見出し画像

ロールパンを三つに割る…

via Pinterest

朝食の bread roll を割ってみた。

一回の操作で三つに割る程手先が器用ではないので、先ずは二つに割る。
等分にはならず、一方が少し大きいので、今度はそれを二つに割る。

この記事をほぼ書き終えた後に萬屋安斎様の以下の記事に遭遇した:

ふんふん。これを読んで思い出したのが、何年も前に読んだ「ケーキの切れない非行少年たち」(宮口幸治著、新潮新書)。

アナログ時計を読むにはどんな能力が必要?
https://note.com/angelikafa/n/nafe786510164

三つになったパンを見て、2025年5月に勉強した elliptic curve 楕円曲線isogeny (【日】同種写像) に関する Vélu's formulas を想い出したのだが、私が非行少年でも不良老人でもないと信じたい🙏

これは
    "Elliptic Curves - Number Theory and Cryptography"
    (Lawrence C. Washington 著)
の第12章 Isogenies に掲載されている:


Vélu's formulas - Isogenies

とても記述が長いが以下の定理である:

美しさの欠片も感じられないが、具体的な座標を用いて isogeny を記述することが出来るという点で実用的である。驚く程初等的で、代数幾何学的手法を一部使う以外、楕円曲線の理論に登場する数論的技法は全く不要である。

高尚な哲学もない。世界の秩序とか、宇宙OSとか、ラマヌジャンのMBTI云々等という高邁な言葉は全く無関係である。情緒よりも執念である。

尚、ここで座標と書いているのは Weierstrass 方程式の定義にある変数 x, y のことで、以下のような数学を装った落書きにある「座標」とは異なる:

某記事より… (Screenshot taken on 2026/06/26)

楕円曲線の「座標」には何通りもあって、方程式により選択が出来る。
「選択する」と「揺らす」は全く異なる。

証明は我慢強い計算が必要で、呆れる程ゴリゴリと計算を行うと、
    「見苦しい項が綺麗に消えて行く」
が、これは計算をきちんと行ってのみ味わえることである。
完備 ζ (ゼータ)関数の関数等式の導出はまさに同様な例である😎

『リーマン予想の150年』(黒川信重著、岩波書店)より

数学を詩的な言葉で哲学する殿上人には先ず体感出来ない世界であろう。

定理に記述されている
    C = {∞} ∪ C₂ ∪ R ∪ (−R)
を「子供の絵」風に図示すると、以下のようになる:
(倭国の商人が好む高度な可視化レベルと比較すると幼稚園程度である。)

念の為、以下の「子供の絵」は全く別の理論である:

この L.C. Washington の本は楕円曲線を必要とする computer scientists 及び cryptographers のみを想定読者としてはおらず、楕円曲線の数論と幾何学を勉強する mathematicians も想定しており、例が非常に豊富である👍
(但し検証は読者が行う必要がある。)
最終章はこんな内容⬇️😮
  15 Fermat's Last Theorem
    15.1 Overview
    15.2 Galois Representations
    15.3 Sketch of Ribet's Proof
    15.4 Sketch of Wiles's Proof

Ribet's Proof と書いてあるが、これはフェルマーの最終定理の証明における非常に重要なステップである。有名なサイモン・シンの通俗書に K. Ribet の名前はかなりの回数 ( > 20) 登場し、通俗書第6章にて A. Wiles の言葉で
  「Ribet が志村・谷山予想とフェルマーの最終定理の"繋がり"を証明した」
という記述がある。原文は以下の通り(下線は筆者):

6. The Secret Calculation

L.C. Washington の本から引用すると Ribet の定理は:

と書かれており、この主張を理解する為にはかなりの勉強が必要であるが、フェルマーの最終定理をもう少し詳しく知ろうと思ったら、サイモン・シンの通俗書を読むより那由多倍(つまり遥かに)為になる。当該通俗書で演出付きで書かれていた岩澤理論には一切触れていないが、同様に通俗書で言及されている Kolyvagin には L.C. Washington は FLT とは別の以下の二章にて触れている。(但しかなり高度な内容なので、紹介程度である。)

  • Section 8.9 Galois Cohomology, Chapter 8 Elliptic Curves over Q

  • Section 14.2 Elliptic Curves over Q, Chapter 14 Zeta Functions

ガロア表現の変形理論Hecke Algebraヘッケ環の話もこの最終章に簡単に記述されている。理論無きロマンではなく、ロマンに溢れた理論である。

そして上記 Ribet's Theorem から次が従う:
COROLLARY 15.8
The Taniyama-Shimura-Weil conjecture (for semistable elliptic curves) implies Fermat's Last Theorem.

