{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T04:22:48Z","timestamp":1778127768043,"version":"3.51.4"},"reference-count":69,"publisher":"Oxford University Press (OUP)","issue":"8","license":[{"start":{"date-parts":[[2024,5,25]],"date-time":"2024-05-25T00:00:00Z","timestamp":1716595200000},"content-version":"vor","delay-in-days":1,"URL":"https:\/\/academic.oup.com\/pages\/standard-publication-reuse-rights"}],"funder":[{"name":"Marsden Fund Council"},{"DOI":"10.13039\/501100001509","name":"Royal Society of New Zealand","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001509","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100000038","name":"Natural Sciences and Engineering Research Council of Canada","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100000038","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100004807","name":"DFG","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100004807","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001659","name":"German Research Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Germany\u2019s Excellence Strategy","award":["EXC 2092 CASA - 390781972"],"award-info":[{"award-number":["EXC 2092 CASA - 390781972"]}]},{"DOI":"10.13039\/501100000266","name":"Engineering & Physical Sciences Research Council","doi-asserted-by":"crossref","award":["EP\/P009301\/1"],"award-info":[{"award-number":["EP\/P009301\/1"]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100000266","name":"Engineering & Physical Sciences Research Council","doi-asserted-by":"crossref","award":["EP\/S01361X\/1"],"award-info":[{"award-number":["EP\/S01361X\/1"]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100000266","name":"Engineering & Physical Sciences Research Council","doi-asserted-by":"crossref","award":["EP\/V011324\/1"],"award-info":[{"award-number":["EP\/V011324\/1"]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100000266","name":"Engineering & Physical Sciences Research Council","doi-asserted-by":"crossref","award":["EP\/T517872\/1"],"award-info":[{"award-number":["EP\/T517872\/1"]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"crossref"}]},{"name":"CIAO","award":["ANR-19-CE48-0008"],"award-info":[{"award-number":["ANR-19-CE48-0008"]}]},{"name":"Plan France 2030","award":["ANR-22-PETQ-0008 PQ-TLS"],"award-info":[{"award-number":["ANR-22-PETQ-0008 PQ-TLS"]}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"NSF-CAREER","award":["CNS-1652238"],"award-info":[{"award-number":["CNS-1652238"]}]},{"name":"NSF-CAREER","award":["DMS-1802323"],"award-info":[{"award-number":["DMS-1802323"]}]},{"DOI":"10.13039\/100000893","name":"Simons Foundation","doi-asserted-by":"publisher","award":["822143"],"award-info":[{"award-number":["822143"]}],"id":[{"id":"10.13039\/100000893","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003524","name":"Ministry of Business, Innovation and Employment","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003524","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Marsden Fund Council"},{"DOI":"10.13039\/501100001509","name":"Royal Society of New Zealand","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001509","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024,8,11]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>An important open problem in supersingular isogeny-based cryptography is to produce, without a trusted authority, concrete examples of \u2018hard supersingular curves\u2019 that is equations for supersingular curves for which computing the endomorphism ring is as difficult as it is for random supersingular curves. A related open problem is to produce a hash function to the vertices of the supersingular $\\ell $-isogeny graph, which does not reveal the endomorphism ring, or a path to a curve of known endomorphism ring. Such a hash function would open up interesting cryptographic applications. In this paper, we document a number of (thus far) failed attempts to solve this problem, in the hope that we may spur further research, and shed light on the challenges and obstacles to this endeavour. The mathematical approaches contained in this article include: (i) iterative root-finding for the supersingular polynomial; (ii) gcd\u2019s of specialized modular polynomials; (iii) using division polynomials to create small systems of equations; (iv) taking random walks in the isogeny graph of abelian surfaces, and applying Kummer surfaces and (v) using quantum random walks.