Paper 2026/1486
The supersingular isogeny problem in time and memory $p^{1/3+o(1)}$
Abstract
We prove that under a plausible heuristic assumption (on the smoothness of certain random integers), the supersingular isogeny problem can be solved in time and memory $p^{1/3 + o(1)}$. This improves upon the previous best complexity of $p^{1/2} \cdot(\log p)^{O(1)}$. This problem is arguably the central hard problem underlying isogeny-based cryptography, and the cost of its resolution is a major (and often the only) factor in the choice of secure parameters. The impact on concrete parameter sets remains to be clarified, as the asymptotic advantage of the new algorithm is mitigated by a superpolynomial overhead hiding in the $o(1)$ exponent, and by its high memory requirement.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- Post-quantumIsogeniesEndomorphismsSupersingular elliptic curvesCryptanalysisAttacks
- Contact author(s)
- benjamin wesolowski @ ens-lyon fr
- History
- 2026-07-23: approved
- 2026-07-20: received
- See all versions
- Short URL
- https://ia.cr/2026/1486
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1486,
author = {Benjamin Wesolowski},
title = {The supersingular isogeny problem in time and memory $p^{1/3+o(1)}$},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1486},
year = {2026},
url = {https://eprint.iacr.org/2026/1486}
}