A note on the security of CSIDH

06/10/2018
by   Jean-François Biasse, et al.
0

We propose an algorithm for computing an isogeny between two elliptic curves E_1,E_2 defined over finite field such that there is an imaginary quadratic order O satisfying O≃End(E_i) for i = 1,2. This concerns ordinary curves and supersingular curves defined over F_p (used in the recent CSIDH proposal). Our algorithm has heuristic asymptotic run time e^O(√((|Δ|))) and requires polynomial quantum space in Poly((|Δ|)) where Δ is the discriminant of O. We also describe a probabilistic attack against CSIDH that takes advantage of the structure of the ideal class group Cl(O) of O. Suppose M satisfies M| N where N := #Cl(O), then there is a quantum attack with run time e^O(√((N'))) and a classical attack in time O(√(N')) that succeeds with probability 1/M where N' := N/M.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/03/2022

On the decisional Diffie-Hellman problem for class group actions on oriented elliptic curves

We show how the Weil pairing can be used to evaluate the assigned charac...
research
03/12/2023

New Space-Efficient Quantum Algorithm for Binary Elliptic Curves using the Optimized Division Algorithm

In previous research, quantum resources were concretely estimated for so...
research
07/19/2021

Higher-degree supersingular group actions

We investigate the isogeny graphs of supersingular elliptic curves over ...
research
07/12/2018

Fast Exact Algorithms Using Hadamard Product of Polynomials

In this paper we develop an efficient procedure for computing a (scaled)...
research
11/29/2022

Trustless unknown-order groups

Groups of unknown order are of major interest due to their applications ...
research
10/06/2021

Beyond quadratic speedups in quantum attacks on symmetric schemes

In this paper, we report the first quantum key-recovery attack on a symm...
research
11/19/2019

Robust Learning of Discrete Distributions from Batches

Let d be the lowest L_1 distance to which a k-symbol distribution p can ...

Please sign up or login with your details

Forgot password? Click here to reset