CS 812 Lecture 10 2/14/24 Wednesday B/S 7.1, 7.7 Modular Square Roots: Reliability of Cipolla's Algorithm Square Roots mod Prime Powers Square Roots mod General n Last time we discussed solving x^2 == a (mod p) when p is an odd prime. When p==3 mod 4 there is a formula: sqrt(a) = +- a^{(p+1)/4} All known efficient algorithms for p == 1 mod 4 use randomization. Cipolla's algorithm (1903) Goal: find the square root of a in (Zp*)^2, p an odd prime. Choose t in Zp at random If t^2 - 4a == 0, return +- t/2 If (t^2 - 4a|p) = +1, the algorithm fails (try again) Else [t^2 - 4a is a nonresidue for p] Let f = X^2 + tX + a [irreducible over Zp] return +- X ^ {(p+1)/2} mod f(X). Correctness was discussed last time. Reliability: about 50% of the t's are "good". To prove this note that the only bad t's are those for which there exists u != 0 [t^2 - 4a = u^2] So the number of bad t's is at most (1/2) [# of Zp solutions to t^2 - 4a = u^2] By changing variables, x = t/(2b), y = u/(2b) with b^2 = a, we will be done if we can count the solutions to x^2 - y^2 = 1. (*) It is known from classical geometry that any conic section has a parametrization by rational functions. Here, we use x = (s^2+1)/(s^2 - 1), y = 2s/(s^2 - 1); the inverse mapping is s = y/(x-1). [You can get an idea of why it works by drawing the locus of (*) in R^2. This is a hyperbola H, going through P = (1,0). s is the slope of the line L through P. L meets H in exactly one point, as long as s != +- 1. Draw the picture.] The "forward" map s |--> (x,y) is 1-1 from Zp - {+-1} onto {(x,y) : x^2 - y^2 = 1} - {(1,0)}. So p - 2 >= [# of Fp solutions to (*)] - 1, giving (1/2) [p-1] = p/2 - 1/2 as an upper estimate for the number of "bad" t's. This is a new kind of algorithm: it uses randomness in an essential way, and we can only guarantee good performance "on average," over the random choices used by the algorithm. If you run it repeatedly until it succeeds, the expected number of bops is O( (lg p)^3 ). This kind of procedure, where you can trust any answer you get, is often called a Las Vegas algorithm. Computing square roots mod prime powers. We'll only treat p odd. To solve x^2 == a (mod p^e), we can solve it modulo p, p^2, p^4, p^8, ... until the exponent is big enough. We'll assume gcd(a,p) = 1. The base case is handled by previous algorithms. To go from p^k to p^{2k}, assume that x_0^2 == a (mod p^k). We seek an x_1 for which (x_0 + p^k x_1)^2 == a (mod p^{2k}) Expanding the square and rearranging we get [x_0^2 - a] + 2 x_0 x_1 p^k == 0 (mod p^{2k}) which holds iff [x_0^2 - a]/p + 2 a x_0 x_1 == 0 (mod p^k}) This is a linear congruence that we can solve for x_1, since 2 a x_0 is not divisible by p. This is similar to Newton iteration in that we double the "precision" (exponent of p) at each stage. Therefore, the number of bops needed to get to p^e from the starting square root mod p is "O" of (lg p^e)^2 + (lg p^{e/2})^2 + (lg p^{(e/4))^2 + ... = O( lg^2 (p^e) ). Solving x^2 == a mod n for a in (Zn*)^2. If we know the factorization of n, we can use the Chinese remainder theorem. The idea is to let n = p1^e1 ... pr^er, find the square roots modulo each prime power, and recombine. If the pi are all odd there will be 2^r solutions. Is the factorization of n necessary? Suppose we have a magic box B that, when given any pair (a,n) where a is a quadratic residue mod n, provides a square root of a mod n. Then we can use B to factor n efficiently. In 1979, Rabin gave an elegant proof of this. All the ideas appear in the case n=pq, where p and q are distinct primes. Remember that by the Chinese Remainder theorem: ~ Zn = Zp (+) Zq. I can choose y at random from Zn*, and present (a,n) to the box B, where a = y^2 mod n. B will return some x, say x <--> (x1,x2) B did not know which y I squared to get a. So, given x, there are four equally likely possibilities: y <--> ( x1, x2) y <--> ( x1,-x2) y <--> (-x1, x2) y <--> (-x1,-x2) So x+y <--> ( 2 x1, 2 x2) x+y <--> ( 2 x1, 0) x+y <--> ( 0, x2) x+y <--> (-2 x1,-2 x2) With probability 1/2, then, gcd(x+y,n) will split n. For Rabin's original argument, see M.O. Rabin, Digitalized signatures and public-key functions as intractable as factorization, MIT Laboratory for Computer Science Report MIT/LCS/TR-212, 1979.