The Supersingular Endomorphism Ring and One Endomorphism Problems are Equivalent
Aurel Page, Benjamin Wesolowski
摘要
The supersingular Endomorphism Ring problem is the following: given a supersingular elliptic curve, compute all of its endomorphisms. The presumed hardness of this problem is foundational for isogeny-based cryptography. The One Endomorphism problem only asks to find a single non-scalar endomorphism. We prove that these two problems are equivalent, under probabilistic polynomial time reductions. We prove a number of consequences. First, assuming the hardness of the endomorphism ring problem, the Charles-Goren-Lauter hash function is collision resistant, and the SQIsign identification protocol is sound. Second, the endomorphism ring problem is equivalent to the problem of computing arbitrary isogenies between supersingular elliptic curves, a result previously known only for isogenies of smooth degree. Third, there exists an unconditional probabilistic algorithm to solve the endomorphism ring problem in time Õ(p 1/2 ), a result that previously required to assume the generalized Riemann hypothesis. To prove our main result, we introduce a flexible framework for the study of isogeny graphs with additional information. We prove a general and easy-to-use rapid mixing theorem.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- AprèsSQI: Extra Fast Verification for SQIsign Using Extension-Field SigningMaria Corte-Real Santos, Jonathan Komada Eriksen, Michael Meyer, Krijn ReijndersEUROCRYPT 2024 · 被引用 23 次
- A Complete Security Proof of SQIsignMarius A. Aardal, Andrea Basso, Luca De Feo, Sikhar Patranabis 等CRYPTO 2025 · 被引用 11 次
- Isogeny Problems with Level StructureLuca De Feo, Tako Boris Fouotsa, Lorenz PannyEUROCRYPT 2024 · 被引用 10 次
- Average Hardness of SIVP for Module Lattices of Fixed RankKoen de Boer, Aurel Page, Radu Toma, Benjamin WesolowskiSTOC 2026 · 被引用 5 次
- Improved Algorithms for Finding Fixed-Degree Isogenies Between Supersingular Elliptic CurvesBenjamin Bencina, Péter Kutas, Simon-Philipp Merz, Christophe Petit 等CRYPTO 2024 · 被引用 3 次
它引用的顶会 Paper4
- An Efficient Key Recovery Attack on SIDHWouter Castryck, Thomas DecruEUROCRYPT 2023 · 被引用 284 次
- Breaking SIDH in Polynomial TimeDamien RobertEUROCRYPT 2023 · 被引用 158 次
- A Direct Key Recovery Attack on SIDHLuciano Maino, Chloe Martindale, Lorenz Panny, Giacomo Pope 等EUROCRYPT 2023 · 被引用 136 次
- Supersingular Curves You Can TrustAndrea Basso, Giulio Codogni, Deirdre Connolly, Luca De Feo 等EUROCRYPT 2023 · 被引用 43 次
相关 Paper
- Computing the Endomorphism Ring of a Supersingular Elliptic Curve from a Full Rank SuborderMingjie Chen, Christophe PetitEUROCRYPT 2025 · 被引用 2 次
- The supersingular isogeny path and endomorphism ring problems are equivalentBenjamin WesolowskiFOCS 2021 · 被引用 61 次
- Orientations and the Supersingular Endomorphism Ring ProblemBenjamin WesolowskiEUROCRYPT 2022 · 被引用 34 次
- Rational Isogenies from Irrational EndomorphismsWouter Castryck, Lorenz Panny, Frederik VercauterenEUROCRYPT 2020 · 被引用 47 次
- One-Way Functions and Malleability Oracles: Hidden Shift Attacks on Isogeny-Based ProtocolsPéter Kutas, Simon-Philipp Merz, Christophe Petit, Charlotte WeitkämperEUROCRYPT 2021 · 被引用 15 次
