{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,15]],"date-time":"2026-08-15T20:36:07Z","timestamp":1786826167844,"version":"3.56.0"},"publisher-location":"Cham","reference-count":45,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031305887","type":"print"},{"value":"9783031305894","type":"electronic"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-30589-4_15","type":"book-chapter","created":{"date-parts":[[2023,4,15]],"date-time":"2023-04-15T11:02:07Z","timestamp":1681556527000},"page":"423-447","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":264,"title":["An Efficient Key Recovery Attack on\u00a0SIDH"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0191-5216","authenticated-orcid":false,"given":"Wouter","family":"Castryck","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0253-4180","authenticated-orcid":false,"given":"Thomas","family":"Decru","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,4,16]]},"reference":[{"key":"15_CR1","doi-asserted-by":"publisher","unstructured":"Azarderakhsh, R., Jao, D., Leonardi, C.: Post-quantum static-static key agreement using multiple protocol instances. In: Adams, C., Camenisch, J. (eds.) Selected Areas in Cryptography - SAC 2017, pp. 45\u201363. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-72565-9_3","DOI":"10.1007\/978-3-319-72565-9_3"},{"key":"15_CR2","doi-asserted-by":"publisher","unstructured":"Bosma, W., Cannon, J., Playoust, C.: The Magma algebra system. I. The user language. J. Symbolic Comput. 24(3\u20134), 235\u2013265 (1997). https:\/\/doi.org\/10.1006\/jsco.1996.0125","DOI":"10.1006\/jsco.1996.0125"},{"key":"15_CR3","unstructured":"Brock, B.: Superspecial curves of genera two and three. Ph.D. thesis, Princeton University (1994)"},{"key":"15_CR4","doi-asserted-by":"crossref","unstructured":"Bruin, N., Flynn, E.V., Testa, D.: Descent via $$(3,3)$$-isogeny on Jacobians of genus 2 curves. Acta Arithmetica 165(3), 201\u2013223 (2014). http:\/\/eudml.org\/doc\/279018","DOI":"10.4064\/aa165-3-1"},{"key":"15_CR5","doi-asserted-by":"publisher","unstructured":"Canfield, E.R., Erd\u00f6s, P., Pomerance, C.: On a problem of Oppenheim concerning \u201cfactorisatio numerorum.\u201d J. Number Theory 17(1), 1\u201328 (1983). https:\/\/doi.org\/10.1016\/0022-314X(83)90002-1","DOI":"10.1016\/0022-314X(83)90002-1"},{"key":"15_CR6","doi-asserted-by":"publisher","unstructured":"Castryck, W., Decru, T.: Multiradical isogenies. In: Anni, S., Karemaker, V., Lorenzo Garc\u00eda, E. (eds.) 18th International Conference Arithmetic, Geometry, Cryptography, and Coding Theory, Contemporary Mathematics, vol. 779, pp. 57\u201389. American Mathematical Society (2022). https:\/\/doi.org\/10.1090\/conm\/779","DOI":"10.1090\/conm\/779"},{"key":"15_CR7","doi-asserted-by":"publisher","unstructured":"Castryck, W., Lange, T., Martindale, C., Panny, L., Renes, J.: CSIDH: an efficient post-quantum commutative group action. In: Peyrin, T., Galbraith, S. (eds.) Advances in Cryptology - ASIACRYPT 2018, vol. 3, pp. 395\u2013427. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03332-3_15","DOI":"10.1007\/978-3-030-03332-3_15"},{"key":"15_CR8","doi-asserted-by":"crossref","unstructured":"Cosset, R., Robert, D.: Computing $$(\\ell ,\\ell )$$\u2013isogenies in polynomial time on Jacobians of genus 2 curves. Math. Comput. 84(294), 1953\u20131975 (2015). https:\/\/www.ams.org\/journals\/mcom\/2015-84-294\/S0025-5718-2014-02899-8\/","DOI":"10.1090\/S0025-5718-2014-02899-8"},{"key":"15_CR9","doi-asserted-by":"publisher","unstructured":"Costello, C.: B-SIDH: supersingular isogeny Diffie-Hellman using twisted torsion. In: Moriai, S., Wang, H. (eds.) Advances in Cryptology - ASIACRYPT 2020, vol. 2, pp. 440\u2013463. