Searcharxiv⌕ Search

arXiv subjects

Katherine E. Stange

Publications and source records attributed to Katherine E. Stange.

At least 19 recordsLinked to original sources

Eisenstein circle packings and the Eisenpint Schmidt arrangement

The Schmidt arrangement of an imaginary quadratic number field $K$ is the orbit of the extended real line under $\text{PSL}(2, \mathcal{O}_K)$ as Möbius transformations on the extended complex plane. If $K\neq\mathbb{Q}(\sqrt{-3})$, then the resulting set of circles can only intersect tangentially, leading to various classes of integral circle packings, including Apollonian circle packings. When $K=\mathbb{Q}(\sqrt{-3})$, circles can intersect at angles of $\fracπ{3}$ and $\frac{2π}{3}$, making it unclear how to extract circle packings from the arrangement. The goal of this paper is to study a modification of the $\mathbb{Q}(\sqrt{-3})-$Schmidt arrangement called the "Eisenpint Schmidt arrangement" and associated integral "Eisenstein circle packings". In analogy to the study of Apollonian circle packings, we study the number theory of such packings, including associated families of quadratic forms, show the Eisenpint Schmidt arrangement is formed of exactly all primitive Eisenstein circle packings, show strong approximation and classify congruence obstructions, prove a density-one local-global statement, and find quadratic -- but alas no cubic -- reciprocity obstructions. Unexpected aspects of the Eisenstein case include the role of congruence subgroups, the bipartite nature of the packings and reciprocity obstructions, the coefficients of quadratic obstructions, an abundance of extra symmetry, and the need to use "first-odd" quadratic forms.

math.NT↗

Division polynomials for arbitrary isogenies

Following work of Mazur-Tate and Satoh, we extend the definition of division polynomials to arbitrary isogenies of elliptic curves, including those whose kernels do not sum to the identity. In analogy to the classical case of division polynomials for multiplication-by-n, we demonstrate recurrence relations, identities relating to classical elliptic functions, the chain rule describing relationships between division polynomials on source and target curve, and generalizations to higher dimension (i.e., elliptic nets).

math.NT↗

Sesquilinear pairings on elliptic curves

Let $E$ be an elliptic curve with complex multiplication by a ring $R$, where $R$ is an order in an imaginary quadratic field or quaternion algebra. We define sesquilinear pairings ($R$-linear in one variable and $R$-conjugate linear in the other), taking values in an $R$-module, generalizing the Weil and Tate-Lichtenbaum pairings.

math.NT↗

Prime and thickened prime components in Apollonian circle packings

Inspired by a question of Sarnak, we introduce the notion of a prime component in an Apollonian circle packing: a maximal tangency-connected subset having all prime curvatures. We also consider thickened prime components, which are augmented by all circles immediately tangent to the prime component. In both cases, we ask about the curvatures which appear. We consider the residue classes attained by the set of curvatures, the number of circles in such components, the number of distinct integers occurring as curvatures, and the number of prime components in a packing. As part of our investigation, we computed and analysed example components up to around curvature $10^{13}$; software is available.

math.NT↗

Primes represented by shifted quadratic forms: on primitivity and congruence classes

We prove lower bounds of the form $\gg N/(\log N)^{3/2}$ for the number of primes up to $N$ primitively represented by a shifted positive definite integral binary quadratic form, and under the additional condition that primes are from an arithmetic progression. This extends the sieve methods of Iwaniec, who showed such lower bounds without the primitivity and congruence conditions. Imposing primitivity adds some subtleties to the local criteria for representation of a shifted prime: for example, some shifted quadratic forms of discriminant $5 \pmod{8}$ do not primitively represent infinitely many primes. We also provide a careful list of the local conditions under which a genus of an integral binary quadratic form represents an integer, verified by computer, and correcting some minor errors in previous statements. The motivation for this work is as a tool for the study of prime components in Apollonian circle packings [FFH+24]

math.NT↗

Reciprocity obstructions in semigroup orbits in SL(2, Z)

