SearcharxivSearch

arXiv subjects

Momonari Kudo

Publications and source records attributed to Momonari Kudo.

At least 19 recordsLinked to original sources

Explicit cost analysis of Toom-4 multiplication for incomplete NTT in lattice-based cryptography

Polynomial multiplication is fundamental in lattice-based cryptography. While the Number Theoretic Transform (NTT) enables fast multiplication, it imposes constraints on the modulus of the coefficient field. Hafiz et al. (2025) addressed this limitation by analyzing the incomplete NTT, which combines a truncated NTT with conventional multiplication methods In this work, we revisit Toom-4 multiplication in the context of incomplete NTT. Although Toom-4 is asymptotically faster than Karatsuba, its precise cost has not been expressed in a form compatible with the incomplete NTT framework. We present a concrete Toom-4 implementation and derive explicit operation counts that separate additions/subtractions and multiplications over the coefficient field. Our analysis based on addition chains yields a simple cost model for incomplete NTT. Using this model, we analyze hybrid strategies combining Toom-4, Karatsuba, and incomplete NTT. We identify parameter ranges where Toom-4 is advantageous and validate the predicted behavior experimentally.

cs.CR

On superspecial hyperelliptic curves of genus 5 whose automorphism groups contain $(\mathbb{Z}/2\mathbb{Z})^3$

While the numbers of superspecial curves of genus at most 3 are well understood, and several computational approaches have been developed to count superspecial curves of genus 4 with large automorphism groups, much less is known in higher genera. In this paper, we construct a feasible algorithm to enumerate superspecial hyperelliptic curves of genus 5 whose automorphism groups contain $(\mathbb{Z}/2\mathbb{Z})^3$. We implement and executing our algorithm in Magma, we succeeded in enumerating such superspecial curves in every characteristic $11 < p < 1000$.

math.AG

Generalization of semi-regular sequences: Maximal Gr\"{o}bner basis degree, variants of genericness, and related conjectures

Nowadays, the notion of semi-regular sequences, originally proposed by Fr\"oberg, becomes very important not only in Mathematics, but also in Information Science, in particular Cryptology. For example, it is highly expected that randomly generated polynomials form a semi-regular sequence, and based on this observation, secure cryptosystems based on polynomial systems can be devised. In this paper, we deal with a semi-regular sequence and its extension, named a generalized cryptographic semi-regular sequence, and give precise analysis on the complexity of computing a Gr\"obner basis of the ideal generated by such a sequence with help of several regularities of the ideal related to Lazard's bound on maximal Gr\"{o}bner basis degree and other bounds. We also study the genericness of the property that a sequence is semi-regular, and its variants related to Fr\"oberg's conjecture. Moreover, we discuss on the genericness of another important property that the initial ideal is weakly reverse lexicographic, related to Moreno-Soc\'{i}as' conjecture, and show some criteria to examine whether both Fr\"oberg's conjecture and Moreno-Soc\'{i}as' one hold at the same time.

math.AC

Degree bounds and synchronization in Gr\"{o}bner basis computations for affine semi-regular systems

Determining the complexity of computing Gr\"obner bases is an important problem in both theory and practice, and solving degrees provide a central measure of this complexity. We study solving degrees and Gr\"obner basis computations for affine polynomial systems, with particular emphasis on semi-regular sequences. We first derive two upper bounds for the maximum Gr\"obner basis degree of the homogenized system. One is based on a regular initial subsequence of the highest-degree homogeneous parts. When these parts form a semi-regular sequence in nondecreasing degree order, the bound involves the $n$ smallest input degrees together with the largest one. The other bound is expressed in terms of the saturation exponent with respect to the homogenizing variable. Both are obtained by bounding the degree from which the Hilbert function of the quotient ring associated with the homogenized system is constant. We then compare the Buchberger-like Gr\"obner basis computations for an affine system, its homogenization, and its highest-degree homogeneous parts. The first degree fall is characterized by failure of injectivity of multiplication by the homogenizing variable. Before that point, choices of S-pairs and reducers in any computation can be matched in the others, and reduction sequences, remainders, intermediate bases, and leading monomials correspond under specialization. Cryptographic semi-regularity guarantees this correspondence until the step degree first reaches the degree of regularity. At that degree, affine reduction steps that preserve the sugar degree lift to homogeneous ones, yielding upper bounds on the algorithmic solving degree for a computation starting directly from the affine input.

