Table of Contents
Fetching ...

The group structure of elliptic curves over Z/NZ

Massimiliano Sala, Daniele Taufer

TL;DR

This paper classifies the possible groups arising from elliptic curves over Z in terms of the groups E(\mathbb{Z}/N\mathbb {Z}), and provides an isomorphism attack to the ECDLP, which works only by means of finite rings arithmetic rather than involved methods.

Abstract

We characterize the possible groups $E(\mathbb{Z}/N\mathbb{Z})$ arising from elliptic curves over $\mathbb{Z}/N\mathbb{Z}$ in terms of the groups $E(\mathbb{F}_p)$, with $p$ varying among the prime divisors of $N$. This classification is achieved by showing that the infinity part of any elliptic curve over $\mathbb{Z}/p^e\mathbb{Z}$ is a $\mathbb{Z}/p^e\mathbb{Z}$-torsor, of which a generator is exhibited. As a first consequence, when $E(\mathbb{Z}/N\mathbb{Z})$ is a $p$-group, we provide an explicit and sharp bound on its rank. As a second consequence, when $N = p^e$ is a prime power and the projected curve $E(\mathbb{F}_p)$ has trace one, we provide an isomorphism attack to the ECDLP, which works only by means of finite rings arithmetic.

The group structure of elliptic curves over Z/NZ

TL;DR

This paper classifies the possible groups arising from elliptic curves over Z in terms of the groups E(\mathbb{Z}/N\mathbb {Z}), and provides an isomorphism attack to the ECDLP, which works only by means of finite rings arithmetic rather than involved methods.

Abstract

We characterize the possible groups arising from elliptic curves over in terms of the groups , with varying among the prime divisors of . This classification is achieved by showing that the infinity part of any elliptic curve over is a -torsor, of which a generator is exhibited. As a first consequence, when is a -group, we provide an explicit and sharp bound on its rank. As a second consequence, when is a prime power and the projected curve has trace one, we provide an isomorphism attack to the ECDLP, which works only by means of finite rings arithmetic.

Paper Structure

This paper contains 9 sections, 13 theorems, 81 equations.

Key Result

lemma 1

Let $n,m \in \mathbb{Z}_{\geq 1}$ and $A \in M_{n,m}(R)$ be a matrix whose entries are primitive, then the following are equivalent.

Theorems & Definitions (22)

  • definition 1: Primitivity
  • definition 2: Minor ideal
  • definition 3: Strong rank
  • lemma 1
  • definition 4: Projective $n$-space
  • definition 5: Elliptic curve over $R$
  • lemma 2
  • proposition 1: Washington, Corollary 2.32
  • lemma 3: ECNTA, Section 4
  • proposition 2
  • ...and 12 more