SearcharxivSearch

arXiv subjects

Eleni Agathocleous

Publications and source records attributed to Eleni Agathocleous.

7 recordsLinked to original sources

Isogeny Graphs in Superposition and Quantum Onion Routing

Onion routing provides anonymity by layering encryption so that no relay can link sender to destination. A quantum analogue faces a core obstacle: layered quantum encryption generally requires symmetric encryption schemes, whereas classically one would rely on public-key encryption. We propose a symmetric-encryption-based quantum onion routing (QOR) scheme by instantiating each layer with the abelian ideal class group action from the Theory of Complex Multiplication. Session keys are established locally via a Diffie-Hellman key exchange between neighbors in the chain of communication. Furthermore, we propose a novel ''non-local'' key exchange between the sender and receiver. The underlying problem remains hard even for quantum adversaries and underpins the security of current post-quantum schemes. We connect our construction to isogeny graphs and their association schemes, using the Bose-Mesner algebra to formalize commutativity and guide implementation. We give two implementation paths: (i) a universal quantum oracle evaluating the class group action with polynomially many quantum resources, and (ii) an intrinsically quantum approach via continuous-time quantum walks (CTQWs), outlined here and developed in a companion paper. A small Qiskit example illustrates the mechanics (by design, not the efficiency) of the QOR.

quant-ph

Elliptic Curves with positive rank and no integral points

We consider all \emph{odd} fundamental discriminants $D \equiv 2 \bmod 3$ and their mirror discriminants $D' = -3D$, and we study the family of elliptic curves $E_{D'}: y^{2} = x^{3} + 16D'$. We denote by $r_{3}(D)$ and $r_{3}(D')$ the rank of the $3$-part of the ideal class group of $\mathbb{Q}(\sqrt{D})$ and $\mathbb{Q}(\sqrt{D'})$ respectively. We show that every curve in the subfamily of elliptic curves $E_{D'}$ with $r_{3}(D) = r_{3}(D') + 1$ for $D < 0$ (respectively, with $r_{3}(D) = r_{3}(D')$ for $D > 0$) cannot have any integral points, and this is proved unconditionally. By employing results of Satgé and by assuming finiteness of the $3$-primary part of their Tate-Shafarevich group, we show that the curves $E_{D'}$ must have odd rank when $D < 0$ and even rank when $D > 0$. This result is particularly interesting for the case of $D < 0$ since every curve $E_{D'}$ with $r_{3}(D) = r_{3}(D') + 1$ has infinitely many rational points - assuming finiteness of the $3$-primary part of their Tate-Shafarevich group - yet no integral points. We obtain an unconditional result on the existence of elliptic curves with non-trivial rank and no integral points, by defining a parametrised family of such curves with no integral points but with a parametrised rational point, which we prove that it is of infinite order.

math.NT

On the Selmer group and rank of a family of elliptic curves and curves of genus one violating the Hasse principle

We study an infinite family of $j$-invariant zero elliptic curves $E_{D}:y^{2}=x^{3}+16D$ and their $λ$-isogenous curves $E_{D'}:y^{2}=x^{3}-27\cdot16D$, where $D$ and $D' = -3D$ are fundamental discriminants of a specific form, and $λ$ is an isogeny of degree $3$. A result of Honda guarantees that for our discriminants $D$, the quadratic number field $K_{D} = \mathbb{Q}(\sqrt{D})$ always has non-trivial 3-class group. We prove a series of results related to the set of rational points $E_{D'}(\mathbb{Q}) \setminus λ(E_{D}(\mathbb{Q}))$, and the $SL(2,\mathbb{Z})$-equivalence classes of irreducible integral binary cubic forms of discriminant $D$. By assuming finiteness of the Tate-Shafarevich group, we derive a parity result between the rank of $E_{D}$ and the rank of its $3$-Selmer group, and we establish lower and upper bounds for the rank of our elliptic curves. Finally, we give explicit classes of genus-$1$ curves that correspond to irreducible integral binary cubic forms of discriminant $D=48035713$, and we show that every curve in these classes violates the Hasse Principle.

