Length-based conjugacy search in the Braid group
D. Garber, S. Kaplan, M. Teicher, B. Tsaban, U. Vishne
Abstract
Open-access reader
D. Garber, S. Kaplan, M. Teicher, B. Tsaban, U. Vishne
Abstract
Open-access reader
Several key agreement protocols are based on the following "Generalized Conjugacy Search Problem": Find, given elements b_1,...,b_n and xb_1x^{-1},...,xb_nx^{-1} in a nonabelian group G, the conjugator x. In the case of subgroups of the braid group B_N, Hughes and Tannenbaum suggested a length-based approach to finding x. Since the introduction of this approach, its effectiveness and successfulness were debated. We introduce several effective realizations of this approach. In particular, a new length function is defined on B_N which possesses significantly better properties than the natural length associated to the Garside normal form. We give experimental results concerning the success probability of this approach, which suggest that very large computational power is required for this method to successfully solve the Generalized Conjugacy Search Problem when its parameters are as in existing protocols.
OpenAlex reports 3 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Several key agreement protocols are based on the following "Generalized Conjugacy Search Problem": Find, given elements b_1,...,b_n and xb_1x^{-1},...,xb_nx^{-1} in a nonabelian group G, the conjugator x. In the case of subgroups of the braid group B_N, Hughes and Tannenbaum suggested a length-based approach to finding x. Since the introduction of this approach, its effectiveness and successfulness were debated. We introduce several effective realizations of this approach. In particular, a new length function is defined on B_N which possesses significantly better properties than the natural length associated to the Garside normal form. We give experimental results concerning the success probability of this approach, which suggest that very large computational power is required for this method to successfully solve the Generalized Conjugacy Search Problem when its parameters are as in existing protocols.
Key concepts: Braid group, Conjugacy class, Conjugacy problem, Braid, Mathematics, Group (periodic table), Combinatorics, Function (biology)