He Gives C-Sieves on the CSIDH
Chris Peikert
Abstract
Recently, Castryck, Lange, Martindale, Panny, and Renes proposed CSIDH (pronounced “sea-side”) as a candidate post-quantum “commutative group action.” It has attracted much attention and interest, in part because it enables noninteractive Diffie–Hellman-like key exchange with quite small communication. Subsequently, CSIDH has also been used as a foundation for digital signatures. In 2003–04, Kuperberg and then Regev gave asymptotically subexponential quantum algorithms for “hidden shift” problems, which can be used to recover the CSIDH secret key from a public key. In late 2011, Kuperberg gave a follow-up quantum algorithm called the collimation sieve (“c-sieve” for short), which improves the prior ones, in particular by using exponentially less quantum memory and offering more parameter tradeoffs. While recent works have analyzed the concrete cost of the original algorithms (and variants) against CSIDH, nothing of this nature was previously available for the c-sieve. This work fills that gap. Specifically, we generalize Kuperberg’s collimation sieve to work for arbitrary finite cyclic groups, provide some practical efficiency improvements, give a classical (i.e., non-quantum) simulator, run experiments for a wide range of parameters up to the actual CSIDH-512 group order, and concretely quantify the complexity of the c-sieve against CSIDH. Our main conclusion is that the proposed CSIDH parameters provide relatively little quantum security beyond what is given by the cost of quantumly evaluating the CSIDH group action itself (on a uniform superposition). For example, the cost of CSIDH-512 key recovery is only about minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt document document216 quantum evaluations using minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt document document240 bits of quantumly accessible classical memory (plus relatively small other resources). This improves upon a prior estimate of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt document document232.5 evaluations and minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt document document231 qubits of quantum memory, for a variant of Kuperberg’s original sieve. Under the plausible assumption that quantum evaluation does not cost much more than what is given by a recent “best case” analysis, CSIDH-512 can therefore be broken using significantly less than minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt document document264 quantum T-gates. This strongly invalidates its claimed NIST level 1 quantum security, especially when accounting for the MAXDEPTH restriction. Moreover, under analogous assumptions for CSIDH-1024 and -1792, which target higher NIST security levels, except near the high end of the MAXDEPTH range even these instantiations fall short of level 1.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get bd984644-71f0-4577-939c-2703ebae7b6aCited by top-tier papers15
- Post-Quantum TLS Without Handshake SignaturesPeter Schwabe, Douglas Stebila, Thom WiggersCCS 2020 · 162 citations
- Post-quantum WireGuardAndreas Hülsing, Kai-Chun Ning, Peter Schwabe, Florian Weber et al.S&P 2021 · 73 citations
- Group Signatures and More from Isogenies and Lattices: Generic, Simple, and EfficientWard Beullens, Samuel Dobson, Shuichi Katsumata, Yi-Fu Lai et al.EUROCRYPT 2022 · 51 citations
- PEGASIS: Practical Effective Class Group Action using 4-Dimensional IsogeniesPierrick Dartois, Jonathan Komada Eriksen, Tako Boris Fouotsa, Arthur Herlédan Le Merdy et al.CRYPTO 2025 · 25 citations
- CSI -Otter: Isogeny-Based (Partially) Blind Signatures from the Class Group Action with a TwistShuichi Katsumata, Yi-Fu Lai, Jason T. LeGrow, Ling QinCRYPTO 2023 · 22 citations
Related papers
- Quantum Security Analysis of CSIDHXavier Bonnetain, André SchrottenloherEUROCRYPT 2020 · 103 citations
- Another Look at the Quantum Security of the Vectorization Problem with Shifted InputsPaul Frixons, Valerie Gilchrist, Péter Kutas, Simon-Philipp Merz et al.EUROCRYPT 2026
- Improved Torsion-Point Attacks on SIDH VariantsVictoria de Quehen, Péter Kutas, Chris Leonardi, Chloe Martindale et al.CRYPTO 2021 · 4 citations
- An Efficient Key Recovery Attack on SIDHWouter Castryck, Thomas DecruEUROCRYPT 2023 · 284 citations
- M-SIDH and MD-SIDH: Countering SIDH Attacks by Masking InformationTako Boris Fouotsa, Tomoki Moriya, Christophe PetitEUROCRYPT 2023 · 52 citations