<\/jats:p>","DOI":"10.1093\/comjnl\/bxae038","type":"journal-article","created":{"date-parts":[[2024,5,25]],"date-time":"2024-05-25T08:57:12Z","timestamp":1716627432000},"page":"2702-2719","source":"Crossref","is-referenced-by-count":11,"title":["Failing to Hash Into Supersingular Isogeny Graphs"],"prefix":"10.1093","volume":"67","author":[{"given":"Jeremy","family":"Booher","sequence":"first","affiliation":[{"name":"Department of Mathematics, University of Florida , Gainsville, FL 32611 ,","place":["USA"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ross","family":"Bowden","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Bristol , Bristol, BS8 1UB ,","place":["UK"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Javad","family":"Doliskani","sequence":"additional","affiliation":[{"name":"Department of Computing and Software, McMaster University , Hamilton, L8S 4L7 ,","place":["Canada"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tako","family":"Boris Fouotsa","sequence":"additional","affiliation":[{"name":"LASEC , EPFL, 1015 Lausanne ,","place":["Switzerland"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Steven D","family":"Galbraith","sequence":"additional","affiliation":[{"name":"Department of Mathematics, The University of Auckland , Auckland, 1010 ,","place":["New Zealand"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sabrina","family":"Kunzweiler","sequence":"additional","affiliation":[{"name":"Ruhr-Universit\u00e4t Bochum , 44801 Bochum ,","place":["Germany"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Simon-Philipp","family":"Merz","sequence":"additional","affiliation":[{"name":"Department of Computer Science , ETH Zurich, 8092 Z\u00fcrich ,","place":["Switzerland"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christophe","family":"Petit","sequence":"additional","affiliation":[{"name":"Laboratoire d\u2019Informatique, Universit\u00e9 libre de Bruxelles , 1050 Bruxelles ,","place":["Belgium"]},{"name":"University of Birmingham , Birmingham, B15 2TT ,","place":["UK"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Benjamin","family":"Smith","sequence":"additional","affiliation":[{"name":"Inria and Laboratoire d\u2019Informatique (LIX) , CNRS, \u00c9cole polytechnique, Institut Polytechnique de Paris, 91120 Palaiseau,","place":["France"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Katherine E","family":"Stange","sequence":"additional","affiliation":[{"name":"Department of Mathematics, University of Colorado Boulder , Boulder, CO 80309 ,","place":["USA"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yan Bo","family":"Ti","sequence":"additional","affiliation":[{"name":"DSO National Laboratories , 118225 ,","place":["Singapore"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christelle","family":"Vincent","sequence":"additional","affiliation":[{"name":"Department of Mathematics and Statistics, University of Vermont , Burlington, VT 05405 ,","place":["USA"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jos\u00e9 Felipe","family":"Voloch","sequence":"additional","affiliation":[{"name":"School of Mathematics and Statistics, University of Canterbury , Christchurch, 8140 ,","place":["New Zealand"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Charlotte","family":"Weitk\u00e4mper","sequence":"additional","affiliation":[{"name":"University of Birmingham , Birmingham, B15 2TT ,","place":["UK"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lukas","family":"Zobernig","sequence":"additional","affiliation":[{"name":"Department of Mathematics, The University of Auckland , Auckland, 1010 ,","place":["New Zealand"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2024,5,24]]},"reference":[{"key":"2025052320023435800_ref1","first-page":"269","article-title":"Constructing supersingular elliptic curves","volume":"1","author":"Br\u00f6ker","year":"2009","journal-title":"J. Comb. Number