances in Cryptology - EUROCRYPT 2004","author":"D Boneh","year":"2004","unstructured":"Boneh, D., Boyen, X.: Short signatures without random oracles. In: Cachin, C., Camenisch, J.L. (eds.) EUROCRYPT 2004. LNCS, vol. 3027, pp. 56\u201373. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-24676-3_4"},{"key":"14_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"440","DOI":"10.1007\/11426639_26","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2005","author":"D Boneh","year":"2005","unstructured":"Boneh, D., Boyen, X., Goh, E.-J.: Hierarchical identity based encryption with constant size ciphertext. In: Cramer, R. (ed.) EUROCRYPT 2005. LNCS, vol. 3494, pp. 440\u2013456. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11426639_26"},{"key":"14_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1007\/3-540-44647-8_13","volume-title":"Advances in Cryptology \u2014 CRYPTO 2001","author":"D Boneh","year":"2001","unstructured":"Boneh, D., Franklin, M.: Identity-based encryption from the Weil pairing. In: Kilian, J. (ed.) CRYPTO 2001. LNCS, vol. 2139, pp. 213\u2013229. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-44647-8_13"},{"key":"14_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"325","DOI":"10.1007\/978-3-540-30576-7_18","volume-title":"Theory of Cryptography","author":"D Boneh","year":"2005","unstructured":"Boneh, D., Goh, E.-J., Nissim, K.: Evaluating 2-DNF formulas on ciphertexts. In: Kilian, J. (ed.) TCC 2005. LNCS, vol. 3378, pp. 325\u2013341. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/978-3-540-30576-7_18"},{"key":"14_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1007\/978-3-540-85538-5_3","volume-title":"Pairing-Based Cryptography \u2013 Pairing 2008","author":"X Boyen","year":"2008","unstructured":"Boyen, X.: The uber-assumption family. In: Galbraith, S.D., Paterson, K.G. (eds.) Pairing 2008. LNCS, vol. 5209, pp. 39\u201356. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-85538-5_3"},{"key":"14_CR20","doi-asserted-by":"publisher","unstructured":"Brown, D.: On the provable security of ECDSA. In: Advances in Elliptic Curve Cryptography, pp. 21\u201340. Cambridge University Press (2005). https:\/\/doi.org\/10.1017\/cbo9780511546570.004","DOI":"10.1017\/cbo9780511546570.004"},{"issue":"1","key":"14_CR21","doi-asserted-by":"publisher","first-page":"119","DOI":"10.1007\/s10623-003-6154-z","volume":"35","author":"DRL Brown","year":"2005","unstructured":"Brown, D.R.L.: Generic groups, collision resistance, and ECDSA. Des. Codes Crypt. 35(1), 119\u2013152 (2005). https:\/\/doi.org\/10.1007\/s10623-003-6154-z","journal-title":"Des. Codes Crypt."},{"key":"14_CR22","doi-asserted-by":"crossref","unstructured":"Chung, K.M., Lin, H., Mahmoody, M., Pass, R.: On the power of nonuniformity in proofs of security. In: ITCS (2013). http:\/\/doi.acm.org\/10.1145\/2422436.2422480","DOI":"10.1145\/2422436.2422480"},{"issue":"3","key":"14_CR23","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1007\/BF00198464","volume":"6","author":"D Coppersmith","year":"1993","unstructured":"Coppersmith, D.: Modifications to the number field sieve. J. Cryptology 6(3), 169\u2013180 (1993)","journal-title":"J. Cryptology"},{"key":"14_CR24","unstructured":"Coretti, S., Dodis, Y., Guo, S., Steinberger, J.: Random oracles and non-uniformity. Cryptology ePrint Archive, Report 2017\/937 (2017). https:\/\/eprint.iacr.org\/2017\/937"},{"key":"14_CR25","unstructured":"Corrigan-Gibbs, H., Kogan, D.: The discrete-logarithm problem with preprocessing. Cryptology ePrint Archive, Report 2017\/1113 (2017). https:\/\/eprint.iacr.org\/2017\/1113"},{"key":"14_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1007\/BFb0055717","volume-title":"Advances