The supersingular isogeny problem in genus 2 and beyond
Abstract
Let and be supersingular principally polarized abelian varieties of dimension . For any prime , we give an algorithm that finds a path in the -isogeny graph in group operations on a classical computer, and calls to the Grover oracle on a quantum computer. The idea is to find paths from and to nodes that correspond to products of lower dimensional abelian varieties, and to recurse down in dimension until an elliptic path-finding algorithm (such as Delfs--Galbraith) can be invoked to connect the paths in dimension . In the general case where and are any two nodes in the graph, this algorithm presents an asymptotic improvement over all of the algorithms in the current literature. In the special case where and are a known and relatively small number of steps away from each other (as is the case in higher dimensional analogues of SIDH), it gives an asymptotic improvement over the quantum claw finding algorithms and an asymptotic improvement over the classical van Oorschot--Wiener algorithm.
Keywords
Cite
@article{arxiv.1912.00701,
title = {The supersingular isogeny problem in genus 2 and beyond},
author = {Craig Costello and Benjamin Smith},
journal= {arXiv preprint arXiv:1912.00701},
year = {2020}
}