【N.B.】岩澤理論を軽視する意図は微塵も無い、念の為。


面白いことに同じシリーズに以下の本があるが、こちらは2007年に購入している。引退後に数学の勉強に戻ろうと決心したのは2005~2006年だったが、先ずは類体論の復習と楕円曲線の理論が必須、と考えていたからであろう。
これは楕円曲線・超楕円曲線暗号を実際に使う人向けの本であるが、かなり高度な理論に証明なしに言及している。具体例が非常に豊富なのと、全部を読み通す必要もないので、必要に応じて参照している。

Handbook of Elliptic and Hyperelliptic Curve Cryptography (Henri Cohen and Gerhard Frey)

残念ながら Vélu’s formulas に関しては僅か一行の説明に終わっている。

17.2.2 Schoof-Elkies-Atkin's algorithm §17.2 Overview of ℓ-adic methods
Chapter 17 Point Counting on Elliptic and Hyperelliptic Curve (ibid.)

同様に Joseph H. Silverman の楕円曲線の数論に関する標準的な教科書でも以下の簡単な言及に留まっている:

Ⅲ.4 Isogenies, Chapter Ⅲ. The Geometry of Elliptic Curves
"The Arithmetic of Elliptic Curves"

暗号理論超²入門

以下に極めて雑な「考え方」を示す。

有名な RSA

考え方の基本は、素因数分解は桁数が増えるとかなり時間を要する、という点である:

易しい・難しいの定義をしていないが、以下の Wikipedia 記事の例を見れば素因数分解の困難さが判るはずである。

楕円曲線暗号

例を一つ示す:
有限体 Fₚ (p = 2003) 上の楕円曲線 (Elliptic Curve)
    E : y² + 2xy + 8y = x³ + 5x² + 1136x + 531
を考える。楕円曲線の一般論として、解の集合に無限遠点 {∞} を加えてこれを E(Fₚ) と定義すると、{∞} を零として加法が定義出来てそれはアーベル群になり、この場合は Z/1956Z という巡回群になる。
任意の点 P ∊ E(Fₚ) と任意の整数 m に対して P の m倍 [m]P を P⨁ … ⨁P (m個)として定義出来る。

計算すると P = (1118, 269) 及び Q = (1453, 1428) は E(Fₚ) の元であることが確かめられる。(実際に計算出来るし。計算しないと先に進まない…)
楕円曲線暗号の基礎になるのは以下の点である:


Isogeny-Based Cryptography

楕円曲線暗号は軽量だが、Shor's algorithm (量子コンピュータ上で整数の素因数分解を多項式時間で実行できる量子アルゴリズム) によって、秘密鍵が多項式時間で容易に逆算される為、量子コンピュータ耐性を持たない😱
一方、楕円曲線の Isogeny (同種写像) を用いた暗号理論は量子コンピュータ時代の暗号理論の一つと考えられている:

Isogeny-based cryptography is a specific type of post-quantum cryptography that uses certain well-behaved maps between abelian varieties over finite fields (typically elliptic curves) as its core building block.