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_15","DOI":"10.1007\/978-3-030-64834-3_15"},{"key":"15_CR10","unstructured":"Couveignes, J.M.: Hard homogeneous spaces. Cryptology ePrint Archive, Paper 2006\/291 (2006). https:\/\/eprint.iacr.org\/2006\/291"},{"issue":"3","key":"15_CR11","doi-asserted-by":"publisher","first-page":"209","DOI":"10.1515\/jmc-2012-0015","volume":"8","author":"L De Feo","year":"2014","unstructured":"De Feo, L., Jao, D., Pl\u00fbt, J.: Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies. J. Math. Cryptol. 8(3), 209\u2013247 (2014). https:\/\/doi.org\/10.1515\/jmc-2012-0015","journal-title":"J. Math. Cryptol."},{"key":"15_CR12","doi-asserted-by":"publisher","unstructured":"De Feo, L., Kohel, D., Leroux, A., Petit, C., Wesolowski, B.: SQISign: compact post-quantum signatures from quaternions and isogenies. In: Moriai, S., Wang, H. (eds.) Advances in Cryptology - ASIACRYPT 2020, vol. 1, pp. 64\u201393. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64837-4_3","DOI":"10.1007\/978-3-030-64837-4_3"},{"key":"15_CR13","doi-asserted-by":"publisher","unstructured":"De Feo, L., et al.: S\u00e9ta: supersingular encryption from torsion attacks. In: Tibouchi, M., Wang, H. (eds.) Advances in Cryptology - ASIACRYPT 2021, vol. 4, pp. 249\u2013278. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92068-5_9","DOI":"10.1007\/978-3-030-92068-5_9"},{"key":"15_CR14","unstructured":"De Feo, L., et al.: (open project): Is SIKE broken yet? (2022). https:\/\/issikebrokenyet.github.io\/"},{"key":"15_CR15","unstructured":"Djukanovic, M.: Split Jacobians and lower bounds on heights. Ph.D. thesis, Universit\u00e9 de Bordeaux (2017)"},{"key":"15_CR16","doi-asserted-by":"publisher","unstructured":"Eisentr\u00e4ger, K., Hallgren, S., Lauter, K., Morrison, T., Petit, C.: Supersingular isogeny graphs and endomorphism rings: Reductions and solutions. In: Nielsen, J.B., Rijmen, V. (eds.) Advances in Cryptology - EUROCRYPT 2018, vol. 3, pp. 329\u2013368. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-78372-7_11","DOI":"10.1007\/978-3-319-78372-7_11"},{"key":"15_CR17","doi-asserted-by":"publisher","unstructured":"Flynn, E.V., Ti, Y.B.: Genus two isogeny cryptography. In: Ding, J., Steinwandt, R. (eds.) Post-quantum Cryptography, pp. 286\u2013306. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-25510-7_16","DOI":"10.1007\/978-3-030-25510-7_16"},{"key":"15_CR18","doi-asserted-by":"crossref","unstructured":"Fouotsa, T.B., Moriya, T., Petit, C.: M-SIDH and MD-SIDH: countering SIDH attacks by masking information. Cryptology ePrint Archive, Paper 2023\/013 (2023). https:\/\/eprint.iacr.org\/2023\/013","DOI":"10.1007\/978-3-031-30589-4_10"},{"key":"15_CR19","doi-asserted-by":"publisher","unstructured":"Fouotsa, T.B., Petit, C.: SHealS and HealS: isogeny-based PKEs from a key validation method for SIDH. In: Tibouchi, M., Wang, H. (eds.) Advances in Cryptology - ASIACRYPT 2021, vol. 4, pp. 279\u2013307. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92068-5_10","DOI":"10.1007\/978-3-030-92068-5_10"},{"key":"15_CR20","doi-asserted-by":"publisher","unstructured":"Galbraith, S.D., Petit, C., Silva, J.: Identification protocols and signature schemes based on supersingular isogeny problems. In: Takagi, T., Peyrin, T. (eds.) Advances in Cryptology - ASIACRYPT 2017, vol. 1, pp. 3\u201333. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70694-8_1","DOI":"10.1007\/978-3-319-70694-8_1"},{"issue":"10","key":"15_CR21","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s11128-018-2023-6","volume":"17","author":"SD Galbraith","year":"2018","unstructured":"Galbraith, S.D., Vercauteren, F.: Computational problems in supersingular elliptic curve isogenies. Quantum Inf. Process. 17(10), 1\u201322 (2018). https:\/\/doi.org\/10.1007\/s11128-018-2023-6","journal-title":"Quantum Inf. Process."