Secret Keys in Genus-2 SIDH

被引:2
|
作者
Kunzweiler, Sabrina [1 ]
Ti, Yan Bo [2 ]
Weitkaemper, Charlotte [3 ]
机构
[1] Ruhr Univ Bochum, Bochum, Germany
[2] DSO, Singapore, Singapore
[3] Univ Birmingham, Birmingham, W Midlands, England
来源
关键词
Genus-2; SIDH; Isogenies; Adaptive attack;
D O I
10.1007/978-3-030-99277-4_23
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
We present a polynomial-time adaptive attack on the genus-2 variant of SIDH (G2SIDH) and describe an improvement to its secret selection procedure. G2SIDH is a generalisation of the Supersingular Isogeny Diffie-Hellman key exchange into the genus-2 setting and achieves the same security as SIDH while using fields a third of the size. We analyze the keyspace of G2SIDH and achieve an improvement to the secret selection by using symplectic bases for the torsion subgroups. This allows for the near uniform sampling of secrets without needing to solve multiple linear congruences as suggested by Flynn-Ti. More generally, using symplectic bases enables us to classify and enumerate isogeny kernel subgroups and thus simplify the secret sampling step for general genus-2 SIDH-style constructions. The proposed adaptive attack on G2SIDH is able to recover the secret when furnished with an oracle that returns a single bit of information. We ensure that the maliciously generated information provided by the attacker cannot be detected by implementing simple countermeasures, forcing the use of the Fujisaki-Okamoto transform for CCA2-security. We demonstrate this attack and show that it is able to recover the secret isogeny in all cases of G2SIDH using a symplectic basis before extending the strategy to arbitrary bases.
引用
收藏
页码:483 / 507
页数:25
相关论文
共 50 条
  • [1] JACOBIAN IN GENUS-2
    CASSELS, JWS
    [J]. MATHEMATICAL PROCEEDINGS OF THE CAMBRIDGE PHILOSOPHICAL SOCIETY, 1993, 114 : 1 - 8
  • [2] GEOMETRIC UNIFORMIZATION IN GENUS-2
    KUUSALO, T
    NAATANEN, M
    [J]. ANNALES ACADEMIAE SCIENTIARUM FENNICAE SERIES A1-MATHEMATICA, 1995, 20 (02): : 401 - 418
  • [3] THE DISCRIMINANTS OF CURVES OF GENUS-2
    SAITO, T
    [J]. COMPOSITIO MATHEMATICA, 1989, 69 (02) : 229 - 240
  • [4] ON THE THICKNESS OF GRAPHS WITH GENUS-2
    ASANO, K
    [J]. ARS COMBINATORIA, 1994, 38 : 87 - 95
  • [5] ARITHMETIC OF CURVES OF GENUS-2
    CASSELS, JWS
    [J]. NUMBER THEORY AND APPLICATIONS, 1989, 265 : 27 - 35
  • [6] THERE IS ONE GROUP OF GENUS-2
    TUCKER, TW
    [J]. JOURNAL OF COMBINATORIAL THEORY SERIES B, 1984, 36 (03) : 269 - 275
  • [7] Efficient Compression of SIDH Public Keys
    Costello, Craig
    Jao, David
    Longa, Patrick
    Naehrig, Michael
    Renes, Joost
    Urbanik, David
    [J]. ADVANCES IN CRYPTOLOGY - EUROCRYPT 2017, PT I, 2017, 10210 : 679 - 706
  • [8] THE MAPPING CLASS GROUP FOR GENUS-2
    NELSON, JE
    REGGE, T
    [J]. INTERNATIONAL JOURNAL OF MODERN PHYSICS B, 1992, 6 (11-12): : 1847 - 1856
  • [9] Canonical heights on genus-2 Jacobians
    Mueller, Jan Steffen
    Stoll, Michael
    [J]. ALGEBRA & NUMBER THEORY, 2016, 10 (10) : 2153 - 2234
  • [10] FIBER SURFACES IN GENUS-2 CURVES
    GANG, X
    [J]. LECTURE NOTES IN MATHEMATICS, 1985, 1137 : R1 - 103