SearcharxivSearch

arXiv subjects

Aurel Page

Publications and source records attributed to Aurel Page.

12 recordsLinked to original sources

Average hardness of SIVP for module lattices of fixed rank

The problem of finding short vectors in Euclidean lattices is a central hard problem in complexity theory. The case of module lattices (i.e., lattices which are also modules over a number ring) is of particular interest for cryptography and computational number theory. The hardness of finding short vectors in the asymptotic regime where the rank (as a module) is fixed is supporting the security of quantum-resistant cryptographic standards such as ML-DSA and ML-KEM. In this article we prove the average-case hardness of this problem for uniformly random module lattices (with respect to the natural invariant measure on the space of module lattices of any fixed rank). More specifically, we prove a polynomial-time worst-case to average-case self-reduction for the approximate Shortest Independent Vector Problem ($\gamma$-SIVP) where the average case is the (discretized) uniform distribution over module lattices, with a polynomially-bounded loss in the approximation factor, assuming the Extended Riemann Hypothesis. This result was previously known only in the rank-1 case (so-called ideal lattices). That proof critically relied on the fact that the space of ideal lattices is a compact group. In higher rank, the space is neither compact nor a group. Our main tool to overcome the resulting challenges is the theory of automorphic forms, which we use to prove a new quantitative rapid equidistribution result for random walks in the space of module lattices.

math.NT

Vign\'eras orbifolds: isospectrality, regulators, and torsion homology

We develop a new approach to the isospectrality of the orbifolds constructed by Vign\'eras. We give fine sufficient criteria for i-isospectrality in given degree i and for representation equivalence. These allow us to produce very small exotic examples of isospectral orbifolds: hyperbolic 3-orbifolds that are i-isospectral for all i but not representation equivalent, hyperbolic 3-orbifolds that are 0-isospectral but not 1-isospectral, and others. Using the same method, we also give sufficient criteria for rationality of regulator quotients Reg_i(Y_1)^2/Reg_i(Y_2)^2 for Vign\'eras orbifolds Y_1, Y_2, sometimes even when they are not isospectral. Moreover, we establish a link between the primes that enter in these regulator quotients and at which torsion homology of Y_1 and Y_2 can differ, and Galois representations.

math.NT

The supersingular Endomorphism Ring and One Endomorphism problems are equivalent

The supersingular Endomorphism Ring problem is the following: given a supersingular elliptic curve, compute all of its endomorphisms. The presumed hardness of this problem is foundational for isogeny-based cryptography. The One Endomorphism problem only asks to find a single non-scalar endomorphism. We prove that these two problems are equivalent, under probabilistic polynomial time reductions. We prove a number of consequences. First, assuming the hardness of the endomorphism ring problem, the Charles--Goren--Lauter hash function is collision resistant, and the SQIsign identification protocol is sound. Second, the endomorphism ring problem is equivalent to the problem of computing arbitrary isogenies between supersingular elliptic curves, a result previously known only for isogenies of smooth degree. Third, there exists an unconditional probabilistic algorithm to solve the endomorphism ring problem in time O~(sqrt(p)), a result that previously required to assume the generalized Riemann hypothesis. To prove our main result, we introduce a flexible framework for the study of isogeny graphs with additional information. We prove a general and easy-to-use rapid mixing theorem. The proof of this result goes via an augmented Deuring correspondence and the Jacquet-Langlands correspondence.

cs.CR

Computing groups of Hecke characters

We describe algorithms to represent and compute groups of Hecke characters. We make use of an id{\`e}lic point of view and obtain the whole family of such characters, including transcendental ones. We also show how to isolate the algebraic characters, which are of particular interest in number theory. This work has been implemented in Pari/GP, and we illustrate our work with a variety of explicit examples using our implementation.

cs.SC

Sorting and labelling integral ideals in a number field

We define a scheme for labelling and ordering integral ideals of number fields, including prime ideals as a special case. The order we define depends only on the choice of a monic irreducible integral defining polynomial for each field $K$, and we start by defining for each field its unique reduced defining polynomial, after Belabas. We define a total order on the set of prime ideals of $K$ and then extend this to a total order on the set of all nonzero integral ideals of $K$. This order allows us to give a unique label of the form $N.i$, where $N$ is its norm and $i$ is the index of the ideal in the ordered list of all ideals of norm $N$. Our ideal labelling scheme has several nice properties: for a given norm, prime ideals always appear first, and given the factorisation of the norm, the bijection between ideals of norm $N$ and labels is computable in polynomial time. Our motivation for this is to have a well-defined and concise way to sort and label ideals for use in databases such as the LMFDB. We have implemented algorithms which realise this scheme, in Sage, Magma and Pari.

