English

The SEA algorithm for endomorphisms of supersingular elliptic curves

Number Theory 2025-01-28 v1

Abstract

For a prime p>3p{\,>\,}3 and a supersingular elliptic curve EE defined over Fp2\mathbb{F}_{p^2} with j(E){0,1728}{j(E)\notin\{0,1728\}}, consider an endomorphism α\alpha of EE represented as a composition of LL isogenies of degree at most dd. We prove that the trace of α\alpha may be computed in O(n4(logn)2+dLn3)O(n^4(\log n)^2 + dLn^3) bit operations, where n=log(p)n{\,=\,}\log(p), using a generalization of the SEA algorithm for computing the trace of the Frobenius endomorphism of an ordinary elliptic curve. When LO(logp)L\in O(\log p) and dO(1)d\in O(1), this complexity matches the heuristic complexity of the SEA algorithm. Our theorem is unconditional, unlike the complexity analysis of the SEA algorithm, since the kernel of an arbitrary isogeny of a supersingular elliptic curve is defined over an extension of constant degree, independent of pp. We also provide practical speedups, including a fast algorithm to compute the trace of α\alpha modulo pp.

Keywords

Cite

@article{arxiv.2501.16321,
  title  = {The SEA algorithm for endomorphisms of supersingular elliptic curves},
  author = {Travis Morrison and Lorenz Panny and Jana Sotáková and Michael Wills},
  journal= {arXiv preprint arXiv:2501.16321},
  year   = {2025}
}

Comments

16 pages, 1 figure