Related papers: Computing isogenies between supersingular elliptic…
Given an elliptic curve E over a field of positive characteristic p, we consider how to efficiently determine whether E is ordinary or supersingular. We analyze the complexity of several existing algorithms and then present a new approach…
We survey algorithms for computing isogenies between elliptic curves defined over a field of characteristic either 0 or a large prime. We introduce a new algorithm that computes an isogeny of degree $\ell$ ($\ell$ different from the…
In this paper, we study isogeny graphs of supersingular elliptic curves. Supersingular isogeny graphs were introduced as a hard problem into cryptography by Charles, Goren, and Lauter for the construction of cryptographic hash functions…
We propose an algorithm that calculates isogenies between elliptic curves defined over an extension $K$ of $\mathbb{Q}_2$. It consists in efficiently solving with a logarithmic loss of $2$-adic precision the first order differential…
An isogeny between elliptic curves is an algebraic morphism which is a group homomorphism. Many applications in cryptography require evaluating large degree isogenies between elliptic curves efficiently. For ordinary curves of the same…
Computing endomorphism rings of supersingular elliptic curves is an important problem in computational number theory, and it is also closely connected to the security of some of the recently proposed isogeny-based cryptosystems. In this…
A low storage algorithm for constructing isogenies between ordinary elliptic curves was proposed by Galbraith, Hess and Smart (GHS). We give an improvement of this algorithm by modifying the pseudorandom walk so that lower-degree isogenies…
Let $p>3$ be a fixed prime. For a supersingular elliptic curve $E$ over $\mathbb{F}_p$ with $j$-invariant $j(E)\in \mathbb{F}_p\backslash\{0, 1728\}$, it is well known that the Frobenius map $\pi=((x,y)\mapsto (x^p, y^p))\in…
Loops and cycles play an important role in computing endomorphism rings of supersingular elliptic curves and related cryptosystems. For a supersingular elliptic curve $E$ defined over $\mathbb{F}_{p^2}$, if an imaginary quadratic order $O$…
We introduce a special class of supersingular curves over $\mathbb{F}_{p^2}$, characterized by the existence of non-integer endomorphisms of small degree. A number of properties of this set is proved. Most notably, we show that when this…
Let O be a maximal order in the quaternion algebra B_p over Q ramified at p and infinity. The paper is about the computational problem: Construct a supersingular elliptic curve E over F_p such that End(E) = O. We present an algorithm that…
Let $\mathcal{E}/\mathbb{F}_q$ be an elliptic curve, and $P$ a point in $\mathcal{E}(\mathbb{F}_q)$ of prime order $\ell$. V\'elu's formulae let us compute a quotient curve $\mathcal{E}' = \mathcal{E}/\langle{P}\rangle$ and rational maps…
We describe the neighborhood of the vertex $[E_0]$ (resp. $[E_{1728}]$) in the $\ell$-isogeny graph $\mathcal{G}_\ell(\mathbb{F}_{p^2}, -2p)$ of supersingular elliptic curves over the finite field $\mathbb{F}_{p^2}$ when $p>3\ell^2$ (resp.…
Consider two elliptic curves $E,E'$ defined over the finite field $\mathbb{F}_q$, and suppose that there exists an isogeny $\psi$ between $E$ and $E'$. We propose an algorithm that determines $\psi$ from the knowledge of $E$, $E'$ and of…
In this paper, we add the information of level structure to supersingular elliptic curves and study these objects with the motivation of isogeny-based cryptography. Supersingular elliptic curves with level structure map to Eichler orders in…
We will describe an algorithm to construct an elliptic curve $E_{f_q}$ over some prime field $\mathbb{F}_p$ such that such that $|E_{f_q}(\mathbb{F}_p)| = f_q$, where $f_q$ is a probable Fibonacci prime for some prime index $q$. The…
Given two elliptic curves over a finite field having the same cardinality and endomorphism ring, it is known that the curves admit an isogeny between them, but finding such an isogeny is believed to be computationally difficult. The fastest…
Supersingular elliptic curve isogeny graphs underlie isogeny-based cryptography. For isogenies of a single prime degree $\ell$, their structure has been investigated graph-theoretically. We generalise the notion of $\ell$-isogeny graphs to…
Let E be an elliptic curve over a number field K which admits a cyclic p-isogeny with p odd and semistable at primes above p. We determine the root number and the parity of the p-Selmer rank for E/K, in particular confirming the parity…
Let $c<3p/16$ be a prime or $c=1$. Let $E$ be a $\mathbb{Z}[\sqrt{-cp}]$-oriented supersingular elliptic curve defined over $\mathbb{F}_{p^2}$. There exists a $c$-isogeny from $E$ to $E^p$ with kernel $G \subset E[c]$. Given an Eichler…