Accelerate Literature Icon
Want to do a literature review? Try our new Literature Review workflow

Constructing public-key cryptographic schemes based on class group action on a set of isogenous elliptic curves

  • Abstract
  • Literature Map
  • Similar Papers
Abstract
Translate article icon Translate Article Star icon

We propose a public-key encryption scheme and key agreement protocols based on a group action on a set. We construct an implementation of these schemes for the action of the class group $\mathcal{CL}(\mathcal{O}_K)$ of an imaginary quadratic field $K$ on the set $\mathcal{ELL}$p,n$(\mathcal{O}_K)$ of isomorphism classes of elliptic curves over $\mathbb{F}_p$ with $n$ points and the endomorphism ring $\mathcal{O}_K$.This introduces a novel way of using elliptic curves for constructing asymmetric cryptography.

Similar Papers
  • Research Article
  • Cite Count Icon 4
  • 10.1016/j.jnt.2015.05.009
On the number of isomorphism classes of CM elliptic curves defined over a number field
  • Jul 7, 2015
  • Journal of Number Theory
  • Harris B Daniels + 1 more

On the number of isomorphism classes of CM elliptic curves defined over a number field

  • Research Article
  • Cite Count Icon 25
  • 10.1090/mcom/3213
Torsion subgroups of rational elliptic curves over the compositum of all cubic fields
  • May 5, 2017
  • Mathematics of Computation
  • Harris Daniels + 3 more

Let E / Q E/\mathbb {Q} be an elliptic curve and let Q ( 3 ∞ ) \mathbb {Q}(3^\infty ) be the compositum of all cubic extensions of Q \mathbb {Q} . In this article we show that the torsion subgroup of E ( Q ( 3 ∞ ) ) E(\mathbb {Q}(3^\infty )) is finite and we determine 20 possibilities for its structure, along with a complete description of the Q ¯ \overline {\mathbb {Q}} -isomorphism classes of elliptic curves that fall into each case. We provide rational parameterizations for each of the 16 torsion structures that occur for infinitely many Q ¯ \overline {\mathbb {Q}} -isomorphism classes of elliptic curves, and a complete list of j j -invariants for each of the 4 that do not.

  • PDF Download Icon
  • Research Article
  • Cite Count Icon 12
  • 10.46586/tches.v2021.i4.618-649
Batching CSIDH Group Actions using AVX-512
  • Aug 11, 2021
  • IACR Transactions on Cryptographic Hardware and Embedded Systems
  • Hao Cheng + 4 more

Commutative Supersingular Isogeny Diffie-Hellman (or CSIDH for short) is a recently-proposed post-quantum key establishment scheme that belongs to the family of isogeny-based cryptosystems. The CSIDH protocol is based on the action of an ideal class group on a set of supersingular elliptic curves and comes with some very attractive features, e.g. the ability to serve as a “drop-in” replacement for the standard elliptic curve Diffie-Hellman protocol. Unfortunately, the execution time of CSIDH is prohibitively high for many real-world applications, mainly due to the enormous computational cost of the underlying group action. Consequently, there is a strong demand for optimizations that increase the efficiency of the class group action evaluation, which is not only important for CSIDH, but also for related cryptosystems like the signature schemes CSI-FiSh and SeaSign. In this paper, we explore how the AVX-512 vector extensions (incl. AVX-512F and AVX-512IFMA) can be utilized to optimize constant-time evaluation of the CSIDH-512 class group action with the goal of, respectively, maximizing throughput and minimizing latency. We introduce different approaches for batching group actions and computing them in SIMD fashion on modern Intel processors. In particular, we present a hybrid batching technique that, when combined with optimized (8 × 1)-way prime-field arithmetic, increases the throughput by a factor of 3.64 compared to a state-of-the-art (non-vectorized) x64 implementation. On the other hand, vectorization in a 2-way fashion aimed to reduce latency makes our AVX-512 implementation of the group action evaluation about 1.54 times faster than the state-of-the-art. To the best of our knowledge, this paper is the first to demonstrate the high potential of using vector instructions to increase the throughput (resp. decrease the latency) of constant-time CSIDH.

