相关论文: Finding Orientations of Supersingular Elliptic Cur…
Computing endomorphism rings of supersingular elliptic curves is an important problem in computational number theory, and it is also closely connected to the security of some of the recently proposed isogeny-based cryptosystems. In this…
Let $c<3p/16$ be a prime or $c=1$. Let $E$ be a $\mathbb{Z}[\sqrt{-cp}]$-oriented supersingular elliptic curve defined over $\mathbb{F}_{p^2}$. There exists a $c$-isogeny from $E$ to $E^p$ with kernel $G \subset E[c]$. Given an Eichler…
We present a deterministic and explicit algorithm to compute the endomorphism rings of supersingular elliptic curves. As an example we compute the endomorphism rings of all supersingular elliptic curves defined over characteristic…
Let O be a maximal order in the quaternion algebra B_p over Q ramified at p and infinity. The paper is about the computational problem: Construct a supersingular elliptic curve E over F_p such that End(E) = O. We present an algorithm that…
Let $p>3$ be a prime and $E$ be a supersingular elliptic curve defined over $\mathbb{F}_{p^2}$. Let $c$ be a prime with $c < 3p/16$ and $G$ be a subgroup of $E[c]$ of order $c$. The pair $(E,G)$ is called a supersingular elliptic curve with…
We give an algorithm for computing an inseparable endomorphism of a supersingular elliptic curve $E$ defined over $\mathbb F_{p^2}$, which, conditional on GRH, runs in expected $O(p^{1/2}(\log p)^2(\log\log p)^3)$ bit operations and…
In supersingular isogeny-based cryptography, the path-finding problem reduces to the endomorphism ring problem. Can path-finding be reduced to knowing just one endomorphism? It is known that a small endomorphism enables polynomial-time…
We call an order $O$ in a quadratic field $K$ odd (resp. even) if its discriminant is an odd (resp. even) integer. We call an elliptic curve $E$ over the field $C$ of complex numbers with CM odd (resp. even) if its endomorphism ring…
Loops and cycles play an important role in computing endomorphism rings of supersingular elliptic curves and related cryptosystems. For a supersingular elliptic curve $E$ defined over $\mathbb{F}_{p^2}$, if an imaginary quadratic order $O$…
We present two algorithms to compute the endomorphism ring of an ordinary elliptic curve E defined over a finite field F_q. Under suitable heuristic assumptions, both have subexponential complexity. We bound the complexity of the first…
Given an elliptic curve E over a field of positive characteristic p, we consider how to efficiently determine whether E is ordinary or supersingular. We analyze the complexity of several existing algorithms and then present a new approach…
For most algorithms dealing with sets of points in the plane, the only relevant information carried by the input is the combinatorial configuration of the points: the orientation of each triple of points in the set (clockwise,…
In this paper, we add the information of level structure to supersingular elliptic curves and study these objects with the motivation of isogeny-based cryptography. Supersingular elliptic curves with level structure map to Eichler orders in…
For a prime $p{\,>\,}3$ and a supersingular elliptic curve $E$ defined over $\mathbb{F}_{p^2}$ with ${j(E)\notin\{0,1728\}}$, consider an endomorphism $\alpha$ of $E$ represented as a composition of $L$ isogenies of degree at most $d$. We…
It is well known that there is a one-to-one correspondence between supersingular $j$-invariants up to the action of $\text{Gal}(\mathbb{F}_{p^2}/\mathbb{F}_p)$ and type classes of maximal orders in $B_{p,\infty}$ by Deuring's theorem.…
We present a new algorithm for computing the endomorphism ring of an ordinary abelian surface over a finite field which is subexponential and generalizes an algorithm of Bisson and Sutherland for elliptic curves. The correctness of this…
Chevyrev and Galbraith recently devised an algorithm which inputs a maximal order of the quaternion algebra ramified at one prime and infinity and constructs a supersingular elliptic curve whose endomorphism ring is precisely this maximal…
Elliptic curves have a well-known and explicit theory for the construction and application of endomorphisms, which can be applied to improve performance in scalar multiplication. Recent work has extended these techniques to hyperelliptic…
Given an elliptic curve ${\mathcal E}$ over a field $K$ it is a challenging problem to write down explicit elements of its endomorphism ring ${\rm End}({\mathcal E});$ the problem amounts to find all possible solutions to a functional…
We give a deterministic polynomial time algorithm to compute the endomorphism ring of a supersingular elliptic curve in characteristic p, provided that we are given two noncommuting endomorphisms and the factorization of the discriminant of…