<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1 plus MathML 2.0 plus SVG 1.1//EN" "http://www.w3.org/2002/04/xhtml-math-svg/xhtml-math-svg.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
  <head>
    <meta http-equiv="Content-Type" content="application/xhtml+xml; charset=utf-8"/>
    <title>Project-Team:GRACE</title>
    <link rel="stylesheet" href="../static/css/raweb.css" type="text/css"/>
    <meta name="description" content="Highlights of the Year - Highlights of the Year"/>
    <meta name="dc.title" content="Highlights of the Year - Highlights of the Year"/>
    <meta name="dc.subject" content=""/>
    <meta name="dc.publisher" content="INRIA"/>
    <meta name="dc.date" content="(SCHEME=ISO8601) 2015-01"/>
    <meta name="dc.type" content="Report"/>
    <meta name="dc.language" content="(SCHEME=ISO639-1) en"/>
    <meta name="projet" content="GRACE"/>
    <!-- Piwik -->
    <script type="text/javascript" src="/rapportsactivite/piwik.js"></script>
    <noscript><p><img src="//piwik.inria.fr/piwik.php?idsite=49" style="border:0;" alt="" /></p></noscript>
    <!-- End Piwik Code -->
  </head>
  <body>
    <div class="tdmdiv">
      <div class="logo">
        <a href="http://www.inria.fr">
          <img style="align:bottom; border:none" src="../static/img/icons/logo_INRIA-coul.jpg" alt="Inria"/>
        </a>
      </div>
      <div class="TdmEntry">
        <div class="tdmentete">
          <a href="uid0.html">Project-Team Grace</a>
        </div>
        <span>
          <a href="uid1.html">Members</a>
        </span>
      </div>
      <div class="TdmEntry">Overall Objectives<ul><li><a href="./uid3.html">Scientific foundations</a></li></ul></div>
      <div class="TdmEntry">Research Program<ul><li><a href="uid5.html&#10;&#9;&#9;  ">Algorithmic Number Theory</a></li><li><a href="uid9.html&#10;&#9;&#9;  ">Arithmetic Geometry: Curves and
their Jacobians</a></li><li><a href="uid10.html&#10;&#9;&#9;  ">Curve-Based cryptology</a></li><li><a href="uid11.html&#10;&#9;&#9;  ">Algebraic Coding Theory</a></li></ul></div>
      <div class="TdmEntry">Application Domains<ul><li><a href="uid13.html&#10;&#9;&#9;  ">Cryptography and Cryptanalysis</a></li></ul></div>
      <div class="tdmActPage">
        <a href="./uid18.html">Highlights of the Year</a>
      </div>
      <div class="TdmEntry">New Software and Platforms<ul><li><a href="uid22.html&#10;&#9;&#9;  ">Fast Compact Diffie-Hellman</a></li><li><a href="uid26.html&#10;&#9;&#9;  ">Platforms</a></li></ul></div>
      <div class="TdmEntry">New Results<ul><li><a href="uid34.html&#10;&#9;&#9;  ">Weight distribution of
Algebraic-Geometry codes</a></li><li><a href="uid35.html&#10;&#9;&#9;  ">Faster elliptic
and hyperelliptic curve cryptography</a></li><li><a href="uid36.html&#10;&#9;&#9;  ">Quantum factoring</a></li><li><a href="uid37.html&#10;&#9;&#9;  ">Cryptanalysis of code based cryptosystems by filtration attacks</a></li><li><a href="uid40.html&#10;&#9;&#9;  ">Quantum LDPC codes</a></li><li><a href="uid41.html&#10;&#9;&#9;  ">Discrete Logarithm computations in
finite fields with the NFS algorithm</a></li><li><a href="uid49.html&#10;&#9;&#9;  ">Information sets of multiplicity codes</a></li><li><a href="uid50.html&#10;&#9;&#9;  ">Rank metric codes over infinite fields</a></li><li><a href="uid51.html&#10;&#9;&#9;  ">Hash function cryptanalysis</a></li><li><a href="uid54.html&#10;&#9;&#9;  ">Block cipher design and analysis</a></li></ul></div>
      <div class="TdmEntry">Bilateral Contracts and Grants with Industry<ul><li><a href="uid59.html&#10;&#9;&#9;  ">Bilateral Grants with Industry</a></li></ul></div>
