Isogeny-based schemes often come with special requirements on the field of definition of the involved elliptic curves. For instance, the efficiency of SQIsign, a promising candidate in the NIST signature standardisation process, requires a large power of two and a large smooth integer to divide for its prime parameter . We present two new methods that combine previous techniques for finding suitable primes: sieve-and-boost and XGCD-and-boost. We use these methods to find primes for the NIST submission of SQIsign. Furthermore, we show that our methods are flexible and can be adapted to find suitable parameters for other isogeny-based schemes such as AprèsSQI or POKE. For all three schemes, the parameters we present offer the best performance among all parameters proposed in the literature.
References
[AAA+24a]
Marius A. Aardal, Gora Adj, Arwa Alblooshi, Diego Aranha, Isaac A. Canales-Martínez, Jorge Chávez-Saab, Décio Luiz Gazzoni Filho, Krijn Reijnders, and Francisco Rodríguez-Henríquez. Optimized SQIsign 1D verification on Intel and Cortex-M4. Personal communication, manuscript in preparation. 2024.
Marius A. Aardal, Gora Adj, Arwa Alblooshi, Diego Aranha, Isaac A. Canales-Martínez, Jorge Chávez-Saab, Décio Luiz Gazzoni Filho, Krijn Reijnders, and Francisco Rodríguez-Henríquez. Scoring primes for computing isogenies in extension fields. Available at: http://delta.cs.cinvestav.mx/ francisco/codigo.html. 2024.
Giacomo Bruno, Maria Corte-Real Santos, Craig Costello, Jonathan Komada Eriksen, Michael Meyer, Michael Naehrig, and Bruno Sterner. Cryptographic Smooth Neighbors. In Jian Guo and Ron Steinfeld, editors, ASIACRYPT 2023, Part VII, volume 14444 of LNCS, pages 190–221. December 2023. Springer, Singapore. DOI: 10.1007/978-981-99-8739-9_7
Jean-Claude Bajard and Sylvain Duquesne. Montgomery-friendly primes and applications to cryptography. Journal of Cryptographic Engineering, 11(4):399–415, November 2021. DOI: 10.1007/s13389-021-00260-z
Andrea Basso, Luca De Feo, Pierrick Dartois, Antonin Leroux, Luciano Maino, Giacomo Pope, Damien Robert, and Benjamin Wesolowski. SQIsign2D-West: The Fast, the Small, and the Safer. Cryptology ePrint Archive, Paper 2024/760. 2024.
Daniel J Bernstein, Luca De Feo, Antonin Leroux, and Benjamin Smith. Faster computation of isogenies of large prime degree. Open Book Series, 4(1):39–55, 2020. DOI: 10.2140/obs.2020.4.39
Jan Buzek, Junaid Hasan, Jason Liu, Michael Naehrig, and Anthony Vigil. Finding twin smooth integers by solving Pell equations. CoRR, abs/2211.04315, 2022. DOI: 10.48550/ARXIV.2211.04315
William D. Banks and Igor E. Shparlinski. Integers with a large smooth divisor. Integers. Electronic Journal of Combinatorial Number Theory, 7:A17, 11, 2007. DOI: 10.5281/zenodo.8281131
Daniel Cervantes-Vázquez, Mathilde Chenu, Jesús-Javier Chi-Domínguez, Luca De Feo, Francisco Rodríguez-Henríquez, and Benjamin Smith. Stronger and Faster Side-Channel Protections for CSIDH. In Peter Schwabe and Nicolas Thériault, editors, LATINCRYPT 2019, volume 11774 of LNCS, pages 173–193. October 2019. Springer, Cham. DOI: 10.1007/978-3-030-30530-7_9
Fabio Campos, Jorge Chávez-Saab, Jesús-Javier Chi-Domínguez, Michael Meyer, Krijn Reijnders, Francisco Rodríguez-Henríquez, Peter Schwabe, and Thom Wiggers. Optimizations and Practicality of High-Security CSIDH. IACR Communications in Cryptology, 1(1), 2024. DOI: 10.62056/ANJBKSDJA
Jorge Chavez-Saab, Maria Corte-Real Santos, Luca De Feo, Jonathan Komada Eriksen, Basil Hess, David Kohel, Antonin Leroux, Patrick Longa, Michael Meyer, Lorenz Panny, Sikhar Patranabis, Christophe Petit, Francisco Rodríguez-Henríquez, Sina Schaeffler, and Benjamin Wesolowski. SQIsign: Algorithm specifications and supporting documentation. National Institute of Standards and Technology. 2023.
