Paper 2026/2327
The Humbert Form of Discriminant 36, and What It Says About Splitting Detection
Abstract
Explicit equations for the locus $\mathcal{L}_n$ of genus-two curves with a maximal degree-$n$ elliptic subcover have been computed only for $n \le 5$, and by elimination, whose cost is not predictable in advance. The degree formula of [22] changes this. It gives $\deg_w F_n = k(H_{n^2}) - 10\,\nu(n)$ in closed form, and with it a reduced monomial support for the associated Humbert modular form $G_{n^2}$, so that the reconstruction becomes a determined linear problem whose every dimension is known before any computation begins. We carry this out for the first new case it opens, discriminant $36$: we determine $k(H_{36}) = 720$, $\nu(6) = 12$, $\deg_w F_6 = 600$ and an admissible modular basis of size $41962$, and we compute the four Siegel generators explicitly along Kumar's rational parametrisation of $H_{36}$, obtaining in particular a complete factorisation of $\chi_{10}$ whose factors recover the degenerate loci of the family from the modular side. We then draw the consequences for isogeny-based cryptography. The equation $\overline{F}_n$ decides optimal $(n,n)$-splitting at every point of the moduli space in characteristic $p$, with no hypothesis on the Newton polygon; this is asserted but not proved in the cryptographic literature, and the available proof excluded exactly the superspecial locus where the question is asked. The weight $k(H_{n^2})$ bounds, unconditionally and with explicit constants, the number of superspecial nodes that detection at level $n$ adds to the target set of the best known attack in dimension two. And the same torsion count $\nu(n)$ that appears in the degree formula governs the cost of both known detection routes, which places a barrier on raising the level and singles out $n = 6$ as the one case where a new equation can matter in practice.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- Humbert surfacesSiegel modular formsgenus-two curvessplit Jacobiansisogeny-based cryptography.
- Contact author(s)
- shaska @ oakland edu
- History
- 2026-10-05: approved
- 2026-10-04: received
- See all versions
- Short URL
- https://ia.cr/2026/2327
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2327,
author = {Tony Shaska},
title = {The Humbert Form of Discriminant 36, and What It Says About Splitting Detection},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2327},
year = {2026},
url = {https://eprint.iacr.org/2026/2327}
}