Class invariants by the CRT method
|
|
- Cecil Reynolds
- 5 years ago
- Views:
Transcription
1 Class invariants by the CRT method Andreas Enge Andrew V. Sutherland INRIA Bordeaux-Sud-Ouest Massachusetts Institute of Technology ANTS IX Andreas Enge and Andrew Sutherland Class invariants by the CRT method 1 of 17
2 Constructing an elliptic curve E/F q with N points Set t = q + 1 N, assuming t 0 and t < 2 q. Write 4q = t 2 v 2 D with D < 0, and then 1. Compute the Hilbert class polynomial H D (X). 2. Find a root j 0 of H D in F q. Now set k = j 0 /(1728 j 0 ). Either the elliptic curve y 2 = x 3 + 3kx + 2k or its quadratic twist has exactly N points over F q. This is the CM method. Andreas Enge and Andrew Sutherland Class invariants by the CRT method 2 of 17
3 The Hilbert class polynomial The discriminant D uniquely determines an imaginary quadratic order O = Z[τ]. The curve E has CM by O, i.e., End(E) = O. j(τ) is an algebraic integer. H D (X) is its minimal polynomial over K = Q( D). Good news: the coefficients of H D are integers. Bad news: they are really big integers! The total size of H D is O( D log 1+ɛ D ) bits. Andreas Enge and Andrew Sutherland Class invariants by the CRT method 3 of 17
4 Andreas Enge and Andrew Sutherland Class invariants by the CRT method 4 of 17
5 Approximate size of H D D h(d) height bound (bits) total size KB MB MB MB GB GB GB TB TB TB PB These are typical examples ( D 1/2 /h(d) ) Andreas Enge and Andrew Sutherland Class invariants by the CRT method 5 of 17
6 A tale of two ANTS ANTS VIII O( D 1+ɛ ) time H D using CRT [BBEL] (matches complexity of p-adic and complex analytic) CRT method practically slow, restricted to j CM record: D > using complex analytic [E] ANTS IX O( D 1/2+ɛ log q) space H D mod q using CRT [S] (surpasses p-adic and complex analytic) CRT method practically fast, not restricted to j CM record: D > using CRT [ES] Both CM records use class invariants other than j. Andreas Enge and Andrew Sutherland Class invariants by the CRT method 6 of 17
7 Class invariants Let f be a modular function satisfying Ψ(f, j) = 0 for some integer polynomial Ψ(F, J). If f (τ) K (j(τ)) then f (τ) is a class invariant. Its minimal polynomial H D [f ](X) is a class polynomial. We shall assume H D [f ] has integer coefficients. If f 0 is a root of H D [f ] then we may obtain a root j 0 of H D as a root of Ψ(f 0, J). H D [f ] is smaller than H D by a factor of c(f ) = deg F (Ψ)/ deg J (Ψ). Andreas Enge and Andrew Sutherland Class invariants by the CRT method 7 of 17
8 Some particularly useful class invariants Weber f-function Double η-quotients w s p 1,p 2, with p 1 and p 2 prime Atkin functions A N with N prime function level deg F (Ψ) deg J (Ψ) c(f ) ρ f w 3, w 5, A A A ρ is the proportion of fundamental D that yield class invariants. Andreas Enge and Andrew Sutherland Class invariants by the CRT method 8 of 17
9 Computing H D with the CRT For sufficiently many suitable primes p: 1. Find one root j 1 of H D mod p. (test random curves) 2. Find all roots j 1,..., j h of H D mod p. (using isogenies) 3. H D (X) = (X j 1 ) (X j h ) mod p. (via a product tree) Apply the CRT to obtain H D Z[X] or (better) H D mod q. Sufficiently many means O( D 1/2+ɛ ). Suitable means p is of the form 4p = t 2 v 2 D and not very big. See Computing Hilbert class polynomials with the CRT [S] for more details. Andreas Enge and Andrew Sutherland Class invariants by the CRT method 9 of 17
10 Realizing the Galois action via isogenies The class group of O acts on the roots of H D. If [l] cl(o) has prime norm l and j 1 is a root of H D then Φ l (j 1, [l]j 1 ) = 0, where Φ l (X, Y ) is the classical modular polynomial. Typically [l]j 1 and [ l]j 1 are the only roots of Φ l (j 1, X) in F p. We use ideals l 1,..., l k, with prime norms l 1,..., l k, such that every [a] cl(o) may be written uniquely as [a] = [l e 1 1 ] [le k k ] (0 e i < r i ). for some positive integers r 1,..., r k. Andreas Enge and Andrew Sutherland Class invariants by the CRT method 10 of 17
