{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,6]],"date-time":"2026-08-06T15:16:00Z","timestamp":1786029360312,"version":"3.56.0"},"publisher-location":"Cham","reference-count":39,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031305887","type":"print"},{"value":"9783031305894","type":"electronic"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-30589-4_16","type":"book-chapter","created":{"date-parts":[[2023,4,15]],"date-time":"2023-04-15T11:02:07Z","timestamp":1681556527000},"page":"448-471","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":129,"title":["A Direct Key Recovery Attack on\u00a0SIDH"],"prefix":"10.1007","author":[{"given":"Luciano","family":"Maino","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chloe","family":"Martindale","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lorenz","family":"Panny","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Giacomo","family":"Pope","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Benjamin","family":"Wesolowski","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,4,16]]},"reference":[{"key":"16_CR1","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., De\u00a0Feo, L., Leroux, A., Smith, B.: Faster computation of isogenies of large prime degree. In: Galbraith, S. (ed.) ANTS XIV: Proceedings of the Fourteenth Algorithmic Number Theory Symposium, pp. 39\u201355. Mathematical Sciences Publishers (2020). https:\/\/iac.r\/2020\/341","DOI":"10.2140\/obs.2020.4.39"},{"key":"16_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"409","DOI":"10.1007\/978-3-030-17656-3_15","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2019","author":"DJ Bernstein","year":"2019","unstructured":"Bernstein, D.J., Lange, T., Martindale, C., Panny, L.: Quantum circuits for the CSIDH: optimizing quantum evaluation of isogenies. In: Ishai, Y., Rijmen, V. (eds.) EUROCRYPT 2019. LNCS, vol. 11477, pp. 409\u2013441. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-17656-3_15"},{"key":"16_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1007\/978-3-030-34578-5_9","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2019","author":"W Beullens","year":"2019","unstructured":"Beullens, W., Kleinjung, T., Vercauteren, F.: CSI-FiSh: efficient isogeny based signatures through class group computations. In: Galbraith, S.D., Moriai, S. (eds.) ASIACRYPT 2019. LNCS, vol. 11921, pp. 227\u2013247. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-34578-5_9"},{"key":"16_CR4","unstructured":"Bisson, G., Cosset, R., Robert, D.: AVIsogenies (abelian varieties and isogenies). MAGMA package. https:\/\/gitlab.inria.fr\/roberdam\/avisogenies"},{"key":"16_CR5","unstructured":"Bottinelli, P., de\u00a0Quehen, V., Leonardi, C., Mosunov, A., Pawlega, F., Sheth, M.: The Dark SIDH of Isogenies. Preprint (2019). https:\/\/ia.cr\/2019\/1333"},{"key":"16_CR6","doi-asserted-by":"crossref","unstructured":"Br\u00f6ker, R., Howe, E.W., Lauter, K.E., Stevenhagen, P.: Genus-2 curves and Jacobians with a given number of points. LMS J. Comput. Math. 18(1), 170\u2013197 (2015). https:\/\/doi.org\/10.1112\/S1461157014000461","DOI":"10.1112\/S1461157014000461"},{"issue":"1","key":"16_CR7","doi-asserted-by":"publisher","first-page":"213","DOI":"10.2140\/obs.2013.1.213","volume":"1","author":"P Castel","year":"2013","unstructured":"Castel, P.: Solving quadratic equations in dimension 5 or more without factoring. Open Book Ser. 1(1), 213\u2013233 (2013)","journal-title":"Open Book Ser."},{"key":"16_CR8","unstructured":"Castryck, W., Decru, T.: An efficient key recovery attack on SIDH (preliminary version). Preprint (2022). https:\/\/ia.cr\/2022\/975"},{"key":"16_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"395","DOI":"10.1007\/978-3-030-03332-3_15","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2018","author":"W Castryck","year":"2018","unstructured":"Castryck, W., Lange, T., Martindale, C., Panny, L., Renes, J.: CSIDH: an efficient post-quantum commutative group action. In: Peyrin, T., Galbraith, S. (eds.) ASIACRYPT 2018. LNCS, vol. 11274, pp. 395\u2013427. