{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,6]],"date-time":"2026-08-06T15:16:07Z","timestamp":1786029367707,"version":"3.56.0"},"publisher-location":"Cham","reference-count":71,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030033316","type":"print"},{"value":"9783030033323","type":"electronic"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-030-03332-3_15","type":"book-chapter","created":{"date-parts":[[2018,10,26]],"date-time":"2018-10-26T01:23:16Z","timestamp":1540516996000},"page":"395-427","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":420,"title":["CSIDH: An Efficient Post-Quantum Commutative Group Action"],"prefix":"10.1007","author":[{"given":"Wouter","family":"Castryck","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tanja","family":"Lange","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chloe","family":"Martindale","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lorenz","family":"Panny","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Joost","family":"Renes","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2018,10,26]]},"reference":[{"key":"15_CR1","doi-asserted-by":"crossref","unstructured":"Adj, G., Cervantes-V\u00e1zquez, D., Chi-Dom\u00ednguez, J.-J., Menezes, A., Rodr\u00edguez-Henr\u00edquez, F.: On the cost of computing isogenies between supersingular elliptic curves. In: SAC 2018 (2018)","DOI":"10.1007\/978-3-030-10970-7_15"},{"key":"15_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-3-319-16295-9_4","volume-title":"Progress in Cryptology \u2013 LATINCRYPT 2014","author":"DJ Bernstein","year":"2015","unstructured":"Bernstein, D.J., van Gastel, B., Janssen, W., Lange, T., Schwabe, P., Smetsers, S.: TweetNaCl: a crypto library in 100 tweets. In: Aranha, D.F., Menezes, A. (eds.) LATINCRYPT 2014. LNCS, vol. 8895, pp. 64\u201383. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-16295-9_4"},{"key":"15_CR3","doi-asserted-by":"crossref","unstructured":"Biasse, J.-F., Iezzi, A., Jacobson Jr., M.J.: A note on the security of CSIDH (2018). https:\/\/arxiv.org\/abs\/1806.03656. To be published at Kangacrypt 2018","DOI":"10.1007\/978-3-030-05378-9_9"},{"key":"15_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"428","DOI":"10.1007\/978-3-319-13039-2_25","volume-title":"Progress in Cryptology \u2013 INDOCRYPT 2014","author":"J-F Biasse","year":"2014","unstructured":"Biasse, J.-F., Jao, D., Sankar, A.: A quantum algorithm for computing isogenies between supersingular elliptic curves. In: Meier, W., Mukhopadhyay, D. (eds.) INDOCRYPT 2014. LNCS, vol. 8885, pp. 428\u2013442. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-13039-2_25"},{"issue":"2","key":"15_CR5","doi-asserted-by":"publisher","first-page":"101","DOI":"10.1515\/jmc.2011.008","volume":"5","author":"G Bisson","year":"2012","unstructured":"Bisson, G.: Computing endomorphism rings of elliptic curves under the GRH. J. Math. Cryptol. 5(2), 101\u2013114 (2012)","journal-title":"J. Math. Cryptol."},{"key":"15_CR6","unstructured":"Bonnetain, X., Schrottenloher, A.: Quantum security analysis of CSIDH and ordinary isogeny-based schemes. IACR Cryptology ePrint Archive 2018\/537, version 20180621:135910 (2018). https:\/\/eprint.iacr.org\/2018\/537\/20180621:135910"},{"key":"15_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"94","DOI":"10.1007\/3-540-38424-3_7","volume-title":"Advances in Cryptology-CRYPT0\u2019 90","author":"G Brassard","year":"1991","unstructured":"Brassard, G., Yung, M.: One-way group actions. In: Menezes, A.J., Vanstone, S.A. (eds.) CRYPTO 1990. LNCS, vol. 537, pp. 94\u2013107. Springer, Heidelberg (1991). https:\/\/doi.org\/10.1007\/3-540-38424-3_7"},{"issue":"264","key":"15_CR8","doi-asserted-by":"publisher","first-page":"2417","DOI":"10.1090\/S0025-5718-08-02091-7","volume":"77","author":"R Br\u00f6ker","year":"2008","unstructured":"Br\u00f6ker, R.: A $$p$$-adic algorithm to compute the Hilbert class polynomial. Math. Comput. 