{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T01:13:21Z","timestamp":1779326001083,"version":"3.51.4"},"publisher-location":"Cham","reference-count":39,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030842512","type":"print"},{"value":"9783030842529","type":"electronic"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-84252-9_15","type":"book-chapter","created":{"date-parts":[[2021,8,10]],"date-time":"2021-08-10T23:04:26Z","timestamp":1628636666000},"page":"432-470","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":30,"title":["Improved Torsion-Point Attacks on SIDH Variants"],"prefix":"10.1007","author":[{"given":"Victoria","family":"de Quehen","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"P\u00e9ter","family":"Kutas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chris","family":"Leonardi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chloe","family":"Martindale","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lorenz","family":"Panny","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christophe","family":"Petit","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Katherine E.","family":"Stange","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,8,11]]},"reference":[{"key":"15_CR1","doi-asserted-by":"publisher","unstructured":"Adj, G., Cervantes-V\u00e1zquez, D., Chi-Dom\u00ednguez, J.-J., Menezes, A., Rodr\u00edguez-Henr\u00edquez, F.: On the cost of computing isogenies between supersingular elliptic curves. In: Cid, C., Jacobson Jr, M. (eds.) SAC 2018. LNCS, vol. 11349, pp. 322\u2013343. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-10970-7_15","DOI":"10.1007\/978-3-030-10970-7_15"},{"key":"15_CR2","unstructured":"Azarderakhsh, R., Jalali, A., Jao, D., Soukharev, V.: Practical supersingular isogeny group key agreement. IACR Cryptology ePrint Archive 2019\/330 (2019)"},{"key":"15_CR3","unstructured":"Batut, C., Belabas, K., Bernardi, D., Cohen, H., Olivier, M.: User\u2019s Guide to PARI-GP. Universit\u00e9 de Bordeaux I. https:\/\/pari.math.u-bordeaux.fr\/"},{"key":"15_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"428","DOI":"10.1007\/978-3-319-13039-2_25","volume-title":"Progress in Cryptology \u2013 INDOCRYPT 2014","author":"J-F Biasse","year":"2014","unstructured":"Biasse, J.-F., Jao, D., Sankar, A.: A quantum algorithm for computing isogenies between supersingular elliptic curves. In: Meier, W., Mukhopadhyay, D. (eds.) INDOCRYPT 2014. LNCS, vol. 8885, pp. 428\u2013442. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-13039-2_25"},{"key":"15_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"520","DOI":"10.1007\/978-3-030-64834-3_18","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"D Boneh","year":"2020","unstructured":"Boneh, D., Kogan, D., Woo, K.: Oblivious pseudorandom functions from isogenies. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020, Part II. LNCS, vol. 12492, pp. 520\u2013550. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_18"},{"key":"15_CR6","doi-asserted-by":"crossref","unstructured":"Bosma, W., Cannon, J., Playoust, C.: The Magma algebra system I: the user language. J. Symbolic Comput. 24(3\u20134), 235\u2013265 (1997). https:\/\/magma.maths.usyd.edu.au\/","DOI":"10.1006\/jsco.1996.0125"},{"key":"15_CR7","unstructured":"Bottinelli, P., de Quehen, V., Leonardi, C., Mosunov, A., Pawlega, F., Sheth, M.: The dark SIDH of isogenies. IACR Cryptology ePrint Archive 2019\/1333 (2019)"},{"key":"15_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"395","DOI":"10.1007\/978-3-030-03332-3_15","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2018","author":"W Castryck","year":"2018","unstructured":"Castryck, W., Lange, T., Martindale, C., Panny, L., Renes, J.: CSIDH: an efficient post-quantum commutative group action. In: Peyrin, T., Galbraith, S. (eds.) ASIACRYPT 2018, Part III. LNCS, vol. 11274, pp. 395\u2013427. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03332-3_15"},{"key":"15_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"523","DOI":"10.1007\/978-3-030-45724-2_18","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2020","author":"W Castryck","year":"2020","unstructured":"Castryck, W., Panny, L., Vercauteren, F.: Rational isogenies from irrational endomorphisms. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT 2020, Part II. LNCS, vol. 12106, pp. 523\u2013548. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45724-2_18"},{"issue":"1","key":"15_CR10","doi-asserted-by":"publisher","first-page":"414","DOI":"10.1515\/jmc-2019-0034","volume":"14","author":"L Col\u00f2","year":"2020","unstructured":"Col\u00f2, L., David, K.: Orienting supersingular isogeny graphs. J. Math. Cryptology 14(1), 414\u2013437 (2020)","journal-title":"J. Math. Cryptology"},{"key":"15_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"440","DOI":"10.1007\/978-3-030-64834-3_15","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"C Costello","year":"2020","unstructured":"Costello, C.: B-SIDH: supersingular isogeny Diffie-Hellman using twisted torsion. