9.1 Elliptic Curves with a given Endomorphism Ring
نویسنده
چکیده
and we know that this ring is isomorphic to Z or an order O in an imaginary quadratic field K; in fact, the ring on the right is equal to Z or O (viewed as a subring of C).1 To simplify the discussion, we shall treat the isomorphism in (1) as an equality and view elements of End(EL) as elements of Z or O. How might we construct an elliptic curve with endomorphism ring O? An obvious way is to use the lattice L = O. If α ∈ End(EO), then αO ⊆ O, by (1), and therefore α ∈ O, since the ring O contains 1. Conversely, if α ∈ O, then αO ⊆ O, since O is closed under multiplication, and therefore α ∈ End(EO), by (1); thus End(EO) = O. But are there any other (non-isomorphic) examples of elliptic curves with End(E) = O? To answer this question, we would like to classify, up to homethety, the lattices L for which {α : αL ⊆ L} = O. Without loss of generality, we may assume L = [1, τ ], and O = [1, ω]. If End(EL) = O, then we must have ω · 1 = ω ∈ L, so ω = m + nτ , for some m,n ∈ Z. Thus nL = [n, ω −m] = [n, ω] (and O = [1, nτ + m] = [1, nτ ]). So L is homothetic to a sublattice of O, and this sublattice must be closed under multiplication by O; equivalently, L is homothetic to an O-ideal (a subring of O closed under multiplication by O). For any O-ideal L, the set {α ∈ C : αL ⊆ L} is an order that contains O, which we denote O(L). The same is true for any lattice homothetic to an O-ideal, since O(L) depends only on the homethety class of L. We are interested in the cases where O(L) = O, since these are precisely the (homethety classes of) lattices that give rise to elliptic curves EL/C with End(EL) = O. When the condition O(L) = O holds, we say that L is a proper O-ideal. Note that O(L) is always contained in the maximal order OK , so when O = OK every O-ideal is proper, but otherwise this is not true (Problem Set 9 asks for a counter example). Given that O(L) depends only on the homethety class of L, we shall regard two Oideals as equivalent if they are homothetic as lattices; it follows that the ideals a and b are equivalent if and only if (α)a = (β)b for some α, β ∈ O. Since the elliptic curves EL and EL′ are isomorphic if and only if the lattices L and L ′ are homothetic, two proper O-ideals a and b are equivalent if and only if Ea ' Eb. As shown in Problem Set 9, the set cl(O) of equivalence classes of proper O-ideals form a finite abelian group that is isomorphic to the group cl(D) formed by the SL2(Z)-equivalence classes of binary quadratic forms
منابع مشابه
Diffie-Hellman type key exchange protocols based on isogenies
In this paper, we propose some Diffie-Hellman type key exchange protocols using isogenies of elliptic curves. The first method which uses the endomorphism ring of an ordinary elliptic curve $ E $, is a straightforward generalization of elliptic curve Diffie-Hellman key exchange. The method uses commutativity of the endomorphism ring $ End(E) $. Then using dual isogenies, we propose...
متن کاملElliptic Curves over C
that is both analytic (as a mapping of complex manifolds) and algebraic: addition of points in E(C) corresponds to addition in C modulo the lattice L. This correspondence between lattices and elliptic curves over C is known as the Uniformization Theorem; we will spend this lecture and part of the next proving it. To make the correspondence explicit, we need to specify the map Φ from C/L and an ...
متن کاملComplex Multiplication Tests for Elliptic Curves
We consider the problem of checking whether an elliptic curve defined over a given number field has complex multiplication. We study two polynomial time algorithms for this problem, one randomized and the other deterministic. The randomized algorithm can be adapted to yield the discriminant of the endomorphism ring of the curve.
متن کاملMinimal Cm Liftings of Supersingular Elliptic Curves
In this paper, we give a ‘direct’ construction of the endomorphism ring of supersingular elliptic curves over a prime field Fp from ‘ideal classes’ of Q( √−p). We use the result to prove that the result of Kaneko on ‘minimal’ CM liftings of such supersingular elliptic curves is a best possible result. We also prove that the result of Elkies on ‘minimal’ CM liftings of all supersingular elliptic...
متن کاملELLIPTIC CURVES AND MODULAR FORMS Contents
1. January 21, 2010 2 1.1. Why define a curve to be f rather than V (f) ⊂ P(k)? 3 1.2. Cubic plane curves 3 2. January 26, 2010 4 2.1. A little bit about smoothness 4 2.2. Weierstrass form 5 3. January 28, 2010 6 3.1. An algebro-geometric description of the group law in terms of divisors 6 3.2. Why are the two group laws the same? 7 4. February 2, 2010 7 4.1. Overview 7 4.2. Uniqueness of Weier...
متن کاملFast Endomorphism for any Genus 2 Hyperelliptic Curve over a Finite Field of Even Characteristic
In EUROCRYPT 2009, Galbraith, Lin and Scott constructed an efficiently computable endomorphism for a large family of elliptic curves defined over finite fields of large characteristic. They demonstrated that the endomorphism can be used to accelerate scalar multiplication in the elliptic curve cryptosystem based on these curves. In this paper we extend the method to any genus 2 hyperelliptic cu...
متن کامل