Polynomial-time quantum algorithms for Pell's equation and the principal ideal problem

S Hallgren - Journal of the ACM (JACM), 2007 - dl.acm.org
S Hallgren
Journal of the ACM (JACM), 2007dl.acm.org
We give polynomial-time quantum algorithms for three problems from computational
algebraic number theory. The first is Pell's equation. Given a positive nonsquare integer d,
Pell's equation is x 2− dy 2= 1 and the goal is to find its integer solutions. Factoring integers
reduces to finding integer solutions of Pell's equation, but a reduction in the other direction is
not known and appears more difficult. The second problem we solve is the principal ideal
problem in real quadratic number fields. This problem, which is at least as hard as solving …
We give polynomial-time quantum algorithms for three problems from computational algebraic number theory. The first is Pell's equation. Given a positive nonsquare integer d, Pell's equation is x2dy2 = 1 and the goal is to find its integer solutions. Factoring integers reduces to finding integer solutions of Pell's equation, but a reduction in the other direction is not known and appears more difficult. The second problem we solve is the principal ideal problem in real quadratic number fields. This problem, which is at least as hard as solving Pell's equation, is the one-way function underlying the Buchmann--Williams key exchange system, which is therefore broken by our quantum algorithm. Finally, assuming the generalized Riemann hypothesis, this algorithm can be used to compute the class group of a real quadratic number field.
ACM Digital Library