Source author record

Andrew V. Sutherland

Andrew V. Sutherland appears in the imported research catalog. Authorship, coauthor and topic links are available while profile ownership is still unclaimed.

ResearcherUnclaimed source record

Catalog footprint

What is connected

31works
4topics
4close collaborators

Actions

Connect this record

Log in to claim

Research graph

See the researcher in context

Open full explorer

Inspect adjacent papers, topics, institutions and collaborators without losing the researcher page.

Building this map preview

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

31 published item(s)

preprint2022arXiv

Computing images of Galois representations attached to elliptic curves

Let E be an elliptic curve without complex multiplication (CM) over a number field K, and let G_E(ell) be the image of the Galois representation induced by the action of the absolute Galois group of K on the ell-torsion subgroup of E. We present two probabilistic algorithms to simultaneously determine G_E(ell) up to local conjugacy for all primes ell by sampling images of Frobenius elements; one is of Las Vegas type and the other is a Monte Carlo algorithm. They determine G_E(ell) up to one of at most two isomorphic conjugacy classes of subgroups of GL_2(Z/ell Z) that have the same semisimplification, each of which occurs for an elliptic curve isogenous to E. Under the GRH, their running times are polynomial in the bit-size n of an integral Weierstrass equation for E, and for our Monte Carlo algorithm, quasi-linear in n. We have applied our algorithms to the non-CM elliptic curves in Cremona's tables and the Stein--Watkins database, some 140 million curves of conductor up to 10^10, thereby obtaining a conjecturally complete list of 63 exceptional Galois images G_E(ell) that arise for E/Q without CM. Under this conjecture we determine a complete list of 160 exceptional Galois images G_E(ell) the arise for non-CM elliptic curves over quadratic fields with rational j-invariants. We also give examples of exceptional Galois images that arise for non-CM elliptic curves over quadratic fields only when the j-invariant is irrational.

preprint2020arXiv

Sorting and labelling integral ideals in a number field

We define a scheme for labelling and ordering integral ideals of number fields, including prime ideals as a special case. The order we define depends only on the choice of a monic irreducible integral defining polynomial for each field $K$, and we start by defining for each field its unique reduced defining polynomial, after Belabas. We define a total order on the set of prime ideals of $K$ and then extend this to a total order on the set of all nonzero integral ideals of $K$. This order allows us to give a unique label of the form $N.i$, where $N$ is its norm and $i$ is the index of the ideal in the ordered list of all ideals of norm $N$. Our ideal labelling scheme has several nice properties: for a given norm, prime ideals always appear first, and given the factorisation of the norm, the bijection between ideals of norm $N$ and labels is computable in polynomial time. Our motivation for this is to have a well-defined and concise way to sort and label ideals for use in databases such as the LMFDB. We have implemented algorithms which realise this scheme, in Sage, Magma and Pari.

preprint2016arXiv

A census of zeta functions of quartic K3 surfaces over F_2

We compute the complete set of candidates for the zeta function of a K3 surface over F_2 consistent with the Weil conjectures, as well as the complete set of zeta functions of smooth quartic surfaces over F_2. These sets differ substantially, but we do identify natural subsets which coincide. This gives some numerical evidence towards a Honda-Tate theorem for transcendental zeta functions of K3 surfaces; such a result would refine a recent theorem of Taelman, in which one must allow an uncontrolled base field extension.

preprint2016arXiv

Computing L-series of geometrically hyperelliptic curves of genus three

Let C/Q be a curve of genus three, given as a double cover of a plane conic. Such a curve is hyperelliptic over the algebraic closure of Q, but may not have a hyperelliptic model of the usual form over Q. We describe an algorithm that computes the local zeta functions of C at all odd primes of good reduction up to a prescribed bound N. The algorithm relies on an adaptation of the "accumulating remainder tree" to matrices with entries in a quadratic field. We report on an implementation, and compare its performance to previous algorithms for the ordinary hyperelliptic case.