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03332-3_15"},{"key":"16_CR10","doi-asserted-by":"publisher","unstructured":"Cohen, H.: Number Theory: Volume I: Tools and Diophantine Equations, vol. 239. Springer, New York (2008). https:\/\/doi.org\/10.1007\/978-0-387-49923-9","DOI":"10.1007\/978-0-387-49923-9"},{"key":"16_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"440","DOI":"10.1007\/978-3-030-64834-3_15","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"C Costello","year":"2020","unstructured":"Costello, C.: B-SIDH: supersingular isogeny Diffie-Hellman using twisted torsion. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020. LNCS, vol. 12492, pp. 440\u2013463. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_15"},{"key":"16_CR12","unstructured":"Costello, C.: The case for SIKE: a decade of the supersingular isogeny problem. In: The NIST 3rd Post-Quantum Cryptography Standardization Conference (2021). https:\/\/ia.cr\/2021\/543"},{"key":"16_CR13","doi-asserted-by":"publisher","unstructured":"De Feo, L., et al.: S\u00e9ta: supersingular encryption from torsion attacks. In: ASIACRYPT\u00a0(4). LNCS, vol. 13093, pp. 249\u2013278. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92068-5_9","DOI":"10.1007\/978-3-030-92068-5_9"},{"key":"16_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-3-030-64837-4_3","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"L De Feo","year":"2020","unstructured":"De Feo, L., Kohel, D., Leroux, A., Petit, C., Wesolowski, B.: SQISign: compact post-quantum signatures from quaternions and isogenies. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020. LNCS, vol. 12491, pp. 64\u201393. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64837-4_3"},{"key":"16_CR15","unstructured":"Eriksen, J.K., Panny, L., Sot\u00e1kov\u00e1, J., Veroni, M.: Deuring for the People: Supersingular Elliptic Curves with Prescribed Endomorphism Ring in General Characteristic. Preprint (2023). https:\/\/ia.cr\/2023\/106"},{"key":"16_CR16","doi-asserted-by":"publisher","unstructured":"Fouotsa, T.B., Kutas, P., Merz, S., Ti, Y.B.: On the isogeny problem with torsion point information. In: Hanaoka, G., Shikata, J., Watanabe, Y. (eds.) Public Key Cryptography\u00a0(1). LNCS, vol. 13177, pp. 142\u2013161. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-030-97121-2_6","DOI":"10.1007\/978-3-030-97121-2_6"},{"key":"16_CR17","doi-asserted-by":"crossref","unstructured":"von zur Gathen, J., Gerhard, J.: Modern Computer Algebra, 3rd edn. Cambridge University Press, Cambridge (2013)","DOI":"10.1017\/CBO9781139856065"},{"key":"16_CR18","unstructured":"Jao, D., et al.: Supersingular Isogeny Key Encapsulation. Submission to\u00a0[27] (2017, 2019, 2020). https:\/\/sike.org"},{"key":"16_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-642-25405-5_2","volume-title":"Post-Quantum Cryptography","author":"D Jao","year":"2011","unstructured":"Jao, D., De Feo, L.: Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies. In: Yang, B.-Y. (ed.) PQCrypto 2011. LNCS, vol. 7071, pp. 19\u201334. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25405-5_2"},{"key":"16_CR20","doi-asserted-by":"publisher","unstructured":"Kani, E.: The number of curves of genus two with elliptic differentials (1997). https:\/\/doi.org\/10.1515\/crll.1997.485.93","DOI":"10.1515\/crll.1997.485.93"},{"key":"16_CR21","unstructured":"Kunzweiler, S.: Efficient Computation of $${(2^n,2^n)}$$-Isogenies. Preprint (2022). https:\/\/ia.cr\/2022\/990"},{"key":"16_CR22","doi-asserted-by":"publisher","unstructured":"Lubicz, D., Robert, D.: Fast change of level and applications to isogenies. In: ANTS XV: Proceedings of the Fifteenth Algorithmic Number Theory Symposium (2022). https:\/\/doi.org\/10.1007\/s40993-022-00407-9","DOI":"10.1007\/s40993-022-00407-9"},{"key":"16_CR23","unstructured":"Lubicz, D., Somoza, A.: AVIsogenies SageMath package. https:\/\/gitlab.inria.fr\/roberdam\/avisogenies\/-\/tree\/sage"},{"key":"16_CR24","unstructured":"Maino, L., Martindale, C.: An attack on SIDH with arbitrary starting curve. Preprint (2022). Version 2: https:\/\/eprint.iacr.org\/archive\/2022\/1026\/20220825:192029"},{"key":"16_CR25","unstructured":"Maino, L., Martindale, C.: An attack on SIDH with arbitrary starting curve. Preprint (2022). Version 1: https:\/\/eprint.iacr.org\/archive\/2022\/1026\/20220808:211318"},{"key":"16_CR26","doi-asserted-by":"publisher","unstructured":"Milne, J.S.: Abelian varieties. In: Cornell, G., Silverman, J.H. (eds.) Arithmetic Geometry, pp. 103\u2013150. Springer, New