We study orbits of semigroups of $\text{SL}(2,\mathbb{Z})$, and demonstrate reciprocity obstructions: we show that certain such orbits avoid squares, but not as a consequence of obstructions inherited from an algebraic set, and not as a consequence of congruence obstructions. This is in analogy to the reciprocity obstructions recently used to disprove the Apollonian local-global conjecture. We give an example of such an orbit which is known exactly, and misses all squares together with an explicit finite list of sporadic values: the corresponding semigroup is not thin, but is dense in an algebraic variety that does not have such obstructions. We also demonstrate thin semigroups with reciprocity obstructions, including semigroups associated to continued fractions formed from finite alphabets. Zaremba's conjecture states that for continued fractions with coefficients chosen from $\{1,\ldots,5\}$, every positive integer appears as a denominator. Bourgain and Kontorovich proposed a generalization of Zaremba's conjecture in the context of semigroups associated to finite alphabets. We disprove their conjecture. In particular, we demonstrate classes of finite continued fraction expansions which never represent rationals with square denominator, but not as a consequence of congruence obstructions, and for which the limit set has Hausdorff dimension exceeding $1/2$. An example of such a class is continued fractions of the form $[0; a_1, a_2, \ldots, a_n,1,1,2]$, where the $a_i$ are chosen from the set $\{4,8,12,\ldots,128\}$. The object at the heart of these results is a semigroup $Ψ\subseteqΓ_1(4)$ which preserves Kronecker symbols.

math.NT↗

An illustrated introduction to the arithmetic of Apollonian circle packings, continued fractions, and other thin orbits

These notes cover and expand upon the material for two summer schools: The first, which was held at CIRM, Marseille, France, July 10-14, 2023, as part of "Renormalization and Visualization for packing, billiard and surfaces", was titled "Number theory as a door to geometry, dynamics and illustration". The second was held at NSU IMS in Singapore, June 3-7, 2024, as part of "Computational Aspects of Thin Groups", and was titled "Integral packings and number theory". Both courses were put together by a number theorist for students and researchers in other fields. They cover a web of ideas relating to Apollonian circle packings, integral orbits, thin groups, hyperbolic geometry, continued fractions, and Diophantine approximation. The connection of geometry and dynamics to number theory gives an opportunity to illustrate arithmetic by appealing to our visual intuition.

math.NT↗

Traceable random numbers from a nonlocal quantum advantage

The unpredictability of random numbers is fundamental to both digital security and applications that fairly distribute resources. However, existing random number generators have limitations-the generation processes cannot be fully traced, audited, and certified to be unpredictable. The algorithmic steps used in pseudorandom number generators are auditable, but they cannot guarantee that their outputs were a priori unpredictable given knowledge of the initial seed. Device-independent quantum random number generators can ensure that the source of randomness was unknown beforehand, but the steps used to extract the randomness are vulnerable to tampering. Here, for the first time, we demonstrate a fully traceable random number generation protocol based on device-independent techniques. Our protocol extracts randomness from unpredictable non-local quantum correlations, and uses distributed intertwined hash chains to cryptographically trace and verify the extraction process. This protocol is at the heart of a public traceable and certifiable quantum randomness beacon that we have launched. Over the first 40 days of operation, we completed the protocol 7434 out of 7454 attempts -- a success rate of 99.7%. Each time the protocol succeeded, the beacon emitted a pulse of 512 bits of traceable randomness. The bits are certified to be uniform with error times actual success probability bounded by $2^{-64}$. The generation of certifiable and traceable randomness represents one of the first public services that operates with an entanglement-derived advantage over comparable classical approaches.

quant-ph↗

Extending class group action attacks via sesquilinear pairings

We introduce a new tool for the study of isogeny-based cryptography, namely pairings which are sesquilinear (conjugate linear) with respect to the $\mathcal{O}$-module structure of an elliptic curve with CM by an imaginary quadratic order $\mathcal{O}$. We use these pairings to study the security of problems based on the class group action on collections of oriented ordinary or supersingular elliptic curves. This extends work of both (Castryck, Houben, Merz, Mula, Buuren, Vercauteren, 2023) and (De Feo, Fouotsa, Panny, 2024).

math.NT↗

The local-global conjecture for Apollonian circle packings is false

In a primitive integral Apollonian circle packing, the curvatures that appear must fall into one of six or eight residue classes modulo 24. The local-global conjecture states that every sufficiently large integer in one of these residue classes will appear as a curvature in the packing. We prove that this conjecture is false for many packings, by proving that certain quadratic and quartic families are missed. The new obstructions are a property of the thin Apollonian group (and not its Zariski closure), and are a result of quadratic and quartic reciprocity, reminiscent of a Brauer-Manin obstruction. Based on computational evidence, we formulate a new conjecture.

