SearcharxivSearch

arXiv subjects

Sarah Arpin

Publications and source records attributed to Sarah Arpin.

15 recordsLinked to original sources

The Spine: A Supersingular Highway

We consider the structure of the spine of the supersingular $\ell$-isogeny graph for one of the cases which arXiv:2502.03613 was not able to fully describe, $\ell = 2$ and $p = 71, 119\pmod{120}$. We find the distance, eccentricity, and diameter functions, of the components of the spine without the non-trivial edge not defined over $\mathbb{F}_p$. Using these functions, we find the mean diameter of the spine and show how this value distinguishes the different structures of the spine. Thus, allowing us to use explicit computations to provide heuristics on the behavior of the spine's structure as $p$ varies.

math.NT

Supersingular elliptic curves and twisting endomorphisms

We generalize the notion of twisting endomorphisms, first defined by Castryck-Panny-Vercauteran, to the setting of $\mathcal{O}$-oriented supersingular elliptic curves. We give an algorithm to find supersingular elliptic curves over $\mathbb{F}_p$ with a twisting endomorphism of prime degree $\ell$, and we use it to compute a basis of their full endomorphism rings.

math.NT

Digital signature schemes based on code equivalence and syndrome decoding from restricted errors

Digital signature schemes are an important cryptographic tool to ensure data authenticity and integrity in many applications that must be resilient to attacks, including those facilitated by quantum computers. We consider the two digital signature schemes based on error-correcting codes that are second-round candidates in NIST's call for Additional Signature Schemes, which is part of the Post-Quantum Cryptography Standardization Process. Specifically, we provide an overview of the Codes and Restricted Objects Signature Scheme (CROSS) and the Linear Equivalence Signature Scheme (LESS). We describe their underlying problems of syndrome decoding from restricted errors and code equivalence. We review sigma protocols and how they can be transformed into digital signature schemes via the Fiat-Shamir transform. Finally, we explain how this procedure yields code-based digital signatures believed to be post-quantum secure.

cs.CR

Isogeny graphs of abelian varieties and singular ideals in orders

Famously, Kohel proved that isogeny graphs of ordinary elliptic curves are beautifully structured objects, now called volcanos. We prove graph structural theorems for abelian varieties of any dimension with commutative endomorphism ring and containing a fixed locally Bass order, leveraging an ideal-theoretic perspective on isogeny graphs. This generalizes previous results, which relied on restrictive additional assumptions, such as maximal real multiplication, ordinary, and absolutely simple (Brooks, Jetchev, Wesolowski 2017). In particular, our work also applies to non-simple and non-ordinary isogeny classes. To obtain our results, we first prove a structure theorem for the lattice of inclusion of the overorders of a locally Bass order in an \'etale algebra which is of independent interest. This analysis builds on a careful study of local singularities of the orders. We include several examples of volcanoes and isogeny graphs exhibiting unexpected properties ultimately due to our more general setting.

math.NT

The Spine of a Supersingular $\ell$-Isogeny graph

Supersingular elliptic curve $\ell$-isogeny graphs over finite fields offer a setting for a number of quantum-resistant cryptographic protocols. The security analysis of these schemes typically assumes that these graphs behave randomly. Motivated by this debatable assertion, we explore structural properties of these graphs. We detail the behavior, governed by congruence conditions on $p$, of the $\ell$-isogeny graph over $\mathbb{F}_p$ when passing to the spine, i.e. the subgraph induced by the $\mathbb{F}_p$-vertices in the full $\ell$-isogeny graph. We describe the diameter of the spine and offer numerical data on the number of vertices, over both $\mathbb{F}_p$ and $\overline{\mathbb{F}_p}$, in the center of the $\ell$-isogeny graph. Our plots of these counts exhibit a wave-shaped pattern which supports the assertion that centers of supersingular $\ell$-isogeny graphs exhibit the same behavior as those of random $(\ell+1)$-regular graphs.

math.NT

Cycles and Cuts in Supersingular L-Isogeny Graphs

Supersingular elliptic curve isogeny graphs underlie isogeny-based cryptography. For isogenies of a single prime degree $\ell$, their structure has been investigated graph-theoretically. We generalise the notion of $\ell$-isogeny graphs to $L$-isogeny graphs (studied in the prime field case by Delfs and Galbraith), where $L$ is a set of small primes dictating the allowed isogeny degrees in the graph. We analyse the graph-theoretic structure of $L$-isogeny graphs. Our approaches may be put into two categories: cycles and graph cuts. On the topic of cycles, we provide: a count for the number of cycles in the $L$-isogeny graph with cyclic kernels using traces of Brandt matrices; an efficiently computable estimate based on this approach; and a third ideal-theoretic count for a certain subclass of $L$-isogeny cycles. We provide code to compute each of these three counts. On the topic of graph cuts, we compare several algorithms to compute graph cuts which minimise a measure called the edge expansion, outlining a cryptographic motivation for doing so. Our results show that a greedy neighbour algorithm out-performs standard spectral algorithms for computing optimal graph cuts. We provide code and study explicit examples. Furthermore, we describe several directions of active and future research.

