## 数学代写|数论代写Number Theory代考|Trial division up to a small bound

In generating a random prime, most candidates $n$ will in fact be composite, and so it makes sense to cast these out as quickly as possible. Significant efficiency gains can be achieved by testing if a given candidate $n$ is divisible by any small primes up to a given bound $s$, before we subject $n$ to a MillerRabin test. This strategy makes sense, since for a small, “single precision” prime $p$, we can test if $p \mid n$ essentially in time $O(\operatorname{len}(n))$, while a single iteration of the Miller-Rabin test takes time $O\left(\operatorname{len}(n)^3\right)$ steps.

To be more precise, let us define the following algorithm $\operatorname{MRS}(n, t, s)$, which takes as input integers $n, t$, and $s$, with $n>1, t \geq 1$, and $s>1$ :
Algorithm $\operatorname{MRS}(n, t, s)$ :
for each prime $p \leq s$ do
if $p \mid n$ then
if $p=n$ then return true else return false
repeat $t$ times
$\alpha \leftarrow_R{1, \ldots, n-1}$
if $\alpha \notin L_n^{\prime}$ return false
return true

## 数学代写|数论代写Number Theory代考|Generating a random k-bit prime

In some applications, we want to generate a random prime of fixed sizea random 1024-bit prime, for example. More generally, let us consider the following problem: given integer $k \geq 2$, generate a random $k$-bit prime, that is, a prime in the interval $\left[2^{k-1}, 2^k\right)$.

Bertrand’s postulate (Theorem 5.7) implies that there exists a constant $c>0$ such that $\pi\left(2^k\right)-\pi\left(2^{k-1}\right) \geq c 2^{k-1} / k$ for all $k \geq 2$.

Now let us modify Algorithm RP so that it takes as input integer $k \geq 2$, and repeatedly generates a random $n$ in the interval $\left{2^{k-1}, \ldots, 2^k-1\right}$ until IsPrime $(n)$ returns true. Let us call this variant Algorithm $\mathrm{RP}^{\prime}$. Further, let us implement IsPrime $(\cdot)$ as $M R(\cdot, t)$, for some auxiliary parameter $t$, and define $\gamma^{\prime}(k, t)$ to be the probability that the output of Algorithm $\mathrm{RP}^{\prime}$ – with this implementation of IsPrime – is composite.
Then using exactly the same reasoning as above,
$$\gamma^{\prime}(k, t) \leq 4^{-t} \frac{2^{k-1}}{\pi\left(2^k\right)-\pi\left(2^{k-1}\right)}=O\left(4^{-t} k\right)$$

## 数学代写|数论代写Number Theory代考|Trial division up to a small bound

$\alpha \leftarrow_R 1, \ldots, n-1$

## 数学代写|数论代写Number Theory代考|Generating a random k-bit prime

Bertrand 的假设（定理 5.7）意味着存在一个常数 $c>0$ 这样 $\pi\left(2^k\right)-\pi\left(2^{k-1}\right) \geq c 2^{k-1} / k$ 对全 部 $k \geq 2$.

$\backslash$ left 缺少或无法识别的分隔符 直到 IsPrime $(n)$ 返回真。让我们称这种变体算法 $\mathrm{RP}^{\prime}$. 进一步，让我们实现 $\operatorname{IsPrime}(\cdot)$ 作为 $M R(\cdot, t)$ ， 对于一些辅助参数 $t$, 并定义 $\gamma^{\prime}(k, t)$ 是算法输 出的概率 $R^{\prime}$ – 使用 IsPrime 的这个实现 – 是复合的。

$$\gamma^{\prime}(k, t) \leq 4^{-t} \frac{2^{k-1}}{\pi\left(2^k\right)-\pi\left(2^{k-1}\right)}=O\left(4^{-t} k\right)$$

