HOW TO CONSTRUCT CSIDH ON QUADRATIC AND TWISTED EDWARDS CURVES
Open Access
- 1 January 2022
- journal article
- Published by Borys Grinchenko Kyiv University in Cybersecurity: Education, Science, Technique
- Vol. 3 (15), 148-163
- https://doi.org/10.28925/2663-4023.2022.15.148163
Abstract
In one of the famous works, an incorrect formulation and an incorrect solution of the implementation problem of the CSIDH algorithm on Edwards curves is discovered. A detailed critique of this work with a proof of the fallacy of its concept is given. Specific properties of three non-isomorphic classes of supersingular curves in the generalized Edwards form is considered: complete, quadratic, and twisted Edwards curves. Conditions for the existence of curves of all classes with the order p+1 of curves over a prime field are determined. The implementation of the CSIDH algorithm on isogenies of odd prime degrees based on the use of quadratic twist pairs of elliptic curves. To this end, the CSIDH algorithm can be construct both on complete Edwards curves with quadratic twist within this class, and on quadratic and twisted Edwards curves forming pairs of quadratic twist. In contrast to this, the authors of a well-known work are trying to prove theorems with statement about existing a solution within one class of curves with a parameter that is a square. The critical analysis of theorems, lemmas, and erroneous statements in this work is given. Theorem 2 on quadratic twist in classes of Edwards curves is proved. A modification of the CSIDH algorithm based on isogenies of quadratic and twisted Edwards curves is presented. To illustrate the correct solution of the problem, an example of Alice and Bob calculations in the secret sharing scheme according to the CSIDH algorithm is considered.Keywords
This publication has 13 references indexed in Scilit:
- Optimized Method for Computing Odd-Degree Isogenies on Edwards CurvesPublished by Springer Science and Business Media LLC ,2019
- Supersingular Twisted Edwards Curves over Prime Fields.* II. Supersingular Twisted Edwards Curves with the j-Invariant Equal to 663Cybernetics and Systems Analysis, 2019
- Supersingular Twisted Edwards Curves Over Prime Fields. I. Supersingular Twisted Edwards Curves with j-Invariants Equal to Zero and 123Cybernetics and Systems Analysis, 2019
- Towards Optimized and Constant-Time CSIDH on Embedded DevicesPublished by Springer Science and Business Media LLC ,2019
- CSIDH: An Efficient Post-Quantum Commutative Group ActionPublished by Springer Science and Business Media LLC ,2018
- Differential Addition on Twisted Edwards CurvesLecture Notes in Computer Science, 2017
- Number of curves in the generalized Edwards form with minimal even cofactor of the curve orderProblems of Information Transmission, 2017
- Analogues of Vélu’s formulas for isogenies on alternate models of elliptic curvesMathematics of Computation, 2015
- Twisted Edwards CurvesPublished by Springer Science and Business Media LLC ,2008
- Faster Addition and Doubling on Elliptic CurvesPublished by Springer Science and Business Media LLC ,2007