Computational Number Theory

Elliptic curves play a very important role in modern mathematics with applications ranging from the very theoretical to the very computational. For example, they are the backbone of Wiles proof of Fermat’s Last Theorem and of one of the most widely used cryptosystem.
More recently, isogenies of elliptic curves and abelian varieties gained attention as well.
They are used in different cryptographic schemes that are proposed in the context of post-quantum cryptography.
To make these schemes efficient, and to evaluate their security, it is important to understand the underlying mathematics.
Our workshop will gather experts working on the computational tools involving elliptic curves, abelian varieties and isogenies, as well as experts working on the cryptographic applications.

Organizers

INRIA Bordeaux

Aix-Marseille Université

Université Côte d’Azur

Speakers

Semi-plenary speakers

IBM Research Europe

University of Calgary

Invited speakers

Virginia Tech

Simon Fraser University

KU Leuven

University of Waterloo

INRIA Nancy Grand Est

INRIA Bordeaux

Université Grenoble Alpes

KU Leuven

Leiden University

University of Tokyo

CNRS LORIA

ENS Lyon

University of Birmingham

Universität Duisburg-Essen

Ben-Gurion University of the Negev

Leiden University

University of Sydney

Monday, 13 July

[HS 08 – 1st Floor]

14:00-14:30

Nils Bruin (Simon Fraser University)

(2,2,2)-Isogeny descent on Jacobians of plane quartics

We describe an approach to compute Selmer groups of polarized (2,2,2)-isogenies on quadratic twists of Jacobians of plane quartics, in the presence of completely split 2-torsion. By comparing their sizes with the full 2-Selmer groups we can show the presence of 2-torsion in the Tate-Shafarevich groups of some absolutely simple abelian 3-folds with rank 1 endomorphism rings.
The computational challenges lie in the determination of the relevant quadratic twists as well as in computing the local images of some non-trivial twists of Jacobians.
This is joint work with Emiel Haakma.

14:30-15:00

Jean Kieffer (CNRS LORIA)

Fast evaluation of Riemann theta functions in any dimension

The Riemann theta functions are complex-analytic functions that are intimately linked to the theory of abelian varieties over the complex numbers. In computations, the problem often arises to evaluate theta functions at a given point (vector and period matrix) to a certain numerical precision; possibly hundreds of thousands of digits for applications in number theory. In this talk, I will present an algorithm to evaluate Riemann theta functions in quasi-linear time in terms of the required precision, in any dimension, and with rigorous error bounds. Timings from our FLINT implementation demonstrate that high precisions have become reachable in dimensions up to 10. This is joint work with Noam D. Elkies.

15:00-15:30

Maria Corte Real Santos (ENS Lyon)

Computing isogenies of odd degree in any dimension

In this talk, we will discuss the efficient computation of polarised isogenies between principally polarised abelian varieties, focusing particularly on the odd degree case. The talk will begin with an overview of the existing methods for computing odd degree isogenies. We will explore why the “natural” generalisation of Vélu’s method does not work in dimension greater than 1, and how this obstruction was resolved in two lines of work: the first is due to Bisson, Cosset, Lubicz, and Robert using the theory of theta functions; the second — taken by Bruin, Flynn, and Testa and later extended in joint work with Costello, Flynn, and Smith — uses more algebraic methods. We finish the talk by exploring how we can use ideas from these two approaches to obtain an algorithm that outperforms the current state-of-the-art. This is based on joint work with Dartois, Robert, and Smith.

15:30-16:00

Annamaria Iezzi (Université Grenoble Alpes)

Computing endomorphism rings of abelian surfaces over finite fields

In this talk, we investigate the problem of computing endomorphism rings of abelian varieties over finite fields and discuss its applications to isogeny-based cryptography. We focus on principally polarized abelian surfaces and cover all possible surface types, including cases that are often omitted in the literature, such as non-ordinary and non-simple abelian surfaces. For each type surface, we survey known results and, whenever possible, we provide improvements and missing results, highlighting the main algorithmic challenges involved. This is a joint work with Samuele Anni, Gaetan Bisson, Elisa Lorenzo García and Benjamin Wesolowski.

16:00-16:30 Coffee Break

16:30-17:30 semi-plenary talk

Renate Scheidler (University of Calgary)

The spine of a supersingular ell-isogeny graph

Supersingular elliptic curve ell-isogeny graphs over finite fields offer a setting for a number of quantum-resistant cryptographic protocols. The security analysis of these schemes typically assumes that these graphs behave randomly. Motivated by this assertion, we explore structural properties of these graphs. We detail the behaviour, governed by congruence conditions on p, of the ell-isogeny graph over the field F_p when passing to the spine, i.e. the subgraph induced by the F_p-vertices in the full ell-isogeny graph. We describe the diameter of the spine and offer numerical data on the number of vertices, over both F_p and its algebraic closure, in the center of the ell-isogeny graph. Our plots of these counts exhibit a wave-shaped pattern which supports the assertion that centers of supersingular ell-isogeny graphs exhibit the same behavior as those of random (ell+1)-regular graphs. This is joint work with Sarah Arpin and Taha Hedayat.