"Isogeny-based cryptography" (by Chloe Martindale & Lorenz Panny)

興味が湧いたので以下の論文を下に勉強してみた:

"Computational problems in supersingular elliptic curve isogenies"
(Steven D. Galbraith and Frederik Vercauteren)

内容が非常に濃い上に、多くの資料に目を通す必要があり、いつもの通りに理解するのに時間が掛かったが
    ECDH (Elliptic Curve Diffie-Hellman)
    ⬇️
    SIDH (Supersingular Isogeny Diffie-Hellman)
という進化を具体的に理解出来たので、少し嬉しく思っている。そしてこの理論において前述の Vélu's formulas は基本的である。


残念ながら、2022年にはこの手法 (SIDH/SIKE) に対する cracking の事例が報告された:

Feisty Duck's Cryptography & Security Newsletter https://www.feistyduck.com/newsletter/issue_92_the_end_of_sidh_and_sike

A post-quantum key exchange method once considered promising is apparently insecure and can be completely broken with classical computers. Researchers recently published attacks on both supersingular isogeny Diffie-Hellman (SIDH) and the supersingular isogeny key encapsulation (SIKE) variation that was submitted for NIST's post-quantum competition.
These key exchange methods use so-called isogenies over supersingular elliptic curves. Using these mathematical objects for cryptography is a relatively new idea: the SIDH algorithm was published in 2011 by Luca de Feo, David Jao, and Jérôme Plût.
SIDH was seen as promising because the key size was relatively small compared to many other post-quantum methods. Also, as the name indicates, the algorithm works similarly to the Diffie-Hellman key exchange.
But all of this has probably become irrelevant, as a paper posted by Wouter Castryck and Thomas Decru from KU Leuven described an attack that allows for completely breaking SIDH and SIKE in less than an hour. Independently, the attack was also described by Luciano Maino and Chloe Martindale from the University of Bristol. These attacks would only work in special cases of SIDH, but a later improvement of the attack by Damien Robert from Inria Bordeaux completely breaks SIDH. Steven Galbraith has given a description of the mathematical ideas behind the attack in a blog post and explained how the three different published papers relate to each other in a second blog post. Galbraith was also a guest in the Security. Cryptography. Whatever. podcast episode that covered the attack.

ibid.

以下の記事はこの攻撃に関する研究論文ではないが、問題の概要を理解には助けになる。

最新の研究(2026年)では

In 2022, Castryck and Decru introduced an attack that broke several isogeny-based schemes, including SIKE, which had advanced to the final round of the NIST Post-Quantum Cryptography Standardization Competition. Despite this attack, research on isogeny-based cryptography has continued, primarily due to the compact key sizes offered by these schemes compared to other post-quantum approaches. There are now many isogeny-based schemes that are resistant to the Castryck-Decru attack. These schemes typically involve advanced mathematical structures that may require significant time and effort to study.
In this paper, we provide a structured survey of isogeny-based signature schemes that are resistant to the Castryck-Decru attack, aiming to facilitate an understanding of the current landscape and the most practically relevant schemes in this area. We categorize these signature schemes into two main classes: those based on the CSIDH group action and the SQIsign family. For each class, we discuss their fundamental design principles, security assumptions, and specific constructions. We also compare their performance and compactness. Additionally, we describe one representative scheme from each class that is particularly relevant in practice due to its efficiency or compactness. In conclusion, we compare the performance of the schemes discussed in this work with other post-quantum signature schemes.

Survey of isogeny-based signature schemes resistant to Castryck–Decru attack
(J. S. Bobrysheva, A. S. Zelenetsky and V. V. Davydov)
IACR Nesw Item: 05 March 2026 (International Association for Cryptologic Research)

SIDH/SIKE は死んだが Isogeny を用いた暗号理論は研究が続いている:


Star Tracker

The following articles sound irrelevant to this content, but highly inspiring:

これは暗号理論とは別の話だが、
    ECC (Elliptic Curve Cryptography) ➡️ IBC (Isogeny Based Cryptography)
という暗号理論のシフトに対応するかの如く
    GPS ➡️ Digital Star Tracker
という発展を位置づけることが可能と感じた次第である。
勿論、この対比はかなり比喩的である。
尚、Digital Star Tracker は GPS を置き換えるものではない。
少し調べてみたが、面白い技術であると感じた👍

最後に、何故このような対比を想起したかについて。
長い説明を避ける為、supersingular isogeny graph を添付する:
(出典:S.D. Galbraith and F. Vercauteren による上記の論文)

グラフの各「点」が一つの楕円曲線である💫

Digital Star Tracker を教えて下さったトマリエ様に感謝🙏


[Header Image Credit] T and O map via Wikimedia Commons
🟪

いいなと思ったら応援しよう!