Theory"},{"key":"2025052320023435800_ref2","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1007\/s00145-007-9002-x","article-title":"Cryptographic hash functions from expander graphs","volume":"22","author":"Charles","year":"2009","journal-title":"J. Cryptology"},{"key":"2025052320023435800_ref3","volume-title":"Hard homogeneous spaces","author":"Couveignes","year":"2006"},{"key":"2025052320023435800_ref4","volume-title":"Public-key cryptosystem based on isogenies","author":"Rostovtsev","year":"2006"},{"key":"2025052320023435800_ref5","doi-asserted-by":"crossref","first-page":"395","DOI":"10.1007\/978-3-030-03332-3_15","article-title":"CSIDH: An efficient post-quantum commutative group action","volume-title":"ASIACRYPT 2018","author":"Castryck","year":"2018"},{"key":"2025052320023435800_ref6","doi-asserted-by":"crossref","first-page":"163","DOI":"10.1007\/978-3-319-70972-7_9","article-title":"A post-quantum digital signature scheme based on supersingular isogenies","volume-title":"Int. Conf. on Financial Cryptography and Data Security","author":"Yoo","year":"2017"},{"key":"2025052320023435800_ref7","doi-asserted-by":"crossref","first-page":"130","DOI":"10.1007\/s00145-019-09316-0","article-title":"Identification protocols and signature schemes based on supersingular isogeny problems","volume":"33","author":"Galbraith","year":"2020","journal-title":"J. Cryptol."},{"key":"2025052320023435800_ref8","first-page":"759","article-title":"SeaSign: Compact isogeny signatures from class group actions. EUROCRYPT (3)","volume-title":"Lecture Notes in Computer Science","author":"Feo","year":"2019"},{"key":"2025052320023435800_ref9","first-page":"271","article-title":"Faster SeaSign signatures through improved rejection sampling. PQCrypto 2019","volume-title":"Lecture Notes in Computer Science","author":"Decru","year":"2019"},{"key":"2025052320023435800_ref10","first-page":"227","article-title":"CSI-FiSh: Efficient isogeny based signatures through class group computations. ASIACRYPT (1)","volume-title":"Lecture Notes in Computer Science","author":"Beullens","year":"2019"},{"key":"2025052320023435800_ref11","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1007\/978-3-030-64837-4_3","article-title":"SQISign: Compact post-quantum signatures from quaternions and isogenies","volume-title":"ASIACRYPT 2020","author":"Feo","year":"2020"},{"key":"2025052320023435800_ref12","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1007\/978-3-642-25405-5_2","article-title":"Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies","volume-title":"Int. Workshop on Post-Quantum Cryptography","author":"Jao","year":"2011"},{"key":"2025052320023435800_ref13","volume-title":"An efficient key recovery attack on SIDH (preliminary version)","author":"Castryck","year":"2022"},{"key":"2025052320023435800_ref14","volume-title":"An attack on SIDH with arbitrary starting curve. Cryptology ePrint Archive","author":"Maino","year":"2022"},{"key":"2025052320023435800_ref15","volume-title":"Breaking SIDH in polynomial time","author":"Robert","year":"2022"},{"key":"2025052320023435800_ref16","first-page":"329","article-title":"Supersingular isogeny graphs and endomorphism rings: reductions and solutions","volume-title":"EUROCRYPT 2018 Proceedings, Part III","author":"Eisentr\u00e4ger","year":"2018"},{"key":"2025052320023435800_ref17","first-page":"63","article-title":"On the security of supersingular isogeny cryptosystems","volume-title":"ASIACRYPT 2016 Proc., Part I","author":"Galbraith","year":"2016"},{"key":"2025052320023435800_ref18","doi-asserted-by":"crossref","first-page":"1100","DOI":"10.1109\/FOCS52979.2021.00109","article-title":"The supersingular isogeny path and endomorphism ring problems are equivalent","volume-title":"2021 IEEE 62nd Annual Symposium on Foundations of Computer Science (FOCS)","author":"Wesolowski","year":"2022"},{"key":"2025052320023435800_ref19","first-page":"7","article-title":"Supersingular curves with small noninteger endomorphisms","volume-title":"ANTS XIV\u2014Proc. of the Fourteenth Algorithmic Number Theory Symposium","author":"Boneh","year":"2020"},{"key":"2025052320023435800_ref20","first-page":"523","article-title":"Rational