The Supersingular Endomorphism Ring and One Endomorphism Problems are Equivalent

被引:0
|
作者
Page, Aurel [1 ]
Wesolowski, Benjamin [2 ]
机构
[1] Univ Bordeaux, CNRS, INRIA, Bordeaux INP,IMB,UMR 5251, F-33400 Talence, France
[2] ENS Lyon, CNRS, UMPA, UMR 5669, Lyon, France
基金
欧洲研究理事会;
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The supersingular Endomorphism Ring problem is the following: given a supersingular elliptic curve, compute all of its endomorphisms. The presumed hardness of this problem is foundational for isogeny-based cryptography. The One Endomorphism problem only asks to find a single non-scalar endomorphism. We prove that these two problems are equivalent, under probabilistic polynomial time reductions. We prove a number of consequences. First, assuming the hardness of the endomorphism ring problem, the Charles-Goren-Lauter hash function is collision resistant, and the SQIsign identification protocol is sound for uniformly random keys. Second, the endomorphism ring problem is equivalent to the problem of computing arbitrary isogenies between supersingular elliptic curves, a result previously known only for isogenies of smooth degree. Third, there exists an unconditional probabilistic algorithm to solve the endomorphism ring problem in time (O) over tilde (p(1/2)), a result that previously required to assume the generalized Riemann hypothesis. To prove our main result, we introduce a flexible framework for the study of isogeny graphs with additional information. We prove a general and easy-to-use rapid mixing theorem.
引用
收藏
页码:388 / 417
页数:30
相关论文
共 50 条
  • [1] The Supersingular Endomorphism Ring and One Endomorphism Problems are Equivalent
    Page, Aurel
    Wesolowski, Benjamin
    ADVANCES IN CRYPTOLOGY, PT VII, EUROCRYPT 2024, 2024, 14657 : 388 - 417
  • [2] The supersingular isogeny path and endomorphism ring problems are equivalent
    Wesolowski, Benjamin
    2021 IEEE 62ND ANNUAL SYMPOSIUM ON FOUNDATIONS OF COMPUTER SCIENCE (FOCS 2021), 2022, : 1100 - 1111
  • [3] Orientations and the Supersingular Endomorphism Ring Problem
    Wesolowski, Benjamin
    ADVANCES IN CRYPTOLOGY - EUROCRYPT 2022, PT III, 2022, 13277 : 345 - 371
  • [4] Constructing supersingular elliptic curves with a given endomorphism ring
    Chevyrev, Ilya
    Galbraith, Steven D.
    LMS JOURNAL OF COMPUTATION AND MATHEMATICS, 2014, 17 : 71 - 91
  • [5] Generating Supersingular Elliptic Curves over Fp with Unknown Endomorphism Ring
    Mokrani, Youcef
    Jao, David
    PROGRESS IN CRYPTOLOGY - INDOCRYPT 2023, PT I, 2024, 14459 : 159 - 174
  • [6] Supersingular Isogeny Graphs and Endomorphism Rings: Reductions and Solutions
    Eisentrager, Kirsten
    Hallgren, Sean
    Lauter, Kristin
    Morrison, Travis
    Petit, Christophe
    ADVANCES IN CRYPTOLOGY - EUROCRYPT 2018, PT III, 2018, 10822 : 329 - 368
  • [7] Computing supersingular endomorphism rings using inseparable endomorphisms
    Fuselier, Jenny
    Iezzi, Annamaria
    Kozek, Mark
    Morrison, Travis
    Namoijam, Changningphaabi
    JOURNAL OF ALGEBRA, 2025, 668 : 145 - 189
  • [8] Endomorphism rings of supersingular elliptic curves over Fp
    Li, Songsong
    Ouyang, Yi
    Xu, Zheng
    FINITE FIELDS AND THEIR APPLICATIONS, 2020, 62
  • [9] Orienteering with One Endomorphism
    Arpin S.
    Chen M.
    Lauter K.E.
    Scheidler R.
    Stange K.E.
    Tran H.T.N.
    La Matematica, 2023, 2 (3): : 523 - 582
  • [10] ENDOMORPHISM RING OF AN INDUCED MODULE
    TUCKER, PA
    MICHIGAN MATHEMATICAL JOURNAL, 1965, 12 (02) : 197 - &