77(264), 2417\u20132435 (2008)","journal-title":"Math. Comput."},{"issue":"260","key":"15_CR9","doi-asserted-by":"publisher","first-page":"2161","DOI":"10.1090\/S0025-5718-07-01980-1","volume":"76","author":"R Br\u00f6ker","year":"2007","unstructured":"Br\u00f6ker, R., Stevenhagen, P.: Efficient CM-constructions of elliptic curves over finite fields. Math. Comput. 76(260), 2161\u20132179 (2007)","journal-title":"Math. Comput."},{"key":"15_CR10","series-title":"Algorithms and Computation in Mathematics","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-46368-9","volume-title":"Binary Quadratic Forms: An Algorithmic Approach","author":"J Buchmann","year":"2007","unstructured":"Buchmann, J., Vollmer, U.: Binary Quadratic Forms: An Algorithmic Approach. Algorithms and Computation in Mathematics, vol. 20. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-46368-9"},{"issue":"1","key":"15_CR11","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1007\/s00145-007-9002-x","volume":"22","author":"DX Charles","year":"2009","unstructured":"Charles, D.X., Lauter, K.E., Goren, E.Z.: Cryptographic hash functions from expander graphs. J. Cryptol. 22(1), 93\u2013113 (2009)","journal-title":"J. Cryptol."},{"issue":"1","key":"15_CR12","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1515\/jmc-2012-0016","volume":"8","author":"AM Childs","year":"2014","unstructured":"Childs, A.M., Jao, D., Soukharev, V.: Constructing elliptic curve isogenies in quantum subexponential time. J. Math. Cryptol. 8(1), 1\u201329 (2014)","journal-title":"J. Math. Cryptol."},{"key":"15_CR13","series-title":"Lecture Notes in Mathematics","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/BFb0099440","volume-title":"Number Theory Noordwijkerhout 1983","author":"H Cohen","year":"1984","unstructured":"Cohen, H., Lenstra Jr., H.W.: Heuristics on class groups of number fields. In: Jager, H. (ed.) Number Theory Noordwijkerhout 1983. LNM, vol. 1068, pp. 33\u201362. Springer, Heidelberg (1984)"},{"key":"15_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"303","DOI":"10.1007\/978-3-319-70697-9_11","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2017","author":"C Costello","year":"2017","unstructured":"Costello, C., Hisil, H.: A simple and compact algorithm for SIDH with arbitrary degree isogenies. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017. LNCS, vol. 10625, pp. 303\u2013329. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70697-9_11"},{"key":"15_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"572","DOI":"10.1007\/978-3-662-53018-4_21","volume-title":"Advances in Cryptology \u2013 CRYPTO 2016","author":"C Costello","year":"2016","unstructured":"Costello, C., Longa, P., Naehrig, M.: Efficient algorithms for supersingular isogeny Diffie-Hellman. In: Robshaw, M., Katz, J. (eds.) CRYPTO 2016. LNCS, vol. 9814, pp. 572\u2013601. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53018-4_21"},{"key":"15_CR16","unstructured":"Costello, C., Smith, B.: Montgomery curves and their arithmetic: the case of large characteristic fields. IACR Cryptology ePrint Archive 2017\/212 (2017). https:\/\/ia.cr\/2017\/212"},{"key":"15_CR17","unstructured":"Couveignes, J.