11 Enumerating the roots of H D mod p Given a root j 1 of H D mod p, all the roots of H D mod p may be enumerated with the recursive algorithm below. ENUMERATE(j 1, l 1,..., l k ): 1. Arbitrarily choose a root j 2 of Φ lk (j 1, X) in F p. 2. For i from 3 to r k : Let j i be the root of Φ lk (j i 1, X)/(X j i 2 ) in F p. 3. If k = 1 then output j 1,..., j rk and return. 4. ENUMERATE(j i, l 1,..., l k 1 ) for i from 1 to r k. Strategy 1: Convert j 1 to f 1 and enumerate f 1,..., f h. This requires modular polynomials Φ f l. Strategy 2: Convert j 1,..., j h to f 1,..., f h. This requires us to choose directions consistently. Andreas Enge and Andrew Sutherland Class invariants by the CRT method 11 of 17
12 Choosing directions consistently Having walked one path of l-isogenies, we can ensure that all parallel paths are oriented in the same direction. j l 1 j l 2 j l 3 l j r l l j 1 l j 2 Instead of picking j 2 arbitrarily, we compute the polynomial φ(x) = gcd ( Φ l (j 1, X), Φ l (j 2, X) ) and let j 2 be its unique root (if 4l2 l 2 < D then deg φ = 1). We can compute j 3,..., j r in the same way. Computing GCDs is easier than finding roots! Andreas Enge and Andrew Sutherland Class invariants by the CRT method 12 of 17
13 CRT class polynomial computations: H D [f ] vs. H D Example 1 Example 2 Example 3 Example 4 D function f A 71 A 47 A 71 A 59 H D time H D time (gcds) H D [f ] time size factor * total speedup Times in CPU seconds (3.0 GHz AMD Phenom II) These examples computed H D or H D [f ] modulo a cryptographic-size prime q. They were used to construct pairing-friendly curves of prime order. Andreas Enge and Andrew Sutherland Class invariants by the CRT method 13 of 17
14 Invariants with ramified level For the Atkin functions and the double η-quotients, when the primes dividing the level ramify in Q( D), the class polynomial H D [f ] is a perfect square. In this case we can simply compute H D [f ], which reduces both the degree and the coefficient size by a factor of 2. If 71 divides D, for example, the polynomial H D [A 71 ] is approximately = 144 times smaller than H D. This beats Weber f with c(f) = 72. Andreas Enge and Andrew Sutherland Class invariants by the CRT method 14 of 17
15 CRT vs Complex Analytic complex analytic CRT CRT mod q D h(d) w 3,13 f w 3,13 f w 3,13 f Times in CPU seconds (3.0 GHz AMD Phenom II) For the CRT timings, H D [f ] was computed both over Z and modulo a 256-bit prime q. Andreas Enge and Andrew Sutherland Class invariants by the CRT method 15 of 17
16 A record CM construction We computed the square-root of the class polynomial H D [A 71 ] using the discriminant D with D = > We then used the CM method to construct an elliptic curve E of prime order over a 256-bit prime field F q. The endomorphism ring of E is isomorphic to an imaginary quadratic order with class number h(d) = > Andreas Enge and Andrew Sutherland Class invariants by the CRT method 16 of 17
17 ECC Brainpool Standard Security Requirements The class number of the maximal order of the endomorphism ring of E is larger than This condition excludes curves that are generated by the well-known CM-method. This is no longer true. Andreas Enge and Andrew Sutherland Class invariants by the CRT method 17 of 17
18 Class invariants by the CRT method Andreas Enge Andrew V. Sutherland INRIA Bordeaux-Sud-Ouest Massachusetts Institute of Technology ANTS IX Andreas Enge and Andrew Sutherland Class invariants by the CRT method 1 of 17
Computing modular polynomials with the Chinese Remainder Theorem
Computing modular polynomials with the Chinese Remainder Theorem Andrew V. Sutherland Massachusetts Institute of Technology ECC 009 Reinier Bröker Kristin Lauter Andrew V. Sutherland (MIT) Computing modular
More informationModular polynomials and isogeny volcanoes
Modular polynomials and isogeny volcanoes Andrew V. Sutherland February 3, 010 Reinier Bröker Kristin Lauter Andrew V. Sutherland (MIT) Modular polynomials and isogeny volcanoes 1 of 9 Isogenies An isogeny
More informationOn the evaluation of modular polynomials
On the evaluation of modular polynomials Andrew V. Sutherland Massachusetts Institute of Technology ANTS X July 10, 2012 http://math.mit.edu:/ drew 1 / 16 Introduction Let l be a prime and let F q be a
More informationComputing the modular equation
Computing the modular equation Andrew V. Sutherland (MIT) Barcelona-Boston-Tokyo Number Theory Seminar in Memory of Fumiyuki Momose Andrew V. Sutherland (MIT) Computing the modular equation 1 of 8 The
More informationConstructing genus 2 curves over finite fields
Constructing genus 2 curves over finite fields Kirsten Eisenträger The Pennsylvania State University Fq12, Saratoga Springs July 15, 2015 1 / 34 Curves and cryptography RSA: most widely used public key
