A note on the cost of computing odd degree isogenies

Daniel Cervantes-Vázquez and Francisco Rodríguez-Henríquez

Abstract: Finding an isogenous supersingular elliptic curve of a prescribed odd degree is an important building block for all the isogeny-based protocols proposed to date. In this note we present several strategies for the efficient construction of odd degree isogenies, which outperform previously reported methods when dealing with isogeny degrees in the range $[7, 2^{20}].$

Category / Keywords: public-key cryptography / Isogeny-based cryptography, post-quantum cryptography, CSIDH, Isogeny, Isogenies, supersingular

Date: received 28 Nov 2019, last revised 9 Dec 2019

Contact author: dcervantes at computacion cs cinvestav mx , francisco@cs cinvestav mx

