Computing Isomorphisms between Products of Supersingular Elliptic Curves
This work provides the first explicit polynomial-time method for computing isomorphisms between products of supersingular elliptic curves, which is a foundational problem in isogeny-based cryptography.
The paper presents polynomial-time algorithms for computing isomorphisms between products of supersingular elliptic curves over finite fields, leveraging the Deuring correspondence to reduce the problem to solving quadratic and linear equations over integers. Under GRH, the algorithm runs in expected polynomial time.
The Deligne-Ogus-Shioda theorem guarantees the existence of isomorphisms between products of supersingular elliptic curves over finite fields. In this paper, we present methods for explicitly computing these isomorphisms in polynomial time, given the endomorphism rings of the curves involved. Our approach leverages the Deuring correspondence, enabling us to reformulate computational isogeny problems into algebraic problems in quaternions. Specifically, we reduce the computation of isomorphisms to solving systems of quadratic and linear equations over the integers derived from norm equations. We develop $\ell$-adic techniques for solving these equations when we have access to a low discriminant subring. Combining these results leads to the description of an efficient probabilistic Las Vegas algorithm for computing the desired isomorphisms. Under GRH, it is proved to run in expected polynomial time.