{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,16]],"date-time":"2026-08-16T10:13:17Z","timestamp":1786875197215,"version":"3.56.0"},"reference-count":66,"publisher":"Springer Science and Business Media LLC","issue":"11","license":[{"start":{"date-parts":[[2024,6,26]],"date-time":"2024-06-26T00:00:00Z","timestamp":1719360000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,6,26]],"date-time":"2024-06-26T00:00:00Z","timestamp":1719360000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100000266","name":"Engineering and Physical Sciences Research Council","doi-asserted-by":"publisher","award":["EP\/V011324\/1."],"award-info":[{"award-number":["EP\/V011324\/1."]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001665","name":"Agence Nationale de la Recherche","doi-asserted-by":"publisher","award":["ANR-20-CE40-0013"],"award-info":[{"award-number":["ANR-20-CE40-0013"]}],"id":[{"id":"10.13039\/501100001665","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001665","name":"Agence Nationale de la Recherche","doi-asserted-by":"publisher","award":["ANR-22-PETQ-0008 PQ-TLS"],"award-info":[{"award-number":["ANR-22-PETQ-0008 PQ-TLS"]}],"id":[{"id":"10.13039\/501100001665","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Hungarian Ministry of Innovation and Technology NRDI Office"},{"name":"J\u00e1nos Bolyai Research Scholarship of the Hungarian Academy of Sciences","award":["ANR-22-PETQ-0008 PQ-TLS"],"award-info":[{"award-number":["ANR-22-PETQ-0008 PQ-TLS"]}]},{"name":"J\u00e1nos Bolyai Research Scholarship of the Hungarian Academy of Sciences","award":["NR-19-CE48\u20130008"],"award-info":[{"award-number":["NR-19-CE48\u20130008"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Des. Codes Cryptogr."],"published-print":{"date-parts":[[2024,11]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>An oriented supersingular elliptic curve is a curve which is enhanced with the information of an endomorphism. Computing the full endomorphism ring of a supersingular elliptic curve is a known hard problem, so one might consider how hard it is to find one such orientation. We prove that access to an oracle which tells if an elliptic curve is <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\mathfrak {O}$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>O<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>-orientable for a fixed imaginary quadratic order <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\mathfrak {O}$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>O<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula> provides non-trivial information towards computing an endomorphism corresponding to the <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\mathfrak {O}$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>O<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>-orientation. We provide explicit algorithms and in-depth complexity analysis. We also consider the question in terms of quaternion algebras. We provide algorithms which compute an embedding of a fixed imaginary quadratic order into a maximal order of the quaternion algebra ramified at <jats:italic>p<\/jats:italic> and <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\infty $$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>\u221e<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>. We provide code implementations in Sagemath (in Stein et\u00a0al. Sage Mathematics Software (Version 10.0), The Sage Development Team, <jats:ext-link xmlns:xlink=\"http:\/\/www.w3.org\/1999\/xlink\" ext-link-type=\"uri\" xlink:href=\"http:\/\/www.sagemath.org\">http:\/\/www.sagemath.org<\/jats:ext-link>, 2023) which is efficient for finding embeddings of imaginary quadratic orders of discriminants up to <jats:italic>O<\/jats:italic>(<jats:italic>p<\/jats:italic>), even for cryptographically sized <jats:italic>p<\/jats:italic>.