SearcharxivSearch

arXiv subjects

Guanju Xiao

Publications and source records attributed to Guanju Xiao.

6 recordsLinked to original sources

Endomorphism Rings of Supersingular Elliptic Curves and Ternary Quadratic Forms

Let $c<3p/16$ be a prime or $c=1$. Let $E$ be a $\mathbb{Z}[\sqrt{-cp}]$-oriented supersingular elliptic curve defined over $\mathbb{F}_{p^2}$. There exists a $c$-isogeny from $E$ to $E^p$ with kernel $G \subset E[c]$. Given an Eichler order corresponding to the endomorphism ring $\text{End}(E,G)=\{ θ\in \text{End}(E): θ(G) \subseteq G \}$, we can compute a ternary quadratic form with discriminant $p$ by solving two square roots in $\mathbb{F}_c$, and the ternary quadratic form corresponds to a maximal order $\mathcal{O} \cong \text{End}(E)$ in $B_{p,\infty}$ by Brandt--Sohn correspondence. Let $D$ be a prime with $D<p$ (resp. $4D<p$). If an imaginary quadratic order with discriminant $-D$ (resp. $-4D$) can be embedded into $\text{End}(E)$, then we can compute a maximal order in $B_{p,\infty}$ corresponding to $\text{End}(E)$ by solving one square root in $\mathbb{F}_D$ and two square roots in $\mathbb{F}_c$. As we know, any isogeny between supersingular elliptic curves can be translated into a kernel ideal of the endomorphism ring. We study the action of the kernel ideal and give a basis of its right order. In general, we propose an efficient algorithm for computing a maximal order from an Eichler order in $B_{p,\infty}$.

math.NT

Oriented Supersingular Elliptic Curves and Eichler Orders

Let $p>3$ be a prime and $E$ be a supersingular elliptic curve defined over $\mathbb{F}_{p^2}$. Let $c$ be a prime with $c < 3p/16$ and $G$ be a subgroup of $E[c]$ of order $c$. The pair $(E,G)$ is called a supersingular elliptic curve with level-$c$ structure, and the endomorphism ring $\text{End}(E,G)$ is isomorphic to an Eichler order with level $c$. We construct two kinds of Eichler orders $\mathcal{O}_c(q,r)$ and $\mathcal{O}'_c(q,r')$ with level $c$. Interestingly, we prove that each $\mathcal{O}_c(q,r)$ or $\mathcal{O}'_c(q,r')$ can represent a primitive reduced binary quadratic form with discriminant $-16cp$ or $-cp$ respectively. If a curve $E$ is $\mathbb{Z}[\sqrt{-cp}]$-oriented or $\mathbb{Z}[\frac{1+\sqrt{-cp}}{2}]$-oriented, then we prove that $\text{End}(E,G)$ is isomorphic to $\mathcal{O}_c(q,r)$ or $\mathcal{O}'_c(q,r')$ respectively. Due to the fact that $\mathbb{Z}[\sqrt{-cp}]$-oriented isogenies between $\mathbb{Z}[\sqrt{-cp}]$-oriented elliptic curves could be represented by quadratic forms, we show that these isogenies are reflected in the corresponding Eichler orders via the composition law for their corresponding quadratic forms.

math.NT

The Endomorphism Rings of Supersingular Elliptic Curves over $\mathbb{F}_p$ and the Binary Quadratic Forms

It is well known that there is a one-to-one correspondence between supersingular $j$-invariants up to the action of $\text{Gal}(\mathbb{F}_{p^2}/\mathbb{F}_p)$ and type classes of maximal orders in $B_{p,\infty}$ by Deuring's theorem. Interestingly, we establish a one-to-one correspondence between $\mathbb{F}_p$-isomorphism classes of supersingular elliptic curves and primitive reduced binary quadratic forms with discriminant $-p$ or $-16p$. Due to this correspondence and the fact that $\mathbb{F}_p$-isogenies between elliptic curves could be represented by quadratic forms, we show that operations of these isogenies on supersingular elliptic curves over $\mathbb{F}_p$ are compatible with the composition of quadratic forms. Based on these results, we could reduce the security of CSIDH cryptosystem to computing this correspondence explicitly.

math.NT

Supersingular $j$-invariants and the Class Number of $\mathbb{Q}(\sqrt{-p})$

For a prime $p>3$, let $D$ be the discriminant of an imaginary quadratic order with $|D|< \frac{4}{\sqrt{3}}\sqrt{p}$. We research the solutions of the class polynomial $H_D(X)$ mod $p$ in $\mathbb{F}_p$ if $D$ is not a quadratic residue in $\mathbb{F}_p$. We also discuss the common roots of different class polynomials in $\mathbb{F}_p$. As a result, we get a deterministic algorithm (Algorithm 3) for computing the class number of $\mathbb{Q}(\sqrt{-p})$. The time complexity of Algorithm 3 is $O(p^{3/4+ε})$.

math.NT

Constructing Cycles in Isogeny Graphs of Supersingular Elliptic Curves

Loops and cycles play an important role in computing endomorphism rings of supersingular elliptic curves and related cryptosystems. For a supersingular elliptic curve $E$ defined over $\mathbb{F}_{p^2}$, if an imaginary quadratic order $O$ can be embedded in $\text{End}(E)$ and a prime $L$ splits into two principal ideals in $O$, we construct loops or cycles in the supersingular $L$-isogeny graph at the vertices which are next to $j(E)$ in the supersingular $\ell$-isogeny graph where $\ell$ is a prime different from $L$. Next, we discuss the lengths of these cycles especially for $j(E)=1728$ and $0$. Finally, we also determine an upper bound on primes $p$ for which there are unexpected $2$-cycles if $\ell$ doesn't split in $O$.

math.NT

On two problems about isogenies of elliptic curves over finite fields

Isogenies occur throughout the theory of elliptic curves. Recently, the cryptographic protocols based on isogenies are considered as candidates of quantum-resistant cryptographic protocols. Given two elliptic curves $E_1, E_2$ defined over a finite field $k$ with the same trace, there is a nonconstant isogeny $β$ from $E_2$ to $E_1$ defined over $k$. This study gives out the index of $\rm{Hom}_{\it k}(\it E_{\rm 1},E_{\rm 2})β$ as a left ideal in $\rm{End}_{\it k}(\it E_{\rm 2})$ and figures out the correspondence between isogenies and kernel ideals. In addition, some results about the non-trivial minimal degree of isogenies between the two elliptic curves are also provided.

math.NT