Fast and Frobenius: Rational Isogeny Evaluation over Finite Fields
Gustavo Banegas, Valerie Gilchrist (ULB), Ana\"elle Le D\'ev\'ehat, (GRACE), Benjamin Smith (GRACE)

TL;DR
This paper introduces optimized algorithms for evaluating elliptic curve isogenies over finite fields, significantly improving efficiency especially when the kernel point is defined over small extension fields, which benefits post-quantum cryptography.
Contribution
It presents new methods that enhance Vélu-style isogeny evaluation for small extension degrees and leverages Galois actions for further improvements.
Findings
Enhanced Vélu-style algorithms for k=1 using special addition chains.
Combined Galois action with isogeny evaluation for k>1.
Achieved faster isogeny computations in relevant cryptographic settings.
Abstract
Consider the problem of efficiently evaluating isogenies of elliptic curves over a finite field , where the kernel is a cyclic group of odd (prime) order: given , , and a point (or several points) on , we want to compute . This problem is at the heart of efficient implementations of group-action- and isogeny-based post-quantum cryptosystems such as CSIDH. Algorithms based on V{\'e}lu's formulae give an efficient solution to this problem when the kernel generator is defined over . However, for general isogenies, is only defined over some extension , even though as a whole (and thus ) is defined over the base field ; and the performance of V{\'e}lu-style algorithms degrades rapidly as grows. In this article we revisit the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptography and Residue Arithmetic · Coding theory and cryptography · Cryptography and Data Security
