{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T04:28:48Z","timestamp":1778128128571,"version":"3.51.4"},"publisher-location":"Cham","reference-count":71,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031683879","type":"print"},{"value":"9783031683886","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-68388-6_8","type":"book-chapter","created":{"date-parts":[[2024,8,16]],"date-time":"2024-08-16T08:02:51Z","timestamp":1723795371000},"page":"183-217","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Improved Algorithms for\u00a0Finding Fixed-Degree Isogenies Between Supersingular Elliptic Curves"],"prefix":"10.1007","author":[{"given":"Benjamin","family":"Ben\u010dina","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"P\u00e9ter","family":"Kutas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Simon-Philipp","family":"Merz","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christophe","family":"Petit","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Miha","family":"Stopar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Charlotte","family":"Weitk\u00e4mper","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,8,17]]},"reference":[{"key":"8_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"322","DOI":"10.1007\/978-3-030-10970-7_15","volume-title":"Selected Areas in Cryptography","author":"G Adj","year":"2019","unstructured":"Adj, G., Cervantes-V\u00e1zquez, D., Chi-Dom\u00ednguez, J.J., Menezes, A., Rodr\u00edguez-Henr\u00edquez, F.: On the cost of computing isogenies between supersingular elliptic curves. In: Cid, C., Jacobson, M., Jr. (eds.) SAC 2018. LNCS, vol. 11349, pp. 322\u2013343. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-10970-7_15"},{"key":"8_CR2","doi-asserted-by":"crossref","unstructured":"Arpin, S., Clements, J., Dartois, P., Eriksen, J.K., Kutas, P., Wesolowski, B.: Finding orientations of supersingular elliptic curves and quaternion orders. Cryptology ePrint Archive, Paper 2023\/1268 (2023). https:\/\/eprint.iacr.org\/2023\/1268","DOI":"10.1007\/s10623-024-01435-5"},{"key":"8_CR3","unstructured":"Basso, A., et\u00a0al.: Exploring SIDH-based signature parameters. Cryptology ePrint Archive, Paper 2023\/1906. To be published at ACNS 2024 (2023). https:\/\/eprint.iacr.org\/2023\/1906"},{"key":"8_CR4","doi-asserted-by":"crossref","unstructured":"Basso, A., Maino, L., Pope, G.: FESTA: fast encryption from supersingular torsion attacks. Cryptology ePrint Archive, Paper 2023\/660 (2023). https:\/\/eprint.iacr.org\/2023\/660","DOI":"10.1007\/978-981-99-8739-9_4"},{"key":"8_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"361","DOI":"10.1007\/978-3-540-72540-4_21","volume-title":"Advances in Cryptology - EUROCRYPT 2007","author":"A Bauer","year":"2007","unstructured":"Bauer, A., Joux, A.: Toward a rigorous variation of Coppersmith\u2019s algorithm on three variables. In: Naor, M. (ed.) EUROCRYPT 2007. LNCS, vol. 4515, pp. 361\u2013378. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-72540-4_21"},{"key":"8_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"609","DOI":"10.1007\/978-3-642-30057-8_36","volume-title":"Public Key Cryptography \u2013 PKC 2012","author":"A Bauer","year":"2012","unstructured":"Bauer, A., Vergnaud, D., Zapalowicz, J.-C.: Inferring sequences produced by nonlinear pseudorandom number generators using Coppersmith\u2019s methods. In: Fischlin, M., Buchmann, J., Manulis, M. (eds.) PKC 2012. LNCS, vol. 7293, pp. 609\u2013626. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-30057-8_36"},{"key":"8_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"294","DOI":"10.1007\/978-3-031-22912-1_13","volume-title":"Progress in Cryptology","author":"E Bellini","year":"2022","unstructured":"Bellini, E., et al.: Parallel isogeny path finding with limited memory. In: Isobe, T., Sarkar, S. (eds.) INDOCRYPT 2022. LNCS, vol. 13774, pp. 294\u2013316. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-22912-1_13"},{"key":"8_CR8","unstructured":"Ben\u010dina, B., Kutas, P., Merz, S.P., Petit, C., Stopar, M., Weitk\u00e4mper, C.: Improved algorithms for finding fixed-degree isogenies between supersingular elliptic curves. Cryptology ePrint Archive (2023). https:\/\/eprint.iacr.org\/2023\/1618"},{"key":"8_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"428","DOI":"10.1007\/978-3-319-13039-2_25","volume-title":"Progress in Cryptology \u2013 INDOCRYPT 2014","author":"J-F Biasse","year":"2014","unstructured":"Biasse, J.-F., Jao, D., Sankar, A.: A quantum algorithm for computing isogenies between supersingular elliptic curves. In: Meier, W., Mukhopadhyay, D. (eds.) INDOCRYPT 2014. LNCS, vol. 8885, pp. 428\u2013442. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-13039-2_25"},{"key":"8_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/3-540-48910-X_1","volume-title":"Advances in Cryptology \u2014 EUROCRYPT \u201999","author":"D Boneh","year":"1999","unstructured":"Boneh, D., Durfee, G.: Cryptanalysis of RSA with private key $$d$$ less than $$N^{0.292}$$. In: Stern, J. (ed.) EUROCRYPT 1999. LNCS, vol. 1592, pp. 1\u201311. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-48910-X_1"},{"key":"8_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"326","DOI":"10.1007\/3-540-48405-1_21","volume-title":"Advances in Cryptology","author":"D Boneh","year":"1999","unstructured":"Boneh, D., Durfee, G., Howgrave-Graham, N.: Factoring $$n= p^{r}q$$ for large\u00a0$$r$$. In: Wiener, M. (ed.) CRYPTO 1999. LNCS, vol. 1666, pp. 326\u2013337. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-48405-1_21"},{"key":"8_CR12","doi-asserted-by":"publisher","unstructured":"Bosma, W., Cannon, J., Playoust, C.: The Magma algebra system. I. The user language. J. Symbolic Comput. 24(3\u20134), 235\u2013265 (1997). https:\/\/doi.org\/10.1006\/jsco.1996.0125. Computational algebra and number theory (London, 1993)","DOI":"10.1006\/jsco.1996.0125"},{"key":"8_CR13","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"423","DOI":"10.1007\/978-3-031-30589-4_15","volume-title":"EUROCRYPT 2023","author":"W Castryck","year":"2023","unstructured":"Castryck, W., Decru, T.: An efficient key recovery attack on SIDH. In: Hazay, C., Stam, M. (eds.) EUROCRYPT 2023. LNCS, vol. 14008, pp. 423\u2013447. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_15"},{"key":"8_CR14","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"762","DOI":"10.1007\/978-3-031-38548-3_25","volume-title":"CRYPTO 2023, Part III","author":"W Castryck","year":"2023","unstructured":"Castryck, W., Houben, M., Merz, S.P., Mula, M., van Buuren, S., Vercauteren, F.: Weak instances of class group action based cryptography via self-pairings. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO 2023, Part III. LNCS, vol. 14083, pp. 762\u2013792. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38548-3_25"},{"key":"8_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"395","DOI":"10.1007\/978-3-030-03332-3_15","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2018","author":"W Castryck","year":"2018","unstructured":"Castryck, W., Lange, T., Martindale, C., Panny, L., Renes, J.: CSIDH: an efficient post-quantum commutative group action. In: Peyrin, T., Galbraith, S. (eds.) ASIACRYPT 2018. LNCS, vol. 11274, pp. 395\u2013427. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03332-3_15"},{"key":"8_CR16","volume-title":"A Course in Computational Algebraic Number Theory","author":"H Cohen","year":"2013","unstructured":"Cohen, H.: A Course in Computational Algebraic Number Theory, vol. 138. Springer, Cham (2013)"},{"key":"8_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"178","DOI":"10.1007\/3-540-68339-9_16","volume-title":"Advances in Cryptology \u2014 EUROCRYPT \u201996","author":"D Coppersmith","year":"1996","unstructured":"Coppersmith, D.: Finding a small root of a bivariate integer equation; factoring with high bits known. In: Maurer, U. (ed.) EUROCRYPT 1996. LNCS, vol. 1070, pp. 178\u2013189. Springer, Heidelberg (1996). https:\/\/doi.org\/10.1007\/3-540-68339-9_16"},{"key":"8_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"155","DOI":"10.1007\/3-540-68339-9_14","volume-title":"Advances in Cryptology \u2014 EUROCRYPT \u201996","author":"D Coppersmith","year":"1996","unstructured":"Coppersmith, D.: Finding a small root of a univariate modular equation. In: Maurer, U. (ed.) EUROCRYPT 1996. LNCS, vol. 1070, pp. 155\u2013165. Springer, Heidelberg (1996). https:\/\/doi.org\/10.1007\/3-540-68339-9_14"},{"issue":"4","key":"8_CR19","doi-asserted-by":"publisher","first-page":"233","DOI":"10.1007\/s001459900030","volume":"10","author":"D Coppersmith","year":"1997","unstructured":"Coppersmith, D.: Small solutions to polynomial equations, and low exponent RSA vulnerabilities. J. Cryptol. 10(4), 233\u2013260 (1997)","journal-title":"J. Cryptol."},{"key":"8_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"492","DOI":"10.1007\/978-3-540-24676-3_29","volume-title":"Advances in Cryptology - EUROCRYPT 2004","author":"J-S Coron","year":"2004","unstructured":"Coron, J.-S.: Finding small roots of bivariate integer polynomial equations revisited. In: Cachin, C., Camenisch, J.L. (eds.) EUROCRYPT 2004. LNCS, vol. 3027, pp. 492\u2013505. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-24676-3_29"},{"key":"8_CR21","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"285","DOI":"10.1007\/978-3-031-15982-4_10","volume-title":"CRYPTO 2022, Part III","author":"M Corte-Real Santos","year":"2022","unstructured":"Corte-Real Santos, M., Costello, C., Shi, J.: Accelerating the Delfs-Galbraith algorithm with fast subfield root detection. In: Dodis, Y., Shrimpton, T. (eds.) CRYPTO 2022, Part III. LNCS, vol. 13509, pp. 285\u2013314. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-15982-4_10"},{"key":"8_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"505","DOI":"10.1007\/978-3-030-45388-6_18","volume-title":"Public-Key Cryptography \u2013 PKC 2020","author":"C Costello","year":"2020","unstructured":"Costello, C., Longa, P., Naehrig, M., Renes, J., Virdia, F.: Improved classical cryptanalysis of SIKE in practice. In: Kiayias, A., Kohlweiss, M., Wallden, P., Zikas, V. (eds.) PKC 2020. LNCS, vol. 12111, pp. 505\u2013534. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45388-6_18"},{"key":"8_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"440","DOI":"10.1007\/978-3-030-64834-3_15","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"C Costello","year":"2020","unstructured":"Costello, C.: B-SIDH: supersingular isogeny Diffie-Hellman using twisted torsion. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020, Part II. LNCS, vol. 12492, pp. 440\u2013463. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_15"},{"key":"8_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-3-030-64837-4_3","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"L De Feo","year":"2020","unstructured":"De Feo, L., Kohel, D., Leroux, A., Petit, C., Wesolowski, B.: SQISign: compact post-quantum signatures from quaternions and isogenies. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020. LNCS, vol. 12491, pp. 64\u201393. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64837-4_3"},{"issue":"2","key":"8_CR25","doi-asserted-by":"publisher","first-page":"425","DOI":"10.1007\/s10623-014-0010-1","volume":"78","author":"C Delfs","year":"2016","unstructured":"Delfs, C., Galbraith, S.D.: Computing isogenies between supersingular elliptic curves over $$\\mathbb{F} _p$$. Des. Codes Crypt. 78(2), 425\u2013440 (2016)","journal-title":"Des. Codes Crypt."},{"key":"8_CR26","doi-asserted-by":"crossref","unstructured":"Deuring, M.: Die Typen der Multiplikatorenringe elliptischer Funktionenk\u00f6rper: G. Herglotz zum 60. Geburtstag gewidmet. In: Abhandlungen aus dem mathematischen Seminar der Universit\u00e4t Hamburg, vol.\u00a014, pp. 197\u2013272 (1941)","DOI":"10.1007\/BF02940746"},{"key":"8_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"329","DOI":"10.1007\/978-3-319-78372-7_11","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2018","author":"K Eisentr\u00e4ger","year":"2018","unstructured":"Eisentr\u00e4ger, K., Hallgren, S., Lauter, K., Morrison, T., Petit, C.: Supersingular isogeny graphs and endomorphism rings: reductions and solutions. In: Nielsen, J.B., Rijmen, V. (eds.) EUROCRYPT 2018, Part III. LNCS, vol. 10822, pp. 329\u2013368. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-78372-7_11"},{"issue":"1","key":"8_CR28","doi-asserted-by":"publisher","first-page":"215","DOI":"10.2140\/obs.2020.4.215","volume":"4","author":"K Eisentr\u00e4ger","year":"2020","unstructured":"Eisentr\u00e4ger, K., Hallgren, S., Leonardi, C., Morrison, T., Park, J.: Computing endomorphism rings of supersingular elliptic curves and connections to path-finding in isogeny graphs. Open Book Series 4(1), 215\u2013232 (2020)","journal-title":"Open Book Series"},{"key":"8_CR29","unstructured":"Eriksen, J.K., Leroux, A.: Computing orientations from the endomorphism ring of supersingular curves and applications. Cryptology ePrint Archive, Paper 2024\/146 (2024). https:\/\/eprint.iacr.org\/2024\/146"},{"key":"8_CR30","unstructured":"Fouotsa, T.B., Kutas, P., Merz, S.P., Ti, Y.B.: On the isogeny problem with torsion point information. Cryptology ePrint Archive, Paper 2021\/153 (2021). https:\/\/eprint.iacr.org\/2021\/153"},{"key":"8_CR31","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"142","DOI":"10.1007\/978-3-030-97121-2_6","volume-title":"PKC 2022","author":"TB Fouotsa","year":"2022","unstructured":"Fouotsa, T.B., Kutas, P., Merz, S.P., Ti, Y.B.: On the isogeny problem with torsion point information. In: Hanaoka, G., Shikata, J., Watanabe, Y. (eds.) PKC 2022. LNCS, vol. 13177, pp. 142\u2013161. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-030-97121-2_6"},{"key":"8_CR32","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"282","DOI":"10.1007\/978-3-031-30589-4_10","volume-title":"EUROCRYPT 2023","author":"TB Fouotsa","year":"2023","unstructured":"Fouotsa, T.B., Moriya, T., Petit, C.: M-SIDH and MD-SIDH: countering SIDH attacks by masking information. In: Hazay, C., Stam, M. (eds.) EUROCRYPT 2023. LNCS, vol. 14008, pp. 282\u2013309. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_10"},{"key":"8_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1007\/978-3-662-53887-6_3","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2016","author":"SD Galbraith","year":"2016","unstructured":"Galbraith, S.D., Petit, C., Shani, B., Ti, Y.B.: On the security of supersingular isogeny cryptosystems. In: Cheon, J.H., Takagi, T. (eds.) ASIACRYPT 2016. LNCS, vol. 10031, pp. 63\u201391. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53887-6_3"},{"key":"8_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"100","DOI":"10.1007\/0-387-34799-2_9","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 88","author":"M Girault","year":"1990","unstructured":"Girault, M., Toffin, P., Vall\u00e9e, B.: Computation of approximate $$l$$-th roots modulo $$n$$ and application to cryptography. In: Goldwasser, S. (ed.) CRYPTO 1988. LNCS, vol. 403, pp. 100\u2013117. Springer, New York (1990). https:\/\/doi.org\/10.1007\/0-387-34799-2_9"},{"key":"8_CR35","doi-asserted-by":"crossref","unstructured":"Grover, L.K.: A fast quantum mechanical algorithm for database search. In: Proceedings of the Twenty-Eighth Annual ACM Symposium on the Theory of Computing, Philadelphia, Pennsylvania, USA, 22\u201324 May 1996, pp. 212\u2013219 (1996)","DOI":"10.1145\/237814.237866"},{"key":"8_CR36","volume-title":"An Introduction to the Theory of Numbers","author":"GH Hardy","year":"1979","unstructured":"Hardy, G.H., Wright, E.M., et al.: An Introduction to the Theory of Numbers. Oxford University Press, Oxford (1979)"},{"key":"8_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"403","DOI":"10.1007\/3-540-39799-X_29","volume-title":"Advances in Cryptology \u2014 CRYPTO \u201985 Proceedings","author":"J Hastad","year":"1986","unstructured":"Hastad, J.: N using RSA with low exponent in a public key network. In: Williams, H.C. (ed.) CRYPTO 1985. LNCS, vol. 218, pp. 403\u2013408. Springer, Heidelberg (1986). https:\/\/doi.org\/10.1007\/3-540-39799-X_29"},{"key":"8_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1007\/BFb0024458","volume-title":"Crytography and Coding","author":"N Howgrave-Graham","year":"1997","unstructured":"Howgrave-Graham, N.: Finding small roots of univariate modular equations revisited. In: Darnell, M. (ed.) Cryptography and Coding 1997. LNCS, vol. 1355, pp. 131\u2013142. Springer, Heidelberg (1997). https:\/\/doi.org\/10.1007\/BFb0024458"},{"key":"8_CR39","unstructured":"W.R. Inc.: Mathematica, Version 11, Champaign, IL (2023). https:\/\/www.wolfram.com\/mathematica"},{"key":"8_CR40","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-642-25405-5_2","volume-title":"Post-Quantum Cryptography","author":"D Jao","year":"2011","unstructured":"Jao, D., De Feo, L.: Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies. In: Yang, B.-Y. (ed.) PQCrypto 2011. LNCS, vol. 7071, pp. 19\u201334. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25405-5_2"},{"key":"8_CR41","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1007\/978-3-030-26948-7_2","volume-title":"Advances in Cryptology \u2013 CRYPTO 2019","author":"S Jaques","year":"2019","unstructured":"Jaques, S., Schanck, J.M.: Quantum cryptanalysis in the RAM model: claw-finding attacks on SIKE. In: Boldyreva, A., Micciancio, D. (eds.) CRYPTO 2019. LNCS, vol. 11692, pp. 32\u201361. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-26948-7_2"},{"key":"8_CR42","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"158","DOI":"10.1007\/BFb0054124","volume-title":"Advances in Cryptology \u2014 EUROCRYPT\u201998","author":"CS Jutla","year":"1998","unstructured":"Jutla, C.S.: On finding small solutions of modular multivariate polynomial equations. In: Nyberg, K. (ed.) EUROCRYPT 1998. LNCS, vol. 1403, pp. 158\u2013170. Springer, Heidelberg (1998). https:\/\/doi.org\/10.1007\/BFb0054124"},{"issue":"5","key":"8_CR43","doi-asserted-by":"publisher","first-page":"1714","DOI":"10.1137\/080734467","volume":"39","author":"M Kirschmer","year":"2010","unstructured":"Kirschmer, M., Voight, J.: Algorithmic enumeration of ideal classes for quaternion orders. SIAM J. Comput. 39(5), 1714\u20131747 (2010)","journal-title":"SIAM J. Comput."