Disorientation Faults in CSIDH
Gustavo Banegas, Juliane Krämer, Tanja Lange, Michael Meyer, Lorenz Panny, Krijn Reijnders, Jana Sotáková, Monika Trimoska
Abstract
. We investigate a new class of fault-injection attacks against the CSIDH family of cryptographic group actions. Our disorientation attacks effectively flip the direction of some isogeny steps. We achieve this by faulting a specific subroutine, connected to the Legendre symbol or Elligator computations performed during the evaluation of the group action. These subroutines are present in almost all known CSIDH implementations. Post-processing a set of faulty samples allows us to infer constraints on the secret key. The details are implementation specific, but we show that in many cases, it is possible to recover the full secret key with only a modest number of successful fault injections and modest computational resources. We provide full details for attacking the original CSIDH proof-of-concept software as well as the CTIDH constant-time ∗ Author list in alphabetical order; see https://ams.org/profession/leaders/ CultureStatement04.pdf . This work began at the online Lorentz Center workshop “Post-Quantum Cryptography for Embedded Systems” held in February 2022. This research was funded in part by the European Commission through H2020 SPARTA,
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0469161d-e8c7-4b90-88ad-5e1831505235Cited by top-tier papers2
- Radical Isogeny FormulaeThomas DecruCRYPTO 2024 · 4 citations
- Deterministic Algorithms for Class Group ActionsMarc HoubenCRYPTO 2025 · 1 citation
Builds on4
- Breaking SIDH in Polynomial TimeDamien RobertEUROCRYPT 2023 · 158 citations
- He Gives C-Sieves on the CSIDHChris PeikertEUROCRYPT 2020 · 120 citations
- Quantum Security Analysis of CSIDHXavier Bonnetain, André SchrottenloherEUROCRYPT 2020 · 103 citations
- Compact, Efficient and UC-Secure Isogeny-Based Oblivious TransferYi-Fu Lai, Steven D. Galbraith, Cyprien Delpech de Saint GuilhemEUROCRYPT 2021 · 43 citations
Related papers
- One-Way Functions and Malleability Oracles: Hidden Shift Attacks on Isogeny-Based ProtocolsPéter Kutas, Simon-Philipp Merz, Christophe Petit, Charlotte WeitkämperEUROCRYPT 2021 · 15 citations
- PEGASIS: Practical Effective Class Group Action using 4-Dimensional IsogeniesPierrick Dartois, Jonathan Komada Eriksen, Tako Boris Fouotsa, Arthur Herlédan Le Merdy et al.CRYPTO 2025 · 25 citations
- Orientations and the Supersingular Endomorphism Ring ProblemBenjamin WesolowskiEUROCRYPT 2022 · 34 citations
- Accelerating the Delfs-Galbraith Algorithm with Fast Subfield Root DetectionMaria Corte-Real Santos, Craig Costello, Jia ShiCRYPTO 2022 · 10 citations
- Improved Torsion-Point Attacks on SIDH VariantsVictoria de Quehen, Péter Kutas, Chris Leonardi, Chloe Martindale et al.CRYPTO 2021 · 4 citations
