DOI: 10.62056/a66chevtw ISSN: 3006-5496

Efficient DDH Distinguishers in Class Groups of Orders in $ℚ(√(-3))$

Antonio Sanso

We give an explicit algorithm to evaluate an efficiently computable cubic genus invariant on ideal class groups of non-maximal imaginary quadratic orders in K = ( 3 ) . Concretely, we consider the order 𝒪 Δ of discriminant Δ = 3 f 2 with conductor f > 1 . We assume that f is known as an integer, but its prime factorization is not; instead, we are given only a single nontrivial factor a f arising in Dedekind's parametrization of these discriminants (so that the complementary factor needed in the cubic-residuosity test can be recovered as an integer from ( f , a ) , without factoring it).

Under these assumptions, our method computes a nontrivial two-valued genus invariant on the ideal class group of 𝒪 Δ , taking values + 1 and 1 , whose + 1 -fiber is a distinguished index- 3 subgroup singled out by classical work of Dedekind; equivalently, the invariant takes the value + 1 if and only if the ideal class lies in that subgroup.

The construction is inspired by work of Dedekind and Shanks on index- 3 subgroups of quadratic form class groups and their characterization via cubic residuosity of primes represented by form classes. We prove correctness and analyze the running time of the resulting evaluation procedure, and we validate the approach with a SageMath implementation. As an application, we obtain an explicit Decisional Diffie–Hellman (DDH) distinguisher in cyclic subgroups of the class group generated by an element outside the distinguished index- 3 subgroup, under the same partial-factorization assumption.

More from our Archive