Paper 2024/1180

Fast computation of 2-isogenies in dimension 4 and cryptographic applications

Pierrick Dartois, Inria Bordeaux - Sud-Ouest Research Centre, Institut de Mathématiques de Bordeaux
Abstract

Dimension 4 isogenies have first been introduced in cryptography for the cryptanalysis of Supersingular Isogeny Diffie-Hellman (SIDH) and have been used constructively in several schemes, including SQIsignHD, a derivative of SQIsign isogeny based signature scheme. Unlike in dimensions 2 and 3, we can no longer rely on the Jacobian model and its derivatives to compute isogenies. In dimension 4 (and higher), we can only use theta-models. Previous works by Romain Cosset, David Lubicz and Damien Robert have focused on the computation of -isogenies in theta-models of level n coprime to (which requires to use ng coordinates in dimension g). For cryptographic applications, we need to compute chains of 2-isogenies, requiring to use 3g coordinates in dimension g with state of the art algorithms. In this paper, we present algorithms to compute chains of -isogenies between abelian varieties of dimension with theta-coordinates of level , generalizing a previous work by Pierrick Dartois, Luciano Maino, Giacomo Pope and Damien Robert in dimension . We propose an implementation of these algorithms in dimension to compute endomorphisms of elliptic curve products derived from Kani's lemma with applications to SQIsignHD and SIDH cryptanalysis. We are now able to run a complete key recovery attack on SIDH when the endomorphism ring of the starting curve is unknown within a few seconds on a laptop for all NIST SIKE parameters.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Preprint.
Keywords
IsogeniesHigher dimensionDimension 4Theta modelSIDHSQIsignHD
Contact author(s)
pierrick dartois @ u-bordeaux fr
History
2024-07-25: approved
2024-07-22: received
See all versions
Short URL
https://ia.cr/2024/1180
License
Creative Commons Attribution-NonCommercial-ShareAlike
CC BY-NC-SA

BibTeX

@misc{cryptoeprint:2024/1180,
      author = {Pierrick Dartois},
      title = {Fast computation of 2-isogenies in dimension 4 and cryptographic applications},
      howpublished = {Cryptology {ePrint} Archive, Paper 2024/1180},
      year = {2024},
      url = {https://eprint.iacr.org/2024/1180}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.