More informationIdentifying supersingular elliptic curves
Identifying supersingular elliptic curves Andrew V. Sutherland Massachusetts Institute of Technology January 6, 2012 http://arxiv.org/abs/1107.1140 Andrew V. Sutherland (MIT) Identifying supersingular
More informationClass polynomials for abelian surfaces
Class polynomials for abelian surfaces Andreas Enge LFANT project-team INRIA Bordeaux Sud-Ouest andreas.enge@inria.fr http://www.math.u-bordeaux.fr/~aenge LFANT seminar 27 January 2015 (joint work with
More informationExplicit Complex Multiplication
Explicit Complex Multiplication Benjamin Smith INRIA Saclay Île-de-France & Laboratoire d Informatique de l École polytechnique (LIX) Eindhoven, September 2008 Smith (INRIA & LIX) Explicit CM Eindhoven,
More informationComputing the endomorphism ring of an ordinary elliptic curve
Computing the endomorphism ring of an ordinary elliptic curve Massachusetts Institute of Technology April 3, 2009 joint work with Gaetan Bisson http://arxiv.org/abs/0902.4670 Elliptic curves An elliptic
More informationComputing modular polynomials in dimension 2 ECC 2015, Bordeaux
Computing modular polynomials in dimension 2 ECC 2015, Bordeaux Enea Milio 29/09/2015 Enea Milio Computing modular polynomials 29/09/2015 1 / 49 Computing modular polynomials 1 Dimension 1 : elliptic curves
More informationFORMAL GROUPS OF CERTAIN Q-CURVES OVER QUADRATIC FIELDS
Sairaiji, F. Osaka J. Math. 39 (00), 3 43 FORMAL GROUPS OF CERTAIN Q-CURVES OVER QUADRATIC FIELDS FUMIO SAIRAIJI (Received March 4, 000) 1. Introduction Let be an elliptic curve over Q. We denote by ˆ
More informationElliptic Curves Spring 2015 Lecture #23 05/05/2015
18.783 Elliptic Curves Spring 2015 Lecture #23 05/05/2015 23 Isogeny volcanoes We now want to shift our focus away from elliptic curves over C and consider elliptic curves E/k defined over any field k;
More informationON THE EVALUATION OF MODULAR POLYNOMIALS
ON THE EVALUATION OF MODULAR POLYNOMIALS ANDREW V. SUTHERLAND Abstract. We present two algorithms that, given a prime l and an elliptic curve E/F q, directly compute the polynomial Φ l (j(e), Y ) F q[y
More informationGenus 2 Curves of p-rank 1 via CM method
School of Mathematical Sciences University College Dublin Ireland and Claude Shannon Institute April 2009, GeoCrypt Joint work with Laura Hitt, Michael Naehrig, Marco Streng Introduction This talk is about
More informationFast, twist-secure elliptic curve cryptography from Q-curves
Fast, twist-secure elliptic curve cryptography from Q-curves Benjamin Smith Team GRACE INRIA Saclay Île-de-France Laboratoire d Informatique de l École polytechnique (LIX) ECC #17, Leuven September 16,
More informationCONSTRUCTING SUPERSINGULAR ELLIPTIC CURVES. Reinier Bröker
CONSTRUCTING SUPERSINGULAR ELLIPTIC CURVES Reinier Bröker Abstract. We give an algorithm that constructs, on input of a prime power q and an integer t, a supersingular elliptic curve over F q with trace
More informationIgusa Class Polynomials
Genus 2 day, Intercity Number Theory Seminar Utrecht, April 18th 2008 Overview Igusa class polynomials are the genus 2 analogue of the classical Hilbert class polynomial. For each notion, I will 1. tell
More informationComputing the image of Galois
Computing the image of Galois Andrew V. Sutherland Massachusetts Institute of Technology October 9, 2014 Andrew Sutherland (MIT) Computing the image of Galois 1 of 25 Elliptic curves Let E be an elliptic
More informationIgusa class polynomials
Number Theory Seminar Cambridge 26 April 2011 Elliptic curves An elliptic curve E/k (char(k) 2) is a smooth projective curve y 2 = x 3 + ax 2 + bx + c. Q P P Q E is a commutative algebraic group Endomorphisms
More informationComputers and Mathematics with Applications. Ramanujan s class invariants and their use in elliptic curve cryptography
Computers and Mathematics with Applications 59 ( 9 97 Contents lists available at Scienceirect Computers and Mathematics with Applications journal homepage: www.elsevier.com/locate/camwa Ramanujan s class
More informationCounting points on genus 2 curves over finite
Counting points on genus 2 curves over finite fields Chloe Martindale May 11, 2017 These notes are from a talk given in the Number Theory Seminar at the Fourier Institute, Grenoble, France, on 04/05/2017.
