Computing supersingular endomorphism rings using inseparable endomorphisms

被引:0
|
作者
Fuselier, Jenny [1 ]
Iezzi, Annamaria [2 ,3 ,4 ]
Kozek, Mark [5 ]
Morrison, Travis [6 ]
Namoijam, Changningphaabi [7 ]
机构
[1] High Point Univ, Dept Math Sci, High Point, NC 27268 USA
[2] Univ Grenoble Alpes, CNRS, Grenoble INP, LJK, F-38000 Grenoble, France
[3] Univ Napoli Federico II, Dipartimento Matemat & Applicazioni, I-80126 Naples, Italy
[4] Univ Polynesie Francaise, Lab GAATI, F-98702 Faaa, France
[5] Whittier Coll, Dept Math & Comp Sci, Whittier, CA 90601 USA
[6] Virginia Tech, Dept Math, Blacksburg, VA 24060 USA
[7] Colby Coll, Dept Math, Waterville, ME 04901 USA
基金
美国国家科学基金会;
关键词
Supersingular elliptic curves; Quaternion algebras; Cryptography; MODULAR-FORMS;
D O I
10.1016/j.jalgebra.2025.01.012
中图分类号
O1 [数学];
学科分类号
0701 ; 070101 ;
摘要
We give an algorithm for computing an inseparable endomorphism of a supersingular elliptic curve E defined over Fp2, which, conditional on GRH, runs in expected O(p1/2(log p)2(log log p)3) bit operations and requires O((logp)2) storage. This matches the time and storage complexity of the best conditional algorithms for computing a nontrivial supersingular endomorphism, such as those of Eisentr & auml;ger-Hallgren-Leonardi-Morrison-Park and Delfs- Galbraith. Unlike these prior algorithms, which require two paths from E to a curve defined over Fp, the algorithm we introduce only requires one; thus when combined with the algorithm of Corte-Real Santos-Costello-Shi, our algorithm will be faster in practice. Moreover, our algorithm produces endomorphisms with predictable discriminants, enabling us to prove properties about the orders they generate. With two calls to our algorithm, we can provably compute a Bass sub order of End(E). This result is then used in an algorithm for computing a basis for End(E) with the same time complexity, assuming GRH. We also argue that End(E) can be computed using O(1) calls to our algorithm along with polynomial overhead, conditional on a heuristic assumption about the distribution of the discriminants of these endomorphisms. Conditional on GRH and this additional heuristic, this yields a O(p1/2(logp)2(log log p)3) algorithm for computing End(E) requiring O((logp)2) storage. (c) 2025 Elsevier Inc. All rights are reserved, including those for text and data mining, AI training, and similar technologies.
引用
收藏
页码:145 / 189
页数:45
相关论文
共 50 条
  • [1] Supersingular Isogeny Graphs and Endomorphism Rings: Reductions and Solutions
    Eisentrager, Kirsten
    Hallgren, Sean
    Lauter, Kristin
    Morrison, Travis
    Petit, Christophe
    ADVANCES IN CRYPTOLOGY - EUROCRYPT 2018, PT III, 2018, 10822 : 329 - 368
  • [2] Endomorphism rings of supersingular elliptic curves over Fp
    Li, Songsong
    Ouyang, Yi
    Xu, Zheng
    FINITE FIELDS AND THEIR APPLICATIONS, 2020, 62
  • [3] ENDOMORPHISM RINGS OF SUPERSINGULAR ELLIPTIC CURVES OVER Fp AND BINARY QUADRATIC FORMS
    Xiao, Guanju
    Zhou, Zijian
    Deng, Yingpu
    Qu, Longjiang
    ADVANCES IN MATHEMATICS OF COMMUNICATIONS, 2024,
  • [4] ENDOMORPHISM RINGS OF SUPERSINGULAR ELLIPTIC CURVES OVER Fp AND BINARY QUADRATIC FORMS
    Xiao, Guanju
    Zhou, Zijian
    Deng, Yingpu
    Qu, Longjiang
    ADVANCES IN MATHEMATICS OF COMMUNICATIONS, 2025, 19 (02) : 698 - 715
  • [5] The Supersingular Endomorphism Ring and One Endomorphism Problems are Equivalent
    Page, Aurel
    Wesolowski, Benjamin
    ADVANCES IN CRYPTOLOGY, PT VII, EUROCRYPT 2024, 2024, 14657 : 388 - 417
  • [6] The Supersingular Endomorphism Ring and One Endomorphism Problems are Equivalent
    Page, Aurel
    Wesolowski, Benjamin
    ADVANCES IN CRYPTOLOGY, PT VI, EUROCRYPT 2024, 2024, 14656 : 388 - 417
  • [7] Orientations and the Supersingular Endomorphism Ring Problem
    Wesolowski, Benjamin
    ADVANCES IN CRYPTOLOGY - EUROCRYPT 2022, PT III, 2022, 13277 : 345 - 371
  • [8] Computing endomorphism rings and Frobenius matrices of Drinfeld modules
    Garai, Sumita
    Papikian, Mihran
    JOURNAL OF NUMBER THEORY, 2022, 237 : 145 - 164
  • [9] COMPUTING WITH ENDOMORPHISM-RINGS OF MODULAR-REPRESENTATIONS
    SCHNEIDER, GJA
    JOURNAL OF SYMBOLIC COMPUTATION, 1990, 9 (5-6) : 607 - 636
  • [10] Computing endomorphism rings of elliptic curves under the GRH
    Bisson, Gaetan
    JOURNAL OF MATHEMATICAL CRYPTOLOGY, 2011, 5 (02) : 101 - 113