Related papers: Computing supersingular endomorphism rings using i…
We construct new families of elliptic curves over \(\FF_{p^2}\) with efficiently computable endomorphisms, which can be used to accelerate elliptic curve-based cryptosystems in the same way as Gallant-Lambert-Vanstone (GLV) and…
Elliptic curves have a well-known and explicit theory for the construction and application of endomorphisms, which can be applied to improve performance in scalar multiplication. Recent work has extended these techniques to hyperelliptic…
Let $p>3$ be a prime and $E$ be a supersingular elliptic curve defined over $\mathbb{F}_{p^2}$. Let $c$ be a prime with $c < 3p/16$ and $G$ be a subgroup of $E[c]$ of order $c$. The pair $(E,G)$ is called a supersingular elliptic curve with…
In supersingular isogeny-based cryptography, the path-finding problem reduces to the endomorphism ring problem. Can path-finding be reduced to knowing just one endomorphism? It is known that a small endomorphism enables polynomial-time…
Generalizing a method of Sutherland and the author for elliptic curves, we design a subexponential algorithm for computing the endomorphism rings of ordinary abelian varieties of dimension two over finite fields. Although its correctness…
This paper presents algorithmic approaches to study superspecial hyperelliptic curves. The algorithms proposed in this paper are: an algorithm to enumerate superspecial hyperelliptic curves of genus $g$ over finite fields $\mathbb{F}_q$,…
For an elliptic curve $E$ over a finite field $\F_q$, where $q$ is a prime power, we propose new algorithms for testing the supersingularity of $E$. Our algorithms are based on the Polynomial Identity Testing (PIT) problem for the $p$-th…
We address complexity issues for linear differential equations in characteristic $p>0$: resolution and computation of the $p$-curvature. For these tasks, our main focus is on algorithms whose complexity behaves well with respect to $p$. We…
We present several new algorithms to evaluate modular polynomials of level $\ell$ modulo a prime $p$ on an input $j$. More precisely, we introduce two new generic algorithms, sharing the following similarities: they are based on a CRT…
Assuming GRH, we present an algorithm which inputs a prime $p$ and outputs the set of fundamental discriminants $D<0$ such that the reduction map modulo a prime above $p$ from elliptic curves with CM by $\order_{D}$ to supersingular…
We characterize the possible groups $E(\mathbb{Z}/N\mathbb{Z})$ arising from elliptic curves over $\mathbb{Z}/N\mathbb{Z}$ in terms of the groups $E(\mathbb{F}_p)$, with $p$ varying among the prime divisors of $N$. This classification is…
We consider algebraic affine and projective curves of Edwards \cite{E, SkOdProj} over a finite field $\text{F}_{p^n}$. Most cryptosystems of the modern cryptography \cite{SkBlock} can be naturally transform into elliptic curves \cite{Kob}.…
Let $E$ be an elliptic curve defined over a number field $K$. We say that a prime number $p$ is exceptional for $(E,K)$ if $E$ admits a $p$-isogeny defined over $K$. The so-called exceptional set of all such prime numbers is finite if and…
We introduce a special class of supersingular curves over $\mathbb{F}_{p^2}$, characterized by the existence of non-integer endomorphisms of small degree. A number of properties of this set is proved. Most notably, we show that when this…
Let $p$ be a prime, $E$ be a supersingular elliptic curve defined over $\bar{\mathbb{F}}_p$, and $\mathscr{O}$ be its (geometric) endomorphism ring. Earlier results of Chevyrev-Galbraith and Goren-Love have shown that the successive minima…
We give a detailed account of the use of $\mathbb{Q}$-curve reductions to construct elliptic curves over $\mathbb{F}\_{p^2}$ with efficiently computable endomorphisms, which can be used to accelerate elliptic curve-based cryptosystems in…
Tate's algorithm tells us that for an elliptic curve $E$ over a local field $K$ of residue characteristic $\geq 5$, $E/K$ has potentially good reduction if and only if $\text{ord}(j_E)\geq 0$. It also tells us that when $E/K$ is semistable…
State-of-the-art parallel sorting algorithms for distributed-memory architectures are based on computing a balanced partitioning via sampling and histogramming. By finding samples that partition the sorted keys into evenly-sized chunks,…
Let p>3 be a prime and let E, E' be supersingular elliptic curves over F_p. We want to construct an isogeny phi: E --> E'. The currently fastest algorithm for finding isogenies between supersingular elliptic curves solves this problem by…
An important open problem in supersingular isogeny-based cryptography is to produce, without a trusted authority, concrete examples of "hard supersingular curves" that is, equations for supersingular curves for which computing the…