More informationIsogeny graphs, modular polynomials, and point counting for higher genus curves
Isogeny graphs, modular polynomials, and point counting for higher genus curves Chloe Martindale July 7, 2017 These notes are from a talk given in the Number Theory Seminar at INRIA, Nancy, France. The
More informationCounting points on elliptic curves over F q
Counting points on elliptic curves over F q Christiane Peters DIAMANT-Summer School on Elliptic and Hyperelliptic Curve Cryptography September 17, 2008 p.2 Motivation Given an elliptic curve E over a finite
More informationApplications of Complex Multiplication of Elliptic Curves
Applications of Complex Multiplication of Elliptic Curves MASTER THESIS Candidate: Massimo CHENAL Supervisor: Prof. Jean-Marc COUVEIGNES UNIVERSITÀ DEGLI STUDI DI PADOVA UNIVERSITÉ BORDEAUX 1 Facoltà di
More informationIsogenies in a quantum world
Isogenies in a quantum world David Jao University of Waterloo September 19, 2011 Summary of main results A. Childs, D. Jao, and V. Soukharev, arxiv:1012.4019 For ordinary isogenous elliptic curves of equal
More informationMA 162B LECTURE NOTES: THURSDAY, FEBRUARY 26
MA 162B LECTURE NOTES: THURSDAY, FEBRUARY 26 1. Abelian Varieties of GL 2 -Type 1.1. Modularity Criteria. Here s what we ve shown so far: Fix a continuous residual representation : G Q GLV, where V is
More information14 Ordinary and supersingular elliptic curves
18.783 Elliptic Curves Spring 2015 Lecture #14 03/31/2015 14 Ordinary and supersingular elliptic curves Let E/k be an elliptic curve over a field of positive characteristic p. In Lecture 7 we proved that
More informationNon-generic attacks on elliptic curve DLPs
Non-generic attacks on elliptic curve DLPs Benjamin Smith Team GRACE INRIA Saclay Île-de-France Laboratoire d Informatique de l École polytechnique (LIX) ECC Summer School Leuven, September 13 2013 Smith
More informationCounting points on elliptic curves: Hasse s theorem and recent developments
Counting points on elliptic curves: Hasse s theorem and recent developments Igor Tolkov June 3, 009 Abstract We introduce the the elliptic curve and the problem of counting the number of points on the
More informationAbstracts of papers. Amod Agashe
Abstracts of papers Amod Agashe In this document, I have assembled the abstracts of my work so far. All of the papers mentioned below are available at http://www.math.fsu.edu/~agashe/math.html 1) On invisible
More informationAddition sequences and numerical evaluation of modular forms
Addition sequences and numerical evaluation of modular forms Fredrik Johansson (INRIA Bordeaux) Joint work with Andreas Enge (INRIA Bordeaux) William Hart (TU Kaiserslautern) DK Statusseminar in Strobl,
More informationCOMPLEX MULTIPLICATION: LECTURE 15
COMPLEX MULTIPLICATION: LECTURE 15 Proposition 01 Let φ : E 1 E 2 be a non-constant isogeny, then #φ 1 (0) = deg s φ where deg s is the separable degree of φ Proof Silverman III 410 Exercise: i) Consider
More informationConstructing Class invariants
Constructing Class invariants Aristides Kontogeorgis Department of Mathematics University of Athens. Workshop Thales 1-3 July 2015 :Algebraic modeling of topological and computational structures and applications,
More informationMappings of elliptic curves
Mappings of elliptic curves Benjamin Smith INRIA Saclay Île-de-France & Laboratoire d Informatique de l École polytechnique (LIX) Eindhoven, September 2008 Smith (INRIA & LIX) Isogenies of Elliptic Curves
More informationModular forms and the Hilbert class field
Modular forms and the Hilbert class field Vladislav Vladilenov Petkov VIGRE 2009, Department of Mathematics University of Chicago Abstract The current article studies the relation between the j invariant
More informationElliptic curves: Theory and Applications. Day 4: The discrete logarithm problem.
