An order is a commutative ring that as an abelian group is finitely generated and free. A commutative ring is reduced if it has no non-zero nilpotent elements. In this paper we use a new tool, namely, the fact that every reduced order has a universal grading, to answer questions about realizing orders as group rings. In particular, we address the Isomorphism Problem for group rings in the case where the ring is a reduced order. We prove that any non-zero reduced order R can be written as a group ring in a unique “maximal” way, up to isomorphism. More precisely, there exist a ring A and a finite abelian group G, both uniquely determined up to isomorphism, such that R≅A[G] as rings, and such that if B is a ring and H is a group, then R≅B[H] as rings if and only if there is a finite abelian group J such that B≅A[J] as rings and J×H≅G as groups. Computing A and G for given R can be done by means of an algorithm that is not quite polynomial-time. We also give a description of the automorphism group of R in terms of A and G.
We propose a new idea for public key quantum money. In the abstract sense, our bills are encoded as a joint eigenstate of a fixed system of commuting unitary operators. We perform some basic analysis of this black box system and show that it is resistant to black box attacks. In order to instantiate this protocol, one needs to find a cryptographically complicated system of computable, commuting, unitary operators. To fill this need, we propose using Brandt operators acting on the Brandt modules associated to certain quaternion algebras. We explain why we believe this instantiation is likely to be secure.
We show that if a rational map is constant on each isomorphism class of unpolarized abelian varieties of a given dimension, then it is a constant map. Our results are motivated by and shed light on a proposed construction of a cryptographic protocol for multiparty non-interactive key exchange.
We study the Jacobian $J$ of the smooth projective curve $C$ of genus $r-1$ with affine model $y^r = x^{r-1}(x + 1)(x + t)$ over the function field $\mathbb{F}_p(t)$, when $p$ is prime and $r\ge 2$ is an integer prime to $p$. When $q$ is a power of $p$ and $d$ is a positive integer, we compute the $L$-function of $J$ over $\mathbb{F}_q(t^{1/d})$ and show that the Birch and Swinnerton-Dyer conjecture holds for $J$ over $\mathbb{F}_q(t^{1/d})$. When $d$ is divisible by $r$ and of the form $p^\nu +1$, and $K_d := \mathbb{F}_p(\mu_d,t^{1/d})$, we write down explicit points in $J(K_d)$, show that they generate a subgroup $V$ of rank $(r-1)(d-2)$ whose index in $J(K_d)$ is finite and a power of $p$, and show that the order of the Tate-Shafarevich group of $J$ over $K_d$ is $[J(K_d):V]^2$. When $r>2$, we prove that the new part of $J$ is isogenous over $\overline{\mathbb{F}_p(t)}$ to the square of a simple abelian variety of dimension $\phi(r)/2$ with endomorphism algebra $\mathbb{Z}[\mu_r]^+$. For a prime $\ell$ with $\ell \nmid pr$, we prove that $J[\ell](L)=\{0\}$ for any abelian extension $L$ of $\overline{\mathbb{F}}_p(t)$.
We describe a framework for constructing an efficient non-interactive key exchange (NIKE) protocol for n parties for any n >= 2. Our approach is based on the problem of computing isogenies between isogenous elliptic curves, which is believed to be difficult. We do not obtain a working protocol because of a missing step that is currently an open mathematical problem. What we need to complete our protocol is an efficient algorithm that takes as input an abelian variety presented as a product of isogenous elliptic curves, and outputs an isomorphism invariant of the abelian variety. Our framework builds a cryptographic invariant map, which is a new primitive closely related to a cryptographic multilinear map, but whose range does not necessarily have a group structure. Nevertheless, we show that a cryptographic invariant map can be used to build several cryptographic primitives, including NIKE, that were previously constructed from multilinear maps and indistinguishability obfuscation.
A CM-order is a reduced order equipped with an involution that mimics complex conjugation. The Witt-Picard group of such an order is a certain group of ideal classes that is closely related to the "minus part" of the class group. We present a deterministic polynomial-time algorithm for the following problem, which may be viewed as a special case of the principal ideal testing problem: given a CM-order, decide whether two given elements of its Witt-Picard group are equal. In order to prevent coefficient blow-up, the algorithm operates with lattices rather than with ideals. An important ingredient is a technique introduced by Gentry and Szydlo in a cryptographic context. Our application of it to lattices over CM-orders hinges upon a novel existence theorem for auxiliary ideals, which we deduce from a result of Konyagin and Pomerance in elementary number theory.
For commutative rings, we introduce the notion of a universal grading, which can be viewed as the “largest possible grading”. While not every commutative ring (or order) has a universal grading, we prove that every reduced order has a universal grading, and this grading is by a finite group. Examples of graded orders are provided by group rings of finite abelian groups over rings of integers in number fields. We also generalize known properties of nilpotents, idempotents, and roots of unity in such group rings to the case of graded orders; this has applications to cryptography. Lattices play an important role in this paper; a novel aspect is that our proofs use that the additive group of any reduced order can in a natural way be equipped with a lattice structure.
