















Jake Doliskani, McMaster University
David Jao, University of Waterloo
In this paper, we study the problem of sampling random supersingular elliptic curves with unknown endomorphism rings. This problem has recently gained considerable attention as many isogeny-based cryptographic protocols require such ``secure'' curves for instantation, while existing methods achieve this only in a trusted-setup setting. We present the first provable quantum polynomial-time algorithms for sampling such curves with high probability, one of which is based on an algorithm of Booher et. al. One variant runs heuristically in $\tilde{O}(\log^{5.5} p)$ quantum gate complexity, and in $\tilde{O}(\log^{20} p)$ under the Generalized Riemann Hypothesis, and outputs a curve that is provably secure assuming average-case hardness of the endomorphism ring problem. Another variant samples uniform $\mathcal O$-oriented curves with unknown endomorphism rings, for any imaginary quadratic order $\mathcal O$, with security based on the quantum average-hardness of Vectorization problem. When accompanied by an interactive quantum computation verification protocol, our algorithms provide a secure instantiation of the CGL hash function and related primitives and show quantum advantage over classical algorithms. Our analysis relies on a new spectral delocalization result for supersingular $\ell$-isogeny graphs: we prove the Quantum Unique Ergodicity conjecture and provide numerical evidence for complete eigenvector delocalization. We also prove a stronger $\varepsilon$-separation property for eigenvalues of isogeny graphs than that predicted in the quantum money protocol of Kane, Sharif, and Silverberg, thereby removing a key heuristic assumption in their construction.
Note: A security proof for the QPE-based sampled curves is added. In addition, a new algorithm for sampling uniformly secure oriented curves has been introduced.
BibTeX
@misc{cryptoeprint:2026/171,
author = {Maher Mamah and Jake Doliskani and David Jao},
title = {Spectral Theory of Isogeny Graphs and Quantum Sampling of Secure Supersingular Elliptic Curves},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/171},
year = {2026},
url = {https://eprint.iacr.org/2026/171}
}
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。