Results 1 
3 of
3
A Simplified Quadratic Frobenius Primality Test
, 2005
"... The publication of the quadratic Frobenius primality test [6] has stimulated a lot of research, see e.g. [4, 10, 11]. In this test as well as in the MillerRabin test [13], a composite number may be declared as probably prime. Repeating several tests decreases that error probability. While most of t ..."
Abstract

Cited by 1 (0 self)
 Add to MetaCart
The publication of the quadratic Frobenius primality test [6] has stimulated a lot of research, see e.g. [4, 10, 11]. In this test as well as in the MillerRabin test [13], a composite number may be declared as probably prime. Repeating several tests decreases that error probability. While most of the above research papers focus on minimising the error probability as a function of the number of tests (or, more generally, of the computational e ort) asymptotically, we present a simplified variant SQFT of the quadratic Frobenius test. This test is so simple that it can easily be implemented on a smart card. During prime number generation, a large number of composite numbers must be tested before a (probable) prime is found. Therefore we need a fast test, such as the MillerRabin test with a small basis, to rule out most prime candidates quickly before a promising candidate will be tested with a more sophisticated variant of the QFT. Our test SQFT makes optimum use of the information gathered by a previous MillerRabin test. It has run time equivalent to two MillerRabin tests; and it achieves a worstcase error probability of 2 −12t with t tests. Most cryptographic standards require an averagecase error probability of at most 2 −80 or 2 −100, see e.g. [7], when prime numbers are generated in public key systems. Our test SQFT achieves an averagecase error probability of 2 −134 with two test rounds for 500−bit primes. We also present a more sophisticated version SQFT3 of our test that has run time and worstcase error probability comparable to the test EQFTwc presented in [4] in all cases. The test SQFT3 avoids the computation of cubic residuosity symbols, as required in the test EQFTwc.