Weak Instances of Class Group Action Based Cryptography via Self-pairings
Wouter Castryck, Marc Houben, Simon-Philipp Merz, Marzio Mula, Sam van Buuren, Frederik Vercauteren
摘要
In this paper we study non-trivial self-pairings with cyclic domains that are compatible with isogenies between elliptic curves oriented by an imaginary quadratic order O. We prove that the order m of such a self-pairing necessarily satisfies m | ∆O (and even 2m | ∆O if 4 | ∆O and 4m | ∆O if 8 | ∆O) and is not a multiple of the field characteristic. Conversely, for each m satisfying these necessary conditions, we construct a family of non-trivial cyclic self-pairings of order m that are compatible with oriented isogenies, based on generalized Weil and Tate pairings. As an application, we identify weak instances of class group actions on elliptic curves assuming the degree of the secret isogeny is known. More in detail, we show that if m 2 | ∆O for some prime power m then given two primitively O-oriented elliptic curves (E, ι) and (E ′ , ι ′ ) = [a](E, ι) connected by an unknown invertible ideal a ⊆ O, we can recover a essentially at the cost of a discrete logarithm computation in a group of order m 2 , assuming the norm of a is given and is smaller than m 2 . We give concrete instances, involving ordinary elliptic curves over finite fields, where this turns into a polynomial time attack. Finally, we show that these self-pairings simplify known results on the decisional Diffie-Hellman problem for class group actions on oriented elliptic curves.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Isogeny Problems with Level StructureLuca De Feo, Tako Boris Fouotsa, Lorenz PannyEUROCRYPT 2024 · 被引用 10 次
- Improved Algorithms for Finding Fixed-Degree Isogenies Between Supersingular Elliptic CurvesBenjamin Bencina, Péter Kutas, Simon-Philipp Merz, Christophe Petit 等CRYPTO 2024 · 被引用 3 次
- Deterministic Algorithms for Class Group ActionsMarc HoubenCRYPTO 2025 · 被引用 1 次
它引用的顶会 Paper5
- An Efficient Key Recovery Attack on SIDHWouter Castryck, Thomas DecruEUROCRYPT 2023 · 被引用 284 次
- Breaking SIDH in Polynomial TimeDamien RobertEUROCRYPT 2023 · 被引用 158 次
- A Direct Key Recovery Attack on SIDHLuciano Maino, Chloe Martindale, Lorenz Panny, Giacomo Pope 等EUROCRYPT 2023 · 被引用 136 次
- The supersingular isogeny path and endomorphism ring problems are equivalentBenjamin WesolowskiFOCS 2021 · 被引用 61 次
- Breaking the Decisional Diffie-Hellman Problem for Class Group Actions Using Genus TheoryWouter Castryck, Jana Sotáková, Frederik VercauterenCRYPTO 2020 · 被引用 29 次
相关 Paper
- PEGASIS: Practical Effective Class Group Action using 4-Dimensional IsogeniesPierrick Dartois, Jonathan Komada Eriksen, Tako Boris Fouotsa, Arthur Herlédan Le Merdy 等CRYPTO 2025 · 被引用 25 次
- Orientations and the Supersingular Endomorphism Ring ProblemBenjamin WesolowskiEUROCRYPT 2022 · 被引用 34 次
- sfqt-sfPegasis: Simpler and Faster Effective Class Group ActionsPierrick Dartois, Jonathan Komada Eriksen, Riccardo Invernizzi, Frederik VercauterenEUROCRYPT 2026 · 被引用 2 次
- One-Way Functions and Malleability Oracles: Hidden Shift Attacks on Isogeny-Based ProtocolsPéter Kutas, Simon-Philipp Merz, Christophe Petit, Charlotte WeitkämperEUROCRYPT 2021 · 被引用 15 次
- On the Conversion of Module Representations for Higher Dimensional Supersingular IsogeniesAurel Page, Damien Robert, Julien SoumierCRYPTO 2026 · 被引用 3 次
