Paper 2026/215
Endomorphisms via splittings
Abstract
One of the fundamental hardness assumptions underlying isogeny-based cryptography is the problem of finding a non-trivial endomorphism of a given supersingular elliptic curve. We show that this problem is related to the problem of finding a good splitting of a principally polarized superspecial abelian surface. We provide formal security reductions, as well as a proof-of-concept implementation of an algorithm to compute endomorphisms of elliptic curves by solving the splitting problem.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Published elsewhere. PQCrypto 2026
- Keywords
- Isogeny-based cryptographyabelian varietiessecurity assumptionsimplementation
- Contact author(s)
-
sabrina kunzweiler @ math u-bordeaux fr
min yi shen0403106 @ gmail com - History
- 2026-02-12: revised
- 2026-02-10: received
- See all versions
- Short URL
- https://ia.cr/2026/215
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/215,
author = {Sabrina Kunzweiler and Min-Yi Shen},
title = {Endomorphisms via splittings},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/215},
year = {2026},
url = {https://eprint.iacr.org/2026/215}
}