<\/jats:p>","DOI":"10.1007\/s10623-024-01435-5","type":"journal-article","created":{"date-parts":[[2024,6,26]],"date-time":"2024-06-26T14:04:45Z","timestamp":1719410685000},"page":"3447-3493","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Finding orientations of supersingular elliptic curves and quaternion orders"],"prefix":"10.1007","volume":"92","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2202-1673","authenticated-orcid":false,"given":"Sarah","family":"Arpin","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"James","family":"Clements","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pierrick","family":"Dartois","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jonathan Komada","family":"Eriksen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"P\u00e9ter","family":"Kutas","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Benjamin","family":"Wesolowski","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,6,26]]},"reference":[{"key":"1435_CR1","doi-asserted-by":"publisher","DOI":"10.1007\/s44007-023-00053-2","author":"S Arpin","year":"2023","unstructured":"Arpin S., Chen M., Lauter K.E., Scheidler R., Stange K.E., Tran H.T.: Orienteering with one endomorphism. La Mat. (2023). https:\/\/doi.org\/10.1007\/s44007-023-00053-2.","journal-title":"La Mat."},{"key":"1435_CR2","unstructured":"Arpin S., Chen M., Lauter K.E., Scheidler R., Stange K.E., Tran H.T.N.: Orientations and cycles in supersingular isogeny graphs. To appear in the Proceedings of Women in Number Theory 5 (2022)."},{"key":"1435_CR3","volume-title":"Festa: Fast Encryption from Supersingular Torsion Attacks","author":"A Basso","year":"2023","unstructured":"Basso A., Maino L., Pope G.: Festa: Fast Encryption from Supersingular Torsion Attacks. Springer, Berlin (2023)."},{"key":"1435_CR4","first-page":"1618","volume":"2023","author":"B Ben\u010dina","year":"2023","unstructured":"Ben\u010dina B., Kutas P., Merz S.-P., Petit C., Stopar M., Weitk\u00e4mper C.: Improved algorithms for finding fixed-degree isogenies between supersingular elliptic curves. Cryptol. ePrint Arch. 2023, 1618 (2023).","journal-title":"Cryptol. ePrint Arch."},{"key":"1435_CR5","volume-title":"\u00dcber die Darstellung von positiven: ganzen Zahlen durch die primitiven, bin\u00e4ren quadratischen Formen einer nicht-quadratischen Diskriminante","author":"P Bernays","year":"1912","unstructured":"Bernays P.: \u00dcber die Darstellung von positiven: ganzen Zahlen durch die primitiven, bin\u00e4ren quadratischen Formen einer nicht-quadratischen Diskriminante. Dieterich, Mainz (1912)."},{"key":"1435_CR6","doi-asserted-by":"crossref","unstructured":"Bernstein D.J., De\u00a0Feo L., Leroux A., Smith B.: Faster computation of isogenies of large prime degree. In: Proceedings of the Fourteenth Algorithmic Number Theory Symposium, pp. 39\u201355, University of California, Berkeley, MSP (2020).","DOI":"10.2140\/obs.2020.4.39"},{"key":"1435_CR7","doi-asserted-by":"publisher","first-page":"1755","DOI":"10.1090\/S0025-5718-08-02066-8","volume":"77","author":"A Bostan","year":"2008","unstructured":"Bostan A., Morain F., Salvy B., Schost E.: Fast algorithms for computing isogenies between elliptic curves. Math. Comput. 77, 1755\u20131778 (2008).","journal-title":"Math. Comput."},{"issue":"2","key":"1435_CR8","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1007\/s12188-011-0059-y","volume":"81","author":"D Brink","year":"2011","unstructured":"Brink D., Moree P., Osburn R.: Principal forms $$X^2+nY^2$$ representing many integers. Abh. Math. Semin. Univ. Hambg. 81(2), 129\u2013139 (2011).","journal-title":"Abh. Math. Semin. Univ. Hambg."},{"key":"1435_CR9","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1007\/BFb0091539","volume-title":"The Development of the Number Field Sieve","author":"JP Buhler","year":"1993","unstructured":"Buhler J.P., Lenstra H.W., Pomerance C.: Factoring integers with the number field sieve. In: Lenstra A.K., Lenstra H.W. (eds.) The Development of the Number Field Sieve, pp. 50\u201394. Springer, Berlin (1993)."