Elliptic curves: Theory and Applications. Day 4: The discrete logarithm problem. Elisa Lorenzo García Université de Rennes 1 14-09-2017 Elisa Lorenzo García (Rennes 1) Elliptic Curves 4 14-09-2017 1 /
More informationElliptic Curve Primality Proving
Università degli Studi Roma Tre Facoltà di Scienze Matematiche, Fisiche e Naturali Corso di Laurea Magistrale in Matematica Tesi di Laurea Magistrale in Matematica Elliptic Curve Primality Proving SINTESI
More informationIntroduction to Arithmetic Geometry Fall 2013 Lecture #24 12/03/2013
18.78 Introduction to Arithmetic Geometry Fall 013 Lecture #4 1/03/013 4.1 Isogenies of elliptic curves Definition 4.1. Let E 1 /k and E /k be elliptic curves with distinguished rational points O 1 and
More informationPublic Key Encryption
Public Key Encryption 3/13/2012 Cryptography 1 Facts About Numbers Prime number p: p is an integer p 2 The only divisors of p are 1 and p s 2, 7, 19 are primes -3, 0, 1, 6 are not primes Prime decomposition
More informationOn elliptic curves in characteristic 2 with wild additive reduction
ACTA ARITHMETICA XCI.2 (1999) On elliptic curves in characteristic 2 with wild additive reduction by Andreas Schweizer (Montreal) Introduction. In [Ge1] Gekeler classified all elliptic curves over F 2
More informationComputing Hilbert Class Polynomials
Computing Hilbert Class Polynomials Juliana Belding 1, Reinier Bröker 2, Andreas Enge 3, Kristin Lauter 2 1 Dept. of Mathematics, University of Maryland, College Park, MD 20742, USA 2 Microsoft Research,
More informationConstructing Abelian Varieties for Pairing-Based Cryptography
for Pairing-Based CWI and Universiteit Leiden, Netherlands Workshop on Pairings in Arithmetic Geometry and 4 May 2009 s MNT MNT Type s What is pairing-based cryptography? Pairing-based cryptography refers
More informationCLASS FIELD THEORY AND COMPLEX MULTIPLICATION FOR ELLIPTIC CURVES
CLASS FIELD THEORY AND COMPLEX MULTIPLICATION FOR ELLIPTIC CURVES FRANK GOUNELAS 1. Class Field Theory We ll begin by motivating some of the constructions of the CM (complex multiplication) theory for
More information1. Group Theory Permutations.
1.1. Permutations. 1. Group Theory Problem 1.1. Let G be a subgroup of S n of index 2. Show that G = A n. Problem 1.2. Find two elements of S 7 that have the same order but are not conjugate. Let π S 7
More informationGenerating Subfields
Generating Subfields joint with Marc van Hoeij, Andrew Novocin Jürgen Klüners Universität Paderborn Number Theory Conference, Bordeaux, 14th January 2013 Jürgen Klüners (Universität Paderborn) Generating
More informationHow many elliptic curves can have the same prime conductor? Alberta Number Theory Days, BIRS, 11 May Noam D. Elkies, Harvard University
How many elliptic curves can have the same prime conductor? Alberta Number Theory Days, BIRS, 11 May 2013 Noam D. Elkies, Harvard University Review: Discriminant and conductor of an elliptic curve Finiteness
More informationAn introduction to the algorithmic of p-adic numbers
An introduction to the algorithmic of p-adic numbers David Lubicz 1 1 Universté de Rennes 1, Campus de Beaulieu, 35042 Rennes Cedex, France Outline Introduction 1 Introduction 2 3 4 5 6 7 8 When do we
More informationSome algebraic number theory and the reciprocity map
Some algebraic number theory and the reciprocity map Ervin Thiagalingam September 28, 2015 Motivation In Weinstein s paper, the main problem is to find a rule (reciprocity law) for when an irreducible
More informationA Course in Computational Algebraic Number Theory
Henri Cohen 2008 AGI-Information Management Consultants May be used for personal purporses only or by libraries associated to dandelon.com network. A Course in Computational Algebraic Number Theory Springer
More informationON ISOGENY GRAPHS OF SUPERSINGULAR ELLIPTIC CURVES OVER FINITE FIELDS
ON ISOGENY GRAPHS OF SUPERSINGULAR ELLIPTIC CURVES OVER FINITE FIELDS GORA ADJ, OMRAN AHMADI, AND ALFRED MENEZES Abstract. We study the isogeny graphs of supersingular elliptic curves over finite fields,
More informationISOGENY GRAPHS OF ORDINARY ABELIAN VARIETIES