  • Book Chapter
  • 10.1007/978-3-642-35211-9_1
On the Isomorphism Classes of Elliptic Curves with 2-Torsion Points
  • Jan 1, 2012
  • Hongfeng Wu + 1 more

This paper presents explicit formulas for the number of isomorphism classes of elliptic curves with 2-torsion points over finite fields. These results also can be used in the elliptic curve cryptosystems and classification problems.Keywordselliptic curvecryptographyisomorphism classesfinite field

  • Book Chapter
  • Cite Count Icon 474
  • 10.1007/978-3-540-76900-2_3
Faster Addition and Doubling on Elliptic Curves
  • Dec 2, 2007
  • Daniel J Bernstein + 1 more

Edwards recently introduced a new normal form for elliptic curves. Every elliptic curve over a non-binary field is birationally equivalent to a curve in Edwards form over an extension of the field, and in many cases over the original field.This paper presents fast explicit formulas (and register allocations) for group operations on an Edwards curve. The algorithm for doubling uses only 3M + 4S, i.e., 3 field multiplications and 4 field squarings. If curve parameters are chosen to be small then the algorithm for mixed addition uses only 9M + 1S and the algorithm for non-mixed addition uses only 10M + 1S. Arbitrary Edwards curves can be handled at the cost of just one extra multiplication by a curve parameter.For comparison, the fastest algorithms known for the popular “a 4 = −3 Jacobian” form use 3M + 5S for doubling; use 7M + 4S for mixed addition; use 11M + 5S for non-mixed addition; and use 10M + 4S for non-mixed addition when one input has been added before.The explicit formulas for non-mixed addition on an Edwards curve can be used for doublings at no extra cost, simplifying protection against side-channel attacks. Even better, many elliptic curves (approximately 1/4 of all isomorphism classes of elliptic curves over a non-binary finite field) are birationally equivalent — over the original field — to Edwards curves where this addition algorithm works for all pairs of curve points, including inverses, the neutral element, etc.This paper contains an extensive comparison of different forms of elliptic curves and different coordinate systems for the basic group operations (doubling, mixed addition, non-mixed addition, and unified addition) as well as higher-level operations such as multi-scalar multiplication.

  • Research Article
  • Cite Count Icon 18
  • 10.4310/mrl.2012.v19.n2.a6
Isomorphism classes of elliptic curves over a finite field in some thin families
  • Dec 30, 1899
  • Mathematical Research Letters
  • Javier Cilleruelo + 2 more

For a prime p and a given square box, B, we consider all elliptic curves Er,s : Y 2 = X 3 + rX + s defined over a field Fp of p elements with coefficients (r, s) ∈ B. We obtain a nontrivial upper bound for the number of such curves which are isomorphic to ag iven one overFp, in terms of the size of B. We also give an optimal lower bound on the number of distinct isomorphic classes represented.

  • Book Chapter
  • Cite Count Icon 3
  • 10.1007/978-1-4615-3198-2_3
Isomorphism Classes of Elliptic Curves Over Finite Fields
  • Jan 1, 1993
  • Alfred Menezes

In this chapter, we count the isomorphism classes of elliptic curves over finite fields K. For the case K = F 2 m, we list a representative, in Weierstrass form, of each isomorphism class. We determine #E(F 2 m) for each supersingular curve E defined over F 2 m.

  • Research Article
  • Cite Count Icon 20
  • 10.1016/j.jnt.2007.10.008
Elliptic curves, modular forms, and sums of Hurwitz class numbers
  • Jan 28, 2008
  • Journal of Number Theory
  • Brittany Brown + 5 more

Elliptic curves, modular forms, and sums of Hurwitz class numbers

  • Research Article
  • Cite Count Icon 1
  • 10.1017/fms.2024.127
Average Analytic Ranks of Elliptic Curves over Number Fields
  • Jan 1, 2025
  • Forum of Mathematics, Sigma
  • Tristan Phillips

We give a conditional bound for the average analytic rank of elliptic curves over an arbitrary number field. In particular, under the assumptions that all elliptic curves over a number field K are modular and have L-functions which satisfy the Generalized Riemann Hypothesis, we show that the average analytic rank of isomorphism classes of elliptic curves over K is bounded above by $(9\deg (K)+1)/2$ , when ordered by naive height. A key ingredient in the proof is giving asymptotics for the number of elliptic curves over an arbitrary number field with a prescribed local condition; these results are obtained by proving general results for counting points of bounded height on weighted projective stacks with a prescribed local condition, which may be of independent interest.

