On the decisional Diffie-Hellman problem for class group actions on oriented elliptic curves

10/03/2022
by   Wouter Castryck, et al.
0

We show how the Weil pairing can be used to evaluate the assigned characters of an imaginary quadratic order 𝒪 in an unknown ideal class [𝔞] ∈Cl(𝒪) that connects two given 𝒪-oriented elliptic curves (E, ι) and (E', ι') = [𝔞](E, ι). When specialized to ordinary elliptic curves over finite fields, our method is conceptually simpler and often somewhat faster than a recent approach due to Castryck, Sotáková and Vercauteren, who rely on the Tate pairing instead. The main implication of our work is that it breaks the decisional Diffie-Hellman problem for practically all oriented elliptic curves that are acted upon by an even-order class group. It can also be used to better handle the worst cases in Wesolowski's recent reduction from the vectorization problem for oriented elliptic curves to the endomorphism ring problem, leading to a method that always works in sub-exponential time.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/27/2023

On the Discrete Logarithm Problem for elliptic curves over local fields

The Discrete Logarithm Problem (DLP) for elliptic curves has been extens...
research
06/10/2018

A note on the security of CSIDH

We propose an algorithm for computing an isogeny between two elliptic cu...
research
09/30/2022

Formalized Class Group Computations and Integral Points on Mordell Elliptic Curves

Diophantine equations are a popular and active area of research in numbe...
research
11/29/2022

Trustless unknown-order groups

Groups of unknown order are of major interest due to their applications ...
research
07/19/2021

Higher-degree supersingular group actions

We investigate the isogeny graphs of supersingular elliptic curves over ...
research
04/26/2018

Accelerating the Couveignes Rostovtsev Stolbunov key exchange protocol

We study a key exchange protocol based on isogenies between ordinary ell...
research
09/21/2023

The supersingular endomorphism ring problem given one endomorphism

Given a supersingular elliptic curve E and a non-scalar endomorphism α o...

Please sign up or login with your details

Forgot password? Click here to reset