Supersingular Isogeny Graphs and Endomorphism Rings: Reductions and Solutions

被引:58
|
作者
Eisentrager, Kirsten [1 ]
Hallgren, Sean [2 ]
Lauter, Kristin [3 ]
Morrison, Travis [1 ]
Petit, Christophe [4 ]
机构
[1] Penn State Univ, Dept Math, University Pk, PA 16802 USA
[2] Penn State Univ, Dept Comp Sci & Engn, University Pk, PA 16802 USA
[3] Microsoft Res, Redmond, WA USA
[4] Univ Birmingham, Birmingham, W Midlands, England
来源
ADVANCES IN CRYPTOLOGY - EUROCRYPT 2018, PT III | 2018年 / 10822卷
基金
美国国家科学基金会; 英国工程与自然科学研究理事会;
关键词
ALGORITHM;
D O I
10.1007/978-3-319-78372-7_11
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we study several related computational problems for supersingular elliptic curves, their isogeny graphs, and their endomorphism rings. We prove reductions between the problem of path finding in the l-isogeny graph, computing maximal orders isomorphic to the endomorphism ring of a supersingular elliptic curve, and computing the endomorphism ring itself. We also give constructive versions of Deuring's correspondence, which associates to a maximal order in a certain quaternion algebra an isomorphism class of supersingular elliptic curves. The reductions are based on heuristics regarding the distribution of norms of elements in quaternion algebras. We show that conjugacy classes of maximal orders have a representative of polynomial size, and we define a way to represent endomorphism ring generators in a way that allows for efficient evaluation at points on the curve. We relate these problems to the security of the Charles-Goren-Lauter hash function. We provide a collision attack for special but natural parameters of the hash function and prove that for general parameters its preimage and collision resistance are also equivalent to the endomorphism ring computation problem.
引用
收藏
页码:329 / 368
页数:40
相关论文
共 50 条
  • [41] Identification Protocols and Signature Schemes Based on Supersingular Isogeny Problems
    Galbraith, Steven D.
    Petit, Christophe
    Silva, Javier
    JOURNAL OF CRYPTOLOGY, 2020, 33 (01) : 130 - 175
  • [42] Supersingular Isogeny Diffie-Hellman Authenticated Key Exchange
    Fujioka, Atsushi
    Takashima, Katsuyuki
    Terada, Shintaro
    Yoneyama, Kazuki
    INFORMATION SECURITY AND CRYPTOLOGY (ICISC 2018), 2019, 11396 : 177 - 195
  • [43] Faster Key Generation of Supersingular Isogeny Diffie-Hellman
    Lin, Kaizhan
    Zhang, Fangguo
    Zhao, Chang-An
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2022, E105 (08)
  • [44] ENDOMORPHISM NEAR RINGS THAT ARE RINGS
    MALONE, JJ
    NOTICES OF THE AMERICAN MATHEMATICAL SOCIETY, 1975, 22 (01): : A87 - A87
  • [45] Identification Protocols and Signature Schemes Based on Supersingular Isogeny Problems
    Steven D. Galbraith
    Christophe Petit
    Javier Silva
    Journal of Cryptology, 2020, 33 : 130 - 175
  • [46] Jacobians in isogeny classes of supersingular abelian threefolds in characteristic 2
    Nart, Enric
    Ritzenthaler, Christophe
    FINITE FIELDS AND THEIR APPLICATIONS, 2008, 14 (03) : 676 - 702
  • [47] Identification Protocols and Signature Schemes Based on Supersingular Isogeny Problems
    Galbraith, Steven D.
    Petit, Christophe
    Silva, Javier
    ADVANCES IN CRYPTOLOGY - ASIACRYPT 2017, PT I, 2017, 10624 : 3 - 33
  • [48] Optimized Modular Multiplication for Supersingular Isogeny Diffie-Hellman
    Liu, Weiqiang
    Ni, Jian
    Liu, Zhe
    Liu, Chunyang
    O'Neill, Maire
    IEEE TRANSACTIONS ON COMPUTERS, 2019, 68 (08) : 1249 - 1255
  • [49] Identification protocols and signature schemes based on supersingular isogeny problems
    Galbraith, Steven D.
    Petit, Christophe
    Silva, Javier
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2017, 10624 LNCS : 3 - 33
  • [50] Constructing supersingular elliptic curves with a given endomorphism ring
    Chevyrev, Ilya
    Galbraith, Steven D.
    LMS JOURNAL OF COMPUTATION AND MATHEMATICS, 2014, 17 : 71 - 91