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020, Part II. LNCS, vol. 12492, pp. 440\u2013463. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_15"},{"issue":"243","key":"15_CR12","doi-asserted-by":"publisher","first-page":"1417","DOI":"10.1090\/S0025-5718-02-01480-1","volume":"72","author":"J Cremona","year":"2003","unstructured":"Cremona, J., David, R.: Efficient solution of rational conics. Math. Comput. 72(243), 1417\u20131441 (2003)","journal-title":"Math. Comput."},{"key":"15_CR13","unstructured":"de Quehen, V., et al.: Improved torsion-point attacks on SIDH variants. Full version of this article. IACR Cryptology ePrint Archive 2020\/633 (2021). https:\/\/ia.cr\/2020\/633"},{"key":"15_CR14","unstructured":"Delpech de Saint Guilhem, C., Kutas, P., Petit, C., Silva, J.: S\u00c9TA: supersingular encryption from torsion attacks. IACR Cryptology ePrint Archive 2019\/1291 (2019)"},{"issue":"2","key":"15_CR15","doi-asserted-by":"publisher","first-page":"425","DOI":"10.1007\/s10623-014-0010-1","volume":"78","author":"C Delfs","year":"2016","unstructured":"Delfs, C., Galbraith, S.D.: Computing isogenies between supersingular elliptic curves over $$\\mathbb{F}_p$$. Des. Codes Crypt. 78(2), 425\u2013440 (2016)","journal-title":"Des. Codes Crypt."},{"key":"15_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"329","DOI":"10.1007\/978-3-319-78372-7_11","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2018","author":"K Eisentr\u00e4ger","year":"2018","unstructured":"Eisentr\u00e4ger, K., Hallgren, S., Lauter, K., Morrison, T., Petit, C.: Supersingular isogeny graphs and endomorphism rings: reductions and solutions. In: Nielsen, J.B., Rijmen, V. (eds.) EUROCRYPT 2018, Part III. LNCS, vol. 10822, pp. 329\u2013368. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-78372-7_11"},{"key":"15_CR17","doi-asserted-by":"crossref","unstructured":"Furukawa, S., Kunihiro, N., Takashima, K.: Multi-party key exchange protocols from supersingular isogenies. In: ISITA, pp. 208\u2013212. IEEE (2018)","DOI":"10.23919\/ISITA.2018.8664316"},{"key":"15_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1007\/978-3-662-53887-6_3","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2016","author":"SD Galbraith","year":"2016","unstructured":"Galbraith, S.D., Petit, C., Shani, B., Ti, Y.B.: On the security of supersingular isogeny cryptosystems. In: Cheon, J.H., Takagi, T. (eds.) ASIACRYPT 2016, Part I. LNCS, vol. 10031, pp. 63\u201391. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53887-6_3"},{"issue":"3","key":"15_CR19","doi-asserted-by":"publisher","first-page":"245","DOI":"10.1007\/BF01271370","volume":"3","author":"G Ivanyos","year":"1993","unstructured":"Ivanyos, G., R\u00f3nyai, L.: Finding maximal orders in semisimple algebras over $$\\mathbb{Q}$$. Comput. Complex. 3(3), 245\u2013261 (1993)","journal-title":"Comput. Complex."},{"key":"15_CR20","doi-asserted-by":"crossref","unstructured":"Jao, D., et al.: Supersingular isogeny key encapsulation. Updated version of [21] for round 3 of [29] (2020)","DOI":"10.1007\/978-3-642-27739-9_1572-1"},{"key":"15_CR21","unstructured":"Jao, D., et al.: Supersingular isogeny key encapsulation. Submission to [29] (2017). https:\/\/sike.org"},{"key":"15_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-642-25405-5_2","volume-title":"Post-Quantum Cryptography","author":"D Jao","year":"2011","unstructured":"Jao, D., De Feo, L.: Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies. In: Yang, B.-Y. (ed.) PQCrypto 2011. LNCS, vol. 7071, pp. 19\u201334. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25405-5_2"},{"key":"15_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1007\/978-3-030-26948-7_2","volume-title":"Advances in Cryptology \u2013 CRYPTO 2019","author":"S Jaques","year":"2019","unstructured":"Jaques, S., Schanck, J.M.: Quantum cryptanalysis in the RAM model: claw-finding attacks on SIKE. In: Boldyreva, A., Micciancio, D. (eds.) CRYPTO 2019, Part I. LNCS, vol. 11692, pp. 32\u201361. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-26948-7_2"},{"key":"15_CR24","doi-asserted-by":"crossref","unstructured":"Jaques, S., Schrottenloher, A.: Low-gate quantum golden collision finding. In: SAC 2020. Springer (2020)","DOI":"10.1007\/978-3-030-81652-0_13"},{"issue":"4","key":"15_CR25","first-page":"849","volume":"26","author":"M Kaneko","year":"1989","unstructured":"Kaneko, M.: Supersingular $$j$$-invariants as singular moduli mod $$p$$. Osaka J. Math. 26(4), 849\u2013855 (1989)","journal-title":"Osaka J. Math."},{"key":"15_CR26","doi-asserted-by":"publisher","first-page":"418","DOI":"10.1112\/S1461157014000151","volume":"17A","author":"D Kohel","year":"2014","unstructured":"Kohel, D., Lauter, K., Petit, C., Tignol, J.