-M.: Hard homogeneous spaces. IACR Cryptology ePrint Archive 2006\/291 (2006). https:\/\/ia.cr\/2006\/291"},{"key":"15_CR18","series-title":"Pure and Applied Mathematics","doi-asserted-by":"publisher","DOI":"10.1002\/9781118400722","volume-title":"Primes of the Form $$x^2+ny^2$$: Fermat, Class Field Theory, and Complex Multiplication","author":"DA Cox","year":"2013","unstructured":"Cox, D.A.: Primes of the Form $$x^2+ny^2$$: Fermat, Class Field Theory, and Complex Multiplication. Pure and Applied Mathematics, 2nd edn. Wiley, Hoboken (2013)","edition":"2"},{"key":"15_CR19","unstructured":"De Feo, L.: Mathematics of isogeny based cryptography (2017). https:\/\/arxiv.org\/abs\/1711.04062"},{"issue":"3","key":"15_CR20","doi-asserted-by":"crossref","first-page":"209","DOI":"10.1515\/jmc-2012-0015","volume":"8","author":"L De Feo","year":"2014","unstructured":"De Feo, L., Jao, D., Pl\u00fbt, J.: Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies. J. Math. Cryptol. 8(3), 209\u2013247 (2014)","journal-title":"J. Math. Cryptol."},{"key":"15_CR21","doi-asserted-by":"crossref","unstructured":"De Feo, L., Kieffer, J., Smith, B.: Towards practical key exchange from ordinary isogeny graphs. In: Galbraith, S.D., Peyrin, T. (eds.) ASIACRYPT 2018, LNCS, vol. 11274, pp. xx\u2013yy. Springer, Heidelberg (2018)","DOI":"10.1007\/978-3-030-03332-3_14"},{"issue":"2","key":"15_CR22","doi-asserted-by":"publisher","first-page":"425","DOI":"10.1007\/s10623-014-0010-1","volume":"78","author":"C Delfs","year":"2016","unstructured":"Delfs, C., Galbraith, S.D.: Computing isogenies between supersingular elliptic curves over $$\\mathbb{F}_p$$. Des. Codes Cryptogr. 78(2), 425\u2013440 (2016)","journal-title":"Des. Codes Cryptogr."},{"issue":"6","key":"15_CR23","doi-asserted-by":"publisher","first-page":"644","DOI":"10.1109\/TIT.1976.1055638","volume":"22","author":"W Diffie","year":"1976","unstructured":"Diffie, W., Hellman, M.E.: New directions in cryptography. IEEE Trans. Inf. Theory 22(6), 644\u2013654 (1976)","journal-title":"IEEE Trans. Inf. Theory"},{"key":"15_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1007\/3-540-47721-7_12","volume-title":"Advances in Cryptology\u2014CRYPTO\u2019 86","author":"A Fiat","year":"1987","unstructured":"Fiat, A., Shamir, A.: How to prove yourself: practical solutions to identification and signature problems. In: Odlyzko, A.M. (ed.) CRYPTO 1986. LNCS, vol. 263, pp. 186\u2013194. Springer, Heidelberg (1987). https:\/\/doi.org\/10.1007\/3-540-47721-7_12"},{"key":"15_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"254","DOI":"10.1007\/978-3-642-36362-7_17","volume-title":"Public-Key Cryptography \u2013 PKC 2013","author":"ESV Freire","year":"2013","unstructured":"Freire, E.S.V., Hofheinz, D., Kiltz, E., Paterson, K.G.: Non-interactive key exchange. In: Kurosawa, K., Hanaoka, G. (eds.) PKC 2013. LNCS, vol. 7778, pp. 254\u2013271. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-36362-7_17"},{"key":"15_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"537","DOI":"10.1007\/3-540-48405-1_34","volume-title":"Advances in Cryptology\u2014CRYPTO\u2019 99","author":"E Fujisaki","year":"1999","unstructured":"Fujisaki, E., Okamoto, T.: Secure integration of asymmetric and symmetric encryption schemes. In: Wiener, M. (ed.) CRYPTO 1999. LNCS, vol. 1666, pp. 537\u2013554. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-48405-1_34"},{"key":"15_CR27","doi-asserted-by":"publisher","first-page":"118","DOI":"10.1112\/S1461157000000097","volume":"2","author":"SD Galbraith","year":"1999","unstructured":"Galbraith, S.D.: Constructing isogenies between elliptic curves over finite fields. LMS J. Computat. Math. 2, 118\u2013138 (1999)","journal-title":"LMS J. Computat. Math."