Fast and Frobenius: Rational Isogeny Evaluation over Finite Fields
Abstract
Consider the problem of efficiently evaluating isogenies of elliptic curves over a finite field , where the kernel is a cyclic group of odd (prime) order: given , , and a point (or several points) on , we want to compute . This problem is at the heart of efficient implementations of group-action- and isogeny-based post-quantum cryptosystems such as CSIDH. Algorithms based on V{\'e}lu's formulae give an efficient solution to this problem when the kernel generator is defined over . However, for general isogenies, is only defined over some extension , even though as a whole (and thus ) is defined over the base field ; and the performance of V{\'e}lu-style algorithms degrades rapidly as grows. In this article we revisit the isogeny-evaluation problem with a special focus on the case where . We improve V{\'e}lu-style isogeny evaluation for many cases where using special addition chains, and combine this with the action of Galois to give greater improvements when .
Cite
@article{arxiv.2306.16072,
title = {Fast and Frobenius: Rational Isogeny Evaluation over Finite Fields},
author = {Gustavo Banegas and Valerie Gilchrist and Anaëlle Le Dévéhat and Benjamin Smith},
journal= {arXiv preprint arXiv:2306.16072},
year = {2023}
}