Supersingular Isogeny Graphs and Endomorphism Rings: Reductions and Solutions

被引:58
|
作者
Eisentrager, Kirsten [1 ]
Hallgren, Sean [2 ]
Lauter, Kristin [3 ]
Morrison, Travis [1 ]
Petit, Christophe [4 ]
机构
[1] Penn State Univ, Dept Math, University Pk, PA 16802 USA
[2] Penn State Univ, Dept Comp Sci & Engn, University Pk, PA 16802 USA
[3] Microsoft Res, Redmond, WA USA
[4] Univ Birmingham, Birmingham, W Midlands, England
来源
ADVANCES IN CRYPTOLOGY - EUROCRYPT 2018, PT III | 2018年 / 10822卷
基金
美国国家科学基金会; 英国工程与自然科学研究理事会;
关键词
ALGORITHM;
D O I
10.1007/978-3-319-78372-7_11
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we study several related computational problems for supersingular elliptic curves, their isogeny graphs, and their endomorphism rings. We prove reductions between the problem of path finding in the l-isogeny graph, computing maximal orders isomorphic to the endomorphism ring of a supersingular elliptic curve, and computing the endomorphism ring itself. We also give constructive versions of Deuring's correspondence, which associates to a maximal order in a certain quaternion algebra an isomorphism class of supersingular elliptic curves. The reductions are based on heuristics regarding the distribution of norms of elements in quaternion algebras. We show that conjugacy classes of maximal orders have a representative of polynomial size, and we define a way to represent endomorphism ring generators in a way that allows for efficient evaluation at points on the curve. We relate these problems to the security of the Charles-Goren-Lauter hash function. We provide a collision attack for special but natural parameters of the hash function and prove that for general parameters its preimage and collision resistance are also equivalent to the endomorphism ring computation problem.
引用
收藏
页码:329 / 368
页数:40
相关论文
共 50 条
  • [1] Orienting supersingular isogeny graphs
    Colo, Leonardo
    Kohel, David
    JOURNAL OF MATHEMATICAL CRYPTOLOGY, 2020, 14 (01) : 414 - 437
  • [2] Supersingular isogeny graphs in cryptography
    Lauter, Kristin E.
    Petit, Christophe
    SURVEYS IN COMBINATORICS 2019, 2019, 456 : 143 - 165
  • [3] The supersingular isogeny path and endomorphism ring problems are equivalent
    Wesolowski, Benjamin
    2021 IEEE 62ND ANNUAL SYMPOSIUM ON FOUNDATIONS OF COMPUTER SCIENCE (FOCS 2021), 2022, : 1100 - 1111
  • [4] Sandpile groups of supersingular isogeny graphs
    Munier, Nathanael
    Shnidman, Ari
    JOURNAL DE THEORIE DES NOMBRES DE BORDEAUX, 2023, 35 (03): : 751 - 774
  • [5] Sandpile groups of supersingular isogeny graphs
    Einstein Institute of Mathematics, The Hebrew University of Jerusalem, Edmund J. Safra Campus, Jerusalem
    9190401, Israel
    arXiv, 1600,
  • [6] Failing to Hash Into Supersingular Isogeny Graphs
    Booher, Jeremy
    Bowden, Ross
    Doliskani, Javad
    Boris Fouotsa, Tako
    Galbraith, Steven D.
    Kunzweiler, Sabrina
    Merz, Simon-Philipp
    Petit, Christophe
    Smith, Benjamin
    Stange, Katherine E.
    Ti, Yan Bo
    Vincent, Christelle
    Voloch, Jose Felipe
    Weitkaemper, Charlotte
    Zobernig, Lukas
    COMPUTER JOURNAL, 2024, 67 (08): : 2702 - 2719
  • [7] Computing newforms using supersingular isogeny graphs
    Alex Cowan
    Research in Number Theory, 2022, 8
  • [8] Computing newforms using supersingular isogeny graphs
    Cowan, Alex
    RESEARCH IN NUMBER THEORY, 2022, 8 (04)
  • [9] Constructing Cycles in Isogeny Graphs of Supersingular Elliptic Curves
    Xiao, Guanju
    Luo, Lixia
    Deng, Yingpu
    JOURNAL OF MATHEMATICAL CRYPTOLOGY, 2021, 15 (01) : 454 - 464
  • [10] On the zeta functions of supersingular isogeny graphs and modular curves
    Antonio Lei
    Katharina Müller
    Archiv der Mathematik, 2024, 122 (3) : 285 - 294