A Direct Key Recovery Attack on SIDH
Luciano Maino, Chloe Martindale, Lorenz Panny, Giacomo Pope, Benjamin Wesolowski
Abstract
We present an attack on SIDH utilising isogenies between polarized products of two supersingular elliptic curves. In the case of arbitrary starting curve, our attack (discovered independently from [8]) has subexponential complexity, thus significantly reducing the security of SIDH and SIKE. When the endomorphism ring of the starting curve is known, our attack (here derived from [8]) has polynomial-time complexity assuming the generalised Riemann hypothesis. Our attack applies to any isogeny-based cryptosystem that publishes the images of points under the secret isogeny, for example Séta [13] and B-SIDH [11]. It does not apply to CSIDH [9], CSI-FiSh [3], or SQISign [14].
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7a1a528d-f2df-40a1-9093-fc9bee7f75deCited by top-tier papers18
- SQIsignHD: New Dimensions in CryptographyPierrick Dartois, Antonin Leroux, Damien Robert, Benjamin WesolowskiEUROCRYPT 2024 · 69 citations
- Supersingular Curves You Can TrustAndrea Basso, Giulio Codogni, Deirdre Connolly, Luca De Feo et al.EUROCRYPT 2023 · 43 citations
- The Supersingular Endomorphism Ring and One Endomorphism Problems are EquivalentAurel Page, Benjamin WesolowskiEUROCRYPT 2024 · 28 citations
- CSI -Otter: Isogeny-Based (Partially) Blind Signatures from the Class Group Action with a TwistShuichi Katsumata, Yi-Fu Lai, Jason T. LeGrow, Ling QinCRYPTO 2023 · 22 citations
- Weak Instances of Class Group Action Based Cryptography via Self-pairingsWouter Castryck, Marc Houben, Simon-Philipp Merz, Marzio Mula et al.CRYPTO 2023 · 20 citations
Builds on3
- Breaking SIDH in Polynomial TimeDamien RobertEUROCRYPT 2023 · 158 citations
- The supersingular isogeny path and endomorphism ring problems are equivalentBenjamin WesolowskiFOCS 2021 · 61 citations
- Improved Torsion-Point Attacks on SIDH VariantsVictoria de Quehen, Péter Kutas, Chris Leonardi, Chloe Martindale et al.CRYPTO 2021 · 4 citations
Related papers
- An Efficient Key Recovery Attack on SIDHWouter Castryck, Thomas DecruEUROCRYPT 2023 · 284 citations
- Orientations and the Supersingular Endomorphism Ring ProblemBenjamin WesolowskiEUROCRYPT 2022 · 34 citations
- Rational Isogenies from Irrational EndomorphismsWouter Castryck, Lorenz Panny, Frederik VercauterenEUROCRYPT 2020 · 47 citations
- One-Way Functions and Malleability Oracles: Hidden Shift Attacks on Isogeny-Based ProtocolsPéter Kutas, Simon-Philipp Merz, Christophe Petit, Charlotte WeitkämperEUROCRYPT 2021 · 15 citations
- M-SIDH and MD-SIDH: Countering SIDH Attacks by Masking InformationTako Boris Fouotsa, Tomoki Moriya, Christophe PetitEUROCRYPT 2023 · 52 citations