Wouter Castryck and Thomas Decru. An Efficient Key Recovery Attack on SIDH. In Carmit Hazay and Martijn Stam, editors, EUROCRYPT 2023, Part V, volume 14008 of LNCS, pages 423–447. April 2023. Springer, Cham. DOI: 10.1007/978-3-031-30589-4_15
Maria Corte-Real Santos, Jonathan Komada Eriksen, Michael Meyer, and Krijn Reijnders. AprèsSQI: Extra Fast Verification for SQIsign Using Extension-Field Signing. In Marc Joye and Gregor Leander, editors, Advances in Cryptology - EUROCRYPT 2024 - 43rd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Zurich, Switzerland, May 26-30, 2024, Proceedings, Part I, volume 14651 of Lecture Notes in Computer Science, pages 63–93. 2024. Springer. DOI: 10.1007/978-3-031-58716-0_3
Murat Cenk. Karatsuba-like formulae and their associated techniques. Journal of Cryptographic Engineering, 8(3):259–269, September 2018. DOI: 10.1007/s13389-017-0155-8
Craig Costello, Michael Meyer, and Michael Naehrig. Sieving for Twin Smooth Integers with Solutions to the Prouhet-Tarry-Escott Problem. In Anne Canteaut and François-Xavier Standaert, editors, EUROCRYPT 2021, Part I, volume 12696 of LNCS, pages 272–301. October 2021. Springer, Cham. DOI: 10.1007/978-3-030-77870-5_10
Craig Costello. B-SIDH: Supersingular Isogeny Diffie-Hellman Using Twisted Torsion. In Shiho Moriai and Huaxiong Wang, editors, ASIACRYPT 2020, Part II, volume 12492 of LNCS, pages 440–463. December 2020. Springer, Cham. DOI: 10.1007/978-3-030-64834-3_15
Nicolaas G. de Bruijn. On the number of positive integers x and free of prime factors , II. Indag. Math, 38:239–247, 1966. DOI: 10.1016/S1385-7258(66)50029-4
Karl Dickman. On the frequency of numbers containing prime factors of a certain relative magnitude. Arkiv for matematik, astronomi och fysik, 22(10):A–10, 1930.
Luca De Feo, David Kohel, Antonin Leroux, Christophe Petit, and Benjamin Wesolowski. SQISign: Compact Post-quantum Signatures from Quaternions and Isogenies. In Shiho Moriai and Huaxiong Wang, editors, ASIACRYPT 2020, Part I, volume 12491 of LNCS, pages 64–93. December 2020. Springer, Cham. DOI: 10.1007/978-3-030-64837-4_3
Luca De Feo, Antonin Leroux, Patrick Longa, and Benjamin Wesolowski. New Algorithms for the Deuring Correspondence - Towards Practical and Secure SQISign Signatures. In Carmit Hazay and Martijn Stam, editors, EUROCRYPT 2023, Part V, volume 14008 of LNCS, pages 659–690. April 2023. Springer, Cham. DOI: 10.1007/978-3-031-30589-4_23
Pierrick Dartois, Antonin Leroux, Damien Robert, and Benjamin Wesolowski. SQIsignHD: New Dimensions in Cryptography. In Marc Joye and Gregor Leander, editors, Advances in Cryptology - EUROCRYPT 2024 - 43rd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Zurich, Switzerland, May 26-30, 2024, Proceedings, Part I, volume 14651 of Lecture Notes in Computer Science, pages 3–32. 2024. Springer. DOI: 10.1007/978-3-031-58716-0_1
Jonathan Komada Eriksen, Lorenz Panny, Jana Sotáková, and Mattia Veroni. Deuring for the People: Supersingular elliptic curves with prescribed endomorphism ring in general characteristic. In LuCaNT: LMFDB, computation, and number theory, volume 796 of Contemporary Mathematics, pages 339–373. Amer. Math. Soc., Providence, RI 2024. DOI: 10.1090/conm/796/16008