},{"key":"15_CR28","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9781139012843","volume-title":"Mathematics of Public-Key Cryptography","author":"SD Galbraith","year":"2012","unstructured":"Galbraith, S.D.: Mathematics of Public-Key Cryptography. Cambridge University Press, Cambridge (2012)"},{"key":"15_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1007\/978-3-662-53887-6_3","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2016","author":"SD Galbraith","year":"2016","unstructured":"Galbraith, S.D., Petit, C., Shani, B., Ti, Y.B.: On the security of supersingular isogeny cryptosystems. In: Cheon, J.H., Takagi, T. (eds.) ASIACRYPT 2016. LNCS, vol. 10031, pp. 63\u201391. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53887-6_3"},{"key":"15_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-70694-8_1","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2017","author":"SD Galbraith","year":"2017","unstructured":"Galbraith, S.D., Petit, C., Silva, J.: Identification protocols and signature schemes based on supersingular isogeny problems. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017. LNCS, vol. 10624, pp. 3\u201333. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70694-8_1"},{"key":"15_CR31","doi-asserted-by":"crossref","unstructured":"Galbraith, S.D., Vercauteren, F.: Computational problems in supersingular elliptic curve isogenies. Quant. Inf. Process. 17. IACR Cryptology ePrint Archive 2017\/774 (2018). https:\/\/ia.cr\/2017\/774","DOI":"10.1007\/s11128-018-2023-6"},{"key":"15_CR32","doi-asserted-by":"crossref","unstructured":"Grover, L.K.: A fast quantum mechanical algorithm for database search. In: STOC, pp. 212\u2013219. ACM (1996)","DOI":"10.1145\/237814.237866"},{"issue":"4","key":"15_CR33","doi-asserted-by":"publisher","first-page":"837","DOI":"10.1090\/S0894-0347-1989-1002631-0","volume":"2","author":"JL Hafner","year":"1989","unstructured":"Hafner, J.L., McCurley, K.S.: A rigorous subexponential algorithm for computation of class groups. J. Am. Math. Soc. 2(4), 837\u2013850 (1989)","journal-title":"J. Am. Math. Soc."},{"key":"15_CR34","doi-asserted-by":"crossref","unstructured":"Hallgren, S.: Fast quantum algorithms for computing the unit group and class group of a number field. In: STOC, pp. 468\u2013474. ACM (2005)","DOI":"10.1145\/1060590.1060660"},{"key":"15_CR35","doi-asserted-by":"crossref","unstructured":"Hasse, H.: Zur Theorie der abstrakten elliptischen Funktionenk\u00f6rper III. Die Struktur des Meromorphismenrings. Die Riemannsche Vermutung. J. f\u00fcr die reine und angewandte Mathematik 175, 193\u2013208 (1936)","DOI":"10.1515\/crll.1936.175.193"},{"key":"15_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1007\/978-3-319-70500-2_12","volume-title":"Theory of Cryptography","author":"D Hofheinz","year":"2017","unstructured":"Hofheinz, D., H\u00f6velmanns, K., Kiltz, E.: A Modular analysis of the Fujisaki-Okamoto transformation. In: Kalai, Y., Reyzin, L. (eds.) TCC 2017. LNCS, vol. 10677, pp. 341\u2013371. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70500-2_12"},{"key":"15_CR37","unstructured":"Jao, D., Azarderakhsh, R., Campagna, M., Costello, C., De Feo, L., Hess, B., Jalali, A., Koziel, B., LaMacchia, B., Longa, P., Naehrig, M., Renes, J., Soukharev, V., Urbanik, D.: SIKE. Submission to [48]. http:\/\/sike.org"},{"key":"15_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-642-25405-5_2","volume-title":"Post-Quantum Cryptography","author":"D Jao","year":"2011","unstructured":"Jao, D., De Feo, L.: Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies. In: Yang, B.-Y. (ed.) PQCrypto 2011. LNCS, vol. 7071, pp. 19\u201334. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25405-5_2"},{"key":"15_CR39","unstructured":"Jao, D., LeGrow, J., Leonardi, C., Ruiz-Lopez, L.: A subexponential-time, polynomial quantum space algorithm for inverting the CM group action. In: MathCrypt 2018 (2018, to appear)"},{"issue":"6","key":"15_CR40","doi-asserted-by":"publisher","first-page":"1491","DOI":"10.1016\/j.jnt.2008.11.006","volume":"129","author":"D Jao","year":"2009","unstructured":"Jao, D., Miller, S.D., Venkatesan, R.: Expander graphs based on GRH with an application to elliptic curve cryptography. J. Number Theory 129(6), 1491\u20131504 (2009)","journal-title":"J. Number Theory"},{"key":"15_CR41","unstructured":"Kieffer, J.: \u00c9tude et acc\u00e9l\u00e9ration du protocole d\u2019\u00e9change de cl\u00e9s de Couveignes-Rostovtsev-Stolbunov. M\u00e9moire du Master 2, Universit\u00e9 Paris VI (2017). https:\/\/arxiv.org\/abs\/1804.10128"},{"key":"15_CR42","unstructured":"Kohel, D.: Endomorphism rings of elliptic curves over finite fields. Ph.D. thesis, University of California at Berkeley (1996)"},{"issue":"1","key":"15_CR43","doi-asserted-by":"publisher","first-page":"170","DOI":"10.1137\/S0097539703436345","volume":"35","author":"G Kuperberg","year":"2005","unstructured":"Kuperberg, G.: A subexponential-time quantum algorithm for the dihedral hidden subgroup problem. SIAM J. Comput. 35(1), 170\u2013188 (2005)","journal-title":"SIAM J. Comput."},{"key":"15_CR44","unstructured":"Kuperberg, G.: Another subexponential-time quantum algorithm for the dihedral hidden subgroup problem. In: TQC, LIPIcs, vol. 22, pp. 20\u201334. Schloss Dagstuhl - Leibniz-Zentrum f\u00fcr Informatik (2013)"},{"key":"15_CR45","doi-asserted-by":"publisher","first-page":"515","DOI":"10.1007\/BF01457454","volume":"261","author":"HW Lenstra Jr","year":"1982","unstructured":"Lenstra Jr., H.W., Lenstra, A.K., Lov\u00e1sz, L.: Factoring polynomials with rational coefficients. Math. Ann. 261, 515\u2013534 (1982)","journal-title":"Math. Ann."},{"issue":"177","key":"15_CR46","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1090\/S0025-5718-1987-0866113-7","volume":"48","author":"PL Montgomery","year":"1987","unstructured":"Montgomery, P.L.: Speeding the Pollard and elliptic curve methods of factorization. Math. Comput. 48(177), 243\u2013264 (1987)","journal-title":"Math. Comput."},{"issue":"2","key":"15_CR47","doi-asserted-by":"publisher","first-page":"145","DOI":"10.2307\/2312481","volume":"68","author":"LJ Mordell","year":"1961","unstructured":"Mordell, L.J.: The congruence $$(p-1\/2)! \\equiv \\pm 1\\ ({\\rm mod}\\ p)$$. Am. Math. Mon. 68(2), 145\u2013146 (1961)","journal-title":"Am. Math. Mon."},{"key":"15_CR48","unstructured":"National Institute of Standards and Technology: Post-quantum Cryptography Standardization, December 2016. https:\/\/csrc.nist.gov\/Projects\/Post-Quantum-Cryptography\/Post-Quantum-Cryptography-Standardization"},{"key":"15_CR49","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-02295-1","volume-title":"The LLL Algorithm","year":"2010","unstructured":"Nguyen, P.Q., Vall\u00e9e, B. (eds.): The LLL Algorithm. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-02295-1"},{"key":"15_CR50","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"330","DOI":"10.1007\/978-3-319-70697-9_12","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2017","author":"C Petit","year":"2017","unstructured":"Petit, C.: Faster algorithms for isogeny problems using torsion point images. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017. LNCS, vol. 10625, pp. 330\u2013353. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70697-9_12"},{"issue":"1","key":"15_CR51","doi-asserted-by":"publisher","first-page":"127","DOI":"10.1090\/S0273-0979-1990-15918-X","volume":"23","author":"AK Pizer","year":"1990","unstructured":"Pizer, A.K.: Ramanujan graphs and Hecke operators. Bull. Am. Math. Soc. (N.S.) 23(1), 127\u2013137 (1990)","journal-title":"Bull. Am. Math. Soc. (N.S.)"