Paper 2026/191
On the Active Security of the PEARL-SCALLOP Group Action
Abstract
We present an active attack against the PEARL-SCALLOP group action. Modelling Alice as an oracle that outputs the action by a secret ideal class on suitably chosen oriented elliptic curves, we show how to recover the secret using a handful of oracle calls (four for the parameter set targeting a security level equivalent to CSIDH-1024), by reducing to the computation of moderately-sized group action discrete logarithms. The key ingredient to the attack is to employ curves with non-primitive orientations inherent to the PEARL-SCALLOP construction. We provide methods for public-key validation — that is, for deciding whether a given orientation is primitive — and discuss their practicality.
Note: Revision 2026/04/13: corrections in Section 4 and typos.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Published elsewhere. Minor revision. PQCrypto 2026
- Keywords
- Isogeny-based cryptographyclass group actionsactive attacks
- Contact author(s)
-
research @ borisfouotsa com
marc houben @ math u-bordeaux fr
gioella lorenzon @ esat kuleuven be
ryan @ rueg re
parsa tasbihgou @ epfl ch - History
- 2026-04-13: revised
- 2026-02-05: received
- See all versions
- Short URL
- https://ia.cr/2026/191
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/191,
author = {Tako Boris Fouotsa and Marc Houben and Gioella Lorenzon and Ryan Rueger and Parsa Tasbihgou},
title = {On the Active Security of the {PEARL}-{SCALLOP} Group Action},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/191},
year = {2026},
url = {https://eprint.iacr.org/2026/191}
}