math.NT

Elliptic curves over Hasse pairs

We call a pair of distinct prime powers $(q_1,q_2) = (p_1^{a_1},p_2^{a_2})$ a Hasse pair if $|\sqrt{q_1}-\sqrt{q_2}| \leq 1$. For such pairs, we study the relation between the set $\mathcal{E}_1$ of isomorphism classes of elliptic curves defined over $\mathbb{F}_{q_1}$ with $q_2$ points, and the set $\mathcal{E}_2$ of isomorphism classes of elliptic curves over $\mathbb{F}_{q_2}$ with $q_1$ points. When both families $\mathcal{E}_i$ contain only ordinary elliptic curves, we prove that their isogeny graphs are isomorphic. When supersingular curves are involved, we describe which curves might belong to these sets. We also show that if both the $q_i$'s are odd and $\mathcal{E}_1 \cup \mathcal{E}_2 \neq \emptyset$, then $\mathcal{E}_1 \cup \mathcal{E}_2$ always contains an ordinary elliptic curve. Conversely, if $q_1$ is even, then $\mathcal{E}_1 \cup \mathcal{E}_2$ may contain only supersingular curves precisely when $q_2$ is a given power of a Fermat or a Mersenne prime. In the case of odd Hasse pairs, we could not rule out the possibility of an empty union $\mathcal{E}_1 \cup \mathcal{E}_2$, but we give necessary conditions for such a case to exist. In an appendix, Moree and Sofos consider how frequently Hasse pairs occur using analytic number theory, making a connection with Andrica's conjecture on the difference between consecutive primes.

math.NT

On homomorphic encryption using abelian groups: Classical security analysis

In [15], Leonardi and Ruiz-Lopez propose an additively homomorphic public key encryption scheme whose security is expected to depend on the hardness of the learning homomorphism with noise problem (LHN). Choosing parameters for their primitive requires choosing three groups $G$, $H$, and $K$. In their paper, Leonardi and Ruiz-Lopez claim that, when $G$, $H$, and $K$ are abelian, then their public key cryptosystem is not quantum secure. In this paper, we study security for finite abelian groups $G$, $H$, and $K$ in the classical case. Moreover, we study quantum attacks on instantiations with solvable groups.

cs.CR

On the class numbers of real cyclotomic fields of conductor $pq$

The class numbers $h^{+}$ of the real cyclotomic fields are very hard to compute. Methods based on discriminant bounds become useless as the conductor of the field grows and methods employing Leopoldt's decomposition of the class number become hard to use when the field extension is not cyclic of prime power. This is why other methods have been developed which approach the problem from different angles. In this paper we extend one of these methods that was designed for real cyclotomic fields of prime conductor, and we make it applicable to real cyclotomic fields of conductor equal to the product of two distinct odd primes. The main advantage of this method is that it does not exclude the primes dividing the order of the Galois group, in contrast to other methods. We applied our algorithm to real cyclotomic fields of conductor $<$ 2000 and we calculated the full order of the $l$-part of $h^{+}$ for all odd primes $l$ $<$ 10000.

math.NT

The 3-part of the Ideal Class Group of a certain family of real cyclotomic fields

In this paper we study the structure of the $3-$part of the ideal class group of a certain family of real cyclotomic fields with $3-$class number exactly $9$ and conductor equal to the product of two distinct odd primes. We employ known results from Class Field Theory as well as theoretical and numerical results on real cyclic sextic fields, and we show that the $3-$part of the ideal class group of such cyclotomic fields must be cyclic. We present four examples of fields that fall into our category, namely the fields of conductor $3 \cdot 331$, $7 \cdot 67$, $3 \cdot 643$ and $7 \cdot 257$, and they are the only ones amongst all real cyclotomic fields with conductor $pq \leq 2021$. The $3-$part of the class number for the two fields of conductor $3 \cdot 643$ and $7 \cdot 257$ was up to now unknown and we compute it in this paper.

math.NT