},{"key":"15_CR52","unstructured":"Regev, O.: A subexponential time algorithm for the dihedral hidden subgroup problem with polynomial space (2004). https:\/\/arxiv.org\/abs\/quant-ph\/0406151"},{"key":"15_CR53","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"229","DOI":"10.1007\/978-3-319-79063-3_11","volume-title":"Post-Quantum Cryptography","author":"J Renes","year":"2018","unstructured":"Renes, J.: Computing isogenies between Montgomery curves using the action of (0, 0). In: Lange, T., Steinwandt, R. (eds.) PQCrypto 2018. LNCS, vol. 10786, pp. 229\u2013247. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-79063-3_11"},{"key":"15_CR54","unstructured":"Rostovtsev, A., Stolbunov, A.: Public-key cryptosystem based on isogenies. IACR Cryptology ePrint Archive 2006\/145 (2006). https:\/\/ia.cr\/2006\/145"},{"issue":"2","key":"15_CR55","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1016\/0097-3165(87)90003-3","volume":"46","author":"R Schoof","year":"1987","unstructured":"Schoof, R.: Nonsingular plane cubic curves over finite fields. J. Comb. Theory Ser. A 46(2), 183\u2013211 (1987)","journal-title":"J. Comb. Theory Ser. A"},{"key":"15_CR56","doi-asserted-by":"crossref","unstructured":"Shanks, D.: Class number, a theory of factorization, and genera. In: Proceedings of Symposia in Pure Mathematics, vol. 20, pp. 415\u2013440 (1971)","DOI":"10.1090\/pspum\/020\/0316385"},{"issue":"5","key":"15_CR57","doi-asserted-by":"publisher","first-page":"1484","DOI":"10.1137\/S0097539795293172","volume":"26","author":"PW Shor","year":"1997","unstructured":"Shor, P.W.: Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM J. Comput. 26(5), 1484\u20131509 (1997)","journal-title":"SIAM J. Comput."},{"issue":"1","key":"15_CR58","doi-asserted-by":"publisher","first-page":"83","DOI":"10.4064\/aa-1-1-83-86","volume":"1","author":"C Siegel","year":"1935","unstructured":"Siegel, C.: \u00dcber die Classenzahl quadratischer Zahlk\u00f6rper. Acta Arithmetica 1(1), 83\u201386 (1935)","journal-title":"Acta Arithmetica"},{"key":"15_CR59","series-title":"Graduate Texts in Mathematics","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-09494-6","volume-title":"The Arithmetic of Elliptic Curves","author":"JH Silverman","year":"2009","unstructured":"Silverman, J.H.: The Arithmetic of Elliptic Curves. Graduate Texts in Mathematics, vol. 106, 2nd edn. Springer, New York (2009). https:\/\/doi.org\/10.1007\/978-0-387-09494-6","edition":"2"},{"key":"15_CR60","unstructured":"Stolbunov, A.: Public-key encryption based on cycles of isogenous elliptic curves. Master\u2019s thesis, Saint-Petersburg State Polytechnical University (2004). (in Russian)"},{"issue":"2","key":"15_CR61","doi-asserted-by":"publisher","first-page":"215","DOI":"10.3934\/amc.2010.4.215","volume":"4","author":"A Stolbunov","year":"2010","unstructured":"Stolbunov, A.: Constructing public-key cryptographic schemes based on class group action on a set of isogenous elliptic curves. Adv. Math. Commun. 4(2), 215\u2013235 (2010)","journal-title":"Adv. Math. Commun."},{"key":"15_CR62","unstructured":"Stolbunov, A.: Cryptographic schemes based on isogenies. Ph.D. thesis, Norwegian University of Science and Technology (2011)"},{"key":"15_CR63","unstructured":"Sutherland, A.V.: Order computations in generic groups. Ph.D. thesis, Massachusetts Institute of Technology (2007). https:\/\/groups.csail.mit.edu\/cis\/theses\/sutherland-phd.pdf"},{"key":"15_CR64","doi-asserted-by":"publisher","first-page":"317","DOI":"10.1112\/S1461157012001106","volume":"15","author":"AV Sutherland","year":"2012","unstructured":"Sutherland, A.V.: Identifying supersingular elliptic curves. LMS J. Comput. Math. 15, 317\u2013325 (2012)","journal-title":"LMS J. Comput. Math."