Paper 2026/1575

Solving the supersingular isogeny problem in time $p^{2/5+o(1)}$ using bivariate multipoint evaluation

Aleksei Udovenko, University of Luxembourg
Abstract

This note presents a new unconditional attack on the supersingular isogeny problem, with time and memory complexity $p^{2/5+o(1)}$. It builds on the approach by Eisenträger-Hallgren-Leonardi-Morrison-Park (2020) and Fuselier-Iezzi-Kozek-Morrison-Namoijam (2025), and is related to the recent heuristic attack with complexity $p^{1/3+o(1)}$ by Wesolowski (ePrint 2026/1486): all of these search for a separable isogeny from a curve to its Galois conjugate to form a non-scalar endomorphism. Our attack is based on highly theoretical multivariate multipoint evaluation algorithms from Kedlaya-Umans (2008, 2011), Bhargava-Ghosh-Guo-Kumar-Umans (2022), and Ghosh-Harsha-Herdade-Kumar-Saptharishi (2023), and therefore does not threaten isogeny cryptosystems in practice; it is of theoretical interest.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
IsogeniesElliptic curvesOneEndCryptanalysis
Contact author(s)
aleksei @ affine group
History
2026-08-03: approved
2026-07-31: received
See all versions
Short URL
https://ia.cr/2026/1575
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1575,
      author = {Aleksei Udovenko},
      title = {Solving the supersingular isogeny problem in time $p^{2/5+o(1)}$ using bivariate multipoint evaluation},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1575},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1575}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.