math.NT

Generalized class group actions on oriented elliptic curves with level structure

We study a large family of generalized class groups of imaginary quadratic orders $O$ and prove that they act freely and (essentially) transitively on the set of primitively $O$-oriented elliptic curves over a field $k$ (assuming this set is non-empty) equipped with appropriate level structure. This extends, in several ways, a recent observation due to Galbraith, Perrin and Voloch for the ray class group. We show that this leads to a reinterpretation of the action of the class group of a suborder $O' \subseteq O$ on the set of $O'$-oriented elliptic curves, discuss several other examples, and briefly comment on the hardness of the corresponding vectorization problems.

math.NT

Finding Orientations of Supersingular Elliptic Curves and Quaternion Orders

Orientations of supersingular elliptic curves encode the information of an endomorphism of the curve. Computing the full endomorphism ring is a known hard problem, so one might consider how hard it is to find one such orientation. We prove that access to an oracle which tells if an elliptic curve is $\mathfrak{O}$-orientable for a fixed imaginary quadratic order $\mathfrak{O}$ provides non-trivial information towards computing an endomorphism corresponding to the $\mathfrak{O}$-orientation. We provide explicit algorithms and in-depth complexity analysis. We also consider the question in terms of quaternion algebras. We provide algorithms which compute an embedding of a fixed imaginary quadratic order into a maximal order of the quaternion algebra ramified at $p$ and $\infty$. We provide code implementations in Sagemath which is efficient for finding embeddings of imaginary quadratic orders of discriminants up to $O(p)$, even for cryptographically sized $p$.

math.NT

The Scheme of Monogenic Generators II: Local Monogenicity and Twists

This is the sequel paper to arXiv:2108.07185, continuing a study of monogenicity of number rings from a moduli-theoretic perspective. By the results of the first paper in this series, a choice of a generator $θ$ for an $A$-algebra $B$ is a point of the scheme $\mathcal{M}_{B/A}$. In this paper, we study and relate several notions of local monogenicity that emerge from this perspective. We first consider the conditions under which the extension $B/A$ admits monogenerators locally in the Zariski and finer topologies, recovering a theorem of Pleasants as a special case. We next consider the case in which $B/A$ is étale, where the local structure of étale maps allows us to construct a universal monogenicity space and relate it to an unordered configuration space. Finally, we consider when $B/A$ admits local monogenerators that differ only by the action of some group (usually $\mathbb{G}_m$ or $\mathrm{Aff}^1$), giving rise to a notion of twisted monogenerators. In particular, we show a number ring $A$ has class number one if and only if each twisted monogenerator is in fact a global monogenerator $θ$.

math.AG

Orienteering with one endomorphism

In supersingular isogeny-based cryptography, the path-finding problem reduces to the endomorphism ring problem. Can path-finding be reduced to knowing just one endomorphism? It is known that a small endomorphism enables polynomial-time path-finding and endomorphism ring computation (Love-Boneh [36]). An endomorphism gives an explicit orientation of a supersingular elliptic curve. In this paper, we use the volcano structure of the oriented supersingular isogeny graph to take ascending/descending/horizontal steps on the graph and deduce path-finding algorithms to an initial curve. Each altitude of the volcano corresponds to a unique quadratic order, called the primitive order. We introduce a new hard problem of computing the primitive order given an arbitrary endomorphism on the curve, and we also provide a sub-exponential quantum algorithm for solving it. In concurrent work (Wesolowski [54]), it was shown that the endomorphism ring problem in the presence of one endomorphism with known primitive order reduces to a vectorization problem, implying path-finding algorithms. Our path-finding algorithms are more general in the sense that we don't assume the knowledge of the primitive order associated with the endomorphism.

math.NT

The Scheme of Monogenic Generators I: Representability

This is the first in a series of two papers that study monogenicity of number rings from a moduli-theoretic perspective. Given an extension of algebras $B/A$, when is $B$ generated by a single element $θ\in B$ over $A$? In this paper, we show there is a scheme $\mathcal{M}_{B/A}$ parameterizing the choice of a generator $θ\in B$, a "moduli space" of generators. This scheme relates naturally to Hilbert schemes and configuration spaces. We give explicit equations and ample examples.

