English
Related papers

Related papers: Failing to hash into supersingular isogeny graphs

200 papers

We prove that the path-finding problem in $\ell$-isogeny graphs and the endomorphism ring problem for supersingular elliptic curves are equivalent under reductions of polynomial expected time, assuming the generalised Riemann hypothesis.…

Number Theory · Mathematics 2021-11-03 Benjamin Wesolowski

In this paper, we study the problem of sampling random supersingular elliptic curves with unknown endomorphism rings. This problem has recently gained considerable attention as many isogeny-based cryptographic protocols require such…

Quantum Physics · Physics 2026-03-24 Maher Mamah , Jake Doliskani , David Jao

The supersingular Endomorphism Ring problem is the following: given a supersingular elliptic curve, compute all of its endomorphisms. The presumed hardness of this problem is foundational for isogeny-based cryptography. The One Endomorphism…

Cryptography and Security · Computer Science 2023-10-17 Aurel Page , Benjamin Wesolowski

Computing endomorphism rings of supersingular elliptic curves is an important problem in computational number theory, and it is also closely connected to the security of some of the recently proposed isogeny-based cryptosystems. In this…

Number Theory · Mathematics 2020-06-17 Kirsten Eisentraeger , Sean Hallgren , Chris Leonardi , Travis Morrison , Jennifer Park

In this paper, we study isogeny graphs of supersingular elliptic curves. Supersingular isogeny graphs were introduced as a hard problem into cryptography by Charles, Goren, and Lauter for the construction of cryptographic hash functions…

In supersingular isogeny-based cryptography, the path-finding problem reduces to the endomorphism ring problem. Can path-finding be reduced to knowing just one endomorphism? It is known that a small endomorphism enables polynomial-time…

An isogeny graph is a graph whose vertices are principally polarized abelian varieties and whose edges are isogenies between these varieties. In his thesis, Kohel described the structure of isogeny graphs for elliptic curves and showed that…

Number Theory · Mathematics 2019-02-20 Sorina Ionica , Emmanuel Thomé

In this paper, we prove that the supersingular isogeny problem (Isogeny), endomorphism ring problem (EndRing) and maximal order problem (MaxOrder) are equivalent under probabilistic polynomial time reductions, unconditionally. Isogeny-based…

Cryptography and Security · Computer Science 2026-02-03 Arthur Herlédan Le Merdy , Benjamin Wesolowski

We study the problem of generating the endomorphism ring of a supersingular elliptic curve by two cycles in $\ell$-isogeny graphs. We prove a necessary and sufficient condition for the two endomorphisms corresponding to two cycles to be…

The Isogeny to Endomorphism Ring Problem (IsERP) asks to compute the endomorphism ring of the codomain of an isogeny between supersingular curves in characteristic $p$ given only a representation for this isogeny, i.e. some data and an…

Cryptography and Security · Computer Science 2023-06-02 Mingjie Chen , Muhammad Imran , Gábor Ivanyos , Péter Kutas , Antonin Leroux , Christophe Petit

We introduce the notion of isolated genus two curves. As there is no known efficient algorithm to explicitly construct isogenies between two genus two curves with large conductor gap, the discrete log problem (DLP) cannot be efficiently…

Number Theory · Mathematics 2012-02-28 Wenhan Wang

The breakthrough of achieving fully homomorphic encryption sparked enormous studies on where and how to apply homomorphic encryption schemes so that operations can be performed on encrypted data without the secret key while still obtaining…

Cryptography and Security · Computer Science 2021-06-28 Yang Li

An isogeny between elliptic curves is an algebraic morphism which is a group homomorphism. Many applications in cryptography require evaluating large degree isogenies between elliptic curves efficiently. For ordinary curves of the same…

Number Theory · Mathematics 2014-02-12 David Jao , Vladimir Soukharev

This paper contains a survey of supersingular isogeny graphs associated to supersingular elliptic curves and their various applications to cryptography. Within limitation of space, we attempt to address a broad audience and make this part…

Number Theory · Mathematics 2025-06-04 Eyal Z. Goren , Jonathan R. Love

Hash functions map data of arbitrary length to data of predetermined length. Good hash functions are hard to predict, making them useful in cryptography. We are interested in the elliptic curve CGL hash function, which maps a bitstring to…

Cryptography and Security · Computer Science 2021-08-17 Dhruv Bhatia , Kara Fagerstrom , Maximillian Watson

We initiate the study of computational problems on elliptic curve isogeny graphs defined over RSA moduli. We conjecture that several variants of the neighbor-search problem over these graphs are hard, and provide a comprehensive list of…

Number Theory · Mathematics 2019-05-15 Salim Ali Altug , Yilei Chen

Supersingular elliptic curve isogeny graphs underlie isogeny-based cryptography. For isogenies of a single prime degree $\ell$, their structure has been investigated graph-theoretically. We generalise the notion of $\ell$-isogeny graphs to…

Number Theory · Mathematics 2025-12-05 Sarah Arpin , Ross Bowden , James Clements , Wissam Ghantous , Jason T. LeGrow , Krystal Maughan

Isogenies, the mappings of elliptic curves, have become a useful tool in cryptology. These mathematical objects have been proposed for use in computing pairings, constructing hash functions and random number generators, and analyzing the…

Cryptography and Security · Computer Science 2009-10-29 Daniel Shumow

Fix a prime number $\ell$. Graphs of isogenies of degree a power of $\ell$ are well-understood for elliptic curves, but not for higher-dimensional abelian varieties. We study the case of absolutely simple ordinary abelian varieties over a…

Number Theory · Mathematics 2016-10-03 Ernest Hunter Brooks , Dimitar Jetchev , Benjamin Wesolowski

Given two elliptic curves over a finite field having the same cardinality and endomorphism ring, it is known that the curves admit an isogeny between them, but finding such an isogeny is believed to be computationally difficult. The fastest…

Quantum Physics · Physics 2018-04-17 Andrew M. Childs , David Jao , Vladimir Soukharev
‹ Prev 1 2 3 10 Next ›