En poursuivant votre navigation sur ce site, vous acceptez l'utilisation d'un simple cookie d'identification. Aucune autre exploitation n'est faite de ce cookie. OK
1

An efficient break of the supersingular isogeny Diffie-Hellman protocol

Sélection Signaler une erreur
Multi angle
Auteurs : Castryck, Wouter (Auteur de la conférence)
CIRM (Editeur )

Loading the player...

Résumé : Finding an explicit isogeny between two given isogenous elliptic curves over a finite field is considered a hard problem, even for quantum computers. In 2011 this led Jao and De Feo to propose a key exchange protocol that became known as SIDH, shorthand for Supersingular Isogeny Diÿe-Hellman. The security of SIDH does not rely on a pure isogeny problem, due to certain 'auxiliary' elliptic curve points that are exchanged during the protocol (for constructive reasons). In this talk I will discuss a break of SIDH that was discovered in collaboration with Thomas Decru. The attack uses isogenies between abelian surfaces and exploits the aforementioned auxiliary points, so it does not break the pure isogeny problem. I will also discuss improvements of this attack due to Maino et al. and Robert, as well as a countermeasure by Fouotsa et al., along with breaks of this countermeasure in some special cases.

Mots-Clés : elliptic curves; isogenies; abelian surfaces; cryptography

Codes MSC :
14G15 - Finite ground fields
14G50 - Applications to coding theory and cryptography - application à la théorie de codes et à la cryptographie
14H40 - Jacobians, Prym varieties
14H52 - Elliptic curves
14K02 - Isogeny

    Informations sur la Vidéo

    Réalisateur : Hennenfent, Guillaume
    Langue : Anglais
    Date de Publication : 28/06/2023
    Date de Captation : 05/06/2023
    Sous Collection : Research talks
    Catégorie arXiv : Number Theory ; Algebraic Geometry ; Cryptography and Security
    Domaine(s) : Informatique ; Géométrie Complexe & géométrie Algébrique ; Théorie des Nombres
    Format : MP4 (.mp4) - HD
    Durée : 00:54:58
    Audience : Chercheurs ; Etudiants Science Cycle 2 ; Doctoral Students, Post-Doctoral Students
    Download : https://videos.cirm-math.fr/2023-06-08_Castryck.mp4

Informations sur la Rencontre

Nom de la Rencontre : AGCT - Arithmetic, Geometry, Cryptography and Coding Theory / AGCT - Arithmétique, géométrie, cryptographie et théorie des codes
Organisateurs de la Rencontre : Anni, Samuele ; Bruin, Nils ; Kohel, David ; Martindale, Chloe
Dates : 05/06/2023 - 09/06/2023
Année de la rencontre : 2023
URL de la Rencontre : https://conferences.cirm-math.fr/2889.html

Données de citation

DOI : 10.24350/CIRM.V.20055403
Citer cette vidéo: Castryck, Wouter (2023). An efficient break of the supersingular isogeny Diffie-Hellman protocol. CIRM. Audiovisual resource. doi:10.24350/CIRM.V.20055403
URI : http://dx.doi.org/10.24350/CIRM.V.20055403

Voir Aussi

Bibliographie

  • CASTRYCK, Wouter et DECRU, Thomas. An efficient key recovery attack on SIDH. In : Annual International Conference on the Theory and Applications of Cryptographic Techniques. Cham : Springer Nature Switzerland, 2023. p. 423-447. - http://dx.doi.org/10.1007/978-3-031-30589-4_15

  • MAINO, Luciano, MARTINDALE, Chloe, PANNY, Lorenz, et al. A direct key recovery attack on SIDH. In : Annual International Conference on the Theory and Applications of Cryptographic Techniques. Cham : Springer Nature Switzerland, 2023. p. 448-471. - http://dx.doi.org/10.1007/978-3-031-30589-4_16

  • ROBERT, Damien. Breaking SIDH in polynomial time. In : Annual International Conference on the Theory and Applications of Cryptographic Techniques. Cham : Springer Nature Switzerland, 2023. p. 472-503. - http://dx.doi.org/10.1007/978-3-031-30589-4_17



Imagette Video

Sélection Signaler une erreur