Failing to hash into supersingular isogeny graphs

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Booher, Jeremy, Bowden, Ross, Doliskani, Javad, Fouotsa, Tako Boris, Galbraith, Steven D., Kunzweiler, Sabrina, Merz, Simon-Philipp, Petit, Christophe, Smith, Benjamin, Stange, Katherine E., Ti, Yan Bo, Vincent, Christelle, Voloch, José Felipe, Weitkämper, Charlotte, Zobernig, Lukas
Format: Preprint
Published: 2022
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914788752228352
author Booher, Jeremy
Bowden, Ross
Doliskani, Javad
Fouotsa, Tako Boris
Galbraith, Steven D.
Kunzweiler, Sabrina
Merz, Simon-Philipp
Petit, Christophe
Smith, Benjamin
Stange, Katherine E.
Ti, Yan Bo
Vincent, Christelle
Voloch, José Felipe
Weitkämper, Charlotte
Zobernig, Lukas
author_facet Booher, Jeremy
Bowden, Ross
Doliskani, Javad
Fouotsa, Tako Boris
Galbraith, Steven D.
Kunzweiler, Sabrina
Merz, Simon-Philipp
Petit, Christophe
Smith, Benjamin
Stange, Katherine E.
Ti, Yan Bo
Vincent, Christelle
Voloch, José Felipe
Weitkämper, Charlotte
Zobernig, Lukas
contents An important open problem in supersingular isogeny-based cryptography is to produce, without a trusted authority, concrete examples of "hard supersingular curves" that is, equations for supersingular curves for which computing the endomorphism ring is as difficult as it is for random supersingular curves. A related open problem is to produce a hash function to the vertices of the supersingular $\ell$-isogeny graph which does not reveal the endomorphism ring, or a path to a curve of known endomorphism ring. Such a hash function would open up interesting cryptographic applications. In this paper, we document a number of (thus far) failed attempts to solve this problem, in the hope that we may spur further research, and shed light on the challenges and obstacles to this endeavour. The mathematical approaches contained in this article include: (i) iterative root-finding for the supersingular polynomial; (ii) gcd's of specialized modular polynomials; (iii) using division polynomials to create small systems of equations; (iv) taking random walks in the isogeny graph of abelian surfaces; and (v) using quantum random walks.
format Preprint
id arxiv_https___arxiv_org_abs_2205_00135
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle Failing to hash into supersingular isogeny graphs
Booher, Jeremy
Bowden, Ross
Doliskani, Javad
Fouotsa, Tako Boris
Galbraith, Steven D.
Kunzweiler, Sabrina
Merz, Simon-Philipp
Petit, Christophe
Smith, Benjamin
Stange, Katherine E.
Ti, Yan Bo
Vincent, Christelle
Voloch, José Felipe
Weitkämper, Charlotte
Zobernig, Lukas
Number Theory
Cryptography and Security
11G05, 11T71, 14G50, 14K02, 81P94, 94A60, 68Q12
An important open problem in supersingular isogeny-based cryptography is to produce, without a trusted authority, concrete examples of "hard supersingular curves" that is, equations for supersingular curves for which computing the endomorphism ring is as difficult as it is for random supersingular curves. A related open problem is to produce a hash function to the vertices of the supersingular $\ell$-isogeny graph which does not reveal the endomorphism ring, or a path to a curve of known endomorphism ring. Such a hash function would open up interesting cryptographic applications. In this paper, we document a number of (thus far) failed attempts to solve this problem, in the hope that we may spur further research, and shed light on the challenges and obstacles to this endeavour. The mathematical approaches contained in this article include: (i) iterative root-finding for the supersingular polynomial; (ii) gcd's of specialized modular polynomials; (iii) using division polynomials to create small systems of equations; (iv) taking random walks in the isogeny graph of abelian surfaces; and (v) using quantum random walks.
title Failing to hash into supersingular isogeny graphs
topic Number Theory
Cryptography and Security
11G05, 11T71, 14G50, 14K02, 81P94, 94A60, 68Q12
url https://arxiv.org/abs/2205.00135