Paper 2017/504
A simple and compact algorithm for SIDH with arbitrary degree isogenies
Craig Costello and Huseyin Hisil
Abstract
We derive a new formula for computing arbitrary odd-degree isogenies between elliptic curves in Montgomery form. The formula lends itself to a simple and compact algorithm that can efficiently compute any low odd-degree isogenies inside the supersingular isogeny Diffie-Hellman (SIDH) key exchange protocol. Our implementation of this algorithm shows that, beyond the commonly used 3-isogenies, there is a moderate degradation in relative performance of
Metadata
- Available format(s)
-
PDF
- Publication info
- Published by the IACR in ASIACRYPT 2017
- Keywords
- Post-quantum cryptographyisogeny-based cryptographySIDHMontgomery curves.
- Contact author(s)
- craigco @ microsoft com
- History
- 2017-09-11: revised
- 2017-06-02: received
- See all versions
- Short URL
- https://ia.cr/2017/504
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2017/504, author = {Craig Costello and Huseyin Hisil}, title = {A simple and compact algorithm for {SIDH} with arbitrary degree isogenies}, howpublished = {Cryptology {ePrint} Archive, Paper 2017/504}, year = {2017}, url = {https://eprint.iacr.org/2017/504} }