Journal of Mathematical Cryptology (Nov 2020)

A trade-off between classical and quantum circuit size for an attack against CSIDH

  • Biasse Jean-François,
  • Bonnetain Xavier,
  • Pring Benjamin,
  • Schrottenloher André,
  • Youmans William

DOI
https://doi.org/10.1515/jmc-2020-0070
Journal volume & issue
Vol. 15, no. 1
pp. 4 – 17

Abstract

Read online

We propose a heuristic algorithm to solve the underlying hard problem of the CSIDH cryptosystem (and other isogeny-based cryptosystems using elliptic curves with endomorphism ring isomorphic to an imaginary quadratic order 𝒪). Let Δ = Disc(𝒪) (in CSIDH, Δ = −4p for p the security parameter). Let 0 < α < 1/2, our algorithm requires:

Keywords