SearcharxivSearch

arXiv subjects

David Kohel

Publications and source records attributed to David Kohel.

14 recordsLinked to original sources

Weber modular curves and modular isogenies

We study the modular curves defined by Weber functions, and associated modular polynomials, action of $\mathrm{SL}_2(\mathbb{Z})$, and parametrizations of elliptic curves with a view to the study of the isogeny graphs that they determine, particularly for supersingular elliptic curves. In addition to applications to efficient isogeny computation in cryptographic applications, we present an application to explicit Galois representations.

math.NT

On Sato--Tate distributions, extremal traces, and real multiplication in genus 2

The vertical Sato--Tate conjectures gives expected trace distributions for for families of curves. We develop exact expression for the distribution associated to degree-$4$ representations of $\mathrm{USp}(4)$, $\mathrm{SU}(2)\times\mathrm{SU}(2)$ and $\mathrm{SU}(2)$ in the neighborhood of the extremities of the Weil bound. As a consequence we derive qualitative distinctions between the extremal traces arising from generic genus-$2$ curves and genus-$2$ curves with real or quaternionic multiplication. In particular we show, in a specific sense, to what extent curves with real multiplication dominate the contribution to extremal traces.

math.NT

Twisted $\boldsymbol{\mu}_4$-normal form for elliptic curves

We introduce the twisted $\boldsymbol{\mu}_4$-normal form for elliptic curves, deriving in particular addition algorithms with complexity $9\mathbf{M} + 2\mathbf{S}$ and doubling algorithms with complexity $2\mathbf{M} + 5\mathbf{S} + 2\mathbf{m}$ over a binary field. Every ordinary elliptic curve over a finite field of characteristic 2 is isomorphic to one in this family. This improvement to the addition algorithm, applicable to a larger class of curves, is comparable to the $7\mathbf{M} + 2\mathbf{S}$ achieved for the $\boldsymbol{\mu}_4$-normal form, and replaces the previously best known complexity of $13\mathbf{M} + 3\mathbf{S}$ on L\'opez-Dahab models applicable to these twisted curves. The derived doubling algorithm is essentially optimal, without any assumption of special cases. We show moreover that the Montgomery scalar multiplication with point recovery carries over to the twisted models, giving symmetric scalar multiplication adapted to protect against side channel attacks, with a cost of $4\mathbf{M} + 4\mathbf{S} + 1\mathbf{m}_t + 2\mathbf{m}_c$ per bit. In characteristic different from 2, we establish a linear isomorphism with the twisted Edwards model over the base field. This work, in complement to the introduction of $\boldsymbol{\mu}_4$-normal form, fills the lacuna in the body of work on efficient arithmetic on elliptic curves over binary fields, explained by this common framework for elliptic curves in $\boldsymbol{\mu}_4$-normal form over a field of any characteristic. The improvements are analogous to those which the Edwards and twisted Edwards models achieved for elliptic curves over finite fields of odd characteristic, and extend $\boldsymbol{\mu}_4$-normal form to cover the binary NIST curves.

math.NT

Orienting supersingular isogeny graphs

We introduce a category of $\mathcal{O}$-orientedsupersingularellipticcurves and derive properties of the associated oriented and nonoriented $\ell$-isogeny supersingular isogeny graphs. As an application we introduce an oriented super-singular isogeny Diffie-Hellman protocol (OSIDH), analogous to the supersingular isogeny Diffie-Hellman (SIDH) protocol and generalizing the commutative supersingular isogeny Diffie-Hellman (CSIDH) protocol.

math.NT

Arithmetic statistics of Galois groups

We develop a computational framework for the statistical characterization of Galois characters with finite image, with application to characterizing Galois groups and establishing equivalence of characters of finite images of $\mathrm{Gal}(\overline{\mathbb{Q}}/\mathbb{Q})$.

math.NT

A special configuration of $12$ conics and generalized Kummer surfaces

A generalized Kummer surface $X$ obtained as the quotient of an abelian surface by a symplectic automorphism of order 3 contains a $9\mathbf{A}_{2}$-configuration of $(-2)$-curves. Such a configuration plays the role of the $16\mathbf{A}_{1}$-configurations for usual Kummer surfaces. In this paper we construct $9$ other such $9\mathbf{A}_{2}$-configurations on the generalized Kummer surface associated to the double cover of the plane branched over the sextic dual curve of a cubic curve. The new $9\mathbf{A}_{2}$-configurations are obtained by taking the pullback of a certain configuration of $12$ conics which are in special position with respect to the branch curve, plus some singular quartic curves. We then construct some automorphisms of the K3 surface sending one configuration to another. We also give various models of $X$ and of the generic fiber of its natural elliptic pencil.

