Constructing public-key cryptographic schemes based on class group action on a set of isogenous elliptic curves
We propose a public-key encryption scheme and key agreement protocols based on a group action on a set. We construct an implementation of these schemes for the action of the class group $\mathcal{CL}(\mathcal{O}_K)$ of an imaginary quadratic field $K$ on the set $\mathcal{ELL}$p,n$(\mathcal{O}_K)$ of isomorphism classes of elliptic curves over $\mathbb{F}_p$ with $n$ points and the endomorphism ring $\mathcal{O}_K$.This introduces a novel way of using elliptic curves for constructing asymmetric cryptography.
- Research Article
4
- 10.1016/j.jnt.2015.05.009
- Jul 7, 2015
- Journal of Number Theory
On the number of isomorphism classes of CM elliptic curves defined over a number field
- Research Article
25
- 10.1090/mcom/3213
- May 5, 2017
- Mathematics of Computation
Let E / Q E/\mathbb {Q} be an elliptic curve and let Q ( 3 ∞ ) \mathbb {Q}(3^\infty ) be the compositum of all cubic extensions of Q \mathbb {Q} . In this article we show that the torsion subgroup of E ( Q ( 3 ∞ ) ) E(\mathbb {Q}(3^\infty )) is finite and we determine 20 possibilities for its structure, along with a complete description of the Q ¯ \overline {\mathbb {Q}} -isomorphism classes of elliptic curves that fall into each case. We provide rational parameterizations for each of the 16 torsion structures that occur for infinitely many Q ¯ \overline {\mathbb {Q}} -isomorphism classes of elliptic curves, and a complete list of j j -invariants for each of the 4 that do not.
- Research Article
12
- 10.46586/tches.v2021.i4.618-649
- Aug 11, 2021
- IACR Transactions on Cryptographic Hardware and Embedded Systems
Commutative Supersingular Isogeny Diffie-Hellman (or CSIDH for short) is a recently-proposed post-quantum key establishment scheme that belongs to the family of isogeny-based cryptosystems. The CSIDH protocol is based on the action of an ideal class group on a set of supersingular elliptic curves and comes with some very attractive features, e.g. the ability to serve as a “drop-in” replacement for the standard elliptic curve Diffie-Hellman protocol. Unfortunately, the execution time of CSIDH is prohibitively high for many real-world applications, mainly due to the enormous computational cost of the underlying group action. Consequently, there is a strong demand for optimizations that increase the efficiency of the class group action evaluation, which is not only important for CSIDH, but also for related cryptosystems like the signature schemes CSI-FiSh and SeaSign. In this paper, we explore how the AVX-512 vector extensions (incl. AVX-512F and AVX-512IFMA) can be utilized to optimize constant-time evaluation of the CSIDH-512 class group action with the goal of, respectively, maximizing throughput and minimizing latency. We introduce different approaches for batching group actions and computing them in SIMD fashion on modern Intel processors. In particular, we present a hybrid batching technique that, when combined with optimized (8 × 1)-way prime-field arithmetic, increases the throughput by a factor of 3.64 compared to a state-of-the-art (non-vectorized) x64 implementation. On the other hand, vectorization in a 2-way fashion aimed to reduce latency makes our AVX-512 implementation of the group action evaluation about 1.54 times faster than the state-of-the-art. To the best of our knowledge, this paper is the first to demonstrate the high potential of using vector instructions to increase the throughput (resp. decrease the latency) of constant-time CSIDH.
- Book Chapter
- 10.1007/978-3-642-35211-9_1
- Jan 1, 2012
This paper presents explicit formulas for the number of isomorphism classes of elliptic curves with 2-torsion points over finite fields. These results also can be used in the elliptic curve cryptosystems and classification problems.Keywordselliptic curvecryptographyisomorphism classesfinite field
- Book Chapter
474
- 10.1007/978-3-540-76900-2_3
- Dec 2, 2007
Edwards recently introduced a new normal form for elliptic curves. Every elliptic curve over a non-binary field is birationally equivalent to a curve in Edwards form over an extension of the field, and in many cases over the original field.This paper presents fast explicit formulas (and register allocations) for group operations on an Edwards curve. The algorithm for doubling uses only 3M + 4S, i.e., 3 field multiplications and 4 field squarings. If curve parameters are chosen to be small then the algorithm for mixed addition uses only 9M + 1S and the algorithm for non-mixed addition uses only 10M + 1S. Arbitrary Edwards curves can be handled at the cost of just one extra multiplication by a curve parameter.For comparison, the fastest algorithms known for the popular “a 4 = −3 Jacobian” form use 3M + 5S for doubling; use 7M + 4S for mixed addition; use 11M + 5S for non-mixed addition; and use 10M + 4S for non-mixed addition when one input has been added before.The explicit formulas for non-mixed addition on an Edwards curve can be used for doublings at no extra cost, simplifying protection against side-channel attacks. Even better, many elliptic curves (approximately 1/4 of all isomorphism classes of elliptic curves over a non-binary finite field) are birationally equivalent — over the original field — to Edwards curves where this addition algorithm works for all pairs of curve points, including inverses, the neutral element, etc.This paper contains an extensive comparison of different forms of elliptic curves and different coordinate systems for the basic group operations (doubling, mixed addition, non-mixed addition, and unified addition) as well as higher-level operations such as multi-scalar multiplication.
