Paper 2026/137

Hensel-lifting black-box algorithms and fast trace computation for elliptic-curve endomorphisms

Lorenz Panny, Technical University of Munich
Damien Robert, Inria Bordeaux - Sud-Ouest Research Centre
Alessandro Sferlazza, Technical University of Munich
Abstract

We demonstrate a general and efficient technique to Hensel-lift a solution to a system of ($p$‑adically analytic) equations which may be given implicitly in the form of an efficient evaluation algorithm. Contrary to textbook Hensel lifting, we do not require the equations to be represented explicitly; indeed, our main application uses the method for a system of equations that can be exponentially larger than its representation as an arithmetic circuit: we show how to compute traces of separable elliptic-curve endomorphisms over a finite field $\mathbb{F}_q$ by constructing an approximate lift to $\mathbb{Z}_q$. Our examples include endomorphisms represented as a chain of Vélu, √élu, modular, or radical isogenies, as well as HD‑embedded endomorphisms. The resulting trace-computation algorithm outperforms the state of the art both asymptotically and concretely.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Published elsewhere. Major revision. ANTS XVII, 2026
Keywords
elliptic curveendomorphismtraceHensel lifting
Contact author(s)
lorenz @ yx7 cc
damien robert @ inria fr
alessandro sferlazza @ tum de
History
2026-07-03: revised
2026-01-28: received
See all versions
Short URL
https://ia.cr/2026/137
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/137,
      author = {Lorenz Panny and Damien Robert and Alessandro Sferlazza},
      title = {Hensel-lifting black-box algorithms and fast trace computation for elliptic-curve endomorphisms},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/137},
      year = {2026},
      url = {https://eprint.iacr.org/2026/137}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.