Filters








64 Hits in 2.6 sec

Distorting the volcano

Mireille Fouquet, Josep M. Miret, Javier Valera
2018 Finite Fields and Their Applications  
We also provide some relationships among the crater sizes of volcanoes of m-isogenies whose elliptic curves belong to a volcano of ℓ-isogenies.  ...  Volcanoes of ℓ-isogenies of elliptic curves are a special case of graphs with a cycle called crater.  ...  Acknowledgments Research of the authors was partially supported by grants MTM2013-46949-P (Spanish MINECO) and 2014 SGR1666 (Generalitat de Catalunya).  ... 
doi:10.1016/j.ffa.2017.09.006 fatcat:6xp47j4f2fgqjmo55gv4miksji

Isogeny volcanoes

Andrew Sutherland
2013 The Open Book Series  
The remarkable structure and computationally explicit form of isogeny graphs of elliptic curves over a finite field has made them an important tool for computational number theorists and practitioners  ...  of elliptic curve cryptography.  ...  Acknowledgements I am grateful to Gaetan Bisson for his feedback on an early draft of this article, and to the editors for their careful review. The author was supported by NSF grant DMS-1115455.  ... 
doi:10.2140/obs.2013.1.507 fatcat:k75vmyytwvafdk67punumfhbha

On the evaluation of modular polynomials

Andrew Sutherland
2013 The Open Book Series  
The algorithms may be adapted to handle other types of modular polynomials, and we consider applications to point counting and the computation of endomorphism rings.  ...  We present two algorithms that, given a prime ell and an elliptic curve E/Fq, directly compute the polynomial Phi_ell(j(E),Y) in Fq[Y] whose roots are the j-invariants of the elliptic curves that are ell-isogenous  ...  One can decompose horizontal isogenies of large prime degree into an equivalent sequence of isogenies of small prime degrees, which makes them easy to compute; see [Bröker-Charles-Lauter 2008, Jao-Souhkarev  ... 
doi:10.2140/obs.2013.1.531 fatcat:pkkoiwwshfbmdcvuqibnx4nzji

Volcanoes of $\ell$-isogenies of elliptic curves over finite fields: the case $\ell=3^*$

J. M. Miret, D. Sadornil, J. Tena, R. Tomàs, M. Valls
2007 Publicacions matemàtiques  
This paper is devoted to the study of the volcanoes of ℓ-isogenies of elliptic curves over a finite field, focusing on their height as well as on the location of curves across its different levels.  ...  The particular case ℓ = 3 is studied in detail, giving an algorithm to determine the volcano of 3-isogenies of a given elliptic curve. Experimental results are also provided.  ...  This is due to the fact that any isogeny of degree d = d 1 d 2 can be constructed as a composition of isogenies of degrees d 1 and d 2 .  ... 
doi:10.5565/publmat_pjtn05_08 fatcat:wwnk4j2i55da5px66aelmzydge

Isogeny Volcanoes of Elliptic Curves and Sylow Subgroups [chapter]

Mireille Fouquet, Josep M. Miret, Javier Valera
2015 Lecture Notes in Computer Science  
Volcanoes of ℓ-isogenies have also been used by Sutherland [20] to compute the Hilbert class polynomials.  ...  As an application for regular volcanoes, we give an algorithm to compute all the vertices of their craters.  ...  Research of the second and third authors was supported in part by grants MTM2013-46949-P (Spanish MINECO) and 2014 SGR1666 (Generalitat de Catalunya).  ... 
doi:10.1007/978-3-319-16295-9_9 fatcat:rjcrzq7b25gfrj7rja2rmwftum

Orienteering with one endomorphism [article]

Sarah Arpin, Mingjie Chen, Kristin E. Lauter, Renate Scheidler, Katherine E. Stange, Ha T. N. Tran
2022 arXiv   pre-print
We use the theory of oriented supersingular isogeny graphs and algorithms for taking ascending/descending/horizontal steps on such graphs.  ...  It is known that a small endomorphism enables polynomial-time path-finding and endomorphism ring computation (Love-Boneh [36]).  ...  Obtaining ψ • ϕ requires computing four compositions of the form f ( u(x) v(x) ) where f ∈ {u , v , s , t } has degree O(d ).  ... 
arXiv:2201.11079v2 fatcat:hmlhxcrp4jfh5b4vnnojcldg4e

Explicit isogenies in quadratic time in any characteristic

Luca De Feo, Cyril Hugounenq, Jérôme Plût, Éric Schost
2016 LMS Journal of Computation and Mathematics  
We propose an algorithm that determines$\unicode[STIX]{x1D713}$from the knowledge of$E$,$E^{\prime }$and of its degree$r$, by using the structure of the$\ell$-torsion of the curves (where $\ell$ is a prime  ...  Our approach is inspired by a previous algorithm due to Couveignes, which involved computations using the$p$-torsion on the curves.  ...  The degree of an isogeny is its degree as a rational map.  ... 
doi:10.1112/s146115701600036x fatcat:xwuimoo26vgp7oxtaax7mwd3pq

Orientations and cycles in supersingular isogeny graphs [article]