},{"key":"1435_CR10","doi-asserted-by":"crossref","unstructured":"Castryck W., Decru T.: An efficient key recovery attack on SIDH. In: Hazay, C., Stam, M. (eds.) Advances in Cryptology - EUROCRYPT 2023 - 42nd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Lyon, France, April 23\u201327, 2023, Proceedings, Part V, volume 14008 of Lecture Notes in Computer Science, pp. 423\u2013447. Springer (2023).","DOI":"10.1007\/978-3-031-30589-4_15"},{"key":"1435_CR11","doi-asserted-by":"crossref","unstructured":"Castryck W., Lange, T., Martindale, C., Panny, L., Renes, J.: CSIDH: an efficient post-quantum commutative group action. In: Peyrin, T., Galbraith, S.D. (eds.) Advances in Cryptology - ASIACRYPT 2018 - 24th International Conference on the Theory and Application of Cryptology and Information Security, Brisbane, QLD, Australia, December 2-6, 2018, Proceedings, Part III, volume 11274 of Lecture Notes in Computer Science, pp. 395\u2013427. Springer (2018).","DOI":"10.1007\/978-3-030-03332-3_15"},{"issue":"1","key":"1435_CR12","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1007\/s00145-007-9002-x","volume":"22","author":"DX Charles","year":"2009","unstructured":"Charles D.X., Goren E.Z., Lauter K.E.: Cryptographic hash functions from expander graphs. J. Cryptol. 22(1), 93\u2013113 (2009).","journal-title":"J. Cryptol."},{"issue":"1","key":"1435_CR13","doi-asserted-by":"publisher","first-page":"414","DOI":"10.1515\/jmc-2019-0034","volume":"14","author":"L Col\u00f2","year":"2020","unstructured":"Col\u00f2 L., Kohel D.: Orienting supersingular isogeny graphs. J. Math. Cryptol. 14(1), 414\u2013437 (2020).","journal-title":"J. Math. Cryptol."},{"key":"1435_CR14","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-89486-7","volume-title":"Number Theory: An Introduction to Mathematics","author":"WA Coppel","year":"2009","unstructured":"Coppel W.A.: Number Theory: An Introduction to Mathematics. Springer, New York (2009)."},{"key":"1435_CR15","unstructured":"Couveignes, J.M.: Hard homogeneous spaces. IACR Cryptol. ePrint Arch., page 291, (2006)."},{"key":"1435_CR16","doi-asserted-by":"crossref","unstructured":"Dartois P., Leroux A., Robert D., Wesolowski B.: SQISignHD: new dimensions in cryptography. IACR Cryptol. ePrint Arch., pp. 436 (2023).","DOI":"10.1007\/978-3-031-58716-0_1"},{"key":"1435_CR17","doi-asserted-by":"crossref","unstructured":"de\u00a0Bruijn N.G.: On the number of positive integers $$\\le x$$ and free of prime factors $$>y$$, II. Proc. Koninkl. Nederl. Akad. van Wetenschappen Ser. A 3, 239\u2013247 (1966).","DOI":"10.1016\/S1385-7258(66)50029-4"},{"key":"1435_CR18","doi-asserted-by":"crossref","unstructured":"De Feo L., de\u00a0Saint\u00a0Guilhem C.D., Fouotsa T.B., Kutas P., Leroux A., Petit C., Silva J., Wesolowski B.: S\u00e9ta: supersingular encryption from torsion attacks. In: Tibouchi M., Wang H. (eds.) Advances in Cryptology - ASIACRYPT 2021 - 27th International Conference on the Theory and Application of Cryptology and Information Security, Singapore, December 6\u201310, 2021, Proceedings, Part IV, volume 13093 of Lecture Notes in Computer Science, pp. 249\u2013278. Springer (2021).","DOI":"10.1007\/978-3-030-92068-5_9"},{"issue":"2","key":"1435_CR19","doi-asserted-by":"publisher","first-page":"425","DOI":"10.1007\/s10623-014-0010-1","volume":"78","author":"C Delfs","year":"2016","unstructured":"Delfs C., Galbraith S.D.: Computing isogenies between supersingular elliptic curves over $$\\mathbb{F} _p$$. Des. Codes Cryptogr. 78(2), 425\u2013440 (2016).","journal-title":"Des. Codes Cryptogr."},{"key":"1435_CR20","doi-asserted-by":"publisher","first-page":"197","DOI":"10.1007\/BF02940746","volume":"14","author":"M Deuring","year":"1941","unstructured":"Deuring M.: Die Typen der Multiplikatorenringe elliptischer Funktionenk\u00f6rper. Abh. Math. Sem. Hansischen Univ. 14, 197\u2013272 (1941).","journal-title":"Abh. Math. Sem. Hansischen Univ."