in Cryptology \u2014 CRYPTO 1998","author":"R Cramer","year":"1998","unstructured":"Cramer, R., Shoup, V.: A practical public key cryptosystem provably secure against adaptive chosen ciphertext attack. In: Krawczyk, H. (ed.) CRYPTO 1998. LNCS, vol. 1462, pp. 13\u201325. Springer, Heidelberg (1998). https:\/\/doi.org\/10.1007\/BFb0055717"},{"key":"14_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"256","DOI":"10.1007\/3-540-46035-7_17","volume-title":"Advances in Cryptology \u2014 EUROCRYPT 2002","author":"I Damg\u00e5rd","year":"2002","unstructured":"Damg\u00e5rd, I., Koprowski, M.: Generic lower bounds for root extraction and signature schemes in general groups. In: Knudsen, L.R. (ed.) EUROCRYPT 2002. LNCS, vol. 2332, pp. 256\u2013271. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-46035-7_17"},{"key":"14_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"649","DOI":"10.1007\/978-3-642-14623-7_35","volume-title":"Advances in Cryptology \u2013 CRYPTO 2010","author":"A De","year":"2010","unstructured":"De, A., Trevisan, L., Tulsiani, M.: Time space tradeoffs for attacks against one-way functions and PRGs. In: Rabin, T. (ed.) CRYPTO 2010. LNCS, vol. 6223, pp. 649\u2013665. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-14623-7_35"},{"key":"14_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"100","DOI":"10.1007\/3-540-36178-2_6","volume-title":"Advances in Cryptology \u2014 ASIACRYPT 2002","author":"AW Dent","year":"2002","unstructured":"Dent, A.W.: Adapting the weaknesses of the random oracle model to the generic group model. In: Zheng, Y. (ed.) ASIACRYPT 2002. LNCS, vol. 2501, pp. 100\u2013109. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-36178-2_6"},{"key":"14_CR30","unstructured":"Dent, A.W.: The hardness of the DHK problem in the generic group model. Cryptology ePrint Archive, Report 2006\/156 (2006). https:\/\/eprint.iacr.org\/2006\/156"},{"issue":"6","key":"14_CR31","doi-asserted-by":"publisher","first-page":"644","DOI":"10.1109\/TIT.1976.1055638","volume":"22","author":"W Diffie","year":"1976","unstructured":"Diffie, W., Hellman, M.: New directions in cryptography. IEEE Trans. Inf. Theory 22(6), 644\u2013654 (1976)","journal-title":"IEEE Trans. Inf. Theory"},{"key":"14_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"473","DOI":"10.1007\/978-3-319-56614-6_16","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2017","author":"Y Dodis","year":"2017","unstructured":"Dodis, Y., Guo, S., Katz, J.: Fixing cracks in the concrete: random oracles with auxiliary input, revisited. In: Coron, J.-S., Nielsen, J.B. (eds.) EUROCRYPT 2017. LNCS, vol. 10211, pp. 473\u2013495. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-56614-6_16"},{"key":"14_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"112","DOI":"10.1007\/978-3-642-28914-9_7","volume-title":"Theory of Cryptography","author":"Y Dodis","year":"2012","unstructured":"Dodis, Y., Haitner, I., Tentes, A.: On the instantiability of hash-and-sign RSA signatures. In: Cramer, R. (ed.) TCC 2012. LNCS, vol. 7194, pp. 112\u2013132. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-28914-9_7"},{"key":"14_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1007\/3-540-39568-7_2","volume-title":"Advances in Cryptology","author":"T ElGamal","year":"1985","unstructured":"ElGamal, T.: A public key cryptosystem and a signature scheme based on discrete logarithms. In: Blakley, G.R., Chaum, D. (eds.) CRYPTO 1984. LNCS, vol. 196, pp. 10\u201318. Springer, Heidelberg (1985). https:\/\/doi.org\/10.1007\/3-540-39568-7_2"},{"key":"14_CR35","doi-asserted-by":"crossref","unstructured":"Fiat, A., Naor, M.: Rigorous time\/space tradeoffs for inverting functions. In: STOC (1991). http:\/\/doi.acm.org\/10.1145\/103418.103473","DOI":"10.1145\/103418.103473"},{"key":"14_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"458","DOI":"10.1007\/3-540-44448-3_35","volume-title":"Advances in Cryptology \u2014 ASIACRYPT 2000","author":"M Fischlin","year":"2000","unstructured":"Fischlin, M.: A note on security proofs in the generic model. In: Okamoto, T. (ed.) ASIACRYPT 2000. LNCS, vol. 1976, pp. 458\u2013469. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/3-540-44448-3_35"},{"key":"14_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"420","DOI":"10.1007\/978-3-662-45611-8_22","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2014","author":"P-A Fouque","year":"2014","unstructured":"Fouque, P.-A., Joux, A., Mavromati, C.: Multi-user collisions: applications to discrete logarithm, Even-Mansour and PRINCE. In: Sarkar, P., Iwata, T. (eds.) ASIACRYPT 2014. LNCS, vol. 8873, pp. 420\u2013438. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-45611-8_22"},{"issue":"2","key":"14_CR38","doi-asserted-by":"publisher","first-page":"224","DOI":"10.1007\/s00145-009-9048-z","volume":"23","author":"D Freeman","year":"2010","unstructured":"Freeman, D., Scott, M., Teske, E.: A taxonomy of pairing-friendly elliptic curves. J. Cryptology 23(2), 224\u2013280 (2010). https:\/\/doi.org\/10.1007\/s00145-009-9048-z","journal-title":"J. Cryptology"},{"issue":"1","key":"14_CR39","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1007\/s10623-015-0146-7","volume":"78","author":"SD Galbraith","year":"2016","unstructured":"Galbraith, S.D., Gaudry, P.: Recent progress on the elliptic curve discrete logarithm problem. Des. Codes Crypt. 78(1), 51\u201372 (2016). https:\/\/doi.org\/10.1007\/s10623-015-0146-7","journal-title":"Des. Codes Crypt."},{"key":"14_CR40","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"368","DOI":"10.1007\/978-3-642-13013-7_22","volume-title":"Public Key Cryptography \u2013 PKC 2010","author":"SD Galbraith","year":"2010","unstructured":"Galbraith, S.D., Ruprai, R.S.: Using equivalence classes to accelerate solving the discrete logarithm problem in a short interval. In: Nguyen, P.Q., Pointcheval, D. (eds.) PKC 2010. LNCS, vol. 6056, pp. 368\u2013383. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-13013-7_22"},{"issue":"1","key":"14_CR41","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/s00145-001-0011-x","volume":"15","author":"P Gaudry","year":"2002","unstructured":"Gaudry, P., Hess, F., Smart, N.P.: Constructive and destructive facets of Weil descent on elliptic curves. J. Cryptol. 15(1), 19\u201346 (2002). https:\/\/doi.org\/10.1007\/s00145-001-0011-x","journal-title":"J. Cryptol."},{"key":"14_CR42","doi-asserted-by":"publisher","unstructured":"Gennaro, R., Trevisan, L.: Lower bounds on the efficiency of generic cryptographic constructions. In: FOCS (2000). https:\/\/doi.org\/10.1109\/SFCS.2000.892119","DOI":"10.1109\/SFCS.2000.892119"},{"key":"14_CR43","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"469","DOI":"10.1007\/3-540-44598-6_29","volume-title":"Advances in Cryptology \u2014 CRYPTO 2000","author":"R Gennaro","year":"2000","unstructured":"Gennaro, R.: An improved pseudo-random generator based on discrete log. In: Bellare, M. (ed.) CRYPTO 2000. LNCS, vol. 1880, pp. 469\u2013481. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/3-540-44598-6_29"},{"issue":"1","key":"14_CR44","doi-asserted-by":"publisher","first-page":"124","DOI":"10.1137\/0406010","volume":"6","author":"DM Gordon","year":"1993","unstructured":"Gordon, D.M.: Discrete logarithms in GF$$(P)$$ using the number field sieve. SIAM J. Discrete Math. 6(1), 124\u2013138 (1993). https:\/\/doi.org\/10.1137\/0406010","journal-title":"SIAM J. Discrete Math."