ERNEST HUNTER BROOKS DIMITAR JETCHEV BENJAMIN WESOLOWSKI ISOGENY GRAPHS OF ORDINARY ABELIAN VARIETIES PRESENTED AT ECC 2017, NIJMEGEN, THE NETHERLANDS BY BENJAMIN WESOLOWSKI FROM EPFL, SWITZERLAND AN INTRODUCTION
More informationNUNO FREITAS AND ALAIN KRAUS
ON THE DEGREE OF THE p-torsion FIELD OF ELLIPTIC CURVES OVER Q l FOR l p NUNO FREITAS AND ALAIN KRAUS Abstract. Let l and p be distinct prime numbers with p 3. Let E/Q l be an elliptic curve with p-torsion
More informationEquidistributions in arithmetic geometry
Equidistributions in arithmetic geometry Edgar Costa Dartmouth College 14th January 2016 Dartmouth College 1 / 29 Edgar Costa Equidistributions in arithmetic geometry Motivation: Randomness Principle Rigidity/Randomness
More informationarxiv: v3 [math.nt] 7 May 2013
ISOGENY VOLCANOES arxiv:1208.5370v3 [math.nt] 7 May 2013 ANDREW V. SUTHERLAND Abstract. The remarkable structure and computationally explicit form of isogeny graphs of elliptic curves over a finite field
More informationx mv = 1, v v M K IxI v = 1,
18.785 Number Theory I Fall 2017 Problem Set #7 Description These problems are related to the material covered in Lectures 13 15. Your solutions are to be written up in latex (you can use the latex source
More informationIntroduction to Elliptic Curves
IAS/Park City Mathematics Series Volume XX, XXXX Introduction to Elliptic Curves Alice Silverberg Introduction Why study elliptic curves? Solving equations is a classical problem with a long history. Starting
More informationDon Zagier s work on singular moduli
Don Zagier s work on singular moduli Benedict Gross Harvard University June, 2011 Don in 1976 The orbit space SL 2 (Z)\H has the structure a Riemann surface, isomorphic to the complex plane C. We can fix
More informationComputations/Applications
Computations/Applications 1. Find the inverse of x + 1 in the ring F 5 [x]/(x 3 1). Solution: We use the Euclidean Algorithm: x 3 1 (x + 1)(x + 4x + 1) + 3 (x + 1) 3(x + ) + 0. Thus 3 (x 3 1) + (x + 1)(4x
More informationCOMPUTING MODULAR POLYNOMIALS
COMPUTING MODULAR POLYNOMIALS DENIS CHARLES AND KRISTIN LAUTER 1. Introduction The l th modular polynomial, φ l (x, y), parameterizes pairs of elliptic curves with an isogeny of degree l between them.
More informationHONDA-TATE THEOREM FOR ELLIPTIC CURVES
HONDA-TATE THEOREM FOR ELLIPTIC CURVES MIHRAN PAPIKIAN 1. Introduction These are the notes from a reading seminar for graduate students that I organised at Penn State during the 2011-12 academic year.
More informationHeuristics. pairing-friendly abelian varieties
Heuristics on pairing-friendly abelian varieties joint work with David Gruenewald John Boxall john.boxall@unicaen.fr Laboratoire de Mathématiques Nicolas Oresme, UFR Sciences, Université de Caen Basse-Normandie,
More informationIgusa Class Polynomials
, supported by the Leiden University Fund (LUF) Joint Mathematics Meetings, San Diego, January 2008 Overview Igusa class polynomials are the genus 2 analogue of the classical Hilbert class polynomials.
More informationFormal Modules. Elliptic Modules Learning Seminar. Andrew O Desky. October 6, 2017
Formal Modules Elliptic Modules Learning Seminar Andrew O Desky October 6, 2017 In short, a formal module is to a commutative formal group as a module is to its underlying abelian group. For the purpose
More informationABSTRACT. Professor Lawrence Washington Department of Mathematics
ABSTRACT Title of dissertation: NUMBER THEORETIC ALGORITHMS FOR ELLIPTIC CURVES Juliana V. Belding, Doctor of Philosophy, 2008 Dissertation directed by: Professor Lawrence Washington Department of Mathematics
More informationA brief overwiev of pairings
Bordeaux November 22, 2016 A brief overwiev of pairings Razvan Barbulescu CNRS and IMJ-PRG R. Barbulescu Overview pairings 0 / 37 Plan of the lecture Pairings Pairing-friendly curves Progress of NFS attacks
More informationThe Sato-Tate conjecture for abelian varieties
The Sato-Tate conjecture for abelian varieties Andrew V. Sutherland Massachusetts Institute of Technology March 5, 2014 Mikio Sato John Tate Joint work with F. Fité, K.S. Kedlaya, and V. Rotger, and also
