← Hardness assumptions

Supersingular Isogeny Problems

Proposed by: Couveignes (1997/2006), Rostovtsev–Stolbunov (2006) for ordinary curves; Charles–Goren–Lauter (2006), Jao–De Feo (2011), Castryck et al. (CSIDH 2018) for supersingular Category: Isogeny-based / post-quantum

Mathematical form

Supersingular isogeny path problem. Given two supersingular elliptic curves E1,E2E_1, E_2 over Fp2\mathbb{F}_{p^2}, find an isogeny φ:E1E2\varphi : E_1 \to E_2 (equivalently, a path in the \ell-isogeny graph, a Ramanujan expander with p/12\approx p/12 vertices).

Endomorphism ring problem. Given supersingular E/Fp2E/\mathbb{F}_{p^2}, compute End(E)\mathrm{End}(E) (a maximal order in a quaternion algebra). Wesolowski (2021): heuristically equivalent to the path problem.

Group-action (CSIDH/CSI-FiSh) problem. For the class group cl(O)\mathrm{cl}(\mathcal{O}) acting freely and transitively on Ep(O)\mathcal{E}\ell\ell_p(\mathcal{O}), given EE and aE\mathfrak{a} \star E, find a\mathfrak{a} — a “DLP-like” problem without a group law on ciphertexts.

Status — read carefully

Importance

Source: assumptions/isogeny.md — corrections welcome via pull request.