math.NT↗

Failing to hash into supersingular isogeny graphs

An important open problem in supersingular isogeny-based cryptography is to produce, without a trusted authority, concrete examples of "hard supersingular curves" that is, equations for supersingular curves for which computing the endomorphism ring is as difficult as it is for random supersingular curves. A related open problem is to produce a hash function to the vertices of the supersingular $\ell$-isogeny graph which does not reveal the endomorphism ring, or a path to a curve of known endomorphism ring. Such a hash function would open up interesting cryptographic applications. In this paper, we document a number of (thus far) failed attempts to solve this problem, in the hope that we may spur further research, and shed light on the challenges and obstacles to this endeavour. The mathematical approaches contained in this article include: (i) iterative root-finding for the supersingular polynomial; (ii) gcd's of specialized modular polynomials; (iii) using division polynomials to create small systems of equations; (iv) taking random walks in the isogeny graph of abelian surfaces; and (v) using quantum random walks.

math.NT↗

On the importance of illustration for mathematical research

Mathematical understanding is built in many ways. Among these, illustration has been a companion and tool for research for as long as research has taken place. We use the term illustration to encompass any way one might bring a mathematical idea into physical form or experience, including hand-made diagrams or models, computer visualization, 3D printing, and virtual reality, among many others. The very process of illustration itself challenges our mathematical understanding and forces us to answer questions we may not have posed otherwise. It can even make mathematics an experimental science, in which immersive exploration of data and representations drive the cycle of problem, conjecture, and proof. Today, modern technology for the first time places the production of highly complicated models within the reach of many individual mathematicians. Here, we sketch the rich history of illustration, highlight important recent examples of its contribution to research, and examine how it can be viewed as a discipline in its own right.

math.HO↗

Factoring using multiplicative relations modulo $n$: a subexponential algorithm inspired by the index calculus

We demonstrate that a modification of the classical index calculus algorithm can be used to factor integers. More generally, we reduce the factoring problem to finding an overdetermined system of multiplicative relations in any factor base modulo $n$, where $n$ is the integer whose factorization is sought. The algorithm has subexponential runtime $\exp(O(\sqrt{\log n \log \log n}))$ (or $\exp(O( (\log n)^{1/3} (\log \log n)^{2/3} ))$ with the addition of a number field sieve), but requires a rational linear algebra phase, which is more intensive than the linear algebra phase of the classical index calculus algorithm. The algorithm is certainly slower than the best known factoring algorithms, but is perhaps somewhat notable for its simplicity and its similarity to the index calculus.

math.NT↗

Orientations and cycles in supersingular isogeny graphs

The paper concerns several theoretical aspects of oriented supersingular $\ell$-isogeny volcanoes and their relationship to closed walks in the supersingular $\ell$-isogeny graph. Our main result is a bijection between the rims of the union of all oriented supersingular $\ell$-isogeny volcanoes over $\overline{\mathbb{F}}_p$ (up to conjugation of the orientations), and isogeny cycles (non-backtracking closed walks which are not powers of smaller walks) of the supersingular $\ell$-isogeny graph over $\overline{\mathbb{F}}_p$. The exact proof and statement of this bijection are made more intricate by special behaviours arising from extra automorphisms and the ramification of $p$ in certain quadratic orders. We use the bijection to count isogeny cycles of given length in the supersingular $\ell$-isogeny graph exactly as a sum of class numbers of these orders, and also give an explicit upper bound by estimating the class numbers.

