{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:15:42Z","timestamp":1784301342487,"version":"3.55.0"},"publisher-location":"Cham","reference-count":41,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783031070815","type":"print"},{"value":"9783031070822","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-07082-2_13","type":"book-chapter","created":{"date-parts":[[2022,5,28]],"date-time":"2022-05-28T00:09:51Z","timestamp":1653696591000},"page":"345-371","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":31,"title":["Orientations and\u00a0the\u00a0Supersingular Endomorphism Ring Problem"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1249-6077","authenticated-orcid":false,"given":"Benjamin","family":"Wesolowski","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,5,25]]},"reference":[{"issue":"191","key":"13_CR1","doi-asserted-by":"publisher","first-page":"355","DOI":"10.1090\/S0025-5718-1990-1023756-8","volume":"55","author":"E Bach","year":"1990","unstructured":"Bach, E.: Explicit bounds for primality testing and related problems. Math. Comput. 55(191), 355\u2013380 (1990)","journal-title":"Math. Comput."},{"key":"13_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1007\/978-3-030-34578-5_9","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2019","author":"W Beullens","year":"2019","unstructured":"Beullens, W., Kleinjung, T., Vercauteren, F.: CSI-FiSh: efficient isogeny based signatures through class group computations. In: Galbraith, S.D., Moriai, S. (eds.) ASIACRYPT 2019. LNCS, vol. 11921, pp. 227\u2013247. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-34578-5_9"},{"issue":"2","key":"13_CR3","first-page":"283","volume":"8","author":"W Bosma","year":"1996","unstructured":"Bosma, W., Stevenhagen, P.: On the computation of quadratic $$2 $$-class groups. J. de th\u00e9orie des nombres de Bordeaux 8(2), 283\u2013313 (1996)","journal-title":"J. de th\u00e9orie des nombres de Bordeaux"},{"key":"13_CR4","doi-asserted-by":"crossref","unstructured":"Biasse, J.-F., Song, F.: Efficient quantum algorithms for computing class groups and solving the principal ideal problem in arbitrary degree number fields. In: Krauthgamer, R. (ed.) Proceedings of the Twenty-Seventh Annual ACM-SIAM Symposium on Discrete Algorithms - SODA 2016, pp. 893\u2013902. SIAM (2016)","DOI":"10.1137\/1.9781611974331.ch64"},{"key":"13_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1007\/978-3-030-44223-1_7","volume-title":"Post-Quantum Cryptography","author":"W Castryck","year":"2020","unstructured":"Castryck, W., Decru, T.: CSIDH on the surface. In: Ding, J., Tillich, J.-P. (eds.) PQCrypto 2020. LNCS, vol. 12100, pp. 111\u2013129. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-44223-1_7"},{"issue":"1","key":"13_CR6","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1515\/jmc-2012-0016","volume":"8","author":"A Childs","year":"2014","unstructured":"Childs, A., Jao, D., Soukharev, V.: Constructing elliptic curve isogenies in quantum subexponential time. J. Math. Cryptol. 8(1), 1\u201329 (2014)","journal-title":"J. Math. Cryptol."},{"issue":"1","key":"13_CR7","doi-asserted-by":"publisher","first-page":"414","DOI":"10.1515\/jmc-2019-0034","volume":"14","author":"L Col\u00f2","year":"2020","unstructured":"Col\u00f2, L., Kohel, D.: Orienting supersingular isogeny graphs. J. Math. Cryptol. 14(1), 414\u2013437 (2020)","journal-title":"J. Math. Cryptol."},{"issue":"1","key":"13_CR8","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1007\/s00145-007-9002-x","volume":"22","author":"DX Charles","year":"2009","unstructured":"Charles, D.X., Lauter, K.E., Goren, E.Z.: Cryptographic hash functions from expander graphs. J. Cryptol. 22(1), 93\u2013113 (2009)","journal-title":"J. Cryptol."