English
Related papers

Related papers: Cycles in the supersingular $\ell$-isogeny graph a…

200 papers

Computing endomorphism rings of supersingular elliptic curves is an important problem in computational number theory, and it is also closely connected to the security of some of the recently proposed isogeny-based cryptosystems. In this…

Number Theory · Mathematics 2020-06-17 Kirsten Eisentraeger , Sean Hallgren , Chris Leonardi , Travis Morrison , Jennifer Park

Loops and cycles play an important role in computing endomorphism rings of supersingular elliptic curves and related cryptosystems. For a supersingular elliptic curve $E$ defined over $\mathbb{F}_{p^2}$, if an imaginary quadratic order $O$…

Number Theory · Mathematics 2023-12-12 Guanju Xiao , Lixia Luo , Yingpu Deng

Supersingular elliptic curve isogeny graphs underlie isogeny-based cryptography. For isogenies of a single prime degree $\ell$, their structure has been investigated graph-theoretically. We generalise the notion of $\ell$-isogeny graphs to…

Number Theory · Mathematics 2025-12-05 Sarah Arpin , Ross Bowden , James Clements , Wissam Ghantous , Jason T. LeGrow , Krystal Maughan

An isogeny graph is a graph whose vertices are principally polarized abelian varieties and whose edges are isogenies between these varieties. In his thesis, Kohel described the structure of isogeny graphs for elliptic curves and showed that…

Number Theory · Mathematics 2019-02-20 Sorina Ionica , Emmanuel Thomé

Let $c<3p/16$ be a prime or $c=1$. Let $E$ be a $\mathbb{Z}[\sqrt{-cp}]$-oriented supersingular elliptic curve defined over $\mathbb{F}_{p^2}$. There exists a $c$-isogeny from $E$ to $E^p$ with kernel $G \subset E[c]$. Given an Eichler…

Number Theory · Mathematics 2025-07-15 Guanju Xiao , Zijian Zhou , Longjiang Qu

We present a deterministic and explicit algorithm to compute the endomorphism rings of supersingular elliptic curves. As an example we compute the endomorphism rings of all supersingular elliptic curves defined over characteristic…

Number Theory · Mathematics 2007-05-23 Juan Marcos Cerviño

The supersingular Endomorphism Ring problem is the following: given a supersingular elliptic curve, compute all of its endomorphisms. The presumed hardness of this problem is foundational for isogeny-based cryptography. The One Endomorphism…

Cryptography and Security · Computer Science 2023-10-17 Aurel Page , Benjamin Wesolowski

We give an algorithm for computing an inseparable endomorphism of a supersingular elliptic curve $E$ defined over $\mathbb F_{p^2}$, which, conditional on GRH, runs in expected $O(p^{1/2}(\log p)^2(\log\log p)^3)$ bit operations and…

Number Theory · Mathematics 2025-02-03 Jenny Fuselier , Annamaria Iezzi , Mark Kozek , Travis Morrison , Changningphaabi Namoijam

Let $p>3$ be a fixed prime. For a supersingular elliptic curve $E$ over $\mathbb{F}_p$ with $j$-invariant $j(E)\in \mathbb{F}_p\backslash\{0, 1728\}$, it is well known that the Frobenius map $\pi=((x,y)\mapsto (x^p, y^p))\in…

Number Theory · Mathematics 2019-07-30 Songsong Li , Yi Ouyang , Zheng Xu

We give a deterministic polynomial time algorithm to compute the endomorphism ring of a supersingular elliptic curve in characteristic p, provided that we are given two noncommuting endomorphisms and the factorization of the discriminant of…

Number Theory · Mathematics 2026-01-22 Kirsten Eisentraeger , Gabrielle Scullard

We present two algorithms to compute the endomorphism ring of an ordinary elliptic curve E defined over a finite field F_q. Under suitable heuristic assumptions, both have subexponential complexity. We bound the complexity of the first…

Number Theory · Mathematics 2012-06-26 Gaetan Bisson , Andrew V. Sutherland

An important open problem in supersingular isogeny-based cryptography is to produce, without a trusted authority, concrete examples of "hard supersingular curves" that is, equations for supersingular curves for which computing the…

We prove that the path-finding problem in $\ell$-isogeny graphs and the endomorphism ring problem for supersingular elliptic curves are equivalent under reductions of polynomial expected time, assuming the generalised Riemann hypothesis.…

Number Theory · Mathematics 2021-11-03 Benjamin Wesolowski

In this paper, we study the problem of sampling random supersingular elliptic curves with unknown endomorphism rings. This problem has recently gained considerable attention as many isogeny-based cryptographic protocols require such…

Quantum Physics · Physics 2026-03-24 Maher Mamah , Jake Doliskani , David Jao

The Deligne-Ogus-Shioda theorem guarantees the existence of isomorphisms between products of supersingular elliptic curves over finite fields. In this paper, we present methods for explicitly computing these isomorphisms in polynomial time,…

Number Theory · Mathematics 2025-03-31 Pierrick Gaudry , Julien Soumier , Pierre-Jean Spaenlehauer

We design a probabilistic algorithm for computing endomorphism rings of ordinary elliptic curves defined over finite fields that we prove has a subexponential runtime in the size of the base field, assuming solely the generalized Riemann…

Number Theory · Mathematics 2013-02-19 Gaetan Bisson

We introduce a special class of supersingular curves over $\mathbb{F}_{p^2}$, characterized by the existence of non-integer endomorphisms of small degree. A number of properties of this set is proved. Most notably, we show that when this…

Number Theory · Mathematics 2020-06-25 Jonathan Love , Dan Boneh

In supersingular isogeny-based cryptography, the path-finding problem reduces to the endomorphism ring problem. Can path-finding be reduced to knowing just one endomorphism? It is known that a small endomorphism enables polynomial-time…

We present a new algorithm for computing the endomorphism ring of an ordinary abelian surface over a finite field which is subexponential and generalizes an algorithm of Bisson and Sutherland for elliptic curves. The correctness of this…

Number Theory · Mathematics 2019-01-17 Caleb Springer

Let p>3 be a prime and let E, E' be supersingular elliptic curves over F_p. We want to construct an isogeny phi: E --> E'. The currently fastest algorithm for finding isogenies between supersingular elliptic curves solves this problem by…

Number Theory · Mathematics 2013-10-30 Christina Delfs , Steven D. Galbraith
‹ Prev 1 2 3 10 Next ›