},{"issue":"4","key":"14_CR45","doi-asserted-by":"publisher","first-page":"401","DOI":"10.1109\/TIT.1980.1056220","volume":"26","author":"M Hellman","year":"1980","unstructured":"Hellman, M.: A cryptanalytic time-memory trade-off. IEEE Trans. Inf. Theory 26(4), 401\u2013406 (1980). https:\/\/doi.org\/10.1109\/TIT.1980.1056220","journal-title":"IEEE Trans. Inf. Theory"},{"issue":"1","key":"14_CR46","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1007\/s102070100002","volume":"1","author":"D Johnson","year":"2001","unstructured":"Johnson, D., Menezes, A., Vanstone, S.: The elliptic curve digital signature algorithm (ECDSA). Int. J. Inf. Secur. 1(1), 36\u201363 (2001). https:\/\/doi.org\/10.1007\/s102070100002","journal-title":"Int. J. Inf. Secur."},{"key":"14_CR47","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1007\/978-3-319-10683-0_2","volume-title":"Open Problems in Mathematics and Computational Science","author":"A Joux","year":"2014","unstructured":"Joux, A., Odlyzko, A., Pierrot, C.: The past, evolving present, and future of the discrete logarithm. In: Ko\u00e7, \u00c7.K. (ed.) Open Problems in Mathematics and Computational Science, pp. 5\u201336. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-10683-0_2"},{"key":"14_CR48","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"174","DOI":"10.1007\/978-3-662-48797-6_8","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2015","author":"T Kim","year":"2015","unstructured":"Kim, T.: Multiple discrete logarithm problems with auxiliary inputs. In: Iwata, T., Cheon, J.H. (eds.) ASIACRYPT 2015. LNCS, vol. 9452, pp. 174\u2013188. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-48797-6_8"},{"issue":"1","key":"14_CR49","doi-asserted-by":"publisher","first-page":"13","DOI":"10.3934\/amc.2007.1.13","volume":"1","author":"N Koblitz","year":"2007","unstructured":"Koblitz, N., Menezes, A.: Another look at generic groups. Adv. Math. Commun. 1(1), 13\u201328 (2007). https:\/\/doi.org\/10.3934\/amc.2007.1.13","journal-title":"Adv. Math. Commun."},{"key":"14_CR50","doi-asserted-by":"publisher","unstructured":"Koblitz, N., Menezes, A.: Intractable problems in cryptography. In: Conference on Finite Fields and Their Applications (2010). https:\/\/doi.org\/10.1090\/conm\/518\/10212","DOI":"10.1090\/conm\/518\/10212"},{"issue":"2\u20133","key":"14_CR51","doi-asserted-by":"publisher","first-page":"173","DOI":"10.1023\/A:1008354106356","volume":"19","author":"N Koblitz","year":"2000","unstructured":"Koblitz, N., Menezes, A., Vanstone, S.: The state of elliptic curve cryptography. Des. Codes Cryptogr. 19(2\u20133), 173\u2013193 (2000). https:\/\/doi.org\/10.1023\/A:1008354106356","journal-title":"Des. Codes Cryptogr."},{"key":"14_CR52","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"173","DOI":"10.1007\/978-3-540-24632-9_13","volume-title":"Public Key Cryptography \u2013 PKC 2004","author":"T Koshiba","year":"2004","unstructured":"Koshiba, T., Kurosawa, K.: Short exponent Diffie-Hellman problems. In: Bao, F., Deng, R., Zhou, J. (eds.) PKC 2004. LNCS, vol. 2947, pp. 173\u2013186. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-24632-9_13"},{"key":"14_CR53","unstructured":"Kravitz, D.W.: Digital signature algorithm. US Patent 5,231,668 (1993)"},{"key":"14_CR54","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"212","DOI":"10.1007\/3-540-45537-X_17","volume-title":"Selected Areas in Cryptography","author":"F Kuhn","year":"2001","unstructured":"Kuhn, F., Struik, R.: Random walks revisited: extensions of Pollard\u2019s Rho algorithm for computing multiple discrete logarithms. In: Vaudenay, S., Youssef, A.M. (eds.) SAC 2001. LNCS, vol. 2259, pp. 212\u2013229. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-45537-X_17"},{"key":"14_CR55","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"241","DOI":"10.1007\/11935230_16","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2006","author":"G Leander","year":"2006","unstructured":"Leander, G., Rupp, A.: On the equivalence of RSA and factoring regarding generic ring algorithms. In: Lai, X., Chen, K. (eds.) ASIACRYPT 2006. LNCS, vol. 4284, pp. 241\u2013251. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11935230_16"},{"issue":"1","key":"14_CR56","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1515\/156939203321669546","volume":"13","author":"DV Matyukhin","year":"2003","unstructured":"Matyukhin, D.V.: On asymptotic complexity of computing discrete logarithms over GF$$(p)$$. Discrete Math. Appl. 13(1), 27\u201350 (2003). https:\/\/doi.org\/10.1515\/156939203321669546","journal-title":"Discrete Math. Appl."},{"key":"14_CR57","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11586821_1","volume-title":"Cryptography and Coding","author":"U Maurer","year":"2005","unstructured":"Maurer, U.: Abstract models of computation in cryptography. In: Smart, N.P. (ed.) Cryptography and Coding 2005. LNCS, vol. 3796, pp. 1\u201312. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11586821_1"},{"issue":"5","key":"14_CR58","doi-asserted-by":"publisher","first-page":"1639","DOI":"10.1109\/18.259647","volume":"39","author":"AJ Menezes","year":"1993","unstructured":"Menezes, A.J., Okamoto, T., Vanstone, S.A.: Reducing elliptic curve logarithms to logarithms in a finite field. IEEE Trans. Inf. Theory 39(5), 1639\u20131646 (1993). https:\/\/doi.org\/10.1109\/18.259647","journal-title":"IEEE Trans. Inf. Theory"},{"key":"14_CR59","unstructured":"Mihalcik, J.P.: An analysis of algorithms for solving discrete logarithms in fixed groups. Master\u2019s thesis, Naval Postgraduate School (2010). https:\/\/calhoun.nps.edu\/bitstream\/handle\/10945\/5395\/10Mar_Mihalcik.pdf"},{"issue":"11","key":"14_CR60","doi-asserted-by":"publisher","first-page":"594","DOI":"10.1145\/359168.359172","volume":"22","author":"R Morris","year":"1979","unstructured":"Morris, R., Thompson, K.: Password security: a case history. Commun. ACM 22(11), 594\u2013597 (1979). https:\/\/doi.org\/10.1145\/359168.359172","journal-title":"Commun. ACM"},{"issue":"2","key":"14_CR61","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1007\/BF02113297","volume":"55","author":"VI Nechaev","year":"1994","unstructured":"Nechaev, V.I.: Complexity of a determinate algorithm for the discrete logarithm. Math. Notes 55(2), 165\u2013172 (1994). https:\/\/doi.org\/10.1007\/bf02113297","journal-title":"Math. Notes"},{"issue":"2","key":"14_CR62","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1023\/A:1008350005447","volume":"19","author":"A Odlyzko","year":"2000","unstructured":"Odlyzko, A.: Discrete logarithms: the past and the future. Des. Codes Cryptogr. 19(2), 129\u2013145 (2000). https:\/\/doi.org\/10.1023\/A:1008350005447","journal-title":"Des. Codes Cryptogr."},{"key":"14_CR63","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"617","DOI":"10.1007\/978-3-540-45146-4_36","volume-title":"Advances in Cryptology - CRYPTO 2003","author":"P Oechslin","year":"2003","unstructured":"Oechslin, P.: Making a faster cryptanalytic time-memory trade-off. In: Boneh, D. (ed.) CRYPTO 2003. LNCS, vol. 2729, pp. 617\u2013630. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/978-3-540-45146-4_36"},{"key":"14_CR64","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"332","DOI":"10.1007\/3-540-68339-9_29","volume-title":"Advances in Cryptology \u2014 EUROCRYPT 1996","author":"PC van Oorschot","year":"1996","unstructured":"van Oorschot, P.C., Wiener, M.J.: On Diffie-Hellman key agreement with short exponents. In: Maurer, U. (ed.) EUROCRYPT 1996. LNCS, vol. 1070, pp. 332\u2013343. Springer, Heidelberg (1996). https:\/\/doi.org\/10.1007\/3-540-68339-9_29"},{"key":"14_CR65","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"304","DOI":"10.1007\/BFb0055737","volume-title":"Advances in Cryptology \u2014 CRYPTO 1998","author":"S Patel","year":"1998","unstructured":"Patel, S., Sundaram, G.S.: An efficient discrete log pseudo random generator. In: Krawczyk, H. (ed.) CRYPTO 1998. LNCS, vol. 1462, pp. 304\u2013317. Springer, Heidelberg (1998). https:\/\/doi.org\/10.1007\/BFb0055737"},{"issue":"1","key":"14_CR66","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1109\/TIT.1978.1055817","volume":"24","author":"S Pohlig","year":"1978","unstructured":"Pohlig, S., Hellman, M.: An improved algorithm for computing logarithms over $${GF}(p)$$ and its cryptographic significance (corresp.). IEEE Trans. Inf. Theory 24(1), 106\u2013110 (1978). https:\/\/doi.org\/10.1109\/tit.1978.1055817","journal-title":"IEEE Trans. Inf. Theory"},{"issue":"143","key":"14_CR67","doi-asserted-by":"publisher","first-page":"918","DOI":"10.2307\/2006496","volume":"32","author":"JM Pollard","year":"1978","unstructured":"Pollard, J.M.: Monte Carlo methods for index computation (mod $$p$$). Math. Comput. 32(143), 918\u2013924 (1978). https:\/\/doi.org\/10.2307\/2006496","journal-title":"Math. Comput."},{"key":"14_CR68","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1007\/0-387-34805-0_22","volume-title":"Advances in Cryptology \u2014 CRYPTO 1989 Proceedings","author":"CP Schnorr","year":"1990","unstructured":"Schnorr, C.P.: Efficient identification and signatures for smart cards. In: Brassard, G. (ed.) CRYPTO 1989. LNCS, vol. 435, pp. 239\u2013252. Springer, New York (1990). https:\/\/doi.org\/10.1007\/0-387-34805-0_22"},{"key":"14_CR69","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1007\/3-540-44448-3_7","volume-title":"Advances in Cryptology \u2014 ASIACRYPT 2000","author":"CP Schnorr","year":"2000","unstructured":"Schnorr, C.P., Jakobsson, M.: Security of signed ElGamal encryption. In: Okamoto, T. (ed.) ASIACRYPT 2000. LNCS, vol. 1976, pp. 73\u201389. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/3-540-44448-3_7"},{"key":"14_CR70","doi-asserted-by":"publisher","unstructured":"Shanks, D.: Class number, a theory of factorization, and genera (1971). https:\/\/doi.org\/10.1090\/pspum\/020\/0316385","DOI":"10.1090\/pspum\/020\/0316385"},{"key":"14_CR71","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"256","DOI":"10.1007\/3-540-69053-0_18","volume-title":"Advances in Cryptology \u2014 EUROCRYPT 1997","author":"V Shoup","year":"1997","unstructured":"Shoup, V.: Lower bounds for discrete logarithms and related problems. In: Fumy, W. (ed.) EUROCRYPT 1997. LNCS, vol. 1233, pp. 256\u2013266. Springer, Heidelberg (1997). https:\/\/doi.org\/10.1007\/3-540-69053-0_18"},{"key":"14_CR72","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1007\/3-540-45325-3_8","volume-title":"Cryptography and Coding","author":"NP Smart","year":"2001","unstructured":"Smart, N.P.: The exact security of ECIES in the generic group model. In: Honary, B. (ed.) Cryptography and Coding 2001. LNCS, vol. 2260, pp. 73\u201384. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-45325-3_8"},{"issue":"3","key":"14_CR73","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1007\/s001459900052","volume":"12","author":"NP Smart","year":"1999","unstructured":"Smart, N.P.: The discrete logarithm problem on elliptic curves of trace one. J. Cryptol. 