Paper 2023/995

Fast and Frobenius: Rational Isogeny Evaluation over Finite Fields

Gustavo Banegas, Qualcomm France SARL
Valerie Gilchrist, Université Libre de Bruxelles, FRIA
Anaëlle Le Dévéhat, French Institute for Research in Computer Science and Automation, Institut Polytechnique de Paris
Benjamin Smith, French Institute for Research in Computer Science and Automation, Institut Polytechnique de Paris
Abstract

Consider the problem of efficiently evaluating isogenies $\phi: \mathcal{E} \to \mathcal{E}/H$ of elliptic curves over a finite field $\mathbb{F}_q$, where the kernel \(H = \langle{G}\rangle\) is a cyclic group of odd (prime) order: given \(\mathcal{E}\), \(G\), and a point (or several points) $P$ on $\mathcal{E}$, we want to compute $\phi(P)$. This problem is at the heart of efficient implementations of group-action- and isogeny-based post-quantum cryptosystems such as CSIDH. Algorithms based on Vélu's formul\ae{} give an efficient solution to this problem when the kernel generator $G$ is defined over $\mathbb{F}_q$. However, for general isogenies, \(G\) is only defined over some extension $\mathbb{F}_{q^k}$, even though $\langle{G}\rangle$ as a whole (and thus \(\phi\)) is defined over the base field $\mathbb{F}_q$; and the performance of Vélu-style algorithms degrades rapidly as $k$ grows. In this article, we revisit the isogeny-evaluation problem with a special focus on the case where $1 \le k \le 12$. We improve Vélu-style isogeny evaluation for many cases where \(k = 1\) using special addition chains, and combine this with the action of Galois to give greater improvements when \(k > 1\).

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Published elsewhere. Minor revision. Latincrypt 2023
Keywords
IsogenyFrobeniusIsogeny EvaluationCSIDHCRS
Contact author(s)
gustavo @ cryptme in
valerie gilchrist @ ulb be
anaelle le-devehat @ inria fr
smith @ lix polytechnique fr
History
2023-08-08: revised
2023-06-26: received
See all versions
Short URL
https://ia.cr/2023/995
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2023/995,
      author = {Gustavo Banegas and Valerie Gilchrist and Anaëlle Le Dévéhat and Benjamin Smith},
      title = {Fast and Frobenius: Rational Isogeny Evaluation over Finite Fields},
      howpublished = {Cryptology ePrint Archive, Paper 2023/995},
      year = {2023},
      note = {\url{https://eprint.iacr.org/2023/995}},
      url = {https://eprint.iacr.org/2023/995}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.