17:30-18:00

Sarah Arpin (Virginia Tech)

Isogeny graphs of abelian varieties and singular ideals in orders

Isogeny graphs of ordinary elliptic curves are beautifully structured objects (Kohel 1996), now called volcanos. We prove graph structural theorems for abelian varieties of any dimension with commutative endomorphism ring and containing a fixed locally Bass order, leveraging an ideal-theoretic perspective on isogeny graphs. This generalizes previous results, which relied on restrictive additional assumptions, such as maximal real multiplication, ordinary, and absolutely simple (Brooks, Jetchev, Wesolowski 2017). In particular, our work also applies to non-simple and non-ordinary isogeny classes. To obtain our results, we first prove a structure theorem for the lattice of inclusion of the overorders of a locally Bass order in an étale algebra which is of independent interest. This analysis builds on a careful study of local singularities of the orders. We include several examples of volcanoes and isogeny graphs exhibiting unexpected properties ultimately due to our more general setting. This is joint work with Stefano Marseglia and Caleb Springer.

18:00-18:30

Harun Kir (ENS Lyon)

Expansion Properties of the Superspecial Isogeny Graph with Level Structure

The l-isogeny graph is a cornerstone of isogeny-based cryptography. Analyzing its expansion properties is essential for evaluating the underlying hardness of fundamental cryptographic problems. While the one-dimensional superspecial isogeny graph is a well-known Ramanujan graph with optimal expansion, the landscape changes in higher dimensions, which are now significant ingredients in this research area. In this talk, we examine the expansion of higher-dimensional isogeny graphs with/without level structure. Although these graphs are not Ramanujan, we demonstrate that they still exhibit strong expansion properties. Then we discuss applications, including the removal of heuristics from the Costello-Smith algorithm for solving the isogeny problem in dimension 2. This work is in progress and is joint with M. Corte-Real Santos, O. Taïbi, and B. Wesolowski.

Tuesday, 14 July

[HS 08 – 1st Floor]

14:00-14:30

Marco Streng (Leiden University)

Lower bounds for heights of points on elliptic curves over function fields

The height of an arithmetic object is a measure of its complexity, roughly like its bit size. We prove lower bounds on the non-zero heights of points on elliptic curves, which are linear in terms of the height of the elliptic curve, i.e. h(P) > c^-1 h(E).
We do this in the function field setting. Previous bounds in that setting had constants c that were exponential in the genus of the function field, and we bring this down to a cubic polynomial, which appears to be close to optimal and is much more practical.
Our proof was inspired by results obtained using linear optimization.
This is joint work with Bartosz Naskręcki.

14:30-15:00

Sergey Rybakov (Ben-Gurion University of the Negev)

Abelian varieties over finite fields and generalized Deligne modules

According to a result of Tate and Honda, a simple abelian variety A over a finite field is determined up to isogeny by an eigenvalue of the Frobenius endomorphism on the first étale cohomology group of A, the Weil number. The category of abelian varieties over finite fields is much more complicated. Deligne proved that the category of ordinary abelian varieties over a finite field is equivalent to the category of ordinary Deligne modules. Centeleghe and Stix proved a more general result about the category of all abelian varieties. They fix a set of Weil numbers and construct an equivalence from the category of abelian varieties with Frobenius eigenvalues from this set to a subcategory of modules over the endomorphism algebra of a balanced abelian variety. Over a prime field, the target category is the category of Deligne modules, but in general, this category is rather inexplicit. We give a more direct generalization of the Deligne theorem. Namely, we show that the category of abelian varieties over a finite field with a given set of Frobenius eigenvalues is equivalent to a category of modules very similar to Deligne modules.
If time permits, we will discuss a polarized version of this construction.

15:00-16:00

John Voight (University of Sydney)

When torsion distinguishes an abelian surface from its dual

We review a categorical framework suitable for studying Tate modules of abelian varieties under isogeny, useful in explicit matrix computations. As an application, we present abelian surfaces over number fields that are distinguished from their duals via the Galois representation afforded by their torsion. This is joint work with Sarah Frei and Katrina Honigs.

