Paper 2025/1047

Orient Express: Using Frobenius to Express Oriented Isogenies

Wouter Castryck, KU Leuven
Riccardo Invernizzi, KU Leuven
Gioella Lorenzon, KU Leuven
Jonas Meers, Ruhr University Bochum
Frederik Vercauteren, KU Leuven
Abstract

In this paper we study supersingular elliptic curves primitively oriented by an imaginary quadratic order, where the orientation is determined by an endomorphism that factors through the Frobenius isogeny. In this way, we partly recycle one of the main features of CSIDH, namely the fact that the Frobenius orientation can be represented for free. This leads to the most efficient family of ideal-class group actions in a range where the discriminant is significantly larger than the field characteristic $p$. Moreover, if we orient with a non-maximal order $\mathcal{O} \subset \mathbb{Q}(\sqrt{-p})$ and we assume that it is feasible to compute the ideal-class group of the maximal order, then also the ideal-class group of $\mathcal{O}$ is known and we recover the central feature of SCALLOP-like constructions. We propose two variants of our scheme. In the first one, the orientation is by a suborder of the form $\mathbb{Z}[f\sqrt{-p}]$ for some $f$ coprime to $p$, so this is similar to SCALLOP. In the second one, inspired by the work of Chenu and Smith, the orientation is by an order of the form $\mathbb{Z}[\sqrt{-dp}]$ where $d$ is square-free and not a multiple of $p$. We give practical ways of generating parameters, together with a proof-of-concept SageMath implementation of both variants, which shows the effectiveness of our construction.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
isogeny-based cryptographyclass group actionFrobenius endomorphism
Contact author(s)
wouter castryck @ esat kuleuven be
riccardo invernizzi @ esat kuleuven be
gioella lorenzon @ esat kuleuven be
research @ meers org
frederik vercauteren @ esat kuleuven be
History
2025-06-05: approved
2025-06-04: received
See all versions
Short URL
https://ia.cr/2025/1047
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1047,
      author = {Wouter Castryck and Riccardo Invernizzi and Gioella Lorenzon and Jonas Meers and Frederik Vercauteren},
      title = {Orient Express: Using Frobenius to Express Oriented Isogenies},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1047},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1047}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.