{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T07:38:00Z","timestamp":1777534680926,"version":"3.51.4"},"publisher-location":"Cham","reference-count":39,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031385476","type":"print"},{"value":"9783031385483","type":"electronic"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-38548-3_25","type":"book-chapter","created":{"date-parts":[[2023,8,8]],"date-time":"2023-08-08T19:02:27Z","timestamp":1691521347000},"page":"762-792","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":20,"title":["Weak Instances of Class Group Action Based Cryptography via Self-pairings"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0191-5216","authenticated-orcid":false,"given":"Wouter","family":"Castryck","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2158-1353","authenticated-orcid":false,"given":"Marc","family":"Houben","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2475-2966","authenticated-orcid":false,"given":"Simon-Philipp","family":"Merz","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5953-8724","authenticated-orcid":false,"given":"Marzio","family":"Mula","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8826-8014","authenticated-orcid":false,"given":"Sam van","family":"Buuren","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7208-9599","authenticated-orcid":false,"given":"Frederik","family":"Vercauteren","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,8,9]]},"reference":[{"issue":"3\u20134","key":"25_CR1","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1006\/jsco.1996.0125","volume":"24","author":"W Bosma","year":"1997","unstructured":"Bosma, W., Cannon, J., Playoust, C.: The Magma algebra system I: the user language. J. Symb. Comput. 24(3\u20134), 235\u2013265 (1997)","journal-title":"J. Symb. Comput."},{"issue":"2","key":"25_CR2","doi-asserted-by":"publisher","first-page":"323","DOI":"10.5802\/jtnb.764","volume":"23","author":"P Bruin","year":"2011","unstructured":"Bruin, P.: The Tate pairing for Abelian varieties over finite fields. Journal de Th\u00e9orie des Nombres de Bordeaux 23(2), 323\u2013328 (2011)","journal-title":"Journal de Th\u00e9orie des Nombres de Bordeaux"},{"key":"25_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1007\/978-3-030-44223-1_7","volume-title":"Post-Quantum Cryptography","author":"W Castryck","year":"2020","unstructured":"Castryck, W., Decru, T.: CSIDH on the surface. In: Ding, J., Tillich, J.-P. (eds.) PQCrypto 2020. LNCS, vol. 12100, pp. 111\u2013129. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-44223-1_7"},{"key":"25_CR4","doi-asserted-by":"publisher","unstructured":"Castryck, W., Decru, T.: An efficient key recovery attack on SIDH. In: Hazay, C., Stam, M. (eds.) Eurocrypt 2023 Part 5. LNCS, vol. 14008, pp. 423\u2013447. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_15","DOI":"10.1007\/978-3-031-30589-4_15"},{"key":"25_CR5","doi-asserted-by":"publisher","unstructured":"Castryck, W., Lange, T., Martindale, C., Panny, L., Renes, J.: CSIDH: an efficient post-quantum commutative group action. In: Peyrin, T., Galbraith, S. (eds.) ASIACRYPT 2018 Part 3. LNCS, vol. 11274, pp. 395\u2013427. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03332-3_15","DOI":"10.1007\/978-3-030-03332-3_15"},{"key":"25_CR6","doi-asserted-by":"publisher","unstructured":"Castryck, W., Sot\u00e1kov\u00e1, J., Vercauteren, F.: Breaking the decisional Diffie-Hellman problem for class group actions using Genus theory. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020 Part 2. LNCS, vol. 12171, pp. 92\u2013120. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56880-1_4","DOI":"10.1007\/978-3-030-56880-1_4"},{"issue":"4","key":"25_CR7","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1007\/s40993-022-00399-6","volume":"8","author":"W Castryck","year":"2022","unstructured":"Castryck, W., Houben, M., Vercauteren, F., Wesolowski, B.: On the decisional Diffie-Hellman problem for class group actions on oriented elliptic curves. Res. Number Theory 8(4), 99 (2022)","journal-title":"Res. Number Theory"},{"key":"25_CR8","doi-asserted-by":"crossref","unstructured":"Castryck, W., Houben, M., Merz, S.-P., Mula, M., van Buuren, S., Vercauteren, F.: Weak instances of class group action based cryptography via self-pairings (2023). Full version on ePrint Archive available at https:\/\/eprint.iacr.org\/2023\/549","DOI":"10.1007\/978-3-031-38548-3_25"},{"key":"25_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"173","DOI":"10.1007\/978-3-030-30530-7_9","volume-title":"Progress in Cryptology \u2013 LATINCRYPT 2019","author":"D Cervantes-V\u00e1zquez","year":"2019","unstructured":"Cervantes-V\u00e1zquez, D., Chenu, M., Chi-Dom\u00ednguez, J.-J., De Feo, L., Rodr\u00edguez-Henr\u00edquez, F., Smith, B.: Stronger and faster side-channel protections for CSIDH. In: Schwabe, P., Th\u00e9riault, N. (eds.) LATINCRYPT 2019. LNCS, vol. 11774, pp. 173\u2013193. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-30530-7_9"},{"issue":"3","key":"25_CR10","doi-asserted-by":"publisher","first-page":"349","DOI":"10.1007\/s13389-021-00271-w","volume":"12","author":"J Ch\u00e1vez-Saab","year":"2022","unstructured":"Ch\u00e1vez-Saab, J., Chi-Dom\u00ednguez, J.-J., Jaques, S., Rodr\u00edguez-Henr\u00edquez, F.: The SQALE of CSIDH: sublinear V\u00e9lu quantum-resistant isogeny action with low exponents. J. Cryptogr. Eng. 12(3), 349\u2013368 (2022)","journal-title":"J. Cryptogr. Eng."},{"issue":"2","key":"25_CR11","first-page":"85","volume":"1","author":"M Chenu","year":"2021","unstructured":"Chenu, M., Smith, B.: Higher-degree supersingular group actions. Math. Cryptol. 1(2), 85\u2013101 (2021)","journal-title":"Math. Cryptol."},{"issue":"1","key":"25_CR12","doi-asserted-by":"publisher","first-page":"414","DOI":"10.1515\/jmc-2019-0034","volume":"14","author":"L Col\u00f2","year":"2020","unstructured":"Col\u00f2, L., Kohel, D.: Orienting supersingular isogeny graphs. J. Math. Cryptol. 14(1), 414\u2013437 (2020)","journal-title":"J. Math. Cryptol."},{"key":"25_CR13","unstructured":"Couveignes, J.-M.: Hard homogeneous spaces (2006). Unpublished article. https:\/\/eprint.iacr.org\/2006\/291"},{"key":"25_CR14","unstructured":"Cox, D.A.: Primes of the Form $$x^2+ny^2$$: Fermat, Class Field Theory, and Complex Multiplication, vol. 116. Pure and Applied Mathematics, 2nd edn. Wiley (2013)"},{"key":"25_CR15","doi-asserted-by":"publisher","unstructured":"Dartois, P., De Feo, L.: On the security of OSIDH. In: Hanaoka, G., Shikata, J., Watanabe, Y. (eds.) PKC 2022 Part 1. LNCS, vol. 13177, pp. 52\u201381. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-030-97121-2_3","DOI":"10.1007\/978-3-030-97121-2_3"},{"key":"25_CR16","doi-asserted-by":"publisher","unstructured":"De Feo, L., et al.: SCALLOP: scaling the CSI-FiSh. In: Boldyreva, A., Kolesnikov, V. (eds.) PKC 2023 Part 1. LNCS, vol. 13940, pp. 345\u2013375. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-31368-4_13","DOI":"10.1007\/978-3-031-31368-4_13"},{"key":"25_CR17","unstructured":"De Feo, L., et al.: Modular isogeny problems. Private communication"},{"key":"25_CR18","first-page":"865","volume":"62","author":"G Frey","year":"1994","unstructured":"Frey, G., R\u00fcck, H.-G.: A remark concerning $$m$$-divisibility and the discrete logarithm in class groups of curves. Math. Comput. 62, 865\u2013874 (1994)","journal-title":"Math. Comput."},{"key":"25_CR19","doi-asserted-by":"crossref","unstructured":"Galbraith, S.: Pairings. In: Blake, I.F., Seroussi, G., Smart, N.P. (eds.) Advances in Elliptic Curve Cryptography. LMS Lecture Note Series, Chapter 9, vol. 317, pp. 183\u2013213. Cambridge University Press (2005)","DOI":"10.1017\/CBO9780511546570.011"},{"key":"25_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"118","DOI":"10.1007\/3-540-45995-2_15","volume-title":"LATIN 2002: Theoretical Informatics","author":"T Garefalakis","year":"2002","unstructured":"Garefalakis, T.: The generalized Weil pairing and the discrete logarithm problem on elliptic curves. In: Rajsbaum, S. (ed.) LATIN 2002. LNCS, vol. 2286, pp. 118\u2013130. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-45995-2_15"},{"key":"25_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-642-25405-5_2","volume-title":"Post-Quantum Cryptography","author":"D Jao","year":"2011","unstructured":"Jao, D., De Feo, L.: Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies. In: Yang, B.-Y. (ed.) PQCrypto 2011. LNCS, vol. 7071, pp. 19\u201334. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25405-5_2"},{"key":"25_CR22","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1006\/jnth.1996.0015","volume":"56","author":"HW Lenstra","year":"1996","unstructured":"Lenstra, H.W.: Complex multiplication structure of elliptic curves. J. Number Theory 56, 227\u2013241 (1996)","journal-title":"J. Number Theory"},{"key":"25_CR23","doi-asserted-by":"publisher","unstructured":"Maino, L., Martindale, C., Panny, L., Pope, G., Wesolowski, B.: A direct key recovery attack on SIDH. In: Eurocrypt 2023 Part 5. LNCS, vol. 14008, pp. 448\u2013471. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_16","DOI":"10.1007\/978-3-031-30589-4_16"},{"key":"25_CR24","unstructured":"Miller, V.S.: Short programs for functions on curves (1986). Unpublished note https:\/\/crypto.stanford.edu\/miller\/miller.pdf"},{"issue":"4","key":"25_CR25","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1007\/s00145-004-0315-8","volume":"17","author":"VS Miller","year":"2004","unstructured":"Miller, V.S.: The Weil pairing, and its efficient calculation. J. Cryptol. 17(4), 235\u2013261 (2004)","journal-title":"J. Cryptol."},{"key":"25_CR26","doi-asserted-by":"publisher","unstructured":"Moriya, Tomoki, Onuki, Hiroshi, Takagi, Tsuyoshi: SiGamal: a supersingular isogeny-based PKE and its application to a PRF. In: Moriai, Shiho, Wang, Huaxiong (eds.) ASIACRYPT 2020 Part 2. LNCS, vol. 12492, pp. 551\u2013580. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_19","DOI":"10.1007\/978-3-030-64834-3_19"},{"key":"25_CR27","doi-asserted-by":"crossref","unstructured":"Onuki, H.: On oriented supersingular elliptic curves. Finite Fields Appl. 69, Article id 101777 (2021)","DOI":"10.1016\/j.ffa.2020.101777"},{"key":"25_CR28","unstructured":"Robert, D.: Efficient algorithms for Abelian varieties and their moduli spaces. Habilitation \u00e0 Diriger des Recherches (2021)"},{"key":"25_CR29","unstructured":"Robert, D.: Some applications of higher dimensional isogenies to elliptic curves (overview of results) (2022). Preprint https:\/\/eprint.iacr.org\/2022\/1704"},{"key":"25_CR30","unstructured":"Robert, D.: The geometric interpretation of the Tate pairing and its applications (2023). Preprint https:\/\/eprint.iacr.org\/2023\/177"},{"key":"25_CR31","doi-asserted-by":"publisher","unstructured":"Robert, D.: Breaking SIDH in polynomial time. In: Hazay, C., Stam, M. (eds.) Eurocrypt 2023 Part 5. LNCS, vol. 14008, pp. 472\u2013503. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_17","DOI":"10.1007\/978-3-031-30589-4_17"},{"key":"25_CR32","unstructured":"Rostovtsev, A., Stolbunov, A.: Public-key cryptosystem based on isogenies (2006). Unpublished article https:\/\/eprint.iacr.org\/2006\/145"},{"key":"25_CR33","first-page":"81","volume":"47","author":"T Satoh","year":"1998","unstructured":"Satoh, T., Araki, K.: Fermat quotients and the polynomial time discrete log algorithm for anomalous elliptic curves. Commentarii Mathematici Universitatis Sancti Pauli 47, 81\u201392 (1998)","journal-title":"Commentarii Mathematici Universitatis Sancti Pauli"},{"issue":"170","key":"25_CR34","first-page":"483","volume":"44","author":"R Schoof","year":"1985","unstructured":"Schoof, R.: Elliptic curves over finite fields and the computation of square roots mod $$p$$. Math. Comput. 44(170), 483\u2013494 (1985)","journal-title":"Math. Comput."},{"issue":"2","key":"25_CR35","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1016\/0097-3165(87)90003-3","volume":"36","author":"R Schoof","year":"1987","unstructured":"Schoof, R.: Nonsingular plane cubic curves over finite fields. J. Comb. Theory Ser. A 36(2), 183\u2013211 (1987)","journal-title":"J. Comb. Theory Ser. A"},{"key":"25_CR36","doi-asserted-by":"publisher","unstructured":"Silverman, J.H.: The Arithmetic of Elliptic Curves, Graduate Texts in Mathematics, vol. 106, 2nd edn. Springer, Cham (2009). https:\/\/doi.org\/10.1007\/978-0-387-09494-6","DOI":"10.1007\/978-0-387-09494-6"},{"key":"25_CR37","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1007\/s001459900052","volume":"12","author":"NP Smart","year":"1999","unstructured":"Smart, N.P.: The discrete logarithm problem on elliptic curves of trace one. J. Cryptol. 12, 193\u2013196 (1999)","journal-title":"J. Cryptol."},{"key":"25_CR38","doi-asserted-by":"publisher","first-page":"521","DOI":"10.24033\/asens.1183","volume":"2","author":"WC Waterhouse","year":"1969","unstructured":"Waterhouse, W.C.: Abelian varieties over finite fields. Annales scientifiques de l\u2019\u00c9cole Normale Sup\u00e9rieure 2, 521\u2013560 (1969)","journal-title":"Annales scientifiques de l\u2019\u00c9cole Normale Sup\u00e9rieure"},{"key":"25_CR39","doi-asserted-by":"crossref","unstructured":"Wesolowski, B.: The supersingular isogeny path and endomorphism ring problems are equivalent. In: FOCS 2021, pp. 1100\u20131111. IEEE (2022)","DOI":"10.1109\/FOCS52979.2021.00109"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2023"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-38548-3_25","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,26]],"date-time":"2025-07-26T22:02:33Z","timestamp":1753567353000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-38548-3_25"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031385476","9783031385483"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-38548-3_25","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"9 August 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRYPTO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Cryptology Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Santa Barbara, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 August 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 August 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"43","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crypto2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crypto.iacr.org\/2023\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"479","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"124","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"26% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"15","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}