math.NT

Norm relations and computational problems in number fields

For a finite group $G$, we introduce a generalization of norm relations in the group algebra $\mathbb Q[G]$. We give necessary and sufficient criteria for the existence of such relations and apply them to obtain relations between the arithmetic invariants of the subfields of a normal extension of algebraic number fields with Galois group $G$. On the algorithmic side this leads to subfield based algorithms for computing rings of integers, $S$-unit groups and class groups. For the $S$-unit group computation this yields a polynomial time reduction to the corresponding problem in subfields. We compute class groups of large number fields under GRH, and new unconditional values of class numbers of cyclotomic fields.

math.NT

Computing isogenies from modular equations in genus two

We present an algorithm solving the following problem: given two genus 2 curves over a field k with isogenous Jacobians, compute such an isogeny explicitly. This isogeny can be either an l-isogeny or, in the real multiplication case, an isogeny with cyclic kernel; we require that k have large enough characteristic and that the curves be sufficiently generic. Our algorithm uses modular equations for these isogeny types, and makes essential use of an explicit Kodaira--Spencer isomorphism in genus 2.

math.AG

Codes from unit groups of division algebras over number fields

Lenstra and Guruswami described number field analogues of the algebraic geometry codes of Goppa. Recently, the first author and Oggier generalised these constructions to other arithmetic groups: unit groups in number fields and orders in division algebras; they suggested to use unit groups in quaternion algebras but could not completely analyse the resulting codes. We prove that the noncommutative unit group construction yields asymptotically good families of codes for the sum-rank metric from division algebras of any degree, and we estimate the size of the alphabet in terms of the degree.

math.NT

Group representations in the homology of 3-manifolds

If M is a manifold with an action of a group G, then the homology group H_1(M,Q) is naturally a Q[G]-module, where Q[G] denotes the rational group ring. We prove that for every finite group G, and for every Q[G]-module V, there exists a closed hyperbolic 3-manifold M with a free G-action such that the Q[G]-module H_1(M,Q) is isomorphic to V. We give an application to spectral geometry: for every finite set P of prime numbers, there exist hyperbolic 3-manifolds N and N' that are strongly isospectral such that for all p in P, the p-power torsion subgroups of H_1(N,Z) and of H_1(N',Z) have different orders. We also show that, in a certain precise sense, the rational homology of oriented Riemannian 3-manifolds with a G-action "knows" nothing about the fixed point structure under G, in contrast to the 2-dimensional case. The main geometric techniques are Dehn surgery and, for the spectral application, the Cheeger-M\"uller formula, but we also make use of tools from different branches of algebra, most notably of regulator constants, a representation theoretic tool that was originally developed in the context of elliptic curves.

math.GT

Torsion homology and regulators of isospectral manifolds

Given a finite group G, a G-covering of closed Riemannian manifolds, and a so-called G-relation, a construction of Sunada produces a pair of manifolds M_1 and M_2 that are strongly isospectral. Such manifolds have the same dimension and the same volume, and their rational homology groups are isomorphic. We investigate the relationship between their integral homology. The Cheeger-Mueller Theorem implies that a certain product of orders of torsion homology and of regulators for M_1 agrees with that for M_2. We exhibit a connection between the torsion in the integral homology of M_1 and M_2 on the one hand, and the G-module structure of integral homology of the covering manifold on the other, by interpreting the quotients Reg_i(M_1)/Reg_i(M_2) representation theoretically. Further, we prove that the p-primary torsion in the homology of M_1 is isomorphic to that of M_2 for all primes p not dividing #G. For p <= 71, we give examples of pairs of isospectral hyperbolic 3-manifolds for which the p-torsion homology differs, and we conjecture such examples to exist for all primes p.

math.DG

An algorithm for the principal ideal problem in indefinite quaternion algebras

Deciding whether an ideal of a number field is principal and finding a generator is a fundamental problem with many applications in computational number theory. For indefinite quaternion algebras, the decision problem reduces to that in the underlying number field. Finding a generator is hard, and we present a heuristically subexponential algorithm.

math.NT

Computing arithmetic Kleinian groups

Arithmetic Kleinian groups are arithmetic lattices in PSL_2(C). We present an algorithm which, given such a group Gamma, returns a fundamental domain and a finite presentation for Gamma with a computable isomorphism.

math.NT