preprint2016arXiv

Sato-Tate groups of some weight 3 motives

We establish the group-theoretic classification of Sato-Tate groups of self-dual motives of weight 3 with rational coefficients and Hodge numbers h^{3,0} = h^{2,1} = h^{1,2} = h^{0,3} = 1. We then describe families of motives that realize some of these Sato-Tate groups, and provide numerical evidence supporting equidistribution. One of these families arises in the middle cohomology of certain Calabi-Yau threefolds appearing in the Dwork quintic pencil; for motives in this family, our evidence suggests that the Sato-Tate group is always equal to the full unitary symplectic group USp(4).

preprint2016arXiv

Sato-Tate groups of y^2=x^8+c and y^2=x^7-cx

We consider the distribution of normalized Frobenius traces for two families of genus 3 hyperelliptic curves over Q that have large automorphism groups: y^2=x^8+c and y^2=x^7-cx with c in Q*. We give efficient algorithms to compute the trace of Frobenius for curves in these families at primes of good reduction. Using data generated by these algorithms, we obtain a heuristic description of the Sato-Tate groups that arise, both generically and for particular values of c. We then prove that these heuristic descriptions are correct by explicitly computing the Sato-Tate groups via the correspondence between Sato-Tate groups and Galois endomorphism types.

preprint2015arXiv

Deterministic elliptic curve primality proving for a special sequence of numbers

We give a deterministic algorithm that very quickly proves the primality or compositeness of the integers N in a certain sequence, using an elliptic curve E/Q with complex multiplication by the ring of integers of Q(sqrt(-7)). The algorithm uses O(log N) arithmetic operations in the ring Z/NZ, implying a bit complexity that is quasi-quadratic in log N. Notably, neither of the classical "N-1" or "N+1" primality tests apply to the integers in our sequence. We discuss how this algorithm may be applied, in combination with sieving techniques, to efficiently search for very large primes. This has allowed us to prove the primality of several integers with more than 100,000 decimal digits, the largest of which has more than a million bits in its binary representation. At the time it was found, it was the largest proven prime N for which no significant partial factorization of N-1 or N+1 is known.

preprint2014arXiv

A framework for deterministic primality proving using elliptic curves with complex multiplication

We provide a framework for using elliptic curves with complex multiplication to determine the primality or compositeness of integers that lie in special sequences, in deterministic quasi-quadratic time. We use this to find large primes, including the largest prime currently known whose primality cannot feasibly be proved using classical methods.

preprint2014arXiv

Computing Hasse-Witt matrices of hyperelliptic curves in average polynomial time

We present an efficient algorithm to compute the Hasse-Witt matrix of a hyperelliptic curve C/Q modulo all primes of good reduction up to a given bound N, based on the average polynomial-time algorithm recently introduced by Harvey. An implementation for hyperelliptic curves of genus 2 and 3 is more than an order of magnitude faster than alternative methods for N = 2^26.

preprint2014arXiv

Finding elliptic curves with a subgroup of prescribed size

Assuming the Generalized Riemann Hypothesis, we design a deterministic algorithm that, given a prime p and positive integer m=o(sqrt(p)/(log p)^4), outputs an elliptic curve E over the finite field F_p for which the cardinality of E(F_p) is divisible by m. The running time of the algorithm is mp^(1/2+o(1)), and this leads to more efficient constructions of rational functions over F_p whose image is small relative to p. We also give an unconditional version of the algorithm that works for almost all primes p, and give a probabilistic algorithm with subexponential time complexity.

preprint2014arXiv

On the evaluation of modular polynomials

We present two algorithms that, given a prime ell and an elliptic curve E/Fq, directly compute the polynomial Phi_ell(j(E),Y) in Fq[Y] whose roots are the j-invariants of the elliptic curves that are ell-isogenous to E. We do not assume that the modular polynomial Phi_ell(X,Y) is given. The algorithms may be adapted to handle other types of modular polynomials, and we consider applications to point counting and the computation of endomorphism rings. We demonstrate the practical efficiency of the algorithms by setting a new point-counting record, modulo a prime q with more than 5,000 decimal digits, and by evaluating a modular polynomial of level ell = 100,019.

