Structured GGM ⇒ DLOG
Statement
In the structured generic-group model, which extends Shoup’s GGM so that the adversary may exploit the group’s special structure on at most a fraction of group elements and is generic on the rest, every algorithm for DLOG in a group of prime order runs in time — CHW26. This gives tight subexponential lower bounds against index-calculus-style algorithms that exploit the multiplicative structure of smooth integers but are otherwise generic — CHW26.
Notes
- The bound is on running time, whereas Shoup’s generic DLOG bound counts group-operation queries — CHW26, Sho97.