},{"key":"8_CR44","doi-asserted-by":"crossref","unstructured":"Kohel, D., Lauter, K., Petit, C., Tignol, J.P.: On the quaternion $$\\ell $$-isogeny path problem. LMS J. Comput. Math. 17(A), 418\u2013432 (2014)","DOI":"10.1112\/S1461157014000151"},{"key":"8_CR45","unstructured":"Kohel, D.R.: Endomorphism rings of elliptic curves over finite fields. Ph.D. thesis, University of California, Berkeley (1996)"},{"key":"8_CR46","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"242","DOI":"10.1007\/978-3-030-77870-5_9","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2021","author":"P Kutas","year":"2021","unstructured":"Kutas, P., Merz, S.-P., Petit, C., Weitk\u00e4mper, C.: One-way functions and malleability oracles: hidden shift attacks on\u00a0isogeny-based protocols. In: Canteaut, A., Standaert, F.-X. (eds.) EUROCRYPT 2021, Part I. LNCS, vol. 12696, pp. 242\u2013271. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-77870-5_9"},{"key":"8_CR47","doi-asserted-by":"publisher","first-page":"515","DOI":"10.1007\/BF01457454","volume":"261","author":"AK Lenstra","year":"1982","unstructured":"Lenstra, A.K., Lenstra, H.W., Lov\u00e1sz, L.: Factoring polynomials with rational coefficients. Math. Ann. 261, 515\u2013534 (1982)","journal-title":"Math. Ann."},{"key":"8_CR48","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-031-22966-4_1","volume-title":"Advances in Cryptology","author":"A Leroux","year":"2022","unstructured":"Leroux, A.: A new isogeny representation and applications to cryptography. In: Agrawal, S., Lin, D. (eds.) ASIACRYPT 2022. LNCS, vol. 13792, pp. 3\u201335. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-22966-4_1"},{"key":"8_CR49","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"448","DOI":"10.1007\/978-3-031-30589-4_16","volume-title":"Advances in Cryptology","author":"L Maino","year":"2023","unstructured":"Maino, L., Martindale, C., Panny, L., Pope, G., Wesolowski, B.: A direct key recovery attack on SIDH. In: Hazay, C., Stam, M. (eds.) EUROCRYPT 2023, Part V. LNCS, vol. 14008, pp. 448\u2013471. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_16"},{"key":"8_CR50","unstructured":"Moriya, T.: IS-CUBE: an isogeny-based compact KEM using a boxed SIDH diagram. Cryptology ePrint Archive (2023)"},{"key":"8_CR51","doi-asserted-by":"crossref","unstructured":"Nakagawa, K., Onuki, H.: QFESTA: efficient algorithms and parameters for FESTA using quaternion algebras. Cryptology ePrint Archive (2023)","DOI":"10.1007\/978-3-031-68388-6_4"},{"key":"8_CR52","unstructured":"Nitaj, A.: L\u2019algorithme de Cornacchia. Exposition. Math. 13(4), 358\u2013365 (1995)"},{"key":"8_CR53","doi-asserted-by":"crossref","unstructured":"Page, A., Wesolowski, B.: The supersingular endomorphism ring and one endomorphism problems are equivalent. arXiv preprint arXiv:2309.10432 (2023)","DOI":"10.1109\/FOCS52979.2021.00109"},{"key":"8_CR54","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"330","DOI":"10.1007\/978-3-319-70697-9_12","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2017","author":"C Petit","year":"2017","unstructured":"Petit, C.: Faster algorithms for isogeny problems using torsion point images. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017, Part II. LNCS, vol. 10625, pp. 330\u2013353. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70697-9_12"},{"key":"8_CR55","unstructured":"Petit, C., Lauter, K.: Hard and easy problems for supersingular isogeny graphs. Cryptology ePrint Archive, Report 2017\/962 (2017). https:\/\/eprint.iacr.org\/2017\/962"},{"key":"8_CR56","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"432","DOI":"10.1007\/978-3-030-84252-9_15","volume-title":"Advances in Cryptology \u2013 CRYPTO 2021","author":"V de Quehen","year":"2021","unstructured":"de Quehen, V., et al.: Improved torsion-point attacks on SIDH variants. In: Malkin, T., Peikert, C. (eds.) CRYPTO 2021. LNCS, vol. 12827, pp. 432\u2013470. