Post-quantum cryptography from supersingular isogeny problems?

We review existing cryptographic schemes based on the hardness of computing isogenies between supersingular isogenies, and present some attacks against them. In particular, we present new techniques to accelerate the resolution of isogeny problems when the action of the isogeny on a large torsion subgroup is known, and we discuss the impact of these techniques on the supersingular key exchange protocol of Jao-de Feo.

Date:
Speakers:
Christophe Petit
Affiliation:
University of Birmingham