Breaking the decisional Diffie-Hellman problem for class group actions using genus theory

Open Access
Authors
Publication date 2020
Host editors
  • D. Micciancio
  • T. Ristenpart
Book title Advances in Cryptology – CRYPTO 2020
Book subtitle 40th Annual International Cryptology Conference, CRYPTO 2020, Santa Barbara, CA, USA, August 17–21, 2020 : proceedings
ISBN
  • 9783030568795
ISBN (electronic)
  • 9783030568801
Series Lecture Notes in Computer Science
Event 40th Annual International Cryptology Conference
Volume | Issue number II
Pages (from-to) 92-120
Publisher Cham: Springer
Organisations
  • Interfacultary Research - Institute for Logic, Language and Computation (ILLC)
Abstract
In this paper, we use genus theory to analyze the hardness of the decisional Diffie--Hellman problem (DDH) for ideal class groups of imaginary quadratic orders, acting on sets of elliptic curves through isogenies; such actions are used in the Couveignes--Rostovtsev--Stolbunov protocol and in CSIDH. Concretely, genus theory equips every imaginary quadratic order O with a set of assigned characters χ:cl(O)→{±1}, and for each such character and every secret ideal class [a] connecting two public elliptic curves E and E′=[a]⋆E, we show how to compute χ([a]) given only E and E′, i.e., without knowledge of [a]. In practice, this breaks DDH as soon as the class number is even, which is true for a density 1 subset of all imaginary quadratic orders. For instance, our attack works very efficiently for all supersingular elliptic curves over Fp with p≡1mod4. Our method relies on computing Tate pairings and walking down isogeny volcanoes.
Document type Conference contribution
Language English
Published at https://doi.org/10.1007/978-3-030-56880-1_4
Published at https://eprint.iacr.org/2020/151
Downloads
2020-151 (Accepted author manuscript)
Permalink to this page
Back