16:00-16:30 Coffee Break

16:30-17:00

Marc Houben (INRIA Bordeaux)

The Hessian transformation as a modular Lattès map

Lattès maps are rational maps on the projective line that arise as the quotient of an endomorphism of an elliptic curve by a finite subgroup of its automorphism group. They exhibit particularly nice dynamical properties; in particular, their orbit structure is well understood. Through this lens, we study the dynamics of the Hessian transformation on elliptic curves. In particular, we show that it exhibits a Lattès structure arising from a degree-3 endomorphism of the genus-one modular curve X(6). Based on joint work with Dania Lazzarini, Riccardo Lolato, Marzio Mula, Federico Pintore, and Daniele Taufer.

17:00-17:30

Jonathan Love (Leiden University)

Arithmetic intersections on non-split Cartan modular curves

Take two elliptic curves with complex multiplication over a number field, each equipped with a level structure preserved by all endomorphisms. At which primes $p$ does there exist a isomorphism between the elliptic curves mod $p$ that preserves the level structures? This question was answered for $\Gamma_0(N)$ level structure (that is, for elliptic curves with a designated cyclic order $N$ subgroup) by Gross, Kohnen, and Zagier in 1987. A key step in their proof is showing that an isomorphism mod $p$ determines embeddings of the (quadratic) CM orders into a common (quaternion) Eichler order. In this talk, we will discuss what changes in the argument when we replace $\Gamma_0(N)$ with the normalizer of a non-split Cartan subgroup. This is joint work with Elie Studnia and Jan Vonk.

17:30-18:00

Desirée Gijón Gómez (INRIA Nancy Grand Est)

Humbert singular relations and linear modular embeddings of modular and Shimura curves

Humbert singular relations are quadratic relations involving the coefficients of the period matrix of a principally polarized abelian surface (ppas), which inform on the existence of both real multiplications in the ring of symmetric endomorphisms and isogenies to products of elliptic curves. Ppas with quaternionic multiplication admit infinitely many real multiplications, which are encoded by a positive definite binary quadratic form, the refined Humbert invariant. We present the pertinent results (on the complex setting) of Kani, Lin-Yang, Guo-Yang, Hashimoto and Rotger, and apply them to study linear relations of coefficients of the period matrix. As an application, we present modular embeddings for modular curves generalizing the standard diagonal embedding, in the sense that the period matrix has a particularly simple expression.

18:00-18:30

Andreas Pieper (Universität Duisburg-Essen)

Two Mumford-type Shimura curves contained in the Torelli locus

Serre’s open image theorem shows that an abelian variety $A$ with geometric endomorphism algebra $\mathbb{Z}$ has a Galois representation with large image, provided that the dimension of $A$ is a prime number or $6$. This is complemented by abelian varieties of Mumford type. These are fourfolds with no extra endomorphisms and yet the image of the Galois representation is known to be small. Together with T. Bouchet, J. Hanselman, and S. Schiavone we found the first explicit examples of abelian varieties of Mumford type. Surprisingly, there are two special families of Jacobians of Mumford-type. These also provide the first non-PEL examples in the context of the Coleman-Oort conjecture.

Wednesday, 15 July

[HS 08 – 1st Floor]

14:00-14:30

Leonardo Colò (University of Waterloo)

Zero-Knowledge Proofs of Isogeny Diamonds

Commutative diagrams of isogenies between supersingular elliptic curves, which we call isogeny diamonds, have become fundamental to isogeny-based cryptography for both constructive and cryptanalytic purposes. In parallel, proofs of knowledge of isogenies have been widely studied and have found many applications. In this work, we combine these two directions and introduce zero-knowledge proofs of isogeny diamonds, namely, proofs of knowledge of isogenies together with the fact that they form a commutative diagram. We present three constructions in two settings. The first, which we call the WindmillZKP, assumes that the prover knows only two parallel isogenies in the diamond which is relevant for multi-party computation of M-SIDH. The other two, CubeZKP and KaniZKP, assume that the prover knows all four isogenies. We also provide proof-of-concept implementations of the proposed constructions and compare their performance.

14:30-15:00

Jonathan Komada Eriksen (KU Leuven)

MIKE: a fast and post-quantum NIKE

In this talk, we will introduce MIKE, a new post-quantum non-interactive key-exchange based on a symmetric monoidal action of the category of R-modules on the category of proper commutative group schemes with an R-orientation. We will start by describing the abstract properties of this action, before seeing that although the underlying mathematics is rather involved, the resulting algorithms are quite simple. This gives a NIKE with highly favorable properties: it is extremely compact at only 64-byte public keys, reasonably efficient with one full constant-time key-exchange taking less than 5 ms on a laptop, and it comes with provable security reductions to standard problems in the so-called algebraic isogeny model.
This is based on joint work with the MIKE team: Andrea Basso, Pierrick Dartois, Max Duparc, myself, Sabrina Kunzweiler, Michael Meyer, Giacomo Pope, Krijn Reijnders, Damien Robert, Ryan Rueger, and Sina Schaeffler