},{"key":"13_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"395","DOI":"10.1007\/978-3-030-03332-3_15","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2018","author":"W Castryck","year":"2018","unstructured":"Castryck, W., Lange, T., Martindale, C., Panny, L., Renes, J.: CSIDH: an efficient post-quantum commutative group action. In: Peyrin, T., Galbraith, S. (eds.) ASIACRYPT 2018. LNCS, vol. 11274, pp. 395\u2013427. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03332-3_15"},{"key":"13_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"91","DOI":"10.1007\/3-540-45539-6_7","volume-title":"Advances in Cryptology \u2014 EUROCRYPT 2000","author":"J-S Coron","year":"2000","unstructured":"Coron, J.-S., Naccache, D.: Security analysis of the gennaro-halevi-rabin signature scheme. In: Preneel, B. (ed.) EUROCRYPT 2000. LNCS, vol. 1807, pp. 91\u2013101. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/3-540-45539-6_7"},{"key":"13_CR11","unstructured":"Couveignes, J.M.: Hard homogeneous spaces. IACR Cryptology ePrint Archive, Report 2006\/291 (2006). https:\/\/eprint.iacr.org\/2006\/291"},{"key":"13_CR12","unstructured":"Cox, D.A.: Primes of the Form x2+ ny2: Fermat, Class Field Theory, and Complex Multiplication, vol. 34. John Wiley & Sons, Hoboken (2011)"},{"key":"13_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"523","DOI":"10.1007\/978-3-030-45724-2_18","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2020","author":"W Castryck","year":"2020","unstructured":"Castryck, W., Panny, L., Vercauteren, F.: Rational isogenies from irrational endomorphisms. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT 2020. LNCS, vol. 12106, pp. 523\u2013548. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45724-2_18"},{"key":"13_CR14","unstructured":"Chenu, M., Smith, B.: Higher-degree supersingular group actions. In: MathCrypt 2021 - Mathematical Cryptology (2021)"},{"key":"13_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1007\/978-3-030-92068-5_9","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2021","author":"L De Feo","year":"2021","unstructured":"De Feo, L.: S\u00e9ta: supersingular encryption from\u00a0torsion attacks. In: Tibouchi, M., Wang, H. (eds.) ASIACRYPT 2021. LNCS, vol. 13093, pp. 249\u2013278. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92068-5_9"},{"issue":"2","key":"13_CR16","doi-asserted-by":"publisher","first-page":"425","DOI":"10.1007\/s10623-014-0010-1","volume":"78","author":"C Delfs","year":"2014","unstructured":"Delfs, C., Galbraith, S.D.: Computing isogenies between supersingular elliptic curves over $${\\mathbb{F}}_p$$. Designs Codes Cryptogr. 78(2), 425\u2013440 (2014). https:\/\/doi.org\/10.1007\/s10623-014-0010-1","journal-title":"Designs Codes Cryptogr."},{"key":"13_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"329","DOI":"10.1007\/978-3-319-78372-7_11","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2018","author":"K Eisentr\u00e4ger","year":"2018","unstructured":"Eisentr\u00e4ger, K., Hallgren, S., Lauter, K., Morrison, T., Petit, C.: Supersingular isogeny graphs and endomorphism rings: reductions and solutions. In: Nielsen, J.B., Rijmen, V. (eds.) EUROCRYPT 2018. LNCS, vol. 10822, pp. 329\u2013368. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-78372-7_11"},{"issue":"1","key":"13_CR18","doi-asserted-by":"publisher","first-page":"215","DOI":"10.2140\/obs.2020.4.215","volume":"4","author":"K Eisentr\u00e4ger","year":"2020","unstructured":"Eisentr\u00e4ger, K., Hallgren, S., Leonardi, C., Morrison, T., Park, J.: Computing endomorphism rings of supersingular elliptic curves and connections to path-finding in isogeny graphs. Open Book Series 4(1), 215\u2013232 (2020)","journal-title":"Open Book Series"},{"key":"13_CR19","unstructured":"Fouotsa, T.B., Kutas, P., Merz, S.