Luciano Maino, Chloe Martindale, Lorenz Panny, Giacomo Pope, and Benjamin Wesolowski. A Direct Key Recovery Attack on SIDH. In Carmit Hazay and Martijn Stam, editors, EUROCRYPT 2023, Part V, volume 14008 of LNCS, pages 448–471. April 2023. Springer, Cham. DOI: 10.1007/978-3-031-30589-4_16
Damien Robert. Breaking SIDH in Polynomial Time. In Carmit Hazay and Martijn Stam, editors, EUROCRYPT 2023, Part V, volume 14008 of LNCS, pages 472–503. April 2023. Springer, Cham. DOI: 10.1007/978-3-031-30589-4_17
Carl Størmer. Quelques théorèmes sur l'équation de Pell et leurs applications. Christiania Videnskabens Selskabs Skrifter, Math. Nat. Kl, 1897. DOI: 10.1215/ijm/1256067456
Maria Corte-Real Santos, Jonathan Komada Eriksen, Michael Meyer, and
Francisco Rodríguez-Henríquez, Finding Practical Parameters for Isogeny-based Cryptography. IACR Communications in Cryptology, vol. 1, no. 3, Oct 07, 2024, doi: 10.62056/ayojbhey6b.
@article{10.62056/ayojbhey6b,
author={Maria Corte-Real Santos and Jonathan Komada Eriksen and Michael Meyer and Francisco Rodríguez-Henríquez},
title={Finding Practical Parameters for Isogeny-based Cryptography},
volume={1},
number={3},
year={2024},
date={2024-10-07},
issn={3006-5496},
doi={10.62056/ayojbhey6b},
journal={{IACR} Communications in Cryptology},
publisher={International Association for Cryptologic Research}
}
TY - JOUR
AU - Maria Corte-Real Santos
AU - Jonathan Komada Eriksen
AU - Michael Meyer
AU - Francisco Rodríguez-Henríquez
PY - 2024
TI - Finding Practical Parameters for Isogeny-based Cryptography
JF - IACR Communications in Cryptology
JA - CIC
VL - 1
IS - 3
DO - 10.62056/ayojbhey6b
UR - https://doi.org/10.62056/ayojbhey6b
AB - <p> Isogeny-based schemes often come with special requirements on the field of definition of the involved elliptic curves. For instance, the efficiency of SQIsign, a promising candidate in the NIST signature standardisation process, requires a large power of two and a large smooth integer $T$ to divide $p^2-1$ for its prime parameter $p$. We present two new methods that combine previous techniques for finding suitable primes: sieve-and-boost and XGCD-and-boost. We use these methods to find primes for the NIST submission of SQIsign. Furthermore, we show that our methods are flexible and can be adapted to find suitable parameters for other isogeny-based schemes such as AprèsSQI or POKE. For all three schemes, the parameters we present offer the best performance among all parameters proposed in the literature. </p>
ER -
Maria Corte-Real Santos, Jonathan Komada Eriksen, Michael Meyer, and
Francisco Rodríguez-Henríquez, Finding Practical Parameters for Isogeny-based Cryptography. IACR Communications in Cryptology, vol. 1, no. 3, Oct 07, 2024, doi: 10.62056/ayojbhey6b.
Known citations
We do not crawl the web, so we are only able to identify
citations from papers that are registered with a DOI in
crossref.org and the publisher reports their citations to
crossref, and crossref can identify a DOI from the
reference. That includes (most) articles from Springer and
many from ACM, but it excludes citations from USENIX because
they don't issue DOIs. It also excludes citations from arxiv
and eprint. You may find more citations in
Google Scholar.