More information6]. (10) (i) Determine the units in the rings Z[i] and Z[ 10]. If n is a squarefree
Quadratic extensions Definition: Let R, S be commutative rings, R S. An extension of rings R S is said to be quadratic there is α S \R and monic polynomial f(x) R[x] of degree such that f(α) = 0 and S
More informationFaster computation of Heegner points on elliptic curves over Q of rank 1
Faster computation of Heegner points on elliptic curves over Q of rank 1 B. Allombert IMB CNRS/Université Bordeaux 1 11/09/2014 Lignes directrices Introduction Heegner points Quadratic surd Shimura Reciprocity
More informationTorsion subgroups of rational elliptic curves over the compositum of all cubic fields
Torsion subgroups of rational elliptic curves over the compositum of all cubic fields Andrew V. Sutherland Massachusetts Institute of Technology April 7, 2016 joint work with Harris B. Daniels, Álvaro
More informationOptimal curves of genus 1, 2 and 3
Optimal curves of genus 1, 2 and 3 Christophe Ritzenthaler Institut de Mathématiques de Luminy, CNRS Leuven, 17-21 May 2010 Christophe Ritzenthaler (IML) Optimal curves of genus 1, 2 and 3 Leuven, 17-21
More informationA BRIEF INTRODUCTION TO LOCAL FIELDS
A BRIEF INTRODUCTION TO LOCAL FIELDS TOM WESTON The purpose of these notes is to give a survey of the basic Galois theory of local fields and number fields. We cover much of the same material as [2, Chapters
More informationOn the generalized Fermat equation x 2l + y 2m = z p
On the generalized Fermat equation x 2l + y 2m = z p Samuele Anni joint work with Samir Siksek University of Warwick University of Debrecen, 29 th Journées Arithmétiques; 6 th July 2015 Generalized Fermat
More informationTables of elliptic curves over number fields
Tables of elliptic curves over number fields John Cremona University of Warwick 10 March 2014 Overview 1 Why make tables? What is a table? 2 Simple enumeration 3 Using modularity 4 Curves with prescribed
More informationc Copyright 2012 Wenhan Wang
c Copyright 01 Wenhan Wang Isolated Curves for Hyperelliptic Curve Cryptography Wenhan Wang A dissertation submitted in partial fulfillment of the requirements for the degree of Doctor of Philosophy University
More informationExplicit Representation of the Endomorphism Rings of Supersingular Elliptic Curves
Explicit Representation of the Endomorphism Rings of Supersingular Elliptic Curves Ken McMurdy August 20, 2014 Abstract It is well known from the work of Deuring that the endomorphism ring of any supersingular
More information20 The modular equation
18.783 Elliptic Curves Lecture #20 Spring 2017 04/26/2017 20 The modular equation In the previous lecture we defined modular curves as quotients of the extended upper half plane under the action of a congruence
More informationClass invariants for quartic CM-fields
Number Theory Seminar Oxford 2 June 2011 Elliptic curves An elliptic curve E/k (char(k) 2) is a smooth projective curve y 2 = x 3 + ax 2 + bx + c. Q P E is a commutative algebraic group P Q Endomorphisms
More informationALGEBRAIC GEOMETRY COURSE NOTES, LECTURE 4: MORE ABOUT VARIETIES AND REGULAR FUNCTIONS.
ALGERAIC GEOMETRY COURSE NOTES, LECTURE 4: MORE AOUT VARIETIES AND REGULAR FUNCTIONS. ANDREW SALCH. More about some claims from the last lecture. Perhaps you have noticed by now that the Zariski topology
More informationCurves, Cryptography, and Primes of the Form x 2 + y 2 D
Curves, Cryptography, and Primes of the Form x + y D Juliana V. Belding Abstract An ongoing challenge in cryptography is to find groups in which the discrete log problem hard, or computationally infeasible.
More informationConstructing Tower Extensions of Finite Fields for Implementation of Pairing-Based Cryptography
Constructing Tower Extensions of Finite Fields for Implementation of Pairing-Based Cryptography Naomi Benger and Michael Scott, 1 School of Computing, Dublin City University, Ireland nbenger@computing.dcu.ie
More informationEXERCISES IN MODULAR FORMS I (MATH 726) (2) Prove that a lattice L is integral if and only if its Gram matrix has integer coefficients.