- Research Article
18
- 10.4310/mrl.2012.v19.n2.a6
- Dec 30, 1899
- Mathematical Research Letters
For a prime p and a given square box, B, we consider all elliptic curves Er,s : Y 2 = X 3 + rX + s defined over a field Fp of p elements with coefficients (r, s) ∈ B. We obtain a nontrivial upper bound for the number of such curves which are isomorphic to ag iven one overFp, in terms of the size of B. We also give an optimal lower bound on the number of distinct isomorphic classes represented.
- Book Chapter
3
- 10.1007/978-1-4615-3198-2_3
- Jan 1, 1993
In this chapter, we count the isomorphism classes of elliptic curves over finite fields K. For the case K = F 2 m, we list a representative, in Weierstrass form, of each isomorphism class. We determine #E(F 2 m) for each supersingular curve E defined over F 2 m.
- Research Article
20
- 10.1016/j.jnt.2007.10.008
- Jan 28, 2008
- Journal of Number Theory
Elliptic curves, modular forms, and sums of Hurwitz class numbers
- Research Article
1
- 10.1017/fms.2024.127
- Jan 1, 2025
- Forum of Mathematics, Sigma
We give a conditional bound for the average analytic rank of elliptic curves over an arbitrary number field. In particular, under the assumptions that all elliptic curves over a number field K are modular and have L-functions which satisfy the Generalized Riemann Hypothesis, we show that the average analytic rank of isomorphism classes of elliptic curves over K is bounded above by $(9\deg (K)+1)/2$ , when ordered by naive height. A key ingredient in the proof is giving asymptotics for the number of elliptic curves over an arbitrary number field with a prescribed local condition; these results are obtained by proving general results for counting points of bounded height on weighted projective stacks with a prescribed local condition, which may be of independent interest.
- Research Article
1
- 10.1016/j.indag.2024.04.003
- Apr 1, 2024
- Indagationes Mathematicae
For each t∈Q∖{−1,0,1}, define an elliptic curve over Q by Et:y2=x(x+1)(x+t2).Using a formula for the root number W(Et) as a function of t and assuming some standard conjectures about ranks of elliptic curves, we determine (up to a set of density zero) the set of isomorphism classes of elliptic curves E/Q whose Mordell–Weil group contains Z×Z/2Z×Z/4Z, and the set of rational numbers that can be written as a product of the slopes of two rational right triangles.
- Research Article
3
- 10.1070/sm1970v011n02abeh002058
- Feb 28, 1970
- Mathematics of the USSR-Sbornik
We prove the following.Theorem. Let be a number field, and the Jacobian of the curve parametrizing the elliptic curves with distinguished cyclic subgroups of order . If the number is written as , where contains a -simple abelian subvariety such that {\operatorname{rk}} A_k,$ SRC=http://ej.iop.org/images/0025-5734/11/2/A12/tex_sm_2058_img8.gif/> then the set of -isomorphism classes of elliptic curves over the field possessing -points of order is finite.Bibliography: 4 items.
