Better Bounds for Finding Fixed-Degree Isogenies via Coppersmith's Method
Marius A. Aardal, Diego F. Aranha, Yansong Feng, Yiming Gao, Yanbin Pan
摘要
The hardness of finding isogenies of degree between supersingular elliptic curves is a fundamental assumption in isogeny-based cryptography. Let and be supersingular elliptic curves defined over , and let be a smooth integer. %removed > p^1/2 part. At CRYPTO 2024, Benčina et al. proposed an algorithm with time complexity in the classical setting and in the quantum setting.
In this work, we first observe that their analysis omits a sub-exponential factor . We then improve their result to classically and quantumly. Our approach relies on small-root bounds for Coppersmith’s method applied to a four-variable integer equation. To this end, we adapt the explicit asymptotic formulas for small-root bounds introduced by Feng et al. (CRYPTO 2025) in the modular setting to the integer setting. As an additional application, we strengthen the attack of Benčina et al. on the SIDH signature scheme by Basso et al. (ACNS 2024). We expect that these refined techniques for Coppersmith’s method will be valuable for further post-quantum cryptanalysis.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Improved Algorithms for Finding Fixed-Degree Isogenies Between Supersingular Elliptic CurvesBenjamin Bencina, Péter Kutas, Simon-Philipp Merz, Christophe Petit 等CRYPTO 2024 · 被引用 3 次
- Accelerating the Delfs-Galbraith Algorithm with Fast Subfield Root DetectionMaria Corte-Real Santos, Craig Costello, Jia ShiCRYPTO 2022 · 被引用 10 次
- Rational Isogenies from Irrational EndomorphismsWouter Castryck, Lorenz Panny, Frederik VercauterenEUROCRYPT 2020 · 被引用 47 次
- SQIsignHD: New Dimensions in CryptographyPierrick Dartois, Antonin Leroux, Damien Robert, Benjamin WesolowskiEUROCRYPT 2024 · 被引用 69 次
- Improved Torsion-Point Attacks on SIDH VariantsVictoria de Quehen, Péter Kutas, Chris Leonardi, Chloe Martindale 等CRYPTO 2021 · 被引用 4 次