EXERCISES IN MODULAR FORMS I (MATH 726) EYAL GOREN, MCGILL UNIVERSITY, FALL 2007 (1) We define a (full) lattice L in R n to be a discrete subgroup of R n that contains a basis for R n. Prove that L is
More informationFinite Fields and Their Applications
Finite Fields and Their Applications 18 (2012) 1232 1241 Contents lists available at SciVerse ScienceDirect Finite Fields and Their Applications www.elsevier.com/locate/ffa What is your birthday elliptic
More informationElliptic Curves Spring 2013 Lecture #14 04/02/2013
18.783 Elliptic Curves Spring 2013 Lecture #14 04/02/2013 A key ingredient to improving the efficiency of elliptic curve primality proving (and many other algorithms) is the ability to directly construct
More informationResidual modular Galois representations: images and applications
Residual modular Galois representations: images and applications Samuele Anni University of Warwick London Number Theory Seminar King s College London, 20 th May 2015 Mod l modular forms 1 Mod l modular
More informationGenerating Prime Order Elliptic Curves: Difficulties and Efficiency Considerations
Generating Prime Order Elliptic Curves: Difficulties and Efficiency Considerations Elisavet Konstantinou 1,2, Aristides Kontogeorgis 3, Yannis C. Stamatiou 1,3,4, and Christos Zaroliagis 1,2 1 Computer
More informationConstructing Permutation Rational Functions From Isogenies
Constructing Permutation Rational Functions From Isogenies Gaetan Bisson 1 and Mehdi Tibouchi 1 University of French Polynesia NTT Secure Platform Laboratories Abstract. A permutation rational function
More informationEvaluating Large Degree Isogenies between Elliptic Curves
Evaluating Large Degree Isogenies between Elliptic Curves by Vladimir Soukharev A thesis presented to the University of Waterloo in fulfillment of the thesis requirement for the degree of Master of Mathematics
More informationProfinite Groups. Hendrik Lenstra. 1. Introduction
Profinite Groups Hendrik Lenstra 1. Introduction We begin informally with a motivation, relating profinite groups to the p-adic numbers. Let p be a prime number, and let Z p denote the ring of p-adic integers,
More informationCLASS FIELD THEORY NOTES
CLASS FIELD THEORY NOTES YIWANG CHEN Abstract. This is the note for Class field theory taught by Professor Jeff Lagarias. Contents 1. Day 1 1 1.1. Class Field Theory 1 1.2. ABC conjecture 1 1.3. History
More informationIntroduction to Q-curves
Introduction to Q-curves Imin Chen Simon Fraser University ichen@math.sfu.ca November 24, 2008 Introduction Some Galois cohomology Abelian varieties of GL 2 -type Explicit splitting maps for example References
More informationSoftware implementation of Koblitz curves over quadratic fields
Software implementation of Koblitz curves over quadratic fields Thomaz Oliveira 1, Julio López 2 and Francisco Rodríguez-Henríquez 1 1 Computer Science Department, Cinvestav-IPN 2 Institute of Computing,
More information20 The modular equation
18.783 Elliptic Curves Spring 2015 Lecture #20 04/23/2015 20 The modular equation In the previous lecture we defined modular curves as quotients of the extended upper half plane under the action of a congruence
More informationComplex multiplication and canonical lifts
Complex multiplication and canonical lifts David R. Kohel Abstract The problem of constructing CM invariants of higher dimensional abelian varieties presents significant new challenges relative to CM constructions
More informationFrobenius Distributions
Frobenius Distributions Edgar Costa (MIT) September 11th, 2018 Massachusetts Institute of Technology Slides available at edgarcosta.org under Research Polynomials Write f p (x) := f(x) mod p f(x) = a n
More informationEndomorphism algebras of semistable abelian varieties over Q of GL(2)-type
of semistable abelian varieties over Q of GL(2)-type UC Berkeley Tatefest May 2, 2008 The abelian varieties in the title are now synonymous with certain types of modular forms. (This is true because we
More information2,3,5, LEGENDRE: ±TRACE RATIOS IN FAMILIES OF ELLIPTIC CURVES
2,3,5, LEGENDRE: ±TRACE RATIOS IN FAMILIES OF ELLIPTIC CURVES NICHOLAS M. KATZ 1. Introduction The Legendre family of elliptic curves over the λ-line, E λ : y 2 = x(x 1)(x λ), is one of the most familiar,
More informationGalois theory (Part II)( ) Example Sheet 1
Galois theory (Part II)(2015 2016) Example Sheet 1 c.birkar@dpmms.cam.ac.uk (1) Find the minimal polynomial of 2 + 3 over Q. (2) Let K L be a finite field extension such that [L : K] is prime. Show that
More informationAn Alternate Decomposition of an Integer for Faster Point Multiplication on Certain Elliptic Curves
An Alternate Decomposition of an Integer for Faster Point Multiplication on Certain Elliptic Curves Young-Ho Park 1,, Sangtae Jeong 2, Chang Han Kim 3, and Jongin Lim 1 1 CIST, Korea Univ., Seoul, Korea
More informationShort proofs of the universality of certain diagonal quadratic forms
Arch. Math. 91 (008), 44 48 c 008 Birkhäuser Verlag Basel/Switzerland 0003/889X/010044-5, published online 008-06-5 DOI 10.1007/s00013-008-637-5 Archiv der Mathematik Short proofs of the universality of
More informationCDM. Finite Fields. Klaus Sutner Carnegie Mellon University. Fall 2018
CDM Finite Fields Klaus Sutner Carnegie Mellon University Fall 2018 1 Ideals The Structure theorem Where Are We? 3 We know that every finite field carries two apparently separate structures: additive and
More information