Sarah Arpin, Mingjie Chen, Kristin E. Lauter, Renate Scheidler, Katherine E. Stange, Ha T. N. Tran
2022 arXiv   pre-print
Our main result is a bijection between the rims of the union of all oriented supersingular l-isogeny volcanoes over 𝔽̅_p (up to conjugation of the orientations), and isogeny cycles (non-backtracking closed  ...  The paper concerns several theoretical aspects of oriented supersingular l-isogeny volcanoes and their relationship to closed walks in the supersingular l-isogeny graph.  ...  of degree up to post-composition by  ... 
arXiv:2205.03976v1 fatcat:ygvkxwo3iraalhjj6qpp2oj2ha

Hard isogeny problems over RSA moduli and groups with infeasible inversion [article]

Salim Ali Altug, Yilei Chen
2019 arXiv   pre-print
We initiate the study of computational problems on elliptic curve isogeny graphs defined over RSA moduli.  ...  Recall that in a group with infeasible inversion, computing the inverse of a group element is required to be hard, while performing the group operation is easy.  ...  Corollary 6.11 of [Sut] ) that every isogeny of degree ℓ 2 can be decomposed as a composition of two degreeisogenies (which are necessarily cyclic).  ... 
arXiv:1810.00022v2 fatcat:s6ehpuorsnfflfo24kykcvckla

Computational problems in supersingular elliptic curve isogenies

Steven D. Galbraith, Frederik Vercauteren
2018 Quantum Information Processing  
We give a brief survey of elliptic curve isogenies and the computational problems relevant for supersingular isogeny crypto.  ...  The main goal of the paper is to advertise various related computational problems, and to explain the relationships between them, in a way that is accessible to experts in quantum algorithms.  ...  For example, one can form a sequence of t isogenies of degree 2, and the cost to compute the composition is proportional to t, rather than the cost O(2 t ) of computing the composition in a single step  ... 
doi:10.1007/s11128-018-2023-6 fatcat:7zlqrtmefffapbfax5qqwzc42u

Computing isogenies between supersingular elliptic curves over F_p [article]

Christina Delfs, Steven D. Galbraith
2013 arXiv   pre-print
In this paper we consider the structure of the isogeny graph of supersingular elliptic curves over F_p.  ...  We want to construct an isogeny phi: E --> E'.  ...  Acknowledgements We thank David Kohel and Drew Sutherland for helpful conversations and Marco Streng for the idea of the proof of Proposition 2.6.  ... 
arXiv:1310.7789v1 fatcat:pvbpmuwzrvgoncxbqfzaje72nm

Orienting supersingular isogeny graphs

Leonardo Colò, David Kohel
2020 Journal of Mathematical Cryptology  
AbstractWe introduce a category of 𝓞-oriented supersingular elliptic curves and derive properties of the associated oriented and nonoriented ℓ-isogeny supersingular isogeny graphs.  ...  supersingular isogeny Diffie-Hellman (CSIDH) protocol.  ...  The kernel polynomial of degree (q − 1)/2 can be computed directly without need for a splitting field for E [q] , and the computation of a generator isogeny is a one-time precomputation.  ... 
doi:10.1515/jmc-2019-0034 fatcat:ecrikykih5e45pf46q4kpxm2iq

A Subexponential Algorithm for Evaluating Large Degree Isogenies [chapter]

David Jao, Vladimir Soukharev
2010 Lecture Notes in Computer Science  
Our approach is based on factoring the ideal corresponding to the kernel of the isogeny, modulo principal ideals, into a product of smaller prime ideals for which the isogenies can be computed directly  ...  Combined with previous work of Bostan et al., our algorithm yields equations for large degree isogenies in quasi-optimal time given only the starting curve and the kernel.  ...  Under a heuristic assumption of Galbraith et al. [15] , the running time of our algorithm is subexponential in the field size and polynomial in the bit length of the isogeny degree.  ... 
doi:10.1007/978-3-642-14518-6_19 fatcat:yh2lo5vpkvccloa4pi4gcln7hm

On Two Problems About Isogenies of Elliptic Curves Over Finite Fields

Lixia Luo
2020 Communications in Mathematical Research  
In addition, some results about the non-trivial minimal degree of isogenies between two elliptic curves are also provided. Proposition 2.2.  ...  Isogenies occur throughout the theory of elliptic curves. Recently, the cryptographic protocols based on isogenies are considered as candidates of quantum-resistant cryptographic protocols.  ...  Waterhouse also proved that ideal multiplication corresponds to composition of isogenies.  ... 
doi:10.4208/cmr.2020-0071 fatcat:qqurztll5zda5bhou4qldqyfty

Mathematics of Isogeny Based Cryptography [article]

Luca De Feo
2017 arXiv   pre-print
They try to provide a guide for Masters' students to get through the vast literature on elliptic curves, without getting lost on their way to learning isogeny based cryptography.  ...  They are by no means a reference text on the theory of elliptic curves, nor on cryptography; students are encouraged to complement these notes with some of the books recommended in the bibliography.  ...  ., D = 1), and that each isogeny φ i is horizontal, thus their composition eventually forms a cycle, the crater of a volcano.  ... 
arXiv:1711.04062v1 fatcat:i5l6qyzxezhxxbj3a2cee3klwm
« Previous Showing results 1 — 15 out of 64 results