English

A note on the security of CSIDH

Cryptography and Security 2018-08-02 v4

Abstract

We propose an algorithm for computing an isogeny between two elliptic curves E1,E2E_1,E_2 defined over a finite field such that there is an imaginary quadratic order O\mathcal{O} satisfying OEnd(Ei)\mathcal{O}\simeq \operatorname{End}(E_i) for i=1,2i = 1,2. This concerns ordinary curves and supersingular curves defined over Fp\mathbb{F}_p (the latter used in the recent CSIDH proposal). Our algorithm has heuristic asymptotic run time eO(log(Δ))e^{O\left(\sqrt{\log(|\Delta|)}\right)} and requires polynomial quantum memory and eO(log(Δ))e^{O\left(\sqrt{\log(|\Delta|)}\right)} classical memory, where Δ\Delta is the discriminant of O\mathcal{O}. This asymptotic complexity outperforms all other available method for computing isogenies. We also show that a variant of our method has asymptotic run time eO~(log(Δ))e^{\tilde{O}\left(\sqrt{\log(|\Delta|)}\right)} while requesting only polynomial memory (both quantum and classical).

Cite

@article{arxiv.1806.03656,
  title  = {A note on the security of CSIDH},
  author = {Jean-François Biasse and Annamaria Iezzi and Michael J. Jacobson},
  journal= {arXiv preprint arXiv:1806.03656},
  year   = {2018}
}
R2 v1 2026-06-23T02:24:58.635Z