A main goal of the BIRS workshop “An Algebraic Approach to Multilinear Maps for Cryptography” was to bring together cryptographers, number theorists and arithmetic geometers to discuss problems of central importance in electronic communication. The focus of the workshop was on cryptographic multilinear maps. It is an open problem to construct secure cryptographic multilinear maps with more than two arguments in their domain [1]. A solution to this problem would have many applications. These include allowing groups of people to share a common secret securely and the ability to obfuscate computer programs in order to protect the intellectual property they represent. The workshop also dealt with other problems in cryptography such as quantum computation, pseudo-random number generators and applications of isogenies of abelian varieties to cryptography.
The algebras considered in this paper are commutative rings of which the additive group is a finite-dimensional vector space over the field of rational numbers. We present deterministic polynomial-time algorithms that, given such an algebra, determine its nilradical, all of its prime ideals, as well as the corresponding localizations and residue class fields, its largest separable subalgebra, and its primitive idempotents. We also solve the discrete logarithm problem in the multiplicative group of the algebra. While deterministic polynomial-time algorithms were known earlier, our approach is different from previous ones. One of our tools is a primitive element algorithm; it decides whether the algebra has a primitive element and, if so, finds one, all in polynomial time. A methodological novelty is the use of derivations to replace a Hensel-Newton iteration. It leads to an explicit formula for lifting idempotents against nilpotents that is valid in any commutative ring.
We give deterministic polynomial-time algorithms that, given an order, compute the primitive idempotents and determine a set of generators for the group of roots of unity in the order. Also, we show that the discrete logarithm problem in the group of roots of unity can be solved in polynomial time. As an auxiliary result, we solve the discrete logarithm problem for certain unit groups in finite rings. Our techniques, which are taken from commutative algebra, may have further potential in the context of cryptology and computer algebra.
For large ranks, there is no good algorithm that decides whether a given lattice has an orthonormal basis. But when the lattice is given with enough symmetry, we can construct a provably deterministic polynomial-time algorithm to accomplish this, based on the work of Gentry and Szydlo. The techniques involve algorithmic algebraic number theory, analytic number theory, commutative algebra, and lattice basis reduction.
Let $A$ be an abelian variety over $\mathbb{Q}$ of dimension $g$ such that the image of its associated absolute Galois representation $\rho_A$ is open in $\operatorname{GSp}_{2g}(\hat{\mathbb{Z}})$. We investigate the arithmetic of the traces $a_{1, p}$ of the Frobenius at $p$ in $\operatorname{Gal}(\overline{\mathbb{Q}}/\mathbb{Q})$ under $\rho_A$, modulo varying primes $p$. In particular, we obtain upper bounds for the counting function $\#\{p \leq x: a_{1, p} = t\}$ and we prove an Erdos-Kac type theorem for the number of prime factors of $a_{1, p}$. We also formulate a conjecture about the asymptotic behaviour of $\#\{p \leq x: a_{1, p} = t\}$, which generalizes a well-known conjecture of S. Lang and H. Trotter from 1976 about elliptic curves.
We provide a framework for using elliptic curves with complex multiplication to determine the primality or compositeness of integers that lie in special sequences, in deterministic quasi-quadratic time. We use this to find large primes, including the largest prime currently known whose primality cannot feasibly be proved using classical methods.
We present a deterministic polynomial-time algorithm that determines whether a finite module over a finite commutative ring is cyclic, and if it is, outputs a generator.
In this paper we give conditions under which two abelian varieties that are defined over a finite field $F$, and are isogenous over some larger field, are $F$-isogenous. Further, we give conditions under which a given isogeny is defined over $F$.
We put the Gentry-Szydlo algorithm into a mathematical framework, and show that it is part of a general theory of "lattices with symmetry". For large ranks, there is no good algorithm that decides whether a given lattice has an orthonormal basis. But when the lattice is given with enough symmetry, we can construct a provably deterministic polynomial time algorithm to accomplish this, based on the work of Gentry and Szydlo. The techniques involve algorithmic algebraic number theory, analytic number theory, commutative algebra, and lattice basis reduction. This sheds new light on the Gentry-Szydlo algorithm, and the ideas should be applicable to a range of questions in cryptography.
We show that if $E$ is an elliptic curve over ${\bf Q}$ with a ${\bf Q}$-rational isogeny of degree $7$, then the image of the $7$-adic Galois representation attached to $E$ is as large as allowed by the isogeny, except for the curves with complex multiplication by ${\bf Q}(\sqrt{-7})$. The analogous result with $7$ replaced by a prime $p > 7$ was proved by the first author. The present case $p = 7$ has additional interesting complications. We show that any exceptions correspond to the rational points on a certain curve of genus $12$. We then use the method of Chabauty to show that the exceptions are exactly the curves with complex multiplication. As a by-product of one of the key steps in our proof, we determine exactly when there exist elliptic curves over an arbitrary field $k$ of characteristic not $7$ with a $k$-rational isogeny of degree $7$ and a specified Galois action on the kernel of the isogeny, and we give a parametric description of such curves.