},{"key":"15_CR65","doi-asserted-by":"crossref","unstructured":"Sutherland, A.V.: Isogeny volcanoes. In: ANTS X. Open Book Series, vol. 1, pp. 507\u2013530. MSP (2012). https:\/\/arxiv.org\/abs\/1208.5370","DOI":"10.2140\/obs.2013.1.507"},{"issue":"2","key":"15_CR66","doi-asserted-by":"publisher","first-page":"134","DOI":"10.1007\/BF01404549","volume":"2","author":"J Tate","year":"1966","unstructured":"Tate, J.: Endomorphisms of abelian varieties over finite fields. Inventiones Mathematicae 2(2), 134\u2013144 (1966)","journal-title":"Inventiones Mathematicae"},{"key":"15_CR67","unstructured":"The Sage Developers: SageMath, The Sage Mathematics Software System, Version 8.1 (2018). https:\/\/sagemath.org"},{"key":"15_CR68","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"135","DOI":"10.1007\/978-3-642-29011-4_10","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2012","author":"D Unruh","year":"2012","unstructured":"Unruh, D.: Quantum proofs of knowledge. In: Pointcheval, D., Johansson, T. (eds.) EUROCRYPT 2012. LNCS, vol. 7237, pp. 135\u2013152. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-29011-4_10"},{"key":"15_CR69","first-page":"238","volume":"273","author":"J V\u00e9lu","year":"1971","unstructured":"V\u00e9lu, J.: Isog\u00e9nies entre courbes elliptiques. Comptes Rendus de l\u2019Acad\u00e9mie des Sciences de Paris 273, 238\u2013241 (1971)","journal-title":"Comptes Rendus de l\u2019Acad\u00e9mie des Sciences de Paris"},{"key":"15_CR70","doi-asserted-by":"publisher","first-page":"521","DOI":"10.24033\/asens.1183","volume":"2","author":"WC Waterhouse","year":"1969","unstructured":"Waterhouse, W.C.: Abelian varieties over finite fields. Annales scientifiques de l\u2019\u00c9cole Normale Sup\u00e9rieure 2, 521\u2013560 (1969)","journal-title":"Annales scientifiques de l\u2019\u00c9cole Normale Sup\u00e9rieure"},{"key":"15_CR71","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1007\/978-3-319-70972-7_9","volume-title":"Financial Cryptography and Data Security","author":"Y Yoo","year":"2017","unstructured":"Yoo, Y., Azarderakhsh, R., Jalali, A., Jao, D., Soukharev, V.: A post-quantum digital signature scheme based on supersingular isogenies. In: Kiayias, A. (ed.) FC 2017. LNCS, vol. 10322, pp. 163\u2013181. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70972-7_9"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 ASIACRYPT 2018"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-03332-3_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,11,22]],"date-time":"2021-11-22T01:11:28Z","timestamp":1637543488000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-03332-3_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783030033316","9783030033323"],"references-count":71,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-03332-3_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]},"assertion":[{"value":"26 October 2018","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ASIACRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on the Theory and Application of Cryptology and Information Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Brisbane, QLD","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2 December 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6 December 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"asiacrypt2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/asiacrypt.iacr.org\/2018\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"websubrev","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"234","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"65","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"28% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.0","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"17.0","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}