Paper 2026/2327

The Humbert Form of Discriminant 36, and What It Says About Splitting Detection

Tony Shaska, Oakland University
Abstract

Explicit equations for the locus $\mathcal{L}_n$ of genus-two curves with a maximal degree-$n$ elliptic subcover have been computed only for $n \le 5$, and by elimination, whose cost is not predictable in advance. The degree formula of [22] changes this. It gives $\deg_w F_n = k(H_{n^2}) - 10\,\nu(n)$ in closed form, and with it a reduced monomial support for the associated Humbert modular form $G_{n^2}$, so that the reconstruction becomes a determined linear problem whose every dimension is known before any computation begins. We carry this out for the first new case it opens, discriminant $36$: we determine $k(H_{36}) = 720$, $\nu(6) = 12$, $\deg_w F_6 = 600$ and an admissible modular basis of size $41962$, and we compute the four Siegel generators explicitly along Kumar's rational parametrisation of $H_{36}$, obtaining in particular a complete factorisation of $\chi_{10}$ whose factors recover the degenerate loci of the family from the modular side. We then draw the consequences for isogeny-based cryptography. The equation $\overline{F}_n$ decides optimal $(n,n)$-splitting at every point of the moduli space in characteristic $p$, with no hypothesis on the Newton polygon; this is asserted but not proved in the cryptographic literature, and the available proof excluded exactly the superspecial locus where the question is asked. The weight $k(H_{n^2})$ bounds, unconditionally and with explicit constants, the number of superspecial nodes that detection at level $n$ adds to the target set of the best known attack in dimension two. And the same torsion count $\nu(n)$ that appears in the degree formula governs the cost of both known detection routes, which places a barrier on raising the level and singles out $n = 6$ as the one case where a new equation can matter in practice.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Humbert surfacesSiegel modular formsgenus-two curvessplit Jacobiansisogeny-based cryptography.
Contact author(s)
shaska @ oakland edu
History
2026-10-05: approved
2026-10-04: received
See all versions
Short URL
https://ia.cr/2026/2327
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2327,
      author = {Tony Shaska},
      title = {The Humbert Form of Discriminant 36, and What It Says About Splitting Detection},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2327},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2327}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.