},{"key":"1435_CR21","doi-asserted-by":"crossref","unstructured":"Eisentr\u00e4ger K., Hallgren S., Lauter K.E., Morrison T., Petit C.: Supersingular isogeny graphs and endomorphism rings: reductions and solutions. In: Nielsen J.B., Rijmen V. (eds.) Advances in Cryptology - EUROCRYPT 2018 - 37th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Tel Aviv, Israel, April 29\u2013May 3, 2018 Proceedings, Part III, volume 10822 of Lecture Notes in Computer Science, pp. 329\u2013368. Springer (2018).","DOI":"10.1007\/978-3-319-78372-7_11"},{"key":"1435_CR22","doi-asserted-by":"publisher","first-page":"215","DOI":"10.2140\/obs.2020.4.215","volume":"4","author":"K Eisentr\u00e4ger","year":"2020","unstructured":"Eisentr\u00e4ger K., Hallgren S., Leonardi C., Morrison T., Park J.: Computing endomorphism rings of supersingular elliptic curves and connections to path-finding in isogeny graphs. Open Book Ser. 4, 215\u2013232 (2020).","journal-title":"Open Book Ser."},{"key":"1435_CR23","doi-asserted-by":"crossref","unstructured":"Elkies N.D.: Elliptic and modular curves over finite fields and related computational issues. In: Computational perspectives on number theory (Chicago, IL, 1995), volume\u00a07 of AMS\/IP Studies Advanced Mathematics, pp. 21\u201376. American Mathematics Society, Providence, RI (1998).","DOI":"10.1090\/amsip\/007\/03"},{"key":"1435_CR24","doi-asserted-by":"publisher","first-page":"738","DOI":"10.2307\/2371483","volume":"62","author":"P Erd\u00f6s","year":"1940","unstructured":"Erd\u00f6s P., Kac M.: The Gaussian law of errors in the theory of additive number theoretic functions. Am. J. Math. 62, 738\u2013742 (1940).","journal-title":"Am. J. Math."},{"key":"1435_CR25","doi-asserted-by":"crossref","unstructured":"Eriksen J.K., Panny L., Sot\u00e1kov\u00e1 J., Veroni M.: Deuring for the people: supersingular elliptic curves with prescribed endomorphism ring in general characteristic. IACR Cryptol. ePrint Arch., 106 (2023).","DOI":"10.1090\/conm\/796\/16008"},{"key":"1435_CR26","doi-asserted-by":"crossref","unstructured":"Feo L.D., Fouotsa T.B., Kutas P., Leroux A., Merz S., Panny L., Wesolowski B.: SCALLOP: scaling the csi-fish. In: Boldyreva A., Kolesnikov V. (eds.) Public-Key Cryptography - PKC 2023 - 26th IACR International Conference on Practice and Theory of Public-Key Cryptography, Atlanta, GA, USA, May 7\u201310, 2023, Proceedings, Part I, volume 13940 of Lecture Notes in Computer Science, pp. 345\u2013375. Springer (2023).","DOI":"10.1007\/978-3-031-31368-4_13"},{"key":"1435_CR27","doi-asserted-by":"crossref","unstructured":"Feo L.D., Kohel D., Leroux A., Petit C., Wesolowski B.: SQISign: compact post-quantum signatures from quaternions and isogenies. In: Moriai S., Wang H. (eds.) Advances in Cryptology - ASIACRYPT 2020 - 26th International Conference on the Theory and Application of Cryptology and Information Security, Daejeon, South Korea, December 7\u201311, 2020, Proceedings, Part I, volume 12491 of Lecture Notes in Computer Science, pp. 64\u201393. Springer, 2020.","DOI":"10.1007\/978-3-030-64837-4_3"},{"key":"1435_CR28","unstructured":"Fuselier J., Iezzi A., Kozek M., Morrison T., Namoijam C.: Computing supersingular endomorphism rings using inseparable endomorphisms (2023)."},{"key":"1435_CR29","first-page":"267","volume":"44","author":"A Granville","year":"2008","unstructured":"Granville A.: Smooth numbers: computational number theory and beyond. Math. Sci. Res. Inst. Publ. 44, 267\u2013323 (2008).","journal-title":"Math. Sci. Res. Inst. Publ."},{"issue":"6","key":"1435_CR30","doi-asserted-by":"publisher","first-page":"1068","DOI":"10.1137\/0220067","volume":"20","author":"JL Hafner","year":"1991","unstructured":"Hafner J.L., McCurley K.S.: Asymptotically fast triangularization of matrices over rings. SIAM J. Comput. 