preprint2013arXiv

Computing Hilbert class polynomials with the Chinese Remainder Theorem

We present a space-efficient algorithm to compute the Hilbert class polynomial H_D(X) modulo a positive integer P, based on an explicit form of the Chinese Remainder Theorem. Under the Generalized Riemann Hypothesis, the algorithm uses O(|D|^(1/2+o(1))log P) space and has an expected running time of O(|D|^(1+o(1)). We describe practical optimizations that allow us to handle larger discriminants than other methods, with |D| as large as 10^13 and h(D) up to 10^6. We apply these results to construct pairing-friendly elliptic curves of prime order, using the CM method.

preprint2013arXiv

Isogeny volcanoes

The remarkable structure and computationally explicit form of isogeny graphs of elliptic curves over a finite field has made them an important tool for computational number theorists and practitioners of elliptic curve cryptography. This expository paper recounts the theory behind these graphs and examines several recently developed algorithms that realize substantial (often dramatic) performance gains by exploiting this theory.

preprint2012arXiv

Constructing elliptic curves over finite fields with prescribed torsion

We present a method for constructing optimized equations for the modular curve X_1(N) using a local search algorithm on a suitably defined graph of birationally equivalent plane curves. We then apply these equations over a finite field F_q to efficiently generate elliptic curves with nontrivial N-torsion by searching for affine points on X_1(N)(F_q), and we give a fast method for generating curves with (or without) a point of order 4N using X_1(2N).

preprint2012arXiv

Modular polynomials via isogeny volcanoes

We present a new algorithm to compute the classical modular polynomial Phi_n in the rings Z[X,Y] and (Z/mZ)[X,Y], for a prime n and any positive integer m. Our approach uses the graph of n-isogenies to efficiently compute Phi_n mod p for many primes p of a suitable form, and then applies the Chinese Remainder Theorem (CRT). Under the Generalized Riemann Hypothesis (GRH), we achieve an expected running time of O(n^3 (log n)^3 log log n), and compute Phi_n mod m using O(n^2 (log n)^2 + n^2 log m) space. We have used the new algorithm to compute Phi_n with n over 5000, and Phi_n mod m with n over 20000. We also consider several modular functions g for which Phi_n^g is smaller than Phi_n, allowing us to handle n over 60000.

preprint2012arXiv

Sato-Tate distributions of twists of y^2=x^5-x and y^2=x^6+1

We determine the limiting distribution of the normalized Euler factors of an abelian surface A defined over a number field k when A is isogenous to the square of an elliptic curve defined over k with complex multiplication. As an application, we prove the Sato-Tate Conjecture for Jacobians of Q-twists of the curves y^2=x^5-x and y^2=x^6+1, which give rise to 18 of the 34 possibilities for the Sato-Tate group of an abelian surface defined over Q. With twists of these two curves one encounters, in fact, all of the 18 possibilities for the Sato-Tate group of an abelian surface that is isogenous to the square of an elliptic curve with complex multiplication. Key to these results is the twisting Sato-Tate group of a curve, which we introduce in order to study the effect of twisting on the Sato-Tate group of its Jacobian.

preprint2012arXiv

Structure computation and discrete logarithms in finite abelian p-groups

We present a generic algorithm for computing discrete logarithms in a finite abelian p-group H, improving the Pohlig-Hellman algorithm and its generalization to noncyclic groups by Teske. We then give a direct method to compute a basis for H without using a relation matrix. The problem of computing a basis for some or all of the Sylow p-subgroups of an arbitrary finite abelian group G is addressed, yielding a Monte Carlo algorithm to compute the structure of G using O(|G|^0.5) group operations. These results also improve generic algorithms for extracting pth roots in G.

preprint2011arXiv

A local-global principle for rational isogenies of prime degree

Let K be a number field. We consider a local-global principle for elliptic curves E/K that admit (or do not admit) a rational isogeny of prime degree n. For suitable K (including K=Q), we prove that this principle holds when n = 1 mod 4, and for n < 7, but find a counterexample when n = 7 for an elliptic curve with j-invariant 2268945/128. For K = Q we show that, up to isomorphism, this is the only counterexample.

