相关论文: The SEA algorithm for endomorphisms of supersingul…
Computing endomorphism rings of supersingular elliptic curves is an important problem in computational number theory, and it is also closely connected to the security of some of the recently proposed isogeny-based cryptosystems. In this…
We give an algorithm for computing an inseparable endomorphism of a supersingular elliptic curve $E$ defined over $\mathbb F_{p^2}$, which, conditional on GRH, runs in expected $O(p^{1/2}(\log p)^2(\log\log p)^3)$ bit operations and…
Let $p>3$ be a fixed prime. For a supersingular elliptic curve $E$ over $\mathbb{F}_p$ with $j$-invariant $j(E)\in \mathbb{F}_p\backslash\{0, 1728\}$, it is well known that the Frobenius map $\pi=((x,y)\mapsto (x^p, y^p))\in…
Loops and cycles play an important role in computing endomorphism rings of supersingular elliptic curves and related cryptosystems. For a supersingular elliptic curve $E$ defined over $\mathbb{F}_{p^2}$, if an imaginary quadratic order $O$…
Given an elliptic curve E over a field of positive characteristic p, we consider how to efficiently determine whether E is ordinary or supersingular. We analyze the complexity of several existing algorithms and then present a new approach…
Let O be a maximal order in the quaternion algebra B_p over Q ramified at p and infinity. The paper is about the computational problem: Construct a supersingular elliptic curve E over F_p such that End(E) = O. We present an algorithm that…
We present here a formula for expressing the trace of the Frobenius endomorphism of an elliptic curve $E$ over $\mathbb{F}_q$ satisfying $j(E)\neq 0,1728$ and $q\equiv 1 \pmod{12}$ in terms of special values of Gaussian hypergeometric…
Let $c<3p/16$ be a prime or $c=1$. Let $E$ be a $\mathbb{Z}[\sqrt{-cp}]$-oriented supersingular elliptic curve defined over $\mathbb{F}_{p^2}$. There exists a $c$-isogeny from $E$ to $E^p$ with kernel $G \subset E[c]$. Given an Eichler…
We present two algorithms to compute the endomorphism ring of an ordinary elliptic curve E defined over a finite field F_q. Under suitable heuristic assumptions, both have subexponential complexity. We bound the complexity of the first…
Let E be an elliptic curve with complex multiplication by R, where R is an order of discriminant D<-4 of an imaginary quadratic field K . If a prime number p is decomposed completely in the ring class field associated with R, then E has…
Let p>3 be a prime and let E, E' be supersingular elliptic curves over F_p. We want to construct an isogeny phi: E --> E'. The currently fastest algorithm for finding isogenies between supersingular elliptic curves solves this problem by…
We present a specialized point-counting algorithm for a class of elliptic curves over F\_{p^2} that includes reductions of quadratic Q-curves modulo inert primes and, more generally, any elliptic curve over F\_{p^2} with a low-degree…
Orientations of supersingular elliptic curves encode the information of an endomorphism of the curve. Computing the full endomorphism ring is a known hard problem, so one might consider how hard it is to find one such orientation. We prove…
We study the problem of generating the endomorphism ring of a supersingular elliptic curve by two cycles in $\ell$-isogeny graphs. We prove a necessary and sufficient condition for the two endomorphisms corresponding to two cycles to be…
We provide two families of algorithms to compute characteristic polynomials of endomorphisms and norms of isogenies of Drinfeld modules. Our algorithms work for Drinfeld modules of any rank, defined over any base curve. When the base curve…
Given a supersingular elliptic curve E and a non-scalar endomorphism $\alpha$ of E, we prove that the endomorphism ring of E can be computed in classical time about disc(Z[$\alpha$])^1/4 , and in quantum subexponential time, assuming the…
An elliptic curve $E$ defined over a $p$-adic field $K$ with a $p$-isogeny $\phi:E\rightarrow E^\prime$ comes equipped with an invariant $\alpha_{\phi/K}$ that measures the valuation of the leading term of the formal group homomorphism…
The SEA algorithm for computing the cardinality of elliptic curves over finite fields in many characteristic uses modular polynomials. These polynomials come into different flavors, and methods to compute them flourished. Once equipped with…
We present a deterministic and explicit algorithm to compute the endomorphism rings of supersingular elliptic curves. As an example we compute the endomorphism rings of all supersingular elliptic curves defined over characteristic…
In this paper, we investigate extreme values of $\omega(E(\mathbb{F}_p))$, where $E/\mathbb{Q}$ is an elliptic curve with complex multiplication and $\omega$ is the number-of-distinct-prime-divisors function. For fixed $\gamma > 1$, we…