20(6), 1068\u20131083 (1991).","journal-title":"SIAM J. Comput."},{"key":"1435_CR31","doi-asserted-by":"crossref","unstructured":"Jao D., Feo L.D.: Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies. In: Yang B. (ed.) Post-Quantum Cryptography - 4th International Workshop, PQCrypto 2011, Taipei, Taiwan, November 29\u2013December 2, 2011. Proceedings, volume 7071 of Lecture Notes in Computer Science, pp. 19\u201334. Springer (2011).","DOI":"10.1007\/978-3-642-25405-5_2"},{"issue":"4","key":"1435_CR32","first-page":"849","volume":"26","author":"M Kaneko","year":"1989","unstructured":"Kaneko M.: Supersingular $$j$$-invariants as singular moduli $${mod}\\, p$$. Osaka J. Math. 26(4), 849\u2013855 (1989).","journal-title":"Osaka J. Math."},{"issue":"485","key":"1435_CR33","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1515\/crll.1997.485.93","volume":"1997","author":"E Kani","year":"1997","unstructured":"Kani E.: The number of curves of genus two with elliptic differentials. J. Reine Angew. Math. 1997(485), 93\u2013122 (1997).","journal-title":"J. Reine Angew. Math."},{"issue":"A","key":"1435_CR34","doi-asserted-by":"publisher","first-page":"418","DOI":"10.1112\/S1461157014000151","volume":"17","author":"D Kohel","year":"2014","unstructured":"Kohel D., Lauter K., Petit C., Tignol J.-P.: On the quaternion-isogeny path problem. LMS J. Comput. Math. 17(A), 418\u2013432 (2014).","journal-title":"LMS J. Comput. Math."},{"key":"1435_CR35","first-page":"305","volume":"13","author":"E Landau","year":"1908","unstructured":"Landau E.: \u00dcber die einteilung der positiven ganzen zahlen in vier klassen nach der mindestzahl der zu ihrer additiven zusammensetzung erforderlichen quadrate. Arch. Math. Phys. 13, 305\u2013312 (1908).","journal-title":"Arch. Math. Phys."},{"key":"1435_CR36","doi-asserted-by":"crossref","unstructured":"Lang S.: Elliptic functions, volume 112 of Graduate Texts in Mathematics, second edition. Springer, New York. With an appendix by J. Tate (1987).","DOI":"10.1007\/978-1-4612-4752-4"},{"key":"1435_CR37","unstructured":"Lehmer D.H.: Computer technology applied to the theory of numbers. In: Studies in Number Theory, pp.117\u2013151 (1969)."},{"issue":"3","key":"1435_CR38","doi-asserted-by":"publisher","first-page":"649","DOI":"10.2307\/1971363","volume":"126","author":"HW Lenstra","year":"1987","unstructured":"Lenstra H.W.: Factoring integers with elliptic curves. Ann. Math. 126(3), 649\u2013673 (1987).","journal-title":"Ann. Math."},{"key":"1435_CR39","unstructured":"Leroux A.: Computation of hilbert class polynomials and modular polynomials from supersingular elliptic curves. Cryptology ePrint Archive, Paper 2023\/064 (2023). https:\/\/eprint.iacr.org\/2023\/064."},{"key":"1435_CR40","doi-asserted-by":"crossref","unstructured":"Lubicz D., Robert D.: Fast change of level and applications to isogenies. In: Research in Number Theory (ANTS XV Conference), 9(1) (2023).","DOI":"10.1007\/s40993-022-00407-9"},{"key":"1435_CR41","doi-asserted-by":"crossref","unstructured":"Maino L., Martindale C., Panny L., Pope G., Wesolowski B.: A direct key recovery attack on SIDH. In: Hazay C., Stam M. (eds.) Advances in Cryptology - EUROCRYPT 2023 - 42nd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Lyon, France, April 23\u201327, 2023, Proceedings, Part V, volume 14008 of Lecture Notes in Computer Science, pp. 448\u2013471. Springer (2023).","DOI":"10.1007\/978-3-031-30589-4_16"},{"key":"1435_CR42","doi-asserted-by":"publisher","first-page":"108","DOI":"10.1006\/jnth.2001.2722","volume":"93","author":"G Martin","year":"2002","unstructured":"Martin G.: An asymptotic formula for the number of smooth values of a polynomial. J. Number Theory 93, 108\u2013182 (2002).","journal-title":"J. Number Theory"},{"issue":"3\u20134","key":"1435_CR43","first-page":"361","volume":"52","author":"P Moree","year":"2006","unstructured":"Moree P., Osburn R.: Two-dimensional lattices with few distances. Enseign. Math. 52(3\u20134), 361\u2013380 (2006).","journal-title":"Enseign. Math."