Computing Hilbert class polynomials with the Chinese remainder theorem

Andrew Sutherland · Mathematics of Computation · 2010

We present a space-efficient algorithm to compute the Hilbert class polynomial H D ( X ) H_D(X) modulo a positive integer P P , based on an explicit form of the Chinese Remainder Theorem. Under the Generalized Riemann Hypothesis, the algorithm uses O ( | D | 1 / 2 + ϵ log ⁡ P ) O(|D|^{1/2+\epsilon }\log {P}) space and has an expected running time of O ( | D | 1 + ϵ ) O(|D|^{1+\epsilon }) . We describe practical optimizations that allow us to handle larger discriminants than other methods, with | D | |D| as large as 10 13 10^{13} and h ( D ) h(D) up to 10 6 10^{6} . We apply these results to construct pairing-friendly elliptic curves of prime order, using the CM method.

Read the paper · More papers on PaperTik