The Supersingular Endomorphism Ring and One Endomorphism Problems are Equivalent
Aurel Page, Benjamin Wesolowski
Abstract
The supersingular Endomorphism Ring problem is the following: given a supersingular elliptic curve, compute all of its endomorphisms. The presumed hardness of this problem is foundational for isogeny-based cryptography. The One Endomorphism problem only asks to find a single non-scalar endomorphism. We prove that these two problems are equivalent, under probabilistic polynomial time reductions. We prove a number of consequences. First, assuming the hardness of the endomorphism ring problem, the Charles-Goren-Lauter hash function is collision resistant, and the SQIsign identification protocol is sound. Second, the endomorphism ring problem is equivalent to the problem of computing arbitrary isogenies between supersingular elliptic curves, a result previously known only for isogenies of smooth degree. Third, there exists an unconditional probabilistic algorithm to solve the endomorphism ring problem in time Õ(p 1/2 ), a result that previously required to assume the generalized Riemann hypothesis. To prove our main result, we introduce a flexible framework for the study of isogeny graphs with additional information. We prove a general and easy-to-use rapid mixing theorem.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers8
- AprèsSQI: Extra Fast Verification for SQIsign Using Extension-Field SigningMaria Corte-Real Santos, Jonathan Komada Eriksen, Michael Meyer, Krijn ReijndersEUROCRYPT 2024 · 23 citations
- A Complete Security Proof of SQIsignMarius A. Aardal, Andrea Basso, Luca De Feo, Sikhar Patranabis et al.CRYPTO 2025 · 11 citations
- Isogeny Problems with Level StructureLuca De Feo, Tako Boris Fouotsa, Lorenz PannyEUROCRYPT 2024 · 10 citations
- Average Hardness of SIVP for Module Lattices of Fixed RankKoen de Boer, Aurel Page, Radu Toma, Benjamin WesolowskiSTOC 2026 · 5 citations
- Improved Algorithms for Finding Fixed-Degree Isogenies Between Supersingular Elliptic CurvesBenjamin Bencina, Péter Kutas, Simon-Philipp Merz, Christophe Petit et al.CRYPTO 2024 · 3 citations
Builds on4
- An Efficient Key Recovery Attack on SIDHWouter Castryck, Thomas DecruEUROCRYPT 2023 · 284 citations
- Breaking SIDH in Polynomial TimeDamien RobertEUROCRYPT 2023 · 158 citations
- A Direct Key Recovery Attack on SIDHLuciano Maino, Chloe Martindale, Lorenz Panny, Giacomo Pope et al.EUROCRYPT 2023 · 136 citations
- Supersingular Curves You Can TrustAndrea Basso, Giulio Codogni, Deirdre Connolly, Luca De Feo et al.EUROCRYPT 2023 · 43 citations
Related papers
- Computing the Endomorphism Ring of a Supersingular Elliptic Curve from a Full Rank SuborderMingjie Chen, Christophe PetitEUROCRYPT 2025 · 2 citations
- The supersingular isogeny path and endomorphism ring problems are equivalentBenjamin WesolowskiFOCS 2021 · 61 citations
- Orientations and the Supersingular Endomorphism Ring ProblemBenjamin WesolowskiEUROCRYPT 2022 · 34 citations
- Rational Isogenies from Irrational EndomorphismsWouter Castryck, Lorenz Panny, Frederik VercauterenEUROCRYPT 2020 · 47 citations
- One-Way Functions and Malleability Oracles: Hidden Shift Attacks on Isogeny-Based ProtocolsPéter Kutas, Simon-Philipp Merz, Christophe Petit, Charlotte WeitkämperEUROCRYPT 2021 · 15 citations