isogenies from irrational endomorphisms","volume-title":"EUROCRYPT 2020 Proc., Part II","author":"Castryck","year":"2020"},{"key":"2025052320023435800_ref21","first-page":"411","article-title":"Cryptographic group actions and applications","volume-title":"ASIACRYPT 2020 Proc., Part II","author":"Alamati","year":"2020"},{"key":"2025052320023435800_ref22","first-page":"248","volume-title":"Verifiable delay functions from supersingular isogenies and pairings","author":"De Feo","year":"2019"},{"key":"2025052320023435800_ref23","doi-asserted-by":"crossref","first-page":"86","DOI":"10.1007\/978-3-030-42921-8_5","article-title":"Group key exchange from CSIDH and its application to trusted setup in supersingular isogeny cryptosystems","volume-title":"Information Security and Cryptology, Cham","author":"Moriya","year":"2020"},{"key":"2025052320023435800_ref24","doi-asserted-by":"crossref","first-page":"405","DOI":"10.1007\/978-3-031-30617-4_14","article-title":"Supersingular curves you can trust","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2023, Cham","author":"Basso","year":"2023"},{"key":"2025052320023435800_ref25","first-page":"302","article-title":"Delay encryption","volume-title":"Annual Int. Conf. on the Theory and Applications of Cryptographic Techniques","author":"Burdges","year":"2021"},{"key":"2025052320023435800_ref26","first-page":"520","article-title":"Oblivious pseudorandom functions from isogenies","volume-title":"International Conference on the Theory and Application of Cryptology and Information Security","author":"Boneh","year":"2020"},{"key":"2025052320023435800_ref27","first-page":"160","article-title":"Cryptanalysis of an oblivious PRF from supersingular isogenies","volume-title":"International Conference on the Theory and Application of Cryptology and Information Security","author":"Basso","year":"2021"},{"key":"2025052320023435800_ref28","first-page":"330","article-title":"Faster algorithms for isogeny problems using torsion point images. ASIACRYPT 2017 Proc.","volume":"10625","author":"Petit","year":"2017","journal-title":"Part"},{"key":"2025052320023435800_ref29","first-page":"432","article-title":"Improved torsion-point attacks on SIDH variants","volume-title":"CRYPTO 2021 Proc., Part III","author":"Quehen","year":"2021"},{"key":"2025052320023435800_ref30","first-page":"242","article-title":"One-way functions and malleability oracles: hidden shift attacks on isogeny-based protocols","volume-title":"EUROCRYPT 2021 Proc., Part I","author":"Kutas","year":"2021"},{"key":"2025052320023435800_ref31","doi-asserted-by":"crossref","first-page":"169","DOI":"10.1007\/978-3-030-57808-4_9","article-title":"How not to create an isogeny-based PAKE","volume-title":"Int. Conf. on Applied Cryptography and Network Security","author":"Azarderakhsh","year":"2020"},{"key":"2025052320023435800_ref32","article-title":"Orientations and the supersingular endomorphism ring problem","volume":"13277","author":"Wesolowski","year":"2022","journal-title":"Advances in cryptology\u2014EUROCRYPT 2022 Proc., Part III"},{"key":"2025052320023435800_ref33","article-title":"On random sampling of supersingular elliptic curves","author":"Mula","year":"2022"},{"key":"2025052320023435800_ref34","doi-asserted-by":"crossref","DOI":"10.1007\/978-0-387-09494-6","volume-title":"The arithmetic of elliptic curves","author":"Silverman","year":"2009"},{"key":"2025052320023435800_ref35","doi-asserted-by":"crossref","first-page":"1055","DOI":"10.1073\/pnas.71.4.1055","article-title":"A simple proof of Siegel\u2019s theorem","volume":"71","author":"Goldfeld","year":"1974","journal-title":"Proc. Natl. Acad. Sci. U. S. A."