preprint2011arXiv

A low-memory algorithm for finding short product representations in finite groups

We describe a space-efficient algorithm for solving a generalization of the subset sum problem in a finite group G, using a Pollard-rho approach. Given an element z and a sequence of elements S, our algorithm attempts to find a subsequence of S whose product in G is equal to z. For a random sequence S of length d log_2 n, where n=#G and d >= 2 is a constant, we find that its expected running time is O(sqrt(n) log n) group operations (we give a rigorous proof for d > 4), and it only needs to store O(1) group elements. We consider applications to class groups of imaginary quadratic fields, and to finding isogenies between elliptic curves over a finite field.

preprint2011arXiv

On the Distribution of Atkin and Elkies Primes

Given an elliptic curve E over a finite field F_q of q elements, we say that an odd prime ell not dividing q is an Elkies prime for E if t_E^2 - 4q is a square modulo ell, where t_E = q+1 - #E(F_q) and #E(F_q) is the number of F_q-rational points on E; otherwise ell is called an Atkin prime. We show that there are asymptotically the same number of Atkin and Elkies primes ell < L on average over all curves E over F_q, provided that L >= (log q)^e for any fixed e > 0 and a sufficiently large q. We use this result to design and analyse a fast algorithm to generate random elliptic curves with #E(F_p) prime, where p varies uniformly over primes in a given interval [x,2x].

preprint2011arXiv

The probability that the number of points on the Jacobian of a genus 2 curve is prime

In 2000, Galbraith and McKee heuristically derived a formula that estimates the probability that a randomly chosen elliptic curve over a fixed finite prime field has a prime number of rational points. We show how their heuristics can be generalized to Jacobians of curves of higher genus. We then elaborate this in genus 2 and study various related issues, such as the probability of cyclicity and the probability of primality of the number of points on the curve itself. Finally, we discuss the asymptotic behavior as the genus tends to infinity.

preprint2010arXiv

Hyperelliptic curves, L-polynomials, and random matrices

We analyze the distribution of unitarized L-polynomials Lp(T) (as p varies) obtained from a hyperelliptic curve of genus g <= 3 defined over Q. In the generic case, we find experimental agreement with a predicted correspondence (based on the Katz-Sarnak random matrix model) between the distributions of Lp(T) and of characteristic polynomials of random matrices in the compact Lie group USp(2g). We then formulate an analogue of the Sato-Tate conjecture for curves of genus 2, in which the generic distribution is augmented by 22 exceptional distributions, each corresponding to a compact subgroup of USp(4). In every case, we exhibit a curve closely matching the proposed distribution, and can find no curves unaccounted for by our classification.

preprint2009arXiv

Computing the endomorphism ring of an ordinary elliptic curve over a finite field

We present two algorithms to compute the endomorphism ring of an ordinary elliptic curve E defined over a finite field F_q. Under suitable heuristic assumptions, both have subexponential complexity. We bound the complexity of the first algorithm in terms of log q, while our bound for the second algorithm depends primarily on log |D_E|, where D_E is the discriminant of the order isomorphic to End(E). As a byproduct, our method yields a short certificate that may be used to verify that the endomorphism ring is as claimed.

preprint2008arXiv

A Generic Approach to Searching for Jacobians

We consider the problem of finding cryptographically suitable Jacobians. By applying a probabilistic generic algorithm to compute the zeta functions of low genus curves drawn from an arbitrary family, we can search for Jacobians containing a large subgroup of prime order. For a suitable distribution of curves, the complexity is subexponential in genus 2, and O(N^{1/12}) in genus 3. We give examples of genus 2 and genus 3 hyperelliptic curves over prime fields with group orders over 180 bits in size, improving previous results. Our approach is particularly effective over low-degree extension fields, where in genus 2 we find Jacobians over F_{p^2) and trace zero varieties over F_{p^3} with near-prime orders up to 372 bits in size. For p = 2^{61}-1, the average time to find a group with 244-bit near-prime order is under an hour on a PC.