We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

math.NT

Change to browse by:

References & Citations

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo ScienceWISE logo

Mathematics > Number Theory

Title: Orienteering with one endomorphism

Abstract: In supersingular isogeny-based cryptography, the path-finding problem reduces to the endomorphism ring problem. Can path-finding be reduced to knowing just one endomorphism? It is known that a small endomorphism enables polynomial-time path-finding and endomorphism ring computation (Love-Boneh [36]). As this paper neared completion, it was shown that the endomorphism ring problem in the presence of one known endomorphism reduces to a vectorization problem (Wesolowski [54]). In this paper, we give explicit classical and quantum algorithms for path-finding to an initial curve using the knowledge of one endomorphism. An endomorphism gives an explicit orientation of a supersingular elliptic curve. We use the theory of oriented supersingular isogeny graphs and algorithms for taking ascending/descending/horizontal steps on such graphs. Although the most general runtimes are subexponential, we demonstrate a class of (potentially large) endomorphisms, for any supersingular elliptic curve, for which the classical runtime is polynomial.
Comments: 39 pages, 1 figure; 2nd revision implements small corrections and expositional improvements
Subjects: Number Theory (math.NT); Cryptography and Security (cs.CR)
MSC classes: Primary: 14G50, 94A60, 11G05, 14K04, 11-04, Secondary: 11R52
Cite as: arXiv:2201.11079 [math.NT]
  (or arXiv:2201.11079v2 [math.NT] for this version)

Submission history

From: Katherine E. Stange [view email]
[v1] Wed, 26 Jan 2022 17:39:10 GMT (485kb,D)
[v2] Thu, 10 Mar 2022 18:39:00 GMT (239kb,D)

Link back to: arXiv, form interface, contact.