},{"key":"2025052320023435800_ref36","doi-asserted-by":"crossref","first-page":"425","DOI":"10.1007\/s10623-014-0010-1","article-title":"Computing isogenies between supersingular elliptic curves over F_p","volume":"78","author":"Delfs","year":"2016","journal-title":"Des. Codes Cryptogr"},{"key":"2025052320023435800_ref37","doi-asserted-by":"crossref","first-page":"135","DOI":"10.1515\/9783110642094-008","article-title":"A survey on iterations of mappings over finite fields","volume-title":"Combinatorics and Finite Fields: Difference Sets, Polynomials, Pseudorandomness and Applications","author":"Martins","year":"2019"},{"key":"2025052320023435800_ref38","first-page":"329","article-title":"Random mapping statistics. Advances in cryptology\u2014EUROCRYPT \u201989 (Houthalen, 1989)","author":"Flajolet","year":"1990"},{"key":"2025052320023435800_ref39","article-title":"Elliptic functions","volume-title":"Graduate Texts in Mathematics","author":"Lang","year":"1987"},{"key":"2025052320023435800_ref40","first-page":"85","volume-title":"Higher-degree supersingular group actions. Mathematical Cryptology","author":"Chenu","year":"2022"},{"key":"2025052320023435800_ref41","article-title":"Adding level structure to supersingular elliptic curve isogeny graphs","author":"Arpin","year":"2022"},{"key":"2025052320023435800_ref42","first-page":"1","article-title":"Adventures in supersingularland","volume":"0","author":"Arpin","year":"2021","journal-title":"Exp. Math."},{"key":"2025052320023435800_ref43","first-page":"215","article-title":"Computing endomorphism rings of supersingular elliptic curves and connections to path-finding in isogeny graphs","volume-title":"ANTS XIV\u2014Proc. of the Fourteenth Algorithmic Number Theory Symposium","author":"Eisentr\u00e4ger","year":"2020"},{"key":"2025052320023435800_ref44","first-page":"098","article-title":"Orienteering with one endomorphism","author":"Arpin","year":"2022","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"2025052320023435800_ref45","article-title":"On ${\\mathbb{F}}_p$-roots of the Hilbert class polynomial modulo $p$","volume-title":"Journal of Mathematics (PRC)","author":"Chen","year":"2022"},{"key":"2025052320023435800_ref46","doi-asserted-by":"crossref","first-page":"317","DOI":"10.1112\/S1461157012001106","article-title":"Identifying supersingular elliptic curves","volume":"15","author":"Sutherland","year":"2012","journal-title":"LMS J. Comput. Math."},{"key":"2025052320023435800_ref47","doi-asserted-by":"crossref","first-page":"589","DOI":"10.1090\/S0025-5718-07-02017-0","article-title":"On Sch\u00f6nhage\u2019s algorithm and subquadratic integer GCD computation","volume":"77","author":"M\u00f6ller","year":"2008","journal-title":"Math. Comp."},{"key":"2025052320023435800_ref48","doi-asserted-by":"crossref","first-page":"1201","DOI":"10.1090\/S0025-5718-2011-02508-1","article-title":"Modular polynomials via isogeny volcanoes","volume":"81","author":"Br\u00f6ker","year":"2012","journal-title":"Math. Comp."},{"key":"2025052320023435800_ref49","first-page":"483","article-title":"Elliptic curves over finite fields and the computation of square roots $\\operatorname{mod}p$","volume":"44","author":"Schoof","year":"1985","journal-title":"Math. Comp."},{"key":"2025052320023435800_ref50","doi-asserted-by":"crossref","first-page":"155","DOI":"10.1006\/jsco.1998.0271","article-title":"Solving degenerate sparse polynomial systems faster","volume":"28","author":"Rojas","year":"1999","journal-title":"J. Symb. Comput."},{"key":"2025052320023435800_ref51","doi-asserted-by":"crossref","first-page":"121","DOI":"10.1090\/conm\/463\/09051","article-title":"A short guide to p-torsion of abelian varieties in characteristic p","volume-title":"Computational arithmetic geometry","author":"Pries","year":"2008"},{"key":"2025052320023435800_ref52","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1007\/BF01428253","article-title":"Which abelian surfaces are products of elliptic curves?","volume":"214","author":"Oort","year":"1975","journal-title":"Math. Ann."},{"key":"2025052320023435800_ref53","first-page":"285","article-title":"De transformatione integralium Abelianorum primi ordinis commentatio","volume":"16","author":"Richelot","year":"1837","journal-title":"Journal f\u00fcr die reine und angewandte Mathematik"},{"key":"2025052320023435800_ref54","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1515\/crll.1997.485.93","article-title":"The number of curves of genus two with elliptic differentials","volume":"1997","author":"Kani","year":"1997","journal-title":"J. Reine Angew. Math."