-P.: On the quaternion $$\\ell $$-isogeny path problem. LMS J. Comput. Math. 17A, 418\u2013432 (2014)","journal-title":"LMS J. Comput. Math."},{"key":"15_CR27","doi-asserted-by":"crossref","unstructured":"Love, J., Boneh, D.: Supersingular curves with small non-integer endomorphisms. In: Galbraith, S. (ed.) ANTS XIV: Proceedings of the Fourteenth Algorithmic Number Theory Symposium (2020)","DOI":"10.2140\/obs.2020.4.7"},{"key":"15_CR28","unstructured":"Martindale, C., Panny, L.: How to not break SIDH. In: CFAIL 2019 (2019)"},{"key":"15_CR29","unstructured":"National Institute of Standards and Technology: Post-quantum cryptography standardization, December 2016. https:\/\/csrc.nist.gov\/Projects\/Post-Quantum-Cryptography\/Post-Quantum-Cryptography-Standardization"},{"key":"15_CR30","doi-asserted-by":"publisher","first-page":"101777","DOI":"10.1016\/j.ffa.2020.101777","volume":"69","author":"H Onuki","year":"2021","unstructured":"Onuki, H.: On oriented supersingular elliptic curves. Finite Fields Appl. 69, 101777 (2021)","journal-title":"Finite Fields Appl."},{"key":"15_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"330","DOI":"10.1007\/978-3-319-70697-9_12","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2017","author":"C Petit","year":"2017","unstructured":"Petit, C.: Faster algorithms for isogeny problems using torsion point images. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017, Part II. LNCS, vol. 10625, pp. 330\u2013353. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70697-9_12"},{"key":"15_CR32","unstructured":"Petit, C., Lauter, K.E.: Hard and easy problems for supersingular isogeny graphs. IACR Cryptology ePrint Archive 2017\/962 (2017)"},{"key":"15_CR33","doi-asserted-by":"crossref","unstructured":"Pohlig, S., Hellman, M.: An improved algorithm for computing logarithms over $$\\rm GF(p)$$ and its cryptographic significance (corresp.). IEEE Trans. Inf. Theory 24(1), 106\u2013110 (1978)","DOI":"10.1109\/TIT.1978.1055817"},{"key":"15_CR34","unstructured":"Sahu, R.A., Gini, A., Pal, A.: Supersingular isogeny-based designated verifier blind signature. IACR Cryptology ePrint Archive 2019\/1498 (2019)"},{"key":"15_CR35","doi-asserted-by":"crossref","unstructured":"Siegel, C.L.: \u00dcber die Classenzahl quadratischer Zahlk\u00f6rper. Acta Arithmetica, pp. 83\u201386 (1935)","DOI":"10.4064\/aa-1-1-83-86"},{"key":"15_CR36","unstructured":"Simon, D.: Quadratic equations in dimensions 4, 5 and more. Preprint (2005). https:\/\/simond.users.lmno.cnrs.fr\/maths\/Dim4.pdf"},{"key":"15_CR37","unstructured":"Tako, B.F., Kutas, P., Merz, S.-P.: On the isogeny problem with torsion point information. IACR Cryptology ePrint Archive 2021\/153"},{"key":"15_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"536","DOI":"10.1007\/978-3-540-74456-6_48","volume-title":"Mathematical Foundations of Computer Science 2007","author":"S Tani","year":"2007","unstructured":"Tani, S.: An improved claw finding algorithm using quantum walk. In: Ku\u010dera, L., Ku\u010dera, A. (eds.) MFCS 2007. LNCS, vol. 4708, pp. 536\u2013547. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-74456-6_48"},{"key":"15_CR39","doi-asserted-by":"publisher","unstructured":"Voight, J.: Identifying the matrix ring: algorithms for quaternion algebras and quadratic forms. In: Alladi, K., Bhargava, M., Savitt, D., Tiep, P. (eds.) Quadratic and Higher Degree Forms, pp. 255\u2013298. Springer, New York (2013). https:\/\/doi.org\/10.1007\/978-1-4614-7488-3_10","DOI":"10.1007\/978-1-4614-7488-3_10"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2021"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-84252-9_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,8,11]],"date-time":"2024-08-11T00:10:31Z","timestamp":1723335031000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-84252-9_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030842512","9783030842529"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-84252-9_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"11 August 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRYPTO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Cryptology Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 August 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 August 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"41","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crypto2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crypto.iacr.org\/2021\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"426","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"103","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"24% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"20.9","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1 invited paper is also included.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}