- Research Article
25
- 10.1017/fms.2022.38
- Jan 1, 2022
- Forum of Mathematics, Sigma
We discuss the$\ell $-adic case of Mazur’s ‘Program B’ over$\mathbb {Q}$: the problem of classifying the possible images of$\ell $-adic Galois representations attached to elliptic curvesEover$\mathbb {Q}$, equivalently, classifying the rational points on the corresponding modular curves. The primes$\ell =2$and$\ell \ge 13$are addressed by prior work, so we focus on the remaining primes$\ell = 3, 5, 7, 11$. For each of these$\ell $, we compute the directed graph of arithmetically maximal$\ell $-power level modular curves$X_H$, compute explicit equations for all but three of them and classify the rational points on all of them except$X_{\mathrm {ns}}^{+}(N)$, for$N = 27, 25, 49, 121$and two-level$49$curves of genus$9$whose Jacobians have analytic rank$9$.Aside from the$\ell $-adic images that are known to arise for infinitely many${\overline {\mathbb {Q}}}$-isomorphism classes of elliptic curves$E/\mathbb {Q}$, we find only 22 exceptional images that arise for any prime$\ell $and any$E/\mathbb {Q}$without complex multiplication; these exceptional images are realised by 20 non-CM rationalj-invariants. We conjecture that this list of 22 exceptional images is complete and show that any counterexamples must arise from unexpected rational points on$X_{\mathrm {ns}}^+(\ell )$with$\ell \ge 19$, or one of the six modular curves noted above. This yields a very efficient algorithm to compute the$\ell $-adic images of Galois for any elliptic curve over$\mathbb {Q}$.In an appendix with John Voight, we generalise Ribet’s observation that simple abelian varieties attached to newforms on$\Gamma _1(N)$are of$\operatorname {GL}_2$-type; this extends Kolyvagin’s theorem that analytic rank zero implies algebraic rank zero to isogeny factors of the Jacobian of$X_H$.
- Research Article
6
- 10.4064/aa180316-16-10
- Jan 1, 2019
- Acta Arithmetica
Fix an ordinary abelian variety defined over a finite field. The ideal class group of its endomorphism ring acts freely on the set of isogenous varieties with same endomorphism ring, by complex multiplication. Any subgroup of the class group, and generating set thereof, induces an isogeny graph on the orbit of the variety for this subgroup. We compute (under the Generalized Riemann Hypothesis) some bounds on the norms of prime ideals generating it, such that the associated graph has good expansion properties. We use these graphs, together with a recent algorithm of Dudeanu, Jetchev and Robert for computing explicit isogenies in genus 2, to prove random self-reducibility of the discrete logarithm problem within the subclasses of principally polarizable ordinary abelian surfaces with fixed endomorphism ring. In addition, we remove the heuristics in the complexity analysis of an algorithm of Galbraith for explicitly computing isogenies between two elliptic curves in the same isogeny class, and extend it to a more general setting including genus 2.
- Research Article
- 10.1007/s00031-026-09946-2
- Feb 27, 2026
- Transformation Groups
We call an order O in a quadratic field K odd (resp. even) if its discriminant is an odd (resp. even) integer. We call an elliptic curve E over $${\mathbb {C}}$$ with CM odd (resp. even) if its endomorphism ring $$\textrm{End}(E)$$ is an odd (resp. even) order in the imaginary quadratic field $$\textrm{End}(E)\otimes {\mathbb {Q}}$$ . Suppose that $$j(E)\in {\mathbb {R}}$$ and let us consider the set $$\mathscr {J}({\mathbb {R}},E)$$ of all $$j(E^{\prime })$$ where $$E^{\prime }$$ is any elliptic curve that enjoys the following properties: . $$\bullet$$ $$E^{\prime }$$ is isogenous to E; $$\bullet$$ $$j(E^{\prime })\in {\mathbb {R}}$$ ; $$\bullet$$ $$E^{\prime }$$ has the same parity as E. We prove that the closure of $$\mathscr {J}({\mathbb {R}},E)$$ in $${\mathbb {R}}$$ is the closed semi-infinite interval $$(-\infty ,1728]$$ (resp. the whole $${\mathbb {R}}$$ ) if E is odd (resp. even). This paper was inspired by a question of Jean-Louis Colliot-Thélène and Alena Pirutka about the distribution of j-invariants of certain elliptic curves of CM type.
- Research Article
64
- 10.1007/s00208-005-0723-6
- Dec 9, 2005
- Mathematische Annalen
where q = e. The values of j(z) at imaginary quadratic arguments in the upper half of the complex plane are known as singular moduli. Singular moduli are algebraic integers which play prominent roles in classical and modern number theory (see [C, BCSH]). For example, Hilbert class fields of imaginary quadratic fields are generated by singular moduli. Furthermore, isomorphism classes of elliptic curves with complex multiplication are distinguished by singular moduli. Throughout, let d ≡ 0, 3 (mod 4) be a positive integer (so that −d is the discriminant of an order in an imaginary quadratic field), and let H(d) be the Hurwitz-Kronecker class number for the discriminant −d. Let Qd be the set of positive definite integral binary quadratic forms (note. including imprimitive forms, if there are any)