},{"key":"2025052320023435800_ref55","first-page":"151","article-title":"The supersingular isogeny problem in genus 2 and beyond","volume-title":"Int. Conf. on Post-Quantum Cryptography, PQCrypto 2020","author":"Costello","year":"2020"},{"key":"2025052320023435800_ref56","doi-asserted-by":"crossref","DOI":"10.1090\/conm\/779\/15672","article-title":"Automorphisms and isogeny graphs of abelian varieties, with applications to the superspecial Richelot isogeny graph","volume-title":"Arithmetic, geometry, cryptography and coding theory 2021","author":"Florit","year":"2022"},{"key":"2025052320023435800_ref57","first-page":"127","article-title":"Supersingular curves of genus two and class numbers","volume":"57","author":"Ibukiyama","year":"1986","journal-title":"Compositio Mathematica"},{"key":"2025052320023435800_ref58","doi-asserted-by":"crossref","DOI":"10.1017\/CBO9780511526084","article-title":"Prolegomena to a middlebrow arithmetic of curves of genus 2","volume-title":"London Mathematical Society Lecture Note Series","author":"Cassels","year":"1996"},{"key":"2025052320023435800_ref59","article-title":"An atlas of the Richelot isogeny graph","author":"Florit","year":"2022","journal-title":"RIMS K\u00f4ky\u00fbroku Bessatsu"},{"key":"2025052320023435800_ref60","volume-title":"Kummer\u2019s quartic surface","author":"Hudson","year":"1905"},{"key":"2025052320023435800_ref61","doi-asserted-by":"crossref","first-page":"198","DOI":"10.1007\/BF01444020","article-title":"Zur Theorie der Liniencomplexe des ersten und zweiten grades","volume":"2","author":"Klein","year":"1870","journal-title":"Math. Ann."},{"key":"2025052320023435800_ref62","doi-asserted-by":"crossref","DOI":"10.1090\/noti2168","article-title":"Kummer surfaces: 200 years of study","volume":"67","author":"Dolgachev","year":"2020","journal-title":"Notices Amer. Math. Soc."},{"key":"2025052320023435800_ref63","doi-asserted-by":"crossref","first-page":"952","DOI":"10.4153\/CJM-1967-087-5","article-title":"A new look at the Kummer surface","volume":"19","author":"Edge","year":"1967","journal-title":"Can. J. Math."},{"key":"2025052320023435800_ref64","doi-asserted-by":"crossref","first-page":"239","DOI":"10.4064\/aa180416-4-10","article-title":"Diagonal genus 5 curves, elliptic curves over $\\mathbb{Q}(t)$, and rational diophantine quintuples","volume":"190","author":"Stoll","year":"2019","journal-title":"Acta Arithmetica"},{"key":"2025052320023435800_ref65","article-title":"Geometric aspects on Humbert-Edge\u2019s curves of type 5, Kummer surfaces and hyperelliptic curves of genus 2","volume-title":"Glasgow Mathematical Journal","author":"Castorena","year":"2023"},{"key":"2025052320023435800_ref66","article-title":"Quantum money from modular forms, arXiv:1809.05925","author":"Kane","year":"2018"},{"key":"2025052320023435800_ref67","article-title":"Quantum money from quaternion algebras","volume-title":"Mathematical Cryptology","author":"Kane","year":"2022"},{"key":"2025052320023435800_ref68","article-title":"Lecture notes on quantum algorithms","author":"Childs"},{"key":"2025052320023435800_ref69","doi-asserted-by":"crossref","first-page":"792","DOI":"10.1109\/FOCS.2015.54","article-title":"Hamiltonian simulation with nearly optimal dependence on all parameters","volume-title":"2015 IEEE 56th Annual Symposium on Foundations of Computer Science","author":"Berry","year":"2015"}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/67\/8\/2702\/58796453\/bxae038.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/67\/8\/2702\/58796453\/bxae038.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,24]],"date-time":"2025-05-24T00:02:58Z","timestamp":1748044978000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/67\/8\/2702\/7681095"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5,24]]},"references-count":69,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2024,5,24]]},"published-print":{"date-parts":[[2024,8,11]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxae038","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"value":"0010-4620","type":"print"},{"value":"1460-2067","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2024,8]]},"published":{"date-parts":[[2024,5,24]]}}}