},{"issue":"4","key":"15_CR22","doi-asserted-by":"publisher","first-page":"837","DOI":"10.1090\/S0894-0347-1989-1002631-0","volume":"2","author":"JL Hafner","year":"1989","unstructured":"Hafner, J.L., McCurley, K.S.: A rigorous subexponential algorithm for computation of class groups. J. Am. Math. Soc. 2(4), 837\u2013850 (1989). https:\/\/doi.org\/10.1090\/S0894-0347-1989-1002631-0","journal-title":"J. Am. Math. Soc."},{"issue":"3","key":"15_CR23","doi-asserted-by":"publisher","first-page":"315","DOI":"10.1515\/form.2000.008","volume":"12","author":"EW Howe","year":"2000","unstructured":"Howe, E.W., Lepr\u00e9vost, F., Poonen, B.: Large torsion subgroups of split Jacobians of curves of genus two or three. Forum Math. 12(3), 315\u2013364 (2000). https:\/\/doi.org\/10.1515\/form.2000.008","journal-title":"Forum Math."},{"key":"15_CR24","unstructured":"Jao, D., et al.: Supersingular Isogeny Key Encapsulation. https:\/\/csrc.nist.gov\/Projects\/post-quantum-cryptography\/round-4-submissions"},{"key":"15_CR25","doi-asserted-by":"publisher","unstructured":"Jao, D., De Feo, L.: Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies. In: Yang, B.Y. (ed.) Post-Quantum Cryptography, pp. 19\u201334. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25405-5_2","DOI":"10.1007\/978-3-642-25405-5_2"},{"issue":"485","key":"15_CR26","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1515\/crll.1997.485.93","volume":"1997","author":"E Kani","year":"1997","unstructured":"Kani, E.: The number of curves of genus two with elliptic differentials. J. f\u00fcr die reine und angewandte Mathematik 1997(485), 93\u2013122 (1997). https:\/\/doi.org\/10.1515\/crll.1997.485.93","journal-title":"J. f\u00fcr die reine und angewandte Mathematik"},{"key":"15_CR27","doi-asserted-by":"publisher","unstructured":"Kohel, D., Lauter, K., Petit, C., Tignol, J.P.: On the quaternion $$\\ell $$-isogeny path problem. LMS J. Comput. Math. 17(A), 418\u2013432 (2014). https:\/\/doi.org\/10.1112\/S1461157014000151","DOI":"10.1112\/S1461157014000151"},{"issue":"1","key":"15_CR28","doi-asserted-by":"publisher","first-page":"41","DOI":"10.2307\/2000749","volume":"307","author":"RM Kuhn","year":"1988","unstructured":"Kuhn, R.M.: Curves of genus 2 with split Jacobian. Trans. Am. Math. Soc. 307(1), 41\u201349 (1988). https:\/\/doi.org\/10.2307\/2000749","journal-title":"Trans. Am. Math. Soc."},{"key":"15_CR29","doi-asserted-by":"publisher","unstructured":"Love, J., Boneh, D.: Supersingular curves with small non-integer endomorphisms. In: Algorithmic Number Theory Symposium (ANTS-XIV), MSP Open Book Series, vol. 4, pp. 7\u201322 (2020). https:\/\/doi.org\/10.2140\/obs.2020.4.7","DOI":"10.2140\/obs.2020.4.7"},{"key":"15_CR30","unstructured":"Maino, L., Martindale, C.: An attack on SIDH with arbitrary starting curve. Cryptology ePrint Archive, Paper 2022\/1026 (2022). https:\/\/eprint.iacr.org\/2022\/1026"},{"key":"15_CR31","unstructured":"Martindale, C., Panny, L.: How to not break SIDH. Cryptology ePrint Archive, Paper 2019\/558 (2019). https:\/\/eprint.iacr.org\/2019\/558, Presented at CFAIL 2019, Columbia University"},{"key":"15_CR32","unstructured":"Microsoft: SIKE cryptographic challenge. https:\/\/www.microsoft.com\/en-us\/msrc\/sike-cryptographic-challenge"},{"key":"15_CR33","unstructured":"National Institute of Standards and Technology (NIST): Post-quantum cryptography standardization process. https:\/\/csrc.nist.gov\/projects\/post-quantum-cryptography"},{"key":"15_CR34","unstructured":"Oudompheng, R.: A note on implementing direct isogeny determination in the Castryck\u2013Decru attack. https:\/\/www.normalesup.org\/~oudomphe\/textes\/202208-castryck-decru-shortcut.pdf"},{"key":"15_CR35","unstructured":"Oudompheng, R., Pope, G.: A note on reimplementing the Castryck\u2013Decru attack and lessons learned for SageMath. Cryptology ePrint Archive, Paper 2022\/1283 (2022). https:\/\/eprint.iacr.org\/2022\/1283"},{"key":"15_CR36","doi-asserted-by":"publisher","unstructured":"Petit, C.: Faster algorithms for isogeny problems using torsion point images. In: Takagi, T., Peyrin, T. (eds.) Advances in Cryptology - ASIACRYPT 2017, vol. 2, pp. 330\u2013353. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70697-9_12","DOI":"10.1007\/978-3-319-70697-9_12"},{"key":"15_CR37","doi-asserted-by":"publisher","unstructured":"de Quehen, V., et al.: Improved torsion-point attacks on SIDH variants. In: Malkin, T., Peikert, C. (eds.) Advances in Cryptology - CRYPTO 2021, vol. 3, pp. 432\u2013470. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-84252-9_15","DOI":"10.1007\/978-3-030-84252-9_15"},{"key":"15_CR38","unstructured":"Robert, D.: Breaking SIDH in polynomial time. Cryptology ePrint Archive, Paper 2022\/1038 (2022). https:\/\/eprint.iacr.org\/2022\/1038"},{"key":"15_CR39","unstructured":"Rostovtsev, A., Stolbunov, A.: Public-key cryptosystem based on isogenies. Cryptology ePrint Archive, Paper 2006\/145 (2006). https:\/\/eprint.iacr.org\/2006\/145"},{"key":"15_CR40","unstructured":"SageMath: The Sage Mathematics Software System. https:\/\/www.sagemath.org"},{"issue":"96","key":"15_CR41","doi-asserted-by":"publisher","first-page":"551","DOI":"10.2307\/2003544","volume":"20","author":"D Shanks","year":"1966","unstructured":"Shanks, D., Schmid, L.P.: Variations on a theorem of Landau. Part I. Math. Comput. 20(96), 551\u2013569 (1966). https:\/\/doi.org\/10.2307\/2003544","journal-title":"Math. Comput."},{"key":"15_CR42","doi-asserted-by":"crossref","unstructured":"Smith, B.: Explicit endomorphisms and correspondences. Ph.D. thesis, University of Sydney (2006)","DOI":"10.1017\/S0004972700040521"},{"key":"15_CR43","doi-asserted-by":"publisher","unstructured":"Urbanik, D., Jao, D.: SoK: the problem landscape of SIDH. In: Emura, K., Seo, J.H., Watanabe, Y. (eds.) Proceedings of the 5th ACM on ASIA Public-Key Cryptography Workshop, APKC@AsiaCCS, Incheon, Republic of Korea, 4 June 2018, pp. 53\u201360. ACM (2018). https:\/\/doi.org\/10.1145\/3197507.3197516","DOI":"10.1145\/3197507.3197516"},{"key":"15_CR44","doi-asserted-by":"publisher","unstructured":"Wesolowski, B.: The supersingular isogeny path and endomorphism ring problems are equivalent. In: 2021 IEEE 62nd Annual Symposium on Foundations of Computer Science (FOCS), pp. 1100\u20131111 (2022). https:\/\/doi.org\/10.1109\/FOCS52979.2021.00109","DOI":"10.1109\/FOCS52979.2021.00109"},{"key":"15_CR45","unstructured":"Wesolowski, B.: Understanding and improving the Castryck\u2013Decru attack on SIDH (2022). https:\/\/www.bweso.com\/papers.php"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2023"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-30589-4_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,15]],"date-time":"2025-04-15T22:04:36Z","timestamp":1744754676000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-30589-4_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031305887","9783031305894"],"references-count":45,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-30589-4_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"16 April 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Lyon","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 April 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 April 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"42","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2023\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"415","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"109","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"26% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"16","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}