TL;DR
This paper introduces efficient algorithms for computing chains of 2-isogenies in dimension 4 using theta-coordinates, enabling practical cryptanalysis of SIDH and related schemes, which was previously computationally infeasible.
Contribution
It generalizes 2-isogeny computation algorithms to dimension 4 with theta-coordinates, facilitating cryptanalysis of SIDH and related cryptographic protocols.
Findings
Able to perform SIDH key recovery attacks in seconds on standard parameters
Developed algorithms for chains of 2-isogenies in dimension 4
Implemented practical cryptanalysis tools for SIDH and SQIsignHD
Abstract
Dimension 4 isogenies have first been introduced in cryptography for the cryptanalysis of Supersingular Isogeny Diffie-Hellman (SIDH) and have been used constructively in several schemes, including SQIsignHD, a derivative of SQIsign isogeny based signature scheme. Unlike in dimensions 2 and 3, we can no longer rely on the Jacobian model and its derivatives to compute isogenies. In dimension 4 (and higher), we can only use theta-models. Previous works by Romain Cosset, David Lubicz and Damien Robert have focused on the computation of -isogenies in theta-models of level coprime to (which requires to use coordinates in dimension ). For cryptographic applications, we need to compute chains of -isogenies, requiring to use coordinates in dimension with state of the art algorithms. In this paper, we present algorithms to compute chains of…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
