arXiv論文メモ
新着一覧
cs.CR · 査読状況未確認

超特異楕円曲線の同種写像問題に無条件の計算量改善

The Supersingular Isogeny Problem in Time and Memory $p^{1/3+o(1)}$, Unconditionally

José Luis Delgado

この論文をやさしく読む

ひとことで言うと

超特異楕円曲線の自己準同型を探す確率的アルゴリズムについて、従来より良い無条件の漸近計算量を示す理論研究です。

何に役立つ?

同種写像や自己準同型環を求める問題の計算的難しさを評価する基礎になります。関連する暗号の安全性を理論的に検討する材料にもなりますが、特定の実装への攻撃実証ではありません。

この研究の面白いところ

以前は素因数分解に関する仮定が必要だった指数1/3を、滑らかさのヒューリスティックなしで得ています。次数を先に選び、ランダムウォークと2つのリストの照合を組み合わせます。

どこまで分かった?

示されるのは期待時間・メモリの漸近評価であり、有限サイズでの実行時間や定数因子の測定ではありません。アルゴリズムと証明に関する記述は著者の要旨に基づき、証明本文の独立検証は行っていません。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

超特異楕円曲線E/F_(p²)が与えられたとき、OneEnd問題はEの非スカラー自己準同型を求める問題である。既知の帰着により、この問題を解けば、超特異自己準同型環問題と同種写像問題も解ける。Wesolowskiは小さな次数の素因数分解に関する仮定の下で指数1/3を得ていたが、従来の無条件の指数は2/5だった。 本研究では、滑らかさに関するヒューリスティックを用いずに解析したLas Vegasアルゴリズムを示す。その期待時間とメモリは、p^(1/3) exp(O(√(log p・log log p)))=p^(1/3+o(1))である。このアルゴリズムは、小さな素数の積となる次数の族をあらかじめ固定する。既知の数え上げ結果により、曲線からそのFrobenius共役へ至る、これらの次数の同種写像が多数存在する。また、衝突評価により、それらの同種写像が十分多くの相異なる曲線に現れ、ランダムウォークでその一つに到達できることを示す。 そのような曲線から、アルゴリズムは次数を2つに分割し、より短い同種写像のリストを2つ列挙して、到達先を照合することで共役への同種写像を得る。これをFrobeniusと合成すると、求める自己準同型が得られる。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-18(UTC)
最新改訂
2026-09-18 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Given a supersingular elliptic curve $E/\mathbb{F}_{p^2}$, the $\mathsf{OneEnd}$ problem asks for a non-scalar endomorphism of $E$. By known reductions, solving this problem also solves the supersingular endomorphism ring and isogeny problems. Wesolowski obtained exponent $1/3$ under an assumption on the factorization of a small degree, whereas the previous unconditional exponent was $2/5$. We give a Las Vegas algorithm, analyzed without a smoothness heuristic, with expected time and memory \[ p^{1/3}\exp\bigl(O(\sqrt{\log p\,\log\log p})\bigr) = p^{1/3+o(1)}. \] The algorithm fixes in advance a family of degrees that are products of small primes. Known counting results provide many isogenies of these degrees from curves to their Frobenius conjugates, and a collision estimate shows that the isogenies occur on sufficiently many distinct curves for a random walk to reach one of them. From such a curve, the algorithm splits a degree into two parts, enumerates two lists of shorter isogenies, and matches their targets to obtain an isogeny to the conjugate, whose composition with Frobenius gives the required endomorphism.

arXiv ID: 2609.22018 / 要約の誤りについて