The best and worst of supersingular abelian varieties in cryptology

Karl Rubin and Alice Silverberg


For certain security applications, including identity based encryption and short signature schemes, it is useful to have abelian varieties with security parameters that are neither too small nor too large. Supersingular abelian varieties are natural candidates for these applications. This paper determines exactly which values can occur as the security parameters of supersingular abelian varieties (in terms of the dimension of the abelian variety and the size of the finite field), and gives constructions of supersingular abelian varieties which are optimal for use in cryptography.

Note: The paper has been updated, with new results and constructions.

abelian varieties, supersingular, elliptic curves, short signatures
