The supersingular isogeny path and endomorphism ring problems are equivalent

B Wesolowski - 2021 IEEE 62nd Annual Symposium on …, 2022 - ieeexplore.ieee.org
We prove that the path-finding problem in isogeny graphs and the endomorphism ring
problem for supersingular elliptic curves are equivalent under reductions of polynomial …

Supersingular curves you can trust

A Basso, G Codogni, D Connolly, L De Feo… - … Conference on the …, 2023 - Springer
Generating a supersingular elliptic curve such that nobody knows its endomorphism ring is a
notoriously hard task, despite several isogeny-based protocols relying on such an object. A …

SCALLOP-HD: group action from 2-dimensional isogenies

M Chen, A Leroux, L Panny - IACR International Conference on Public …, 2024 - Springer
We present SCALLOP-HD, a novel group action that builds upon the recent SCALLOP
group action introduced by De Feo, Fouotsa, Kutas, Leroux, Merz, Panny and Wesolowski in …

Delay encryption

J Burdges, L De Feo - Annual International Conference on the Theory and …, 2021 - Springer
We introduce a new primitive named Delay Encryption, and give an efficient instantiation
based on isogenies of supersingular curves and pairings. Delay Encryption is related to …

AprèsSQI: Extra fast verification for SQIsign using extension-field signing

M Corte-Real Santos, JK Eriksen, M Meyer… - … Conference on the …, 2024 - Springer
We optimise the verification of the SQIsign signature scheme. By using field extensions in
the signing procedure, we are able to significantly increase the amount of available rational …

Orientations and the supersingular endomorphism ring problem

B Wesolowski - Annual International Conference on the Theory and …, 2022 - Springer
We study two important families of problems in isogeny-based cryptography and how they
relate to each other: computing the endomorphism ring of supersingular elliptic curves, and …

CSIDH on the surface

W Castryck, T Decru - International Conference on Post-Quantum …, 2020 - Springer
For primes p ≡ 3\bmod 4, we show that setting up CSIDH on the surface, ie, using
supersingular elliptic curves with endomorphism ring Z (1+-p)/2, amounts to just a few sign …

Threshold schemes from isogeny assumptions

L De Feo, M Meyer - IACR International Conference on Public-Key …, 2020 - Springer
We initiate the study of threshold schemes based on the Hard Homogeneous Spaces (HHS)
framework of Couveignes. Quantum-resistant HHS based on supersingular isogeny graphs …

Isogeny problems with level structure

L De Feo, TB Fouotsa, L Panny - … on the Theory and Applications of …, 2024 - Springer
Given two elliptic curves and the degree of an isogeny between them, finding the isogeny is
believed to be a difficult problem—upon which rests the security of nearly any isogeny …

Failing to hash into supersingular isogeny graphs

J Booher, R Bowden, J Doliskani… - The Computer …, 2024 - academic.oup.com
An important open problem in supersingular isogeny-based cryptography is to produce,
without a trusted authority, concrete examples of 'hard supersingular curves' that is …