-P.: On the isogeny problem with torsion point information. IACR Cryptology ePrint Archive, Report 2021\/153 (2021). https:\/\/eprint.iacr.org\/2021\/153"},{"issue":"1","key":"13_CR20","doi-asserted-by":"publisher","first-page":"130","DOI":"10.1007\/s00145-019-09316-0","volume":"33","author":"SD Galbraith","year":"2020","unstructured":"Galbraith, S.D., Petit, C., Silva, J.: Identification protocols and signature schemes based on supersingular isogeny problems. J. Cryptol. 33(1), 130\u2013175 (2020)","journal-title":"J. Cryptol."},{"key":"13_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1007\/978-3-662-53887-6_3","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2016","author":"SD Galbraith","year":"2016","unstructured":"Galbraith, S.D., Petit, C., Shani, B., Ti, Y.B.: On the security of supersingular isogeny cryptosystems. In: Cheon, J.H., Takagi, T. (eds.) ASIACRYPT 2016. LNCS, vol. 10031, pp. 63\u201391. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53887-6_3"},{"issue":"1","key":"13_CR22","first-page":"40","volume":"1","author":"S Galbraith","year":"2021","unstructured":"Galbraith, S., Panny, L., Smith, B., Vercauteren, F.: Quantum equivalence of the DLP and CDHP for group actions. Math. Cryptol. 1(1), 40\u201344 (2021)","journal-title":"Math. Cryptol."},{"key":"13_CR23","unstructured":"Jao, D., et al. SIKE: Supersingular isogeny key encapsulation (2017)"},{"key":"13_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-642-25405-5_2","volume-title":"Post-Quantum Cryptography","author":"D Jao","year":"2011","unstructured":"Jao, D., De Feo, L.: Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies. In: Yang, B.-Y. (ed.) PQCrypto 2011. LNCS, vol. 7071, pp. 19\u201334. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25405-5_2"},{"issue":"4","key":"13_CR25","first-page":"849","volume":"26","author":"M Kaneko","year":"1989","unstructured":"Kaneko, M.: Supersingular $$j$$-invariants as singular moduli mod $$p$$. Osaka J. Math. 26(4), 849\u2013855 (1989)","journal-title":"Osaka J. Math."},{"key":"13_CR26","unstructured":"Kitaev, A.Y.: Quantum measurements and the abelian stabilizer problem. arXiv preprint quant-ph\/9511026 (1995)"},{"issue":"A","key":"13_CR27","doi-asserted-by":"publisher","first-page":"418","DOI":"10.1112\/S1461157014000151","volume":"17","author":"D Kohel","year":"2014","unstructured":"Kohel, D., Lauter, K., Petit, C., Tignol, J.A.: On the quaternion $$\\ell $$-isogeny path problem. LMS J. Comput. Math. 17(A), 418\u2013432 (2014)","journal-title":"LMS J. Comput. Math."},{"key":"13_CR28","unstructured":"Kutas, P., Martindale, C., Panny, L., Petit, C., Stange, E.: Weak instances of SIDH variants under improved torsion-point attacks. In: To appear in Advances in Cryptology - CRYPTO 2021, Lecture Notes in Computer Science (2021)"},{"issue":"1","key":"13_CR29","doi-asserted-by":"publisher","first-page":"170","DOI":"10.1137\/S0097539703436345","volume":"35","author":"G Kuperberg","year":"2005","unstructured":"Kuperberg, G.: A subexponential-time quantum algorithm for the dihedral hidden subgroup problem. SIAM J. Comp. 35(1), 170\u2013188 (2005)","journal-title":"SIAM J. Comp."},{"issue":"1","key":"13_CR30","doi-asserted-by":"publisher","first-page":"7","DOI":"10.2140\/obs.2020.4.7","volume":"4","author":"J Love","year":"2020","unstructured":"Love, J., Boneh, D.: Supersingular curves with small noninteger endomorphisms. Open Book Series 4(1), 7\u201322 (2020)","journal-title":"Open Book Series"},{"key":"13_CR31","unstructured":"Lagarias, J.C., Odlyzko, A.M.: Effective versions of the Chebotarev density theorem. In: Algebraic number fields: $$L$$-functions and Galois properties (Proceedings of Symposium, University of Durham, Durham, 1975), pp. 409\u2013464. Academic Press, London (1977)"},{"key":"13_CR32","doi-asserted-by":"crossref","unstructured":"Onuki, H.: On oriented supersingular elliptic curves. Finite Fields and Their Appl. 69, 101777 (2021)","DOI":"10.1016\/j.ffa.2020.101777"},{"key":"13_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"330","DOI":"10.1007\/978-3-319-70697-9_12","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2017","author":"C Petit","year":"2017","unstructured":"Petit, C.: Faster algorithms for isogeny problems using torsion point images. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017. LNCS, vol. 10625, pp. 330\u2013353. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70697-9_12"},{"issue":"2","key":"13_CR34","doi-asserted-by":"publisher","first-page":"340","DOI":"10.1016\/0021-8693(80)90151-9","volume":"64","author":"A Pizer","year":"1980","unstructured":"Pizer, A.: An algorithm for computing modular forms on $$\\gamma _0(n)$$. J. Algebra 64(2), 340\u2013390 (1980)","journal-title":"J. Algebra"},{"issue":"3","key":"13_CR35","doi-asserted-by":"publisher","first-page":"225","DOI":"10.1007\/BF01272075","volume":"2","author":"L R\u00f3nyai","year":"1992","unstructured":"R\u00f3nyai, L.: Algorithmic properties of maximal orders in simple algebras over $$\\mathbf{Q}$$. Comput. Compl. 2(3), 225\u2013243 (1992)","journal-title":"Comput. Compl."},{"issue":"5","key":"13_CR36","doi-asserted-by":"publisher","first-page":"1484","DOI":"10.1137\/S0097539795293172","volume":"26","author":"PW Shor","year":"1997","unstructured":"Shor, P.W.: Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM J. Comput. 26(5), 1484\u20131509 (1997)","journal-title":"SIAM J. Comput."},{"key":"13_CR37","doi-asserted-by":"crossref","unstructured":"Silverman, J.H.: The Arithmetic of Elliptic Curves, volume 106 of Gradute Texts in Mathematics. Springer, Heidelberg (1986)","DOI":"10.1007\/978-1-4757-1920-8"},{"key":"13_CR38","unstructured":"Simon, D.: Quadratic equations in dimensions 4, 5 and more. Preprint (2006). See [?] for a published review"},{"key":"13_CR39","unstructured":"Vign\u00e9ras, M.-F.: Arithm\u00e9tique des alg\u00e8bres de quaternions, vol. 800. Springer, Heidelberg (2006)"},{"key":"13_CR40","doi-asserted-by":"crossref","unstructured":"Voight, J.: Quaternion algebras. In: Graduate Texts in Mathematics, no. 288. Springer, Heidelberg (2021)","DOI":"10.1007\/978-3-030-56694-4"},{"key":"13_CR41","doi-asserted-by":"crossref","unstructured":"Wesolowski, B.: The supersingular isogeny path and endomorphism ring problems are equivalent. In: FOCS 2021\u201362nd Annual IEEE Symposium on Foundations of Computer Science (2022)","DOI":"10.1109\/FOCS52979.2021.00109"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2022"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-07082-2_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,27]],"date-time":"2025-05-27T22:02:50Z","timestamp":1748383370000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-07082-2_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031070815","9783031070822"],"references-count":41,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-07082-2_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"25 May 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Trondheim","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Norway","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 May 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3 June 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"41","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2022\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"372","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"85","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"23% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"18","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Peer review was double-blind with rebuttal.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}