A note on the security of CSIDH
Cryptography and Security
2018-08-02 v4
Abstract
We propose an algorithm for computing an isogeny between two elliptic curves defined over a finite field such that there is an imaginary quadratic order satisfying for . This concerns ordinary curves and supersingular curves defined over (the latter used in the recent CSIDH proposal). Our algorithm has heuristic asymptotic run time and requires polynomial quantum memory and classical memory, where is the discriminant of . This asymptotic complexity outperforms all other available method for computing isogenies. We also show that a variant of our method has asymptotic run time while requesting only polynomial memory (both quantum and classical).
Cite
@article{arxiv.1806.03656,
title = {A note on the security of CSIDH},
author = {Jean-François Biasse and Annamaria Iezzi and Michael J. Jacobson},
journal= {arXiv preprint arXiv:1806.03656},
year = {2018}
}