Improved torsion point attacks on SIDH variants
Victoria de Quehen, P\'eter Kutas, Chris Leonardi, Chloe Martindale,, Lorenz Panny, Christophe Petit, Katherine E. Stange

TL;DR
This paper enhances torsion point attacks on SIDH, significantly lowering the difficulty of certain cryptographic problems, and proposes SIDH variants resistant to these improved attacks, without compromising SIKE security.
Contribution
It strengthens torsion point attack techniques using dual and Frobenius isogenies and constructs SIDH variants designed to resist these attacks.
Findings
Complete break of n-party group key exchange for 6+ parties
Quantum attack for 3+ parties with improved complexity
Implementation of attacks in Magma for 6 parties
Abstract
SIDH is a post-quantum key exchange algorithm based on the presumed difficulty of finding isogenies between supersingular elliptic curves. However, SIDH and related cryptosystems also reveal additional information: the restriction of a secret isogeny to a subgroup of the curve (torsion point information). Petit (2017) was the first to demonstrate that torsion point information could noticeably lower the difficulty of finding secret isogenies. In particular, Petit showed that "overstretched" parameterizations of SIDH could be broken in polynomial time. However, this did not impact the security of any cryptosystems proposed in the literature. The contribution of this paper is twofold: First, we strengthen the techniques of Petit by exploiting additional information coming from a dual and a Frobenius isogeny. This extends the impact of torsion point attacks considerably. In particular, our…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