15:00-16:00 semi-plenary talk

Luca De Feo (IBM Research Europe)

Of grupoids, one-way functors and fingerprints: distilling the essence of isogeny-based cryptography

Cryptography nestles where hard computational problems are found. But computational problems only tell half of the story: the hardness of factoring does not immediately suggest RSA.
It is now universally accepted that the fundamental problem upon which (supersingular) isogeny-based cryptography rests is the Endomorphism Ring Problem, or, equivalently, the Isogeny Problem. But how does one construct cryptographic schemes from it?
A generalization of Discrete Logarithm Cryptography, Cryptographic Group Actions have been a very successful paradigm for constructing isogeny-based protocols. However they only account for a small part of all proposed schemes. Outside of the framework lie several encryption and signature schemes that escape a simple formalization; among them SQIsign, possibly the most revered of all isogeny schemes.
In this talk I will introduce Forensic Categories, an abstract framework for modelling SQIsign-like primitives. Starting from the well known correspondence between quaternionic ideals and isogenies of supersingular curves, I will distill the key algorithmic properties that lead to SQIsign. The results is a category with a set of computational axioms sufficient to instantiate SQIsign-like primitives. We hope that this abstraction will both make SQIsign easier to use and lead to SQIsign-like signatures based on different computational problems.
Joint work with A. Basso, S. Patranabis, I. Radulescu and B. Wesolowski.

16:00-16:30 Coffee Break

16:30-17:00

Eda Kirimli (University of Bristol)

Isogeny problems and refined Humbert invariants

We study principally polarized superspecial abelian surfaces over finite fields through their refined Humbert invariants. We present an explicit method for computing these invariants, together with an algorithm for enumerating principal polarizations. We then discuss several applications. First, we show that computing refined Humbert invariants is computationally equivalent to solving the isogeny problem for supersingular elliptic curves. Second, we explain how these invariants encode information about isogeny degrees between elliptic curves. Finally, we use this perspective to study the splitting behavior of isogeny graphs of principally polarized superspecial abelian surfaces.

17:00-17:30

Mingjie Chen (KU Leuven)

A cryptographic analysis of the isogeny graph of superspecial abelian surfaces with maximal real multiplication

The isogeny graphs of superspecial abelian surfaces with maximal real multiplication were first studied by Charles, Goren, and Lauter in 2009, when they constructed the RM-CGL hash function on these graphs and proved that they are Ramanujan. As a consequence, these graphs enjoy the desired expansion properties, which are either absent or difficult to establish in other higher-dimensional isogeny graphs.
In this talk, we take a closer look at these graphs from a cryptographic perspective and attempt to demonstrate that they are the natural candidate for the supersingular \ell-isogeny graph in dimension two. Specifically, we further investigate their graph-theoretic properties, addressing questions concerning diameters, loops, and multi-edges; we study generic attacks on the path-finding problem in our graph; we provide explicit algorithms for navigating these graphs together with an implementation of the RM-CGL hash function; and we show that the CGL hash function requires a trusted setup by presenting a path-finding algorithm on these graphs in the setting where endomorphism rings are given, which we call RM-KLPT.
RM-KLPT resembles the one-dimensional KLPT algorithm much more closely than KLPT^2 does. This is due to the existence of a higher-dimensional analogue of the Deuring correspondence in the RM setting, which yields significantly shorter paths (p^5.5) compared to KLPT^2. Finally, we conclude by discussing potential cryptographic constructions that may be built from RM-KLPT, and more generally, the higher-dimensional Deuring correspondence.

17:30-18:00

Hiroshi Onuki (The University of Tokyo)

Geometric construction of modular polynomials with level structures

“This talk will present a geometric construction of modular polynomials with level structures.
The construction is given purely algebraically, and does not directly involve the q-expansion of modular forms. As applications, we will give a new proof of the existence of modular polynomials for Montgomery coefficients and Hessian coefficients.

18:00-18:30

Gioella Lorenzon (KU Leuven)

The Shimura class group action on superspecial principally polarized abelian surfaces for cryptography

Isogeny-based cryptography exploits the hardness of computing isogenies between dimension-one abelian varieties, i.e. elliptic curves, to build various cryptographic primitives. Among these is a generalization of classical Diffie-Hellman, through the action of the ideal class group of an imaginary quadratic order on oriented supersingular elliptic curves via isogenies.
In this talk we introduce a generalization of this framework to dimension two, namely the action of the Shimura class group of a quartic CM order on oriented, superspecial, principally polarized abelian surfaces, and discuss related challenges. We propose an instantiation in the case of a biquadratic CM order, with orientations factoring through Frobenius.