Improved Torsion-Point Attacks on SIDH Variants
Victoria de Quehen, Péter Kutas, Chris Leonardi, Chloe Martindale, Lorenz Panny, Christophe Petit, Katherine E. Stange
摘要
SIDH is a post-quantum key exchange algorithm based on the presumed difficulty of finding isogenies between supersingular elliptic curves. However, SIDH and related cryptosystems also reveal additional information: the restriction of a secret isogeny to a subgroup of the curve (torsion-point information). Petit [30] was the first to demonstrate that torsion-point information could noticeably lower the difficulty of finding secret isogenies. In particular, Petit showed that "overstretched" parameterizations of SIDH could be broken in polynomial time. However, this did not impact the security of any cryptosystems proposed in the literature. The contribution of this paper is twofold: First, we strengthen the techniques of [30] by exploiting additional information coming from a dual and a Frobenius isogeny. This extends the impact of torsion-point attacks considerably. In particular, our techniques yield a classical attack that completely breaks the n-party group key exchange of [2], first introduced as GSIDH in [16], for 6 parties or more, and a quantum attack for 3 parties or more that improves on the best known asymptotic complexity. We also provide a Magma implementation of our attack for 6 parties. We give the full range of parameters for which our attacks apply. Second, we construct SIDH variants designed to be weak against our attacks; this includes backdoor choices of starting curve, as well as backdoor choices of base-field prime. We stress that our results do not degrade the security of, or reveal any weakness in, the NIST submission SIKE [19].
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Breaking SIDH in Polynomial TimeDamien RobertEUROCRYPT 2023 · 被引用 158 次
- A Direct Key Recovery Attack on SIDHLuciano Maino, Chloe Martindale, Lorenz Panny, Giacomo Pope 等EUROCRYPT 2023 · 被引用 136 次
- M-SIDH and MD-SIDH: Countering SIDH Attacks by Masking InformationTako Boris Fouotsa, Tomoki Moriya, Christophe PetitEUROCRYPT 2023 · 被引用 52 次
- Supersingular Curves You Can TrustAndrea Basso, Giulio Codogni, Deirdre Connolly, Luca De Feo 等EUROCRYPT 2023 · 被引用 43 次
- CSI -Otter: Isogeny-Based (Partially) Blind Signatures from the Class Group Action with a TwistShuichi Katsumata, Yi-Fu Lai, Jason T. LeGrow, Ling QinCRYPTO 2023 · 被引用 22 次
它引用的顶会 Paper1
相关 Paper
- An Efficient Key Recovery Attack on SIDHWouter Castryck, Thomas DecruEUROCRYPT 2023 · 被引用 284 次
- One-Way Functions and Malleability Oracles: Hidden Shift Attacks on Isogeny-Based ProtocolsPéter Kutas, Simon-Philipp Merz, Christophe Petit, Charlotte WeitkämperEUROCRYPT 2021 · 被引用 15 次
- Quantum Security Analysis of CSIDHXavier Bonnetain, André SchrottenloherEUROCRYPT 2020 · 被引用 103 次
- Better Bounds for Finding Fixed-Degree Isogenies via Coppersmith's MethodMarius A. Aardal, Diego F. Aranha, Yansong Feng, Yiming Gao 等EUROCRYPT 2026 · 被引用 2 次
- SQIsignHD: New Dimensions in CryptographyPierrick Dartois, Antonin Leroux, Damien Robert, Benjamin WesolowskiEUROCRYPT 2024 · 被引用 69 次