  • Research Article
  • Cite Count Icon 1
  • 10.1016/j.indag.2024.04.003
Root numbers of a family of elliptic curves and two applications
  • Apr 1, 2024
  • Indagationes Mathematicae
  • Jonathan Love

For each t∈Q∖{−1,0,1}, define an elliptic curve over Q by Et:y2=x(x+1)(x+t2).Using a formula for the root number W(Et) as a function of t and assuming some standard conjectures about ranks of elliptic curves, we determine (up to a set of density zero) the set of isomorphism classes of elliptic curves E/Q whose Mordell–Weil group contains Z×Z/2Z×Z/4Z, and the set of rational numbers that can be written as a product of the slopes of two rational right triangles.

  • Research Article
  • Cite Count Icon 3
  • 10.1070/sm1970v011n02abeh002058
SOME REMARKS ON THE TORSION OF ELLIPTIC CURVES
  • Feb 28, 1970
  • Mathematics of the USSR-Sbornik
  • M E Novodvorskiĭ + 1 more

We prove the following.Theorem. Let be a number field, and the Jacobian of the curve parametrizing the elliptic curves with distinguished cyclic subgroups of order . If the number is written as , where contains a -simple abelian subvariety such that {\operatorname{rk}} A_k,$ SRC=http://ej.iop.org/images/0025-5734/11/2/A12/tex_sm_2058_img8.gif/> then the set of -isomorphism classes of elliptic curves over the field possessing -points of order is finite.Bibliography: 4 items.

  • PDF Download Icon
  • Research Article
  • Cite Count Icon 25
  • 10.1017/fms.2022.38
-adic images of Galois for elliptic curves over (and an appendix with John Voight)
  • Jan 1, 2022
  • Forum of Mathematics, Sigma
  • Jeremy Rouse + 2 more

We discuss the$\ell $-adic case of Mazur’s ‘Program B’ over$\mathbb {Q}$: the problem of classifying the possible images of$\ell $-adic Galois representations attached to elliptic curvesEover$\mathbb {Q}$, equivalently, classifying the rational points on the corresponding modular curves. The primes$\ell =2$and$\ell \ge 13$are addressed by prior work, so we focus on the remaining primes$\ell = 3, 5, 7, 11$. For each of these$\ell $, we compute the directed graph of arithmetically maximal$\ell $-power level modular curves$X_H$, compute explicit equations for all but three of them and classify the rational points on all of them except$X_{\mathrm {ns}}^{+}(N)$, for$N = 27, 25, 49, 121$and two-level$49$curves of genus$9$whose Jacobians have analytic rank$9$.Aside from the$\ell $-adic images that are known to arise for infinitely many${\overline {\mathbb {Q}}}$-isomorphism classes of elliptic curves$E/\mathbb {Q}$, we find only 22 exceptional images that arise for any prime$\ell $and any$E/\mathbb {Q}$without complex multiplication; these exceptional images are realised by 20 non-CM rationalj-invariants. We conjecture that this list of 22 exceptional images is complete and show that any counterexamples must arise from unexpected rational points on$X_{\mathrm {ns}}^+(\ell )$with$\ell \ge 19$, or one of the six modular curves noted above. This yields a very efficient algorithm to compute the$\ell $-adic images of Galois for any elliptic curve over$\mathbb {Q}$.In an appendix with John Voight, we generalise Ribet’s observation that simple abelian varieties attached to newforms on$\Gamma _1(N)$are of$\operatorname {GL}_2$-type; this extends Kolyvagin’s theorem that analytic rank zero implies algebraic rank zero to isogeny factors of the Jacobian of$X_H$.

