Communications in Cryptology IACR CiC

Finding Practical Parameters for Isogeny-based Cryptography


Maria Corte-Real Santos, Jonathan Komada Eriksen, Michael Meyer, Francisco Rodríguez-Henríquez
Maria Corte-Real Santos ORCID
University College London, London, UK
maria dot santos dot 20 at ucl dot ac dot uk
Jonathan Komada Eriksen ORCID
Norwegian University of Science and Technology, Trondheim, Norway
jonathan dot k dot eriksen at ntnu dot no
Michael Meyer ORCID
University of Regensburg, Regensburg, Germany
michael at random-oracles dot org
Francisco Rodríguez-Henríquez ORCID
Cryptography Research Center, Technology Innovation Institute, Abu Dhabi, United Arab Emirates
francisco dot rodriguez at tii dot ae


Isogeny-based schemes often come with special requirements on the field of definition of the involved elliptic curves. For instance, the efficiency of SQIsign, a promising candidate in the NIST signature standardisation process, requires a large power of two and a large smooth integer $T$ to divide $p^2-1$ for its prime parameter $p$. We present two new methods that combine previous techniques for finding suitable primes: sieve-and-boost and XGCD-and-boost. We use these methods to find primes for the NIST submission of SQIsign. Furthermore, we show that our methods are flexible and can be adapted to find suitable parameters for other isogeny-based schemes such as AprèsSQI or POKE. For all three schemes, the parameters we present offer the best performance among all parameters proposed in the literature.


Submitted: 2024-07-09
Accepted: 2024-09-02
Published: 2024-10-07
Maria Corte-Real Santos, Jonathan Komada Eriksen, Michael Meyer, and Francisco Rodríguez-Henríquez, Finding Practical Parameters for Isogeny-based Cryptography. IACR Communications in Cryptology, vol. 1, no. 3, Oct 07, 2024, 10.62056/ayojbhey6b.


Copyright is held by the author(s)

This work is licensed under a Creative Commons Attribution (CC BY) license.