math.AC

Listing superspecial curves of genus three using Richelot isogeny graphs

In algebraic geometry, superspecial curves are important research objects. While the number of superspecial genus-3 curves in characteristic $p$ is known, the number of hyperelliptic ones among them has not been determined even for small $p$. In this paper, in order to compute the latter number, we give an explicit algorithm for computing the Richelot isogeny graph of superspecial principally polarized abelian varieties of dimension 3 using theta functions. In particular, one can determine whether a given vertex in the graph corresponds to the Jacobian of a genus-3 curve or not, and restore the defining equation of such a genus-3 curve from its theta constants. Our algorithm enables efficient enumeration of superspecial genus-3 curves, as all operations can be performed in $\mathbb{F}_{p^2}$. By implementing the algorithm in Magma, we successfully counted the number of hyperelliptic curves among them for all primes $11 \leq p < 100$.

math.AG

On Hilbert-Poincar\'{e} series of affine semi-regular polynomial sequences and related Gr\"{o}bner bases

Gr\"{o}bner bases are nowadays central tools for solving various problems in commutative algebra and algebraic geometry. A typical use of Gr\"{o}bner bases is the multivariate polynomial system solving, which enables us to construct algebraic attacks against post-quantum cryptographic protocols. Therefore, the determination of the complexity of computing Gr\"{o}bner bases is very important both in theory and in practice: One of the most important cases is the case where input polynomials compose an (overdetermined) affine semi-regular sequence. The first part of this paper aims to present a survey on Gr\"{o}bner basis computation and its complexity. In the second part, we shall give an explicit formula on the (truncated) Hilbert-Poincar\'{e} series associated to the homogenization of an affine semi-regular sequence. Based on the formula, we also study (reduced) Gr\"{o}bner bases of the ideals generated by an affine semi-regular sequence and its homogenization. Some of our results are considered to give mathematically rigorous proofs of the correctness of methods for computing Gr\"{o}bner bases of the ideal generated by an affine semi-regular sequence.

cs.SC

Explicit construction of a plane sextic model for genus-five Howe curves, II

A Howe curve is defined as the normalization of the fiber product over a projective line of two hyperelliptic curves. Howe curves are very useful to produce important classes of curves over fields of positive characteristic, e.g., maximal, superspecial, or supersingular ones. Determining their feasible equations explicitly is a basic problem, and it has been solved in the hyperelliptic case and in the non-hyperelliptic case with genus not greater than $4$. In this paper, we construct an explicit plane sextic model for non-hyperelliptic Howe curves of genus $5$. We also determine the number and type of singularities on our sextic model, and prove that the singularities are generically $4$ double points. Our results together with Moriya-Kudo's recent ones imply that for each $s \in \{2,3,4,5\}$, there exists a non-hyperellptic curve $H$ of genus $5$ with $\mathrm{Aut}(H) \supset \mathbf{V}_4$ such that its associated plane sextic has $s$ double points.

math.AG

Computing superspecial hyperelliptic curves of genus 4 with automorphism group properly containing the Klein 4-group

In algebraic geometry, enumerating or finding superspecial curves in positive characteristic $p$ is important both in theory and in computation. In this paper, we propose feasible algorithms to enumerate or find superspecial hyperelliptic curves of genus $4$ with automorphism group properly containing the Klein $4$-group. Executing the algorithms on Magma, we succeeded in enumerating such superspecial curves for every $p$ with $19 \leq p < 500$, and in finding a single one for every $p$ with $19 \leq p < 7000$.

math.AG

Explicit construction of a plane sextic model for genus-five Howe curves, I

In the past several years, Howe curves have been studied actively in the field of algebraic curves over fields of positive characteristic. Here, a Howe curve is defined as the desingularization of the fiber product over a projective line of two hyperelliptic curves. In this paper, we construct an explicit plane sextic model for non-hyperelliptic Howe curves of genus five. We also determine singularities of our sextic model.