York (1986). https:\/\/doi.org\/10.1007\/978-1-4613-8655-1_5","DOI":"10.1007\/978-1-4613-8655-1_5"},{"key":"16_CR27","unstructured":"National Institute of Standards and Technology: Post-Quantum Cryptography Standardization, December 2016. https:\/\/csrc.nist.gov\/Projects\/Post-Quantum-Cryptography\/Post-Quantum-Cryptography-Standardization"},{"key":"16_CR28","unstructured":"Oudompheng, R., Panny, L., Pope, G., et\u00a0al.: SageMath Reimplementation of the SIDH key recovery attack (2022). https:\/\/github.com\/jack4818\/Castryck-Decru-SageMath"},{"key":"16_CR29","unstructured":"Oudompheng, R., Pope, G.: A note on Reimplementing the Castryck-Decru attack and lessons learned for SageMath. Preprint (2022). https:\/\/ia.cr\/2022\/1283"},{"key":"16_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"330","DOI":"10.1007\/978-3-319-70697-9_12","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2017","author":"C Petit","year":"2017","unstructured":"Petit, C.: Faster algorithms for isogeny problems using torsion point images. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017. LNCS, vol. 10625, pp. 330\u2013353. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70697-9_12"},{"key":"16_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"432","DOI":"10.1007\/978-3-030-84252-9_15","volume-title":"Advances in Cryptology \u2013 CRYPTO 2021","author":"V de Quehen","year":"2021","unstructured":"de Quehen, V., et al.: Improved torsion-point attacks on SIDH variants. In: Malkin, T., Peikert, C. (eds.) CRYPTO 2021. LNCS, vol. 12827, pp. 432\u2013470. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-84252-9_15"},{"key":"16_CR32","unstructured":"Robert, D.: Breaking SIDH in polynomial time. Preprint (2022). https:\/\/ia.cr\/2022\/1038"},{"key":"16_CR33","doi-asserted-by":"crossref","unstructured":"Shoup, V.: Fast construction of irreducible polynomials over finite fields. J. Symb. Comput. 17(5), 371\u2013391 (1994). https:\/\/doi.org\/10.1006\/jsco.1994.1025","DOI":"10.1006\/jsco.1994.1025"},{"key":"16_CR34","doi-asserted-by":"publisher","unstructured":"Silverman, J.H.: The Arithmetic of Elliptic Curves, vol.\u00a0106. Springer, New York (2009). https:\/\/doi.org\/10.1007\/978-0-387-09494-6","DOI":"10.1007\/978-0-387-09494-6"},{"key":"16_CR35","unstructured":"Smith, B.: Explicit endomorphisms and correspondences. Ph.D. thesis, University of Sydney (2005)"},{"key":"16_CR36","unstructured":"The Sage Developers: SageMath, the Sage Mathematics Software System (Version 9.6) (2022). https:\/\/sagemath.org"},{"key":"16_CR37","unstructured":"Ti, Y.B.: Isogenies of Abelian Varieties in Cryptography. Ph.D. thesis, University of Auckland (2019)"},{"key":"16_CR38","doi-asserted-by":"crossref","unstructured":"Wesolowski, B.: The supersingular isogeny path and endomorphism ring problems are equivalent. In: 62nd IEEE Annual Symposium on Foundations of Computer Science, FOCS 2021, Denver, CO, USA, 7\u201310 February 2022, pp. 1100\u20131111. IEEE (2021). https:\/\/doi.org\/10.1109\/FOCS52979.2021.00109","DOI":"10.1109\/FOCS52979.2021.00109"},{"key":"16_CR39","unstructured":"Wesolowski, B.: Understanding and improving the Castryck-Decru attack on SIDH. Preprint (2022)"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2023"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-30589-4_16","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,4,15]],"date-time":"2023-04-15T11:05:17Z","timestamp":1681556717000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-30589-4_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031305887","9783031305894"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-30589-4_16","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"16 April 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Lyon","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 April 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 April 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"42","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2023\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"415","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"109","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"26% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"16","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}