      <div class="TdmEntry">Partnerships and Cooperations<ul><li><a href="uid61.html&#10;&#9;&#9;  ">Regional Initiatives</a></li><li><a href="uid64.html&#10;&#9;&#9;  ">National Initiatives</a></li><li><a href="uid71.html&#10;&#9;&#9;  ">European Initiatives</a></li><li><a href="uid99.html&#10;&#9;&#9;  ">International Initiatives</a></li><li><a href="uid105.html&#10;&#9;&#9;  ">International Research Visitors</a></li></ul></div>
      <div class="TdmEntry">Dissemination<ul><li><a href="uid109.html&#10;&#9;&#9;  ">Promoting Scientific Activities</a></li><li><a href="uid194.html&#10;&#9;&#9;  ">Teaching - Supervision - Juries</a></li><li><a href="uid224.html&#10;&#9;&#9;  ">Popularization</a></li><li><a href="uid228.html&#10;&#9;&#9;  ">Institutional commitment</a></li></ul></div>
      <div class="TdmEntry">
        <div>Bibliography</div>
      </div>
      <div class="TdmEntry">
        <ul>
          <li>
            <a id="tdmbibentmajor" href="bibliography.html">Major publications</a>
          </li>
          <li>
            <a id="tdmbibentyear" href="bibliography.html#year">Publications of the year</a>
          </li>
          <li>
            <a id="tdmbibentfoot" href="bibliography.html#References">References in notes</a>
          </li>
        </ul>
      </div>
    </div>
    <div id="main">
      <div class="mainentete">
        <div id="head_agauche">
          <small><a href="http://www.inria.fr">
	    
	    Inria
	  </a> | <a href="../index.html">
	    
	    Raweb 
	    2015</a> | <a href="http://www.inria.fr/en/teams/grace">Presentation of the Project-Team GRACE</a> | <a href="http://www.lix.polytechnique.fr/cryptologie/">GRACE Web Site
	  </a></small>
        </div>
        <div id="head_adroite">
          <table class="qrcode">
            <tr>
              <td>
                <a href="grace.xml">
                  <img style="align:bottom; border:none" alt="XML" src="../static/img/icons/xml_motif.png"/>
                </a>
              </td>
              <td>
                <a href="grace.pdf">
                  <img style="align:bottom; border:none" alt="PDF" src="IMG/qrcode-grace-pdf.png"/>
                </a>
              </td>
              <td>
                <a href="../grace/grace.epub">
                  <img style="align:bottom; border:none" alt="e-pub" src="IMG/qrcode-grace-epub.png"/>
                </a>
              </td>
            </tr>
            <tr>
              <td/>
              <td>PDF
</td>
              <td>e-Pub
</td>
            </tr>
          </table>
        </div>
      </div>
      <!--FIN du corps du module-->
      <br/>
      <div class="bottomNavigation">
        <div class="tail_aucentre">
          <a href="./uid13.html" accesskey="P"><img style="align:bottom; border:none" alt="previous" src="../static/img/icons/previous_motif.jpg"/> Previous | </a>
          <a href="./uid0.html" accesskey="U"><img style="align:bottom; border:none" alt="up" src="../static/img/icons/up_motif.jpg"/>  Home</a>
          <a href="./uid22.html" accesskey="N"> | Next <img style="align:bottom; border:none" alt="next" src="../static/img/icons/next_motif.jpg"/></a>
        </div>
        <br/>
      </div>
      <div id="textepage">
        <!--DEBUT2 du corps du module-->
        <h2>Section: 
      Highlights of the Year</h2>
        <h3 class="titre3">Highlights of the Year</h3>
        <p>
          <big>
            <b>Freestart collision for the full SHA-1.</b>
          </big>
        </p>
        <p>Together with M. Stevens and T. Peyrin, P. Karpman gave the first freestart collision for the full SHA-1 hash function <a href="./bibliography.html#grace-2015-bid0">[32]</a> .