math.AG

Efficient search for superspecial hyperelliptic curves of genus four with automorphism group containing $\mathbb{Z}_6$

In arithmetic and algebraic geometry, superspecial (s.sp.\ for short) curves are one of the most important objects to be studied, with applications to cryptography and coding theory. If $g \geq 4$, it is not even known whether there exists such a curve of genus $g$ in general characteristic $p > 0$, and in the case of $g=4$, several computational approaches to search for those curves have been proposed. In the genus-$4$ hyperelliptic case, Kudo-Harashita proposed a generic algorithm to enumerate all s.sp.\ curves, and recently Ohashi-Kudo-Harashita presented an algorithm specific to the case where automorphism group contains the Klein 4-group. In this paper, we propose an algorithm with complexity $\tilde{O}(p^4)$ in theory but $\tilde{O}(p^3)$ in practice to enumerate s.sp.\ hyperelliptic curves of genus 4 with automorphism group containing the cyclic group of order $6$. By executing the algorithm over Magma, we enumerate those curves for $p$ up to $1000$. We also succeeded in finding a s.sp.\ hyperelliptic curve of genus $4$ in every $p$ with $p \equiv 2 \pmod{3}$. As a theoretical result, we classify hyperelliptic curves of genus $4$ in terms of automorphism groups in the appendix.

math.AG

Some explicit arithmetic on curves of genus three and their applications

A Richelot isogeny between Jacobian varieties is an isogeny whose kernel is included in the $2$-torsion subgroup of the domain. A Richelot isogeny whose codomain is the product of two or more principally polarized abelian varieties is called a decomposed Richelot isogeny. In this paper, we develop some explicit arithmetic on curves of genus $3$, including algorithms to compute the codomain of a decomposed Richelot isogeny. As solutions to compute the domain of a decomposed Richelot isogeny, explicit formulae of defining equations for Howe curves of genus $3$ are also given. Using the formulae, we shall construct an algorithm with complexity $\tilde{O}(p^3)$ (resp. $\tilde{O}(p^4)$) to enumerate all hyperelliptic (resp. non-hyperelliptic) superspecial Howe curves of genus $3$.

math.AG

Genus-five hyperelliptic or trigonal curves with many rational points in characteristic three

The number $N_9(5)$, the maximal number of $\mathbb{F}_9$-rational points on curves over $\mathbb{F}_9$ of genus $5$ is unknown, but it is known that $32 \le N_9(5)\le 35$. In this paper, we enumerate hyperelliptic curves and trigonal curves over $\mathbb{F}_3$ which have many $\mathbb{F}_9$-rational points (and $\mathbb{F}_3$-rational points), especially the maximal number of $\mathbb{F}_9$-rational points of those curves is $30$. Kudo-Harashita studied the nonhyperelliptic and nontrigonal case,where they found a new example of curves (over $\mathbb{F}_3$) of genus five which attains $32$ and proved that there is no example attaining more than $32$, among sextic plane curves with mild singularities. We conclude from the main results in this paper that we need to search sextic models (i.e., nonhyperelliptic and nontrigonal) with bad singularities, in order to find a genus-five curve over $\mathbb{F}_3$ with at least $33$ $\mathbb{F}_9$-rational points.

math.AG

Computing the space of differential forms of a plane curve and its Cartier-Manin matrix

In this paper, we propose a feasible algorithm to give an explicit basis of the space of regular differential forms on the nonsingular projective model of any given plane algebraic curve. The algorithm is demonstrated for concrete examples, with our implementation over the computer algebra system Magma. As an application, we also describe the Cartier-Manin matrix of the nonsingular projective curve with respect to the basis computed by the algorithm.

math.AG

Polynomial XL: A Variant of the XL Algorithm Using Macaulay Matrices over Polynomial Rings