math.AG

The geometry of efficient arithmetic on elliptic curves

The arithmetic of elliptic curves, namely polynomial addition and scalar multiplication, can be described in terms of global sections of line bundles on $E\times E$ and $E$, respectively, with respect to a given projective embedding of $E$ in $\mathbb{P}^r$. By means of a study of the finite dimensional vector spaces of global sections, we reduce the problem of constructing and finding efficiently computable polynomial maps defining the addition morphism or isogenies to linear algebra. We demonstrate the effectiveness of the method by improving the best known complexity for doubling and tripling, by considering families of elliptic curves admiting a $2$-torsion or $3$-torsion point.

math.NT

Efficient arithmetic on elliptic curves in characteristic 2

We present normal forms for elliptic curves over a field of characteristic $2$ analogous to Edwards normal form, and determine bases of addition laws, which provide strikingly simple expressions for the group law. We deduce efficient algorithms for point addition and scalar multiplication on these forms. The resulting algorithms apply to any elliptic curve over a field of characteristic $2$ with a $4$-torsion point, via an isomorphism with one of the normal forms. We deduce algorithms for duplication in time $2M + 5S + 2m_c$ and for addition of points in time $7M + 2S$, where $M$ is the cost of multiplication, $S$ the cost of squaring, and $m_c$ the cost of multiplication by a constant. By a study of the Kummer curves $\mathcal{K} = E/\{[\pm1]\}$, we develop an algorithm for scalar multiplication with point recovery which computes the multiple of a point $P$ with $4M + 4S + 2m_c + m_t$ per bit where $m_t$ is multiplication by a constant that depends on $P$.

math.NT

Arithmetic of split Kummer surfaces: Montgomery endomorphism of Edwards products

Let $E$ be an elliptic curve, $\mathcal{K}_1$ its Kummer curve $E/\{\pm1\}$, $E^2$ its square product, and $\mathcal{K}_2$ the split Kummer surface $E^2/\{\pm1\}$. The addition law on $E^2$ gives a large endomorphism ring, which induce endomorphisms of $\mathcal{K}_2$. With a view to the practical applications to scalar multiplication on $\mathcal{K}_1$, we study the explicit arithmetic of $\mathcal{K}_2$.

math.NT

On the quaternion $\ell$-isogeny path problem

Let $\cO$ be a maximal order in a definite quaternion algebra over $\mathbb{Q}$ of prime discriminant $p$, and $\ell$ a small prime. We describe a probabilistic algorithm, which for a given left $O$-ideal, computes a representative in its left ideal class of $\ell$-power norm. In practice the algorithm is efficient, and subject to heuristics on expected distributions of primes, runs in expected polynomial time. This breaks the underlying problem for a quaternion analog of the Charles-Goren-Lauter hash function, and has security implications for the original CGL construction in terms of supersingular elliptic curves.

math.NT

Complete addition laws on abelian varieties

We prove that under any projective embedding of an abelian variety A of dimension g, a complete system of addition laws has cardinality at least g+1, generalizing of a result of Bosma and Lenstra for the Weierstrass model of an elliptic curve in P^2. In contrast with this geometric constraint, we moreover prove that if k is any field with infinite absolute Galois group, then there exists, for every abelian variety A/k, a projective embedding and an addition law defined for every pair of k-rational points. For an abelian variety of dimension 1 or 2, we show that this embedding can be the classical Weierstrass model or embedding in P^15, respectively, up to a finite number of counterexamples for |k| less or equal to 5.

math.NT

Counting Points on Genus 2 Curves with Real Multiplication

We present an accelerated Schoof-type point-counting algorithm for curves of genus 2 equipped with an efficiently computable real multiplication endomorphism. Our new algorithm reduces the complexity of genus 2 point counting over a finite field (\F_{q}) of large characteristic from (\widetilde{O}(\log^8 q)) to (\widetilde{O}(\log^5 q)). Using our algorithm we compute a 256-bit prime-order Jacobian, suitable for cryptographic applications, and also the order of a 1024-bit Jacobian.

math.NT

Addition law structure of elliptic curves

The study of alternative models for elliptic curves has found recent interest from cryptographic applications, once it was recognized that such models provide more efficiently computable algorithms for the group law than the standard Weierstrass model. Examples of such models arise via symmetries induced by a rational torsion structure. We analyze the module structure of the space of sections of the addition morphisms, determine explicit dimension formulas for the spaces of sections and their eigenspaces under the action of torsion groups, and apply this to specific models of elliptic curves with parametrized torsion subgroups.

math.NT