The SEA algorithm for endomorphisms of supersingular elliptic curves
Travis Morrison, Lorenz Panny, Jana Sot\'akov\'a, Michael Wills

TL;DR
This paper generalizes the SEA algorithm to efficiently compute the trace of endomorphisms of supersingular elliptic curves, providing theoretical complexity bounds and practical speedups for cryptographic applications.
Contribution
It introduces a new algorithm for computing endomorphism traces on supersingular elliptic curves with proven complexity bounds, extending SEA's capabilities.
Findings
Complexity matches heuristic SEA when L and d are small
Unconditional complexity analysis due to kernel properties
Practical algorithms for trace computation modulo p
Abstract
For a prime and a supersingular elliptic curve defined over with , consider an endomorphism of represented as a composition of isogenies of degree at most . We prove that the trace of may be computed in bit operations, where , using a generalization of the SEA algorithm for computing the trace of the Frobenius endomorphism of an ordinary elliptic curve. When and , this complexity matches the heuristic complexity of the SEA algorithm. Our theorem is unconditional, unlike the complexity analysis of the SEA algorithm, since the kernel of an arbitrary isogeny of a supersingular elliptic curve is defined over an extension of constant degree, independent of . We also provide practical speedups, including a fast algorithm to compute…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptography and Residue Arithmetic · Algebraic Geometry and Number Theory
