AI 中文总结
本文提出一种无启发式假设的拉斯维加斯算法,以 $p^{1/3+o(1)}$ 的期望时间和内存解决超奇异椭圆曲线的 OneEnd 问题,从而改进此前无条件指数 $2/5$ 的结果。
AI 中文摘要
给定一条超奇异椭圆曲线 $E/\mathbb{F}_{p^2}$,$\mathsf{OneEnd}$ 问题要求计算 $E$ 的一个非标量自同态。根据已知的归约,解决该问题同时也能解决超奇异自同态环问题和同源问题。Wesolowski 在关于小次数分解的假设下获得了指数 $1/3$,而此前无条件的指数为 $2/5$。我们给出一个拉斯维加斯算法,其分析不依赖光滑性启发式,期望时间和内存为 \\[ p^{1/3}\exp\bigl(O(\sqrt{\log p\\,\log\log p})\bigr) = p^{1/3+o(1)}. \\] 该算法预先固定一组由小素数乘积构成的次数族。已知的计数结果提供了从曲线到其 Frobenius 共轭的这些次数的多条同源,碰撞估计表明这些同源出现在足够多的不同曲线上,使得随机游走能够到达其中之一。从这样的曲线出发,算法将一个次数分成两部分,枚举两条较短的同源列表,并匹配它们的目标以获得到共轭的同源,该同源与 Frobenius 复合即得到所需的自同态。
英文摘要
Given a supersingular elliptic curve $E/\mathbb{F}_{p^2}$, the $\mathsf{OneEnd}$ problem asks for a non-scalar endomorphism of $E$. By known reductions, solving this problem also solves the supersingular endomorphism ring and isogeny problems. Wesolowski obtained exponent $1/3$ under an assumption on the factorization of a small degree, whereas the previous unconditional exponent was $2/5$. We give a Las Vegas algorithm, analyzed without a smoothness heuristic, with expected time and memory \[ p^{1/3}\exp\bigl(O(\sqrt{\log p\,\log\log p})\bigr) = p^{1/3+o(1)}. \] The algorithm fixes in advance a family of degrees that are products of small primes. Known counting results provide many isogenies of these degrees from curves to their Frobenius conjugates, and a collision estimate shows that the isogenies occur on sufficiently many distinct curves for a random walk to reach one of them. From such a curve, the algorithm splits a degree into two parts, enumerates two lists of shorter isogenies, and matches their targets to obtain an isogeny to the conjugate, whose composition with Frobenius gives the required endomorphism.