},{"key":"1435_CR44","unstructured":"Moriya T.: Is-cube: an isogeny-based compact kem using a boxed sidh diagram. In: Cryptology ePrint Archive (2023)."},{"key":"1435_CR45","doi-asserted-by":"crossref","unstructured":"Nakagawa K., Onuki H.: Qfesta: Efficient algorithms and parameters for festa using quaternion algebras. In: Cryptology ePrint Archive (2023).","DOI":"10.1007\/978-3-031-68388-6_4"},{"key":"1435_CR46","doi-asserted-by":"publisher","DOI":"10.1016\/j.ffa.2020.101777","volume":"69","author":"H Onuki","year":"2021","unstructured":"Onuki H.: On oriented supersingular elliptic curves. Finite Fields Appl. 69, 101777 (2021).","journal-title":"Finite Fields Appl."},{"key":"1435_CR47","unstructured":"Page A., Wesolowski B.: The supersingular endomorphism ring and one endomorphism problems are equivalent. In: Cryptology ePrint Archive, Paper 2023\/1399. https:\/\/eprint.iacr.org\/2023\/1399 (2023)."},{"issue":"2","key":"1435_CR48","doi-asserted-by":"publisher","first-page":"340","DOI":"10.1016\/0021-8693(80)90151-9","volume":"64","author":"A Pizer","year":"1980","unstructured":"Pizer A.: An algorithm for computing modular forms on $$\\gamma _0(n)$$. J. Algebra 64(2), 340\u2013390 (1980).","journal-title":"J. Algebra"},{"key":"1435_CR49","first-page":"A15","volume":"18A","author":"P Pollack","year":"2018","unstructured":"Pollack P., Trevi\u00f1o E.: Finding the four squares in Lagrange\u2019s Theorem. Integers 18A, A15 (2018).","journal-title":"Integers"},{"key":"1435_CR50","doi-asserted-by":"publisher","first-page":"119","DOI":"10.1016\/B978-0-12-386870-1.50014-9","volume-title":"Discrete Algorithms and Complexity","author":"C Pomerance","year":"1987","unstructured":"Pomerance C.: Fast, rigorous factorization and discrete logarithm algorithms. In: Johnson D.S., Nishizeki T., Nozaki A., Wilf H.S. (eds.) Discrete Algorithms and Complexity, pp. 119\u2013143. Academic Press, New York (1987)."},{"key":"1435_CR51","unstructured":"Robert D.: Efficient algorithms for abelian varieties and their moduli spaces (2021). http:\/\/www.normalesup.org\/~robert\/pro\/publications\/academic\/hdr.pdf."},{"key":"1435_CR52","unstructured":"Robert D.: Breaking SIDH in polynomial time. In: Cryptology ePrint Archive, Paper 2022\/1038 (2022)."},{"key":"1435_CR53","unstructured":"Robert D.: Evaluating isogenies in polylogarithmic time. In: IACR Cryptology ePrint Archive, p. 1068 (2022)."},{"key":"1435_CR54","unstructured":"Robert D.: Some applications of higher dimensional isogenies to elliptic curves (overview of results). In: Cryptology ePrint Archive, Paper 2022\/1704. https:\/\/eprint.iacr.org\/2022\/1704 (2022)."},{"key":"1435_CR55","doi-asserted-by":"crossref","unstructured":"Robert D.: Breaking SIDH in polynomial time. In: Hazay C., Stam M. (eds.) Advances in Cryptology - EUROCRYPT 2023 - 42nd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Lyon, France, April 23\u201327, 2023, Proceedings, Part V, volume 14008 of Lecture Notes in Computer Science, pp. 472\u2013503. Springer (2023).","DOI":"10.1007\/978-3-031-30589-4_17"},{"key":"1435_CR56","unstructured":"Rostovtsev A., Stolbunov A.: Public-key cryptosystem based on isogenies. In: Cryptology ePrint Archive, Paper 2006\/145 (2006). https:\/\/eprint.iacr.org\/2006\/145."},{"key":"1435_CR57","doi-asserted-by":"crossref","unstructured":"Sawilla R.E., Silvester A.K., Williams H.C.: A new look at an old equation. In: Algorithmic Number Theory: 8th International Symposium, ANTS-VIII Banff, Canada, May 17\u201322, 2008 Proceedings 8, pp. 37\u201359. Springer (2008).","DOI":"10.1007\/978-3-540-79456-1_2"},{"key":"1435_CR58","doi-asserted-by":"publisher","first-page":"219","DOI":"10.5802\/jtnb.142","volume":"7","author":"R Schoof","year":"1995","unstructured":"Schoof R.: Counting points on elliptic curves over finite fields. J. Th\u00e9o. Nombr. Bordeaux 7, 219\u2013254 (1995).","journal-title":"J. Th\u00e9o. Nombr. Bordeaux"},{"issue":"1","key":"1435_CR59","doi-asserted-by":"publisher","first-page":"83","DOI":"10.4064\/aa-1-1-83-86","volume":"1","author":"CL Seigel","year":"1935","unstructured":"Seigel C.L.: \u00dcber die classenzahl quadratischer zahlk\u00f6rper. Acta Arithm. 