Although theoretical attacks on this function were known since 2005, this work is an important milestone in SHA-1
cryptanalysis and it had a concrete impact on the use of SHA-1 in existing systems, such as TLS certificates.
In particular, the CA/Browser forum (which regroups some of the major industries of the internet) withdrew an internal
ballot proposing to extend the use of SHA-1 in new certificates through 2016. Major browser developers such as Mozilla
are also encouraging the timely withdrawal of SHA-1 certificates by updating the in-browser security warnings when such certificates are used.
This result was also vulgarised in technical press such as <i>Ars Technica</i> and more general newspapers such as <i>Le monde</i>.</p>
        <p>
          <big>
            <b>Discrete logarithm record computation in finite fields</b>
          </big>
        </p>
        <p>F. Morain and A. Guillevic together with P. Gaudry (CARAMEL team, Inria
Nancy Grand Est) and R. Barbulescu (CNRS, IMJ) published a new
discrete logarithm record in a finite field of 180 decimal digits
(dd), i.e. 595 bits. This result was presented at the Eurocrypt 2015
conference <a href="./bibliography.html#grace-2015-bid1">[19]</a> .
The Discrete Logarithm Problem (DLP) is widely studied in prime fields
GF<span class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><mrow><mo>(</mo><mi>p</mi><mo>)</mo></mrow></math></span> and was broken in small characteristic finite fields of the
form GF<span class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><mrow><mo>(</mo><msup><mn>2</mn><mi>n</mi></msup><mo>)</mo></mrow></math></span> and GF<span class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><mrow><mo>(</mo><msup><mn>3</mn><mi>n</mi></msup><mo>)</mo></mrow></math></span> with smooth <span class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><mi>n</mi></math></span> very recently.
It was not known whether the DLP is as hard in extensions of finite
fields compared to prime fields, for the same global size.
With this record of the same size as the most recent record in a prime
field, F. Morain and A. Guillevic showed that DLP in GF<span class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><mrow><mo>(</mo><msup><mi>p</mi><mn>2</mn></msup><mo>)</mo></mrow></math></span> is much
faster than in a prime field of the same size, and even faster than a
factorization of an RSA modulus of the same size.</p>
        <div class="notinline" align="center" style="margin-top:20px">
          <a name="uid19"/>
          <table>
            <caption align="bottom"><strong>Table 
	1. </strong>Comparison of running time for integer
factorization (NFS-IF), discrete logarithm in prime field
(NFS-DL(p)) and in quadratic field (NFS-DL(p 2 )) of same global
size 180 dd.</caption>
            <tr>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;border-left-style:solid;border-left-width:1px;border-top-style:solid;border-top-width:1px;border-bottom-style:solid; border-bottom-width:1px;">Algorithm</td>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;border-top-style:solid;border-top-width:1px;border-bottom-style:solid; border-bottom-width:1px;">relation collection</td>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;border-top-style:solid;border-top-width:1px;border-bottom-style:solid; border-bottom-width:1px;">linear algebra</td>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;border-top-style:solid;border-top-width:1px;border-bottom-style:solid; border-bottom-width:1px;">total</td>
            </tr>
            <tr>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;border-left-style:solid;border-left-width:1px;">NFS-IF</td>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;">5 years</td>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;">5.5 months</td>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;">5.5 years</td>
            </tr>
            <tr>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;border-left-style:solid;border-left-width:1px;">NFS-DL<span xmlns="http://www.w3.org/1999/xhtml" class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><mrow><mo>(</mo><mi>p</mi><mo>)</mo></mrow></math></span></td>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;">50 years</td>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;">80 years</td>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;">130 years</td>
            </tr>
