Related papers: A note on the security of CSIDH
Let $p>3$ be a prime and $E$ be a supersingular elliptic curve defined over $\mathbb{F}_{p^2}$. Let $c$ be a prime with $c < 3p/16$ and $G$ be a subgroup of $E[c]$ of order $c$. The pair $(E,G)$ is called a supersingular elliptic curve with…
We consider a quantum polynomial-time algorithm which solves the discrete logarithm problem for points on elliptic curves over $GF(2^m)$. We improve over earlier algorithms by constructing an efficient circuit for multiplying elements of…
Using methods from analytic number theory, for $m > 5$ and for $m = 4$, we obtain asymptotics with power-saving error terms for counts of elliptic curves with a cyclic $m$-isogeny up to quadratic twist over the rational numbers. For $m >…
An isogeny class of elliptic curves over a finite field is determined by a quadratic Weil polynomial. Gekeler has given a product formula, in terms of congruence considerations involving that polynomial, for the size of such an isogeny…
We establish a classification of the values of \( N \) for which an elliptic curve defined over \( \mathbb{Q} \) with square discriminant admits an \( N \)-isogeny. Furthermore, we determine the values of \( N \) for which two elliptic…
Given a prime q and a negative discriminant D, the CM method constructs an elliptic curve E/\Fq by obtaining a root of the Hilbert class polynomial H_D(X) modulo q. We consider an approach based on a decomposition of the ring class field…
We present a new GCD algorithm of two integers or polynomials. The algorithm is iterative and its time complexity is still $O(n \\log^2 n ~ log \\log n)$ for $n$-bit inputs.
Let F be the cubic field of discriminant -23 and O its ring of integers. Let Gamma be the arithmetic group GL_2 (O), and for any ideal n subset O let Gamma_0 (n) be the congruence subgroup of level n. In a previous paper, two of us (PG and…
For many hard computational problems, simple algorithms that run in time $2^n \cdot n^{O(1)}$ arise, say, from enumerating all subsets of a size-$n$ set. Finding (exponentially) faster algorithms is a natural goal that has driven much of…
We count the number of rational elliptic curves of bounded naive height that have a rational $N$-isogeny, for $N \in \{2,3,4,5,6,8,9,12,16,18\}$. For some $N$, this is done by generalizing a method of Harron and Snowden. For the remaining…
We introduce an algorithm that can be used to compute the canonical height of a point on an elliptic curve over the rationals in quasi-linear time. As in most previous algorithms, we decompose the difference between the canonical and the…
We indicate a strategy in order to construct bilinear multiplication algorithms of type Chudnovsky in large extensions of any finite field. In particular, by using the symmetric version of the generalization of Randriambololona specialized…
We study operators on a singular manifold, here of conical or edge type, and develop a new general approach of representing asymptotics of solutions to elliptic equations close to the singularities. The idea is to construct so-called…
Let $E_{\lambda}$ be the Legendre family of elliptic curves with equation $Y^2=X(X-1)(X-\lambda)$. Given a curve $\mathcal{C}$, satisfying a condition on the degrees of some of its coordinates and parametrizing $m$ points $P_1, \ldots, P_m…
The Fr\'{e}chet distance is a popular distance measure between curves $P$ and $Q$. Conditional lower bounds prohibit $(1 + \varepsilon)$-approximate Fr\'{e}chet distance computations in strongly subquadratic time, even when preprocessing…
As a subproduct of the Schoof-Elkies-Atkin algorithm to count points on elliptic curves defined over finite fields of characteristic p, there exists an algorithm that computes, for l an Elkies prime, l-torsion points in an extension of…
We present normal forms for elliptic curves over a field of characteristic $2$ analogous to Edwards normal form, and determine bases of addition laws, which provide strikingly simple expressions for the group law. We deduce efficient…
Orientations of supersingular elliptic curves encode the information of an endomorphism of the curve. Computing the full endomorphism ring is a known hard problem, so one might consider how hard it is to find one such orientation. We prove…
It has recently been shown that starting with a classical query algorithm (decision tree) and a guessing algorithm that tries to predict the query answers, we can design a quantum algorithm with query complexity $O(\sqrt{GT})$ where $T$ is…
Based on Arimoto's work in 1978, we propose an iterative algorithm for computing the capacity of a discrete memoryless classical-quantum channel with a finite input alphabet and a finite dimensional output, which we call the Blahut-Arimoto…