  • Research Article
  • Cite Count Icon 6
  • 10.4064/aa180316-16-10
Horizontal isogeny graphs of ordinary abelian varieties and the discrete logarithm problem
  • Jan 1, 2019
  • Acta Arithmetica
  • Dimitar Jetchev + 1 more

Fix an ordinary abelian variety defined over a finite field. The ideal class group of its endomorphism ring acts freely on the set of isogenous varieties with same endomorphism ring, by complex multiplication. Any subgroup of the class group, and generating set thereof, induces an isogeny graph on the orbit of the variety for this subgroup. We compute (under the Generalized Riemann Hypothesis) some bounds on the norms of prime ideals generating it, such that the associated graph has good expansion properties. We use these graphs, together with a recent algorithm of Dudeanu, Jetchev and Robert for computing explicit isogenies in genus 2, to prove random self-reducibility of the discrete logarithm problem within the subclasses of principally polarizable ordinary abelian surfaces with fixed endomorphism ring. In addition, we remove the heuristics in the complexity analysis of an algorithm of Galbraith for explicitly computing isogenies between two elliptic curves in the same isogeny class, and extend it to a more general setting including genus 2.

  • Research Article
  • 10.1007/s00031-026-09946-2
Odd and Even Elliptic Curves with Complex Multiplication
  • Feb 27, 2026
  • Transformation Groups
  • Yuri G Zarhin

We call an order O in a quadratic field K odd (resp. even) if its discriminant is an odd (resp. even) integer. We call an elliptic curve E over $${\mathbb {C}}$$ with CM odd (resp. even) if its endomorphism ring $$\textrm{End}(E)$$ is an odd (resp. even) order in the imaginary quadratic field $$\textrm{End}(E)\otimes {\mathbb {Q}}$$ . Suppose that $$j(E)\in {\mathbb {R}}$$ and let us consider the set $$\mathscr {J}({\mathbb {R}},E)$$ of all $$j(E^{\prime })$$ where $$E^{\prime }$$ is any elliptic curve that enjoys the following properties: . $$\bullet$$ $$E^{\prime }$$ is isogenous to E; $$\bullet$$ $$j(E^{\prime })\in {\mathbb {R}}$$ ; $$\bullet$$ $$E^{\prime }$$ has the same parity as E. We prove that the closure of $$\mathscr {J}({\mathbb {R}},E)$$ in $${\mathbb {R}}$$ is the closed semi-infinite interval $$(-\infty ,1728]$$ (resp. the whole $${\mathbb {R}}$$ ) if E is odd (resp. even). This paper was inspired by a question of Jean-Louis Colliot-Thélène and Alena Pirutka about the distribution of j-invariants of certain elliptic curves of CM type.

  • Research Article
  • Cite Count Icon 64
  • 10.1007/s00208-005-0723-6
Hilbert class polynomials and traces of singular moduli
  • Dec 9, 2005
  • Mathematische Annalen
  • Jan Hendrik Bruinier + 2 more

where q = e. The values of j(z) at imaginary quadratic arguments in the upper half of the complex plane are known as singular moduli. Singular moduli are algebraic integers which play prominent roles in classical and modern number theory (see [C, BCSH]). For example, Hilbert class fields of imaginary quadratic fields are generated by singular moduli. Furthermore, isomorphism classes of elliptic curves with complex multiplication are distinguished by singular moduli. Throughout, let d ≡ 0, 3 (mod 4) be a positive integer (so that −d is the discriminant of an order in an imaginary quadratic field), and let H(d) be the Hurwitz-Kronecker class number for the discriminant −d. Let Qd be the set of positive definite integral binary quadratic forms (note. including imprimitive forms, if there are any)

Save Icon
Up Arrow
Open/Close
Notes

Save Important notes in documents

Highlight text to save as a note, or write notes directly

You can also access these Documents in Paperpal, our AI writing tool

Powered by our AI Writing Assistant