            <tr>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;border-left-style:solid;border-left-width:1px;border-bottom-style:solid; border-bottom-width:1px;">NFS-DL<span xmlns="http://www.w3.org/1999/xhtml" class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><mrow><mo>(</mo><msup><mi>p</mi><mn>2</mn></msup><mo>)</mo></mrow></math></span></td>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;border-bottom-style:solid; border-bottom-width:1px;">157 days</td>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;border-bottom-style:solid; border-bottom-width:1px;">18 days (GPU)</td>
              <td xmlns="" style="text-align:center;border-right-style:solid;border-right-width:1px;border-bottom-style:solid; border-bottom-width:1px;">0.5 years</td>
            </tr>
          </table>
        </div>
        <p>F. Morain and A. Guillevic contributed with P. Gaudry and E. Thomé to other
DL computation records in finite fields GF<span class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><mrow><mo>(</mo><msup><mi>p</mi><mn>3</mn></msup><mo>)</mo></mrow></math></span> of 508 bits and 512
bits, and GF<span class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><mrow><mo>(</mo><msup><mi>p</mi><mn>4</mn></msup><mo>)</mo></mrow></math></span> of 392 bits. The practical difficulty is increasing with
the extension degree.</p>
        <div align="center" style="margin-top:10px">
          <a name="uid20">
            <!--...-->
          </a>
          <table title="" class="objectContainer">
            <caption align="bottom"><strong>Figure
	1. </strong>Records of DL computation in finite fields, and RSA
modulus factorization. F. Morain and A. Guillevic contributed to the
records in red in 2014–2015.</caption>
            <tr align="center">
              <td>
                <table>
                  <tr>
                    <td xmlns="" style="height:3px;" align="center">
                      <img xmlns="http://www.w3.org/1999/xhtml" alt="IMG/records-DL-GFp-en.png" src="IMG/records-DL-GFp-en.png"/>
                    </td>
                  </tr>
                </table>
              </td>
            </tr>
          </table>
        </div>
        <p>
          <big>
            <b>CATREL conference</b>
          </big>
        </p>
        <p>The 1st and 2nd of October 2015, F. Morain, B. Smith and A. Guillevic
organized an international workshop to conclude the CATREL project.
There were 14 invited speakers from all around the world, from
Palaiseau with A. Guillevic to as far as Auckland in New Zealand with
S. Galbraith. A. Joux presented an historical summary of DL computation
from the 80's. P. Gaudry, E. Thomé and C. Bouvier from the Caramel Team (Inria
Nancy), presented their contribution, and K. Bhargavan presented the
Logjam attack. There were also members of abroad teams leader in discrete
logarithm record breaking. G. Adj from Mexico and R. Granger and
T. Kleinjung presented their recent records in small characteristic.</p>
        <p>We hosted more than 50 participants for the two intensive days of the
workshop.
The schedule of the workshop is available on the following link.
<a href="http://www.lix.polytechnique.fr/cryptologie/CATREL-workshop">http://www.lix.polytechnique.fr/cryptologie/CATREL-workshop</a> </p>
        <p>
          <big>
            <b>AGC<span class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><msup><mrow/><mn>2</mn></msup></math></span>T 15</b>
          </big>
        </p>
        <p>A. Couvreur was one of the organizers of the conference AGC<span class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><msup><mrow/><mn>2</mn></msup></math></span>T 15
(Arithmetic Geometry Cryptography and Coding Theory) at CIRM (Marseille).
</p>
      </div>
      <!--FIN du corps du module-->
      <br/>
      <div class="bottomNavigation">
        <div class="tail_aucentre">
          <a href="./uid13.html" accesskey="P"><img style="align:bottom; border:none" alt="previous" src="../static/img/icons/previous_motif.jpg"/> Previous | </a>
          <a href="./uid0.html" accesskey="U"><img style="align:bottom; border:none" alt="up" src="../static/img/icons/up_motif.jpg"/>  Home</a>
          <a href="./uid22.html" accesskey="N"> | Next <img style="align:bottom; border:none" alt="next" src="../static/img/icons/next_motif.jpg"/></a>
        </div>
        <br/>
      </div>
    </div>
  </body>
</html>
