PEGASIS: Practical Effective Class Group Action using 4-Dimensional Isogenies
Pierrick Dartois, Jonathan Komada Eriksen, Tako Boris Fouotsa, Arthur Herlédan Le Merdy, Riccardo Invernizzi, Damien Robert, Ryan Rueger, Frederik Vercauteren, Benjamin Wesolowski
Abstract
In this paper, we present the first practical algorithm to compute an effective group action of the class group of any imaginary quadratic order on a set of supersingular elliptic curves primitively oriented by . Effective means that we can act with any element of the class group directly, and are not restricted to acting by products of ideals of small norm, as for instance in CSIDH. Such restricted effective group actions often hamper cryptographic constructions, e.g. in signature or MPC protocols.
Our algorithm is a refinement of the Clapoti approach by Page and Robert, and uses -dimensional isogenies. As such, it runs in polynomial time, does not require the computation of the structure of the class group, nor expensive lattice reductions, and our refinements allows it to be instantiated with the orientation given by the Frobenius endomorphism. This makes the algorithm practical even at security levels as high as CSIDH-4096. Our implementation in SageMath takes 1.5s to compute a group action at the CSIDH-512 security level, 21s at CSIDH-2048 level and around 2 minutes at the CSIDH-4096 level. This marks the first instantiation of an effective cryptographic group action at such high security levels. For comparison, the recent KLaPoTi approach requires around 200s at the CSIDH-512 level in SageMath and 2.5s in Rust.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dc077697-b543-43bb-a039-547d477c72efCited by top-tier papers3
- On the Conversion of Module Representations for Higher Dimensional Supersingular IsogeniesAurel Page, Damien Robert, Julien SoumierCRYPTO 2026 · 3 citations
- sfqt-sfPegasis: Simpler and Faster Effective Class Group ActionsPierrick Dartois, Jonathan Komada Eriksen, Riccardo Invernizzi, Frederik VercauterenEUROCRYPT 2026 · 2 citations
- Another Look at the Quantum Security of the Vectorization Problem with Shifted InputsPaul Frixons, Valerie Gilchrist, Péter Kutas, Simon-Philipp Merz et al.EUROCRYPT 2026
Builds on7
- Breaking SIDH in Polynomial TimeDamien RobertEUROCRYPT 2023 · 158 citations
- He Gives C-Sieves on the CSIDHChris PeikertEUROCRYPT 2020 · 120 citations
- Quantum Security Analysis of CSIDHXavier Bonnetain, André SchrottenloherEUROCRYPT 2020 · 103 citations
- SQIsignHD: New Dimensions in CryptographyPierrick Dartois, Antonin Leroux, Damien Robert, Benjamin WesolowskiEUROCRYPT 2024 · 69 citations
- Fast and Secure Updatable EncryptionColin Boyd, Gareth T. Davies, Kristian Gjøsteen, Yao JiangCRYPTO 2020 · 52 citations
Related papers
- Orientations and the Supersingular Endomorphism Ring ProblemBenjamin WesolowskiEUROCRYPT 2022 · 34 citations
- Weak Instances of Class Group Action Based Cryptography via Self-pairingsWouter Castryck, Marc Houben, Simon-Philipp Merz, Marzio Mula et al.CRYPTO 2023 · 20 citations
- Breaking the Decisional Diffie-Hellman Problem for Class Group Actions Using Genus TheoryWouter Castryck, Jana Sotáková, Frederik VercauterenCRYPTO 2020 · 29 citations
- Rational Isogenies from Irrational EndomorphismsWouter Castryck, Lorenz Panny, Frederik VercauterenEUROCRYPT 2020 · 47 citations
- Deterministic Algorithms for Class Group ActionsMarc HoubenCRYPTO 2025 · 1 citation