12(3), 193\u2013196 (1999). https:\/\/doi.org\/10.1007\/s001459900052","journal-title":"J. Cryptol."},{"key":"14_CR74","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"205","DOI":"10.1007\/978-3-540-74143-5_12","volume-title":"Advances in Cryptology - CRYPTO 2007","author":"D Unruh","year":"2007","unstructured":"Unruh, D.: Random oracles and auxiliary input. In: Menezes, A. (ed.) CRYPTO 2007. LNCS, vol. 4622, pp. 205\u2013223. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-74143-5_12"},{"key":"14_CR75","doi-asserted-by":"publisher","first-page":"277","DOI":"10.1016\/j.ins.2012.01.044","volume":"195","author":"P Wang","year":"2012","unstructured":"Wang, P., Zhang, F.: Computing elliptic curve discrete logarithms with the negation map. Inf. Sci. 195, 277\u2013286 (2012). https:\/\/doi.org\/10.1016\/j.ins.2012.01.044","journal-title":"Inf. Sci."},{"key":"14_CR76","doi-asserted-by":"crossref","unstructured":"Wee, H.: On obfuscating point functions. In: STOC (2005). http:\/\/doi.acm.org\/10.1145\/1060590.1060669","DOI":"10.1145\/1060590.1060669"},{"key":"14_CR77","doi-asserted-by":"crossref","unstructured":"Yao, A.C.C.: Coherent functions and program checkers. In: STOC (1990). http:\/\/doi.acm.org\/10.1145\/100216.100226","DOI":"10.1145\/100216.100226"},{"key":"14_CR78","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"498","DOI":"10.1007\/978-3-319-61204-1_25","volume-title":"Applied Cryptography and Network Security","author":"JHM Ying","year":"2017","unstructured":"Ying, J.H.M., Kunihiro, N.: Bounds in various generalized settings of the discrete logarithm problem. In: Gollmann, D., Miyaji, A., Kikuchi, H. (eds.) ACNS 2017. LNCS, vol. 10355, pp. 498\u2013517. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-61204-1_25"},{"key":"14_CR79","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"817","DOI":"10.1007\/978-3-662-46803-6_27","volume-title":"Advances in Cryptology - EUROCRYPT 2015","author":"A Yun","year":"2015","unstructured":"Yun, A.: Generic hardness of the multiple discrete logarithm problem. In: Oswald, E., Fischlin, M. (eds.) EUROCRYPT 2015. LNCS, vol. 9057, pp. 817\u2013836. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-46803-6_27"},{"issue":"3","key":"14_CR80","doi-asserted-by":"publisher","first-page":"453","DOI":"10.3934\/amc.2017038","volume":"11","author":"F Zhang","year":"2017","unstructured":"Zhang, F., Wang, P., Galbraith, S.: Computing elliptic curve discrete logarithms with improved baby-step giant-step algorithm. Adv. Math. Commun. 11(3), 453\u2013469 (2017). https:\/\/doi.org\/10.3934\/amc.2017038","journal-title":"Adv. Math. Commun."}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2018"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-78375-8_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,7]],"date-time":"2024-03-07T11:27:13Z","timestamp":1709810833000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-78375-8_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319783741","9783319783758"],"references-count":80,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-78375-8_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]},"assertion":[{"value":"31 March 2018","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Tel Aviv","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Israel","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 April 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3 May 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"37","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2018\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}