TY - JOUR
T1 - The SQALE of CSIDH
T2 - sublinear Vélu quantum-resistant isogeny action with low exponents
AU - Chávez-Saab, Jorge
AU - Chi-Domínguez, Jesús Javier
AU - Jaques, Samuel
AU - Rodríguez-Henríquez, Francisco
N1 - Funding Information:
This project has received funding from the European Research Council (ERC) under the European Union’s Horizon 2020 research and innovation programme (grant agreement No 804476). S. Jaques was supported by the University of Oxford Clarendon fund.
Publisher Copyright:
© 2021, The Author(s).
PY - 2022
Y1 - 2022
N2 - Recent independent analyses by Bonnetain–Schrottenloher and Peikert in Eurocrypt 2020 significantly reduced the estimated quantum security of the isogeny-based commutative group action key-exchange protocol CSIDH. This paper refines the estimates of a resource-constrained quantum collimation sieve attack to give a precise quantum security to CSIDH. Furthermore, we optimize large CSIDH parameters for performance while still achieving the NIST security levels 1, 2, and 3. Finally, we provide a C-code constant-time implementation of those CSIDH large instantiations using the square-root-complexity Vélu’s formulas recently proposed by Bernstein, De Feo, Leroux and Smith.
AB - Recent independent analyses by Bonnetain–Schrottenloher and Peikert in Eurocrypt 2020 significantly reduced the estimated quantum security of the isogeny-based commutative group action key-exchange protocol CSIDH. This paper refines the estimates of a resource-constrained quantum collimation sieve attack to give a precise quantum security to CSIDH. Furthermore, we optimize large CSIDH parameters for performance while still achieving the NIST security levels 1, 2, and 3. Finally, we provide a C-code constant-time implementation of those CSIDH large instantiations using the square-root-complexity Vélu’s formulas recently proposed by Bernstein, De Feo, Leroux and Smith.
KW - Isogeny-based cryptography
KW - Post-quantum cryptography
KW - Quantum cryptanalysis
KW - [Constant time implementations]
KW - [Finite field arithmetic]
U2 - 10.1007/s13389-021-00271-w
DO - 10.1007/s13389-021-00271-w
M3 - Article
AN - SCOPUS:85113965282
SN - 2190-8508
VL - 12
JO - JOURNAL OF CRYPTOGRAPHIC ENGINEERING
JF - JOURNAL OF CRYPTOGRAPHIC ENGINEERING
IS - 3
ER -