Fast and Frobenius: Rational Isogeny Evaluation over Finite Fields

06/28/2023
by   Gustavo Banegas, et al.
0

Consider the problem of efficiently evaluating isogenies ϕ: E → E/H of elliptic curves over a finite field 𝔽_q, where the kernel H = ⟨ G⟩ is a cyclic group of odd (prime) order: given E, G, and a point (or several points) P on E, we want to compute ϕ(P). This problem is at the heart of efficient implementations of group-action- and isogeny-based post-quantum cryptosystems such as CSIDH. Algorithms based on Vélu's formulae give an efficient solution to this problem when the kernel generator G is defined over 𝔽_q. However, for general isogenies, G is only defined over some extension 𝔽_q^k, even though ⟨ G⟩ as a whole (and thus ϕ) is defined over the base field 𝔽_q; and the performance of Vélu-style algorithms degrades rapidly as k grows. In this article we revisit the isogeny-evaluation problem with a special focus on the case where 1 ≤ k ≤ 12. We improve Vélu-style isogeny evaluation for many cases where k = 1 using special addition chains, and combine this with the action of Galois to give greater improvements when k > 1.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/25/2019

Isometry-Dual Flags of AG Codes

Consider a complete flag {0} = C_0 < C_1 < ... < C_n = F^n of one-point ...
research
12/02/2020

On circulant matrices and rational points of Artin Schreier's curves

Let 𝔽_q be a finite field with q elements, where q is an odd prime power...
research
07/22/2020

Rational points on complete symmetric hypersurfaces over finite fields

For any affine hypersurface defined by a complete symmetric polynomial i...
research
02/07/2023

Multiplication polynomials for elliptic curves over finite local rings

For a given elliptic curve E over a finite local ring, we denote by E^∞ ...
research
01/08/2018

On Division Polynomial PIT and Supersingularity

For an elliptic curve E over a finite field _q, where q is a prime power...
research
05/09/2019

General Method for Prime-point Cyclic Convolution over the Real Field

A general and fast method is conceived for computing the cyclic convolut...
research
03/14/2022

Computing a Group Action from the Class Field Theory of Imaginary Hyperelliptic Function Fields

We explore algorithmic aspects of a simply transitive commutative group ...

Please sign up or login with your details

Forgot password? Click here to reset