Solving a system of $m$ multivariate quadratic equations in $n$ variables over finite fields (the MQ problem) is one of the important problems in the theory of computer science. The XL algorithm (XL for short) is a major approach for solving the MQ problem with linearization over a coefficient field. Furthermore, the hybrid approach with XL (h-XL) is a variant of XL guessing some variables beforehand. In this paper, we present a variant of h-XL, which we call the \textit{polynomial XL (PXL)}. In PXL, the whole $n$ variables are divided into $k$ variables to be fixed and the remaining $n-k$ variables as ``main variables'', and we generate a Macaulay matrix with respect to the $n-k$ main variables over a polynomial ring of the $k$ (sub-)variables. By eliminating some columns of the Macaulay matrix over the polynomial ring before guessing $k$ variables, the amount of operations required for each guessed value can be reduced compared with h-XL. Our complexity analysis of PXL (under some practical assumptions and heuristics) gives a new theoretical bound, and it indicates that PXL could be more efficient than other algorithms in theory on the random system with $n=m$, which is the case of general multivariate signatures. For example, on systems over the finite field with ${2^8}$ elements with $n=m=80$, the numbers of operations deduced from the theoretical bounds of the hybrid approaches with XL and Wiedemann XL, Crossbred, and PXL with optimal $k$ are estimated as $2^{252}$, $2^{234}$, $2^{237}$, and $2^{220}$, respectively.

cs.SC

The $a$-numbers of non-hyperelliptic curves of genus 3 with cyclic automorphism group of order 6

In this paper, we study non-hyperelliptic curves of genus $3$ with cyclic automorphism group of order $6$. Over an algebraically closed field $K$ of characteristic $\neq 2,3$, such curves are written as plane quartics $C_r: x^3 z + y^4 + r y^2 z^2 + z^4 = 0$ with one parameter $r$. As the first main theorem, we show that $r\neq 0,\pm 2$ and give a necessary and sufficient condition with respect to $r$ and $r'$ such that $C_r \cong C_{r'}$. By describing the Hasse-Witt matrix of $C_r$ in terms of a certain Gauss' hypergeometric series, we obtain the second main theorem, where we determine the possible $a$-number of $C_r$, and give the exact number of isomorphism classes over $K$ of such curves attaining the possible maximal $a$-number.

math.AG

Counting isomorphism classes of superspecial curves

A superspecial curve is a (non-singular) curve over a field of positive characteristic whose Jacobian variety is isomorphic to a product of supersingular elliptic curves over the algebraic closure. It is known that for given genus and characteristic, there exist only finitely many superspecial curves, up to isomorphism over an algebraically closed field. In this article, we give a brief survey on results of counting isomorphism classes of superspecial curves. In particular, this article summarizes some recent results in the case of genera four and five, obtained by the author and S.\ Harashita. We also survey results obtained in a joint work with Harashita and E.\ W.\ Howe, on the enumeration of superspecial curves in a certain class of non-hyperelliptic curves of genus four.

math.AG

Representation of non-special curves of genus 5 as plane sextic curves and its application to finding curves with many rational points

In algebraic geometry, it is important to provide effective parametrizations for families of curves, both in theory and in practice. In this paper, we present such an effective parametrization for the moduli of genus-$5$ curves that are neither hyperelliptic nor trigonal. Subsequently, we construct an algorithm for a complete enumeration of non-special genus-$5$ curves having more rational points than a specified bound, where ``non-special curve'' means that the curve is non-hyperelliptic and non-trigonal with mild singularities of the associated sextic model that we propose. As a practical application, we implement this algorithm using the computer algebra system MAGMA, specifically for curves over the prime field of characteristic $3$.

math.AG

Algorithm to enumerate superspecial Howe curves of genus $4$

A Howe curve is a curve of genus $4$ obtained as the fiber product over $\mathbf{P}^1$ of two elliptic curves. Any Howe curve is canonical. This paper provides an efficient algorithm to find superspecial Howe curves and that to enumerate their isomorphism classes. We discuss not only an algorithm to test the superspeciality but also an algorithm to test isomorphisms for Howe curves. Our algorithms are much more efficient than conventional ones proposed by the authors so far for general canonical curves. We show the existence of a superspecial Howe curve in characteristic $7<p\le 331$ and enumerate the isomorphism classes of superspecial Howe curves in characteristic $p\le 53$, by executing our algorithms over the computer algebra system Magma.

math.NT