Paper 2026/1486

The supersingular isogeny problem in time and memory $p^{1/3+o(1)}$

Benjamin Wesolowski, ENS de Lyon, CNRS, UMPA, UMR 5669, Lyon, France
Abstract

We prove that under a plausible heuristic assumption (on the smoothness of certain random integers), the supersingular isogeny problem can be solved in time and memory $p^{1/3 + o(1)}$. This improves upon the previous best complexity of $p^{1/2} \cdot(\log p)^{O(1)}$. This problem is arguably the central hard problem underlying isogeny-based cryptography, and the cost of its resolution is a major (and often the only) factor in the choice of secure parameters. The impact on concrete parameter sets remains to be clarified, as the asymptotic advantage of the new algorithm is mitigated by a superpolynomial overhead hiding in the $o(1)$ exponent, and by its high memory requirement.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Post-quantumIsogeniesEndomorphismsSupersingular elliptic curvesCryptanalysisAttacks
Contact author(s)
benjamin wesolowski @ ens-lyon fr
History
2026-07-23: approved
2026-07-20: received
See all versions
Short URL
https://ia.cr/2026/1486
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1486,
      author = {Benjamin Wesolowski},
      title = {The supersingular isogeny problem in time and memory $p^{1/3+o(1)}$},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1486},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1486}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.