Structured GGM ⇒ DLOG

Free reduction · generic group model · CHW26 · security loss: time

Statement

In the structured generic-group model, which extends Shoup’s GGM so that the adversary may exploit the group’s special structure on at most a fraction of group elements and is generic on the rest, every algorithm for DLOG in a group of prime order runs in time — CHW26. This gives tight subexponential lower bounds against index-calculus-style algorithms that exploit the multiplicative structure of smooth integers but are otherwise generic — CHW26.

Notes