math.AG

Orientations and cycles in supersingular isogeny graphs

The paper concerns several theoretical aspects of oriented supersingular $\ell$-isogeny volcanoes and their relationship to closed walks in the supersingular $\ell$-isogeny graph. Our main result is a bijection between the rims of the union of all oriented supersingular $\ell$-isogeny volcanoes over $\overline{\mathbb{F}}_p$ (up to conjugation of the orientations), and isogeny cycles (non-backtracking closed walks which are not powers of smaller walks) of the supersingular $\ell$-isogeny graph over $\overline{\mathbb{F}}_p$. The exact proof and statement of this bijection are made more intricate by special behaviours arising from extra automorphisms and the ramification of $p$ in certain quadratic orders. We use the bijection to count isogeny cycles of given length in the supersingular $\ell$-isogeny graph exactly as a sum of class numbers of these orders, and also give an explicit upper bound by estimating the class numbers.

math.NT

Adding Level Structure to Supersingular Elliptic Curve Isogeny Graphs

In this paper, we add the information of level structure to supersingular elliptic curves and study these objects with the motivation of isogeny-based cryptography. Supersingular elliptic curves with level structure map to Eichler orders in a quaternion algebra, just as supersingular elliptic curves map to maximal orders in a quaternion algebra via the classical Deuring correspondence. We study this map and the Eichler orders themselves. We also look at isogeny graphs of supersingular elliptic curves with level structure, and how they relate to graphs of Eichler orders.

math.NT

On the arithmetic of a family of superelliptic curves

Let $p$ be a prime, let $r$ and $q$ be powers of $p$, and let $a$ and $b$ be relatively prime integers not divisible by $p$. Let $C/\mathbb F_{r}(t)$ be the superelliptic curve with affine equation $y^b+x^a=t^q-t$. Let $J$ be the Jacobian of $C$. By work of Pries--Ulmer, $J$ satisfies the Birch and Swinnerton-Dyer conjecture (BSD). Generalizing work of Griffon--Ulmer, we compute the $L$-function of $J$ in terms of certain Gauss sums. In addition, we estimate several arithmetic invariants of $J$ appearing in BSD, including the rank of the Mordell--Weil group $J(\mathbb F_{r}(t))$, the Faltings height of $J$, and the Tamagawa numbers of $J$ in terms of the parameters $a,b,q$. For any $p$ and $r$, we show that for certain $a$ and $b$ depending only on $p$ and $r$, these Jacobians provide new examples of families of simple abelian varieties of fixed dimension and with unbounded analytic and algebraic rank as $q$ varies through powers of $p$. Under a different set of criteria on $a$ and $b$, we prove that the order of the Tate--Shafarevich group of $J$ grows quasilinearly in $q$ as $q \to \infty.$

math.NT

Adventures in Supersingularland

In this paper, we study isogeny graphs of supersingular elliptic curves. Supersingular isogeny graphs were introduced as a hard problem into cryptography by Charles, Goren, and Lauter for the construction of cryptographic hash functions [CGL06]. These are large expander graphs, and the hard problem is to find an efficient algorithm for routing, or path-finding, between two vertices of the graph. We consider four aspects of supersingular isogeny graphs, study each thoroughly and, where appropriate, discuss how they relate to one another. First, we consider two related graphs that help us understand the structure: the `spine' $\mathcal{S}$, which is the subgraph of $\mathcal{G}_\ell(\overline{\mathbb{F}_p})$ given by the $j$-invariants in $\mathbb{F}_p$, and the graph $\mathcal{G}_\ell(\mathbb{F}_p)$, in which both curves and isogenies must be defined over $\mathbb{F}_p$. We show how to pass from the latter to the former. The graph $\mathcal{S}$ is relevant for cryptanalysis because routing between vertices in $\mathbb{F}_p$ is easier than in the full isogeny graph. The $\mathbb{F}_p$-vertices are typically assumed to be randomly distributed in the graph, which is far from true. We provide an analysis of the distances of connected components of $\mathcal{S}$. Next, we study the involution on $\mathcal{G}_\ell(\overline{\mathbb{F}_p})$ that is given by the Frobenius of $\mathbb{F}_p$ and give heuristics on how often shortest paths between two conjugate $j$-invariants are preserved by this involution (mirror paths). We also study the related question of what proportion of conjugate $j$-invariants are $\ell$-isogenous for $\ell = 2,3$. We conclude with experimental data on the diameters of supersingular isogeny graphs when $\ell = 2$ and compare this with previous results on diameters of LPS graphs and random Ramanujan graphs.

math.NT