A trade-off between classical and quantum circuit size for an attack against CSIDH

We propose a heuristic algorithm to solve the underlying hard problem of the CSIDH cryptosystem (and other isogeny-based cryptosystems using elliptic curves with endomorphism ring isomorphic to an imaginary quadratic order 𝒪). Let Δ = Disc(𝒪) (in CSIDH, Δ = −4p for p the security parameter). Let 0 &...

Full description

Bibliographic Details
Main Authors: Biasse Jean-François, Bonnetain Xavier, Pring Benjamin, Schrottenloher André, Youmans William
Format: Article
Language:English
Published: De Gruyter 2020-11-01
Series:Journal of Mathematical Cryptology
Subjects:
Online Access:https://doi.org/10.1515/jmc-2020-0070