Lune

CRYPTO2020Top-tier venue

Breaking the Decisional Diffie-Hellman Problem for Class Group Actions Using Genus Theory

Wouter Castryck, Jana Sotáková, Frederik Vercauteren

2020Year
29Citations
4Top-tier citations

Abstract

In this paper, we use genus theory to analyze the hardness of the decisional Diffie-Hellman problem (DDH) for ideal class groups of imaginary quadratic orders, acting on sets of elliptic curves through isogenies; such actions are used in the Couveignes-Rostovtsev-Stolbunov protocol and in CSIDH. Concretely, genus theory equips every imaginary quadratic order O with a set of assigned characters χ : cl(O) → ±1, and for each such character and every secret ideal class [a] connecting two public elliptic curves E and E = [a] E, we show how to compute χ([a]) given only E and E , i.e. without knowledge of [a]. In practice, this breaks DDH as soon as the class number is even, which is true for a density 1 subset of all imaginary quadratic orders. For instance, our attack works very efficiently for all supersingular elliptic curves over Fp with p ≡ 1 mod 4. Our method relies on computing Tate pairings and walking down isogeny volcanoes.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

Cited by top-tier papers4

Ask how each one uses it

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines