Discrete Log Solver
One group per line: g,h,p separated by comma or space, e.g. 5,8,23 means solve 5^x = 8 (mod 23)
Method:
Solutions:
Formula:
Order of g:
Max results:
Max m digits:
Separator:
Calculation Result
Download CSV
| No. | Input (g,h,p) | Method | Solution x | Verify | Steps | Note |
|---|
Introduction to the tool and how to use it
An online discrete logarithm solver that finds the exponent x in g^x ≡ h (mod p). Enter one g,h,p per line and solve many cases at once.
Input format: one "g,h,p" per line separated by commas or spaces, for example
Three algorithms: BSGS (Baby-step Giant-step, the default - build a baby table of size m = ceil(sqrt(n)) then walk the giant steps), brute force (good for small p, with an iteration cap) and Pohlig-Hellman (for smooth p-1, factor n into prime powers and recombine with CRT). Choose "Compare all" to see the step counts side by side.
Automatic checks: the order of g is detected when you leave it blank; the tool verifies gcd(g,p) = 1 and whether p is prime, and uses h^n ≡ 1 to test whether h lies in the subgroup generated by g, reporting "No solution in the given range" clearly when it does not.
Verification: every computed x is checked with g^x mod p = h and the verification column shows pass or fail; optionally list all solutions x + k·n. All arithmetic uses BigInt with fast exponentiation, p up to 120 digits.
Input format: one "g,h,p" per line separated by commas or spaces, for example
5,8,23 means solve 5^x ≡ 8 (mod 23).Three algorithms: BSGS (Baby-step Giant-step, the default - build a baby table of size m = ceil(sqrt(n)) then walk the giant steps), brute force (good for small p, with an iteration cap) and Pohlig-Hellman (for smooth p-1, factor n into prime powers and recombine with CRT). Choose "Compare all" to see the step counts side by side.
Automatic checks: the order of g is detected when you leave it blank; the tool verifies gcd(g,p) = 1 and whether p is prime, and uses h^n ≡ 1 to test whether h lies in the subgroup generated by g, reporting "No solution in the given range" clearly when it does not.
Verification: every computed x is checked with g^x mod p = h and the verification column shows pass or fail; optionally list all solutions x + k·n. All arithmetic uses BigInt with fast exponentiation, p up to 120 digits.
Message board
All messages →-
No one has spoken up yet — want to go first?