1(1), 83\u201386 (1935).","journal-title":"Acta Arithm."},{"key":"1435_CR60","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-09494-6","volume-title":"The Arithmetic of Elliptic Curves. Graduate Texts in Mathematics","author":"JH Silverman","year":"2009","unstructured":"Silverman J.H.: The Arithmetic of Elliptic Curves. Graduate Texts in Mathematics, vol. 1, 2nd edn Springer, Dordrecht (2009).","edition":"2"},{"key":"1435_CR61","unstructured":"Stein W., et\u00a0al.: Sage Mathematics Software (Version 10.0). The Sage Development Team (2023). http:\/\/www.sagemath.org."},{"key":"1435_CR62","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-56694-4","volume-title":"Quaternion Algebras. Graduate Texts in Mathematics","author":"J Voight","year":"2021","unstructured":"Voight J.: Quaternion Algebras. Graduate Texts in Mathematics, vol. 288. Springer, Cham (2021)."},{"key":"1435_CR63","doi-asserted-by":"crossref","unstructured":"von\u00a0zur Gathen J., Gerhard J.: Modern Computer Algebra, third edition. Cambridge University Press, Cambridge (2013).","DOI":"10.1017\/CBO9781139856065"},{"key":"1435_CR64","first-page":"238","volume":"273","author":"J V\u00e9lu","year":"1971","unstructured":"V\u00e9lu J.: Isog\u00e9nies entre courbes elliptiques. Compt. Rend. Acad. Sci. 273, 238\u2013241 (1971).","journal-title":"Compt. Rend. Acad. Sci."},{"key":"1435_CR65","doi-asserted-by":"crossref","unstructured":"Wesolowski B.: The supersingular isogeny path and endomorphism ring problems are equivalent. In: 62nd IEEE Annual Symposium on Foundations of Computer Science, FOCS 2021, Denver, CO, USA, February 7\u201310, 2022, pp. 1100\u20131111. IEEE (2021).","DOI":"10.1109\/FOCS52979.2021.00109"},{"key":"1435_CR66","doi-asserted-by":"crossref","unstructured":"Wesolowski B.: Orientations and the supersingular endomorphism ring problem. In: Dunkelman O., Dziembowski S. (eds.) Advances in Cryptology - EUROCRYPT 2022 - 41st Annual International Conference on the Theory and Applications of Cryptographic Techniques, Trondheim, Norway, May 30\u2013June 3, 2022, Proceedings, Part III, volume 13277 of Lecture Notes in Computer Science, pp. 345\u2013371. Springer (2022).","DOI":"10.1007\/978-3-031-07082-2_13"}],"container-title":["Designs, Codes and Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10623-024-01435-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10623-024-01435-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10623-024-01435-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,29]],"date-time":"2024-09-29T18:03:04Z","timestamp":1727632984000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10623-024-01435-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6,26]]},"references-count":66,"journal-issue":{"issue":"11","published-print":{"date-parts":[[2024,11]]}},"alternative-id":["1435"],"URL":"https:\/\/doi.org\/10.1007\/s10623-024-01435-5","relation":{},"ISSN":["0925-1022","1573-7586"],"issn-type":[{"value":"0925-1022","type":"print"},{"value":"1573-7586","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,6,26]]},"assertion":[{"value":"15 September 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 May 2024","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 May 2024","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 June 2024","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no financial or proprietary interests in any material discussed in this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}