math.NT↗

Orienteering with one endomorphism

In supersingular isogeny-based cryptography, the path-finding problem reduces to the endomorphism ring problem. Can path-finding be reduced to knowing just one endomorphism? It is known that a small endomorphism enables polynomial-time path-finding and endomorphism ring computation (Love-Boneh [36]). An endomorphism gives an explicit orientation of a supersingular elliptic curve. In this paper, we use the volcano structure of the oriented supersingular isogeny graph to take ascending/descending/horizontal steps on the graph and deduce path-finding algorithms to an initial curve. Each altitude of the volcano corresponds to a unique quadratic order, called the primitive order. We introduce a new hard problem of computing the primitive order given an arbitrary endomorphism on the curve, and we also provide a sub-exponential quantum algorithm for solving it. In concurrent work (Wesolowski [54]), it was shown that the endomorphism ring problem in the presence of one endomorphism with known primitive order reduces to a vectorization problem, implying path-finding algorithms. Our path-finding algorithms are more general in the sense that we don't assume the knowledge of the primitive order associated with the endomorphism.

math.NT↗

Algebraic Number Starscapes

We study the geometry of algebraic numbers in the complex plane, and their Diophantine approximation, aided by extensive computer visualization. Motivated by these images, called algebraic starscapes, we describe the geometry of the map from the coefficient space of polynomials to the root space, focussing on the quadratic and cubic cases. The geometry describes and explains notable features of the illustrations, and motivates a geometric-minded recasting of fundamental results in the Diophantine approximation of the complex plane. The images provide a case-study in the symbiosis of illustration and research, and an entry-point to geometry and number theory for a wider audience. The paper is written to provide an accessible introduction to the study of homogeneous geometry and Diophantine approximation. We investigate the homogeneous geometry of root and coefficient spaces under the natural $\operatorname{PSL}(2;\mathbb{C})$ action, especially in degrees 2 and 3. We rediscover the quadratic and cubic root formulas as isometries, and determine when the map sending certain families of polynomials to their complex roots (our starscape images) are embeddings. We consider complex Diophantine approximation by quadratic irrationals, in terms of hyperbolic distance and the discriminant as a measure of arithmetic height. We recover the quadratic case of results of Bugeaud and Evertse, and give some geometric explanation for the dichotomy they discovered (Bugeaud, Y. and Evertse, J.-H., Approximation of complex algebraic numbers by algebraic numbers of bounded degree, Ann. Sc. Norm. Super. Pisa Cl. Sci. (5) 8 (2009), no. 2, 333-368). Our statements go a little further in distinguishing approximability in terms of whether the target or approximations lie on rational geodesics. The paper comes with accompanying software, and finishes with a wide variety of open problems.

math.NT↗

Improved torsion point attacks on SIDH variants

SIDH is a post-quantum key exchange algorithm based on the presumed difficulty of finding isogenies between supersingular elliptic curves. However, SIDH and related cryptosystems also reveal additional information: the restriction of a secret isogeny to a subgroup of the curve (torsion point information). Petit (2017) was the first to demonstrate that torsion point information could noticeably lower the difficulty of finding secret isogenies. In particular, Petit showed that "overstretched" parameterizations of SIDH could be broken in polynomial time. However, this did not impact the security of any cryptosystems proposed in the literature. The contribution of this paper is twofold: First, we strengthen the techniques of Petit by exploiting additional information coming from a dual and a Frobenius isogeny. This extends the impact of torsion point attacks considerably. In particular, our techniques yield a classical attack that completely breaks the n-party group key exchange of Azarderakhsh et al. for 6 parties or more, and a quantum attack for 3 parties or more that improves on the best known asymptotic complexity. We also provide a Magma implementation of our attack for 6 parties. We give the full range of parameters for which our attacks apply. Second, we construct SIDH variants designed to be weak against our attacks; this includes backdoor choices of starting curve, as well as backdoor choices of base-field prime. We stress that our results do not degrade the security of, or reveal any weakness in, the NIST submission SIKE.

math.NT↗

Monogenic fields arising from trinomials

We call a polynomial monogenic if a root $θ$ has the property that $\mathbb{Z}[θ]$ is the full ring of integers in $\mathbb{Q}(θ)$. Consider the two families of trinomials $x^n + ax + b$ and $x^n + cx^{n-1} + d$. For any $n>2$, we show that these families are monogenic infinitely often and give some positive densities in terms of the coefficients. When $n=5$ or 6 and when a certain factor of the discriminant is square-free, we use the Montes algorithm to establish necessary and sufficient conditions for monogeneity, illuminating more general criteria given by Jakhar, Khanduja, and Sangwan using other methods. Along the way we remark on the equivalence of certain aspects of the Montes algorithm and Dedekind's index criterion.

math.NT↗