Searcharxiv⌕ Search

arXiv subjects

Benjamin Smith

Publications and source records attributed to Benjamin Smith.

62 records · Page 4Linked to original sources

Families of fast elliptic curves from Q-curves

We construct new families of elliptic curves over \(\FF_{p^2}\) with efficiently computable endomorphisms, which can be used to accelerate elliptic curve-based cryptosystems in the same way as Gallant-Lambert-Vanstone (GLV) and Galbraith-Lin-Scott (GLS) endomorphisms. Our construction is based on reducing \(\QQ\)-curves-curves over quadratic number fields without complex multiplication, but with isogenies to their Galois conjugates-modulo inert primes. As a first application of the general theory we construct, for every \(p > 3\), two one-parameter families of elliptic curves over \(\FF_{p^2}\) equipped with endomorphisms that are faster than doubling. Like GLS (which appears as a degenerate case of our construction), we offer the advantage over GLV of selecting from a much wider range of curves, and thus finding secure group orders when \(p\) is fixed. Unlike GLS, we also offer the possibility of constructing twist-secure curves. Among our examples are prime-order curves equipped with fast endomorphisms, with almost-prime-order twists, over \(\FF_{p^2}\) for \(p = 2^{127}-1\) and \(p = 2^{255}-19\).

math.NT↗

Computing low-degree isogenies in genus 2 with the Dolgachev-Lehavi method

Let ell be a prime, and H a curve of genus 2 over a field k of characteristic not 2 or ell. If S is a maximal Weil-isotropic subgroup of Jac(H)[ell], then Jac(H)/S is isomorphic to the Jacobian of some (possibly reducible) curve X. We investigate the Dolgachev--Lehavi method for constructing the curve X, simplifying their approach and making it more explicit. The result, at least for ell=3, is an efficient and easily programmable algorithm suitable for number-theoretic calculations.

math.NT↗

Counting Points on Genus 2 Curves with Real Multiplication

We present an accelerated Schoof-type point-counting algorithm for curves of genus 2 equipped with an efficiently computable real multiplication endomorphism. Our new algorithm reduces the complexity of genus 2 point counting over a finite field (\F_{q}) of large characteristic from (\widetilde{O}(\log^8 q)) to (\widetilde{O}(\log^5 q)). Using our algorithm we compute a 256-bit prime-order Jacobian, suitable for cryptographic applications, and also the order of a 1024-bit Jacobian.

math.NT↗

Families of explicitly isogenous Jacobians of variable-separated curves

We construct six infinite series of families of pairs of curves (X,Y) of arbitrarily high genus, defined over number fields, together with an explicit isogeny from the Jacobian of X to the Jacobian of Y splitting multiplication by 2, 3, or 4. For each family, we compute the isomorphism type of the isogeny kernel and the dimension of the image of the family in the appropriate moduli space. The families are derived from Cassou--Noguès and Couveignes' explicit classification of pairs (f,g) of polynomials such that f(x_1) - g(x_2) is reducible.

math.NT↗

Families of Explicit Isogenies of Hyperelliptic Jacobians

We construct three-dimensional families of hyperelliptic curves of genus 6, 12, and 14, two-dimensional families of hyperelliptic curves of genus 3, 6, 7, 10, 20, and 30, and one-dimensional families of hyperelliptic curves of genus 5, 10 and 15, all of which are equipped with an an explicit isogeny from their Jacobian to another hyperelliptic Jacobian. We show that the Jacobians are generically absolutely simple, and describe the kernels of the isogenies. The families are derived from Cassou--Noguès and Couveignes' explicit classification of pairs $(f,g)$ of polynomials such that $f(x_1) - g(x_2)$ is reducible.

math.NT↗

Isogenies and the Discrete Logarithm Problem in Jacobians of Genus 3 Hyperelliptic Curves

We describe the use of explicit isogenies to translate instances of the Discrete Logarithm Problem (DLP) from Jacobians of hyperelliptic genus 3 curves to Jacobians of non-hyperelliptic genus 3 curves, where they are vulnerable to faster index calculus attacks. We provide explicit formulae for isogenies with kernel isomorphic to $(\ZZ/2\ZZ)^3$ (over an algebraic closure of the base field) for any hyperelliptic genus 3 curve over a field of characteristic not 2 or 3. These isogenies are rational for a positive fraction of all hyperelliptic genus 3 curves defined over a finite field of characteristic $p > 3$. Subject to reasonable assumptions, our constructions give an explicit and efficient reduction of instances of the DLP from hyperelliptic to non-hyperelliptic Jacobians for around 18.57% of all hyperelliptic genus 3 curves over a given finite field. We conclude with a discussion on extending these ideas to isogenies with more general kernels. A condensed version of this work appeared in the proceedings of the EUROCRYPT 2008 conference.

math.NT↗

Distortion maps for genus two curves

Distortion maps are a useful tool for pairing based cryptography. Compared with elliptic curves, the case of hyperelliptic curves of genus g > 1 is more complicated since the full torsion subgroup has rank 2g. In this paper we prove that distortion maps always exist for supersingular curves of genus g>1 and we construct distortion maps in genus 2 (for embedding degrees 4,5,6 and 12).

math.NT↗

Cessation of X-ray Pulsation of GX 1+4

We report results from our weekly monitoring campaign on the X-ray pulsar GX 1+4 with the {\em Rossi X-ray Timing Explorer} satellite. The spin-down trend of GX 1+4 was continuing, with the pulsar being at its longest period ever measured (about 138.7 s). At the late stage of the campaign, the source entered an extended faint state, when its X-ray (2-60 keV) flux decreased significantly to an average level of $\sim 3 \times 10^{-10} ergs cm^{-2} s^{-1}$. It was highly variable in the faint state; the flux dropped to as low as $\sim 3 \times 10^{-11} ergs cm^{-2} s^{-1}$. In several observations during this period, the X-ray pulsation became undetectable. We can, therefore, conclude conservatively that the pulsed fraction, which is normally $\gtrsim$ 70% (peak-to-peak), must have decreased drastically in those cases. This is very similar to what was observed of GX 1+4 in 1996 when it became similarly faint in X-ray. In fact, the flux at which the cessation of X-ray pulsation first occurred is nearly the same as it was in 1996. We suggest that we have, once again, observed the propeller effect in GX 1+4, a phenomenon that is predicted by theoretical models of accreting X-ray pulsars.

astro-ph↗