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-84252-9_15"},{"key":"8_CR57","doi-asserted-by":"crossref","unstructured":"Ribet, K.A.: Bimodules and abelian surfaces. In: Algebraic Number Theory-in Honor of K. Iwasawa, vol.\u00a017, pp. 359\u2013408. Mathematical Society of Japan (1989)","DOI":"10.2969\/aspm\/01710359"},{"key":"8_CR58","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4612-0251-6","volume-title":"Prime Numbers and Computer Methods for Factorization","author":"H Riesel","year":"1994","unstructured":"Riesel, H., Oesterl\u00e9, J., Weinstein, A.: Prime Numbers and Computer Methods for Factorization, vol. 126. Springer, Cham (1994)"},{"key":"8_CR59","unstructured":"Robert, D.: Evaluating isogenies in polylogarithmic time. Cryptology ePrint Archive, Paper 2022\/1068 (2022). https:\/\/eprint.iacr.org\/2022\/1068"},{"key":"8_CR60","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"472","DOI":"10.1007\/978-3-031-30589-4_17","volume-title":"Advances in Cryptology","author":"D Robert","year":"2023","unstructured":"Robert, D.: Breaking SIDH in polynomial time. In: Hazay, C., Stam, M. (eds.) EUROCRYPT 2023. LNCS, vol. 14008, pp. 472\u2013503. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_17"},{"key":"8_CR61","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1007\/978-3-540-79456-1_2","volume-title":"Algorithmic Number Theory","author":"RE Sawilla","year":"2008","unstructured":"Sawilla, R.E., Silvester, A.K., Williams, H.C.: A new look at an old equation. In: van der Poorten, A.J., Stein, A. (eds.) ANTS 2008. LNCS, vol. 5011, pp. 37\u201359. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-79456-1_2"},{"issue":"5","key":"8_CR62","doi-asserted-by":"publisher","first-page":"1484","DOI":"10.1137\/S0097539795293172","volume":"26","author":"PW Shor","year":"1997","unstructured":"Shor, P.W.: Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM J. Comput. 26(5), 1484\u20131509 (1997)","journal-title":"SIAM J. Comput."},{"key":"8_CR63","doi-asserted-by":"crossref","DOI":"10.1007\/978-0-387-09494-6","volume-title":"The Arithmetic of Elliptic Curves","author":"JH Silverman","year":"2009","unstructured":"Silverman, J.H.: The Arithmetic of Elliptic Curves, vol. 106. Springer, Cham (2009)"},{"issue":"50","key":"8_CR64","doi-asserted-by":"publisher","first-page":"5285","DOI":"10.1016\/j.tcs.2009.08.030","volume":"410","author":"S Tani","year":"2009","unstructured":"Tani, S.: Claw finding algorithms using quantum walk. Theor. Comput. Sci. 410(50), 5285\u20135297 (2009)","journal-title":"Theor. Comput. Sci."},{"key":"8_CR65","unstructured":"The Sage Developers: SageMath, the Sage Mathematics Software System (Version 10.0) (2023). https:\/\/www.sagemath.org"},{"key":"8_CR66","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-030-30530-7_1","volume-title":"Progress in Cryptology \u2013 LATINCRYPT 2019","author":"M Tiepelt","year":"2019","unstructured":"Tiepelt, M., Szepieniec, A.: Quantum LLL with an application to Mersenne number cryptosystems. In: Schwabe, P., Th\u00e9riault, N. (eds.) LATINCRYPT 2019. LNCS, vol. 11774, pp. 3\u201323. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-30530-7_1"},{"key":"8_CR67","doi-asserted-by":"publisher","DOI":"10.1007\/BFb0091027","volume-title":"Alg\u00e8bres De Quaternions Sur Un Corps","author":"MF Vign\u00e9ras","year":"1980","unstructured":"Vign\u00e9ras, M.F.: Alg\u00e8bres De Quaternions Sur Un Corps. Springer, Cham (1980)"},{"key":"8_CR68","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-56694-4","volume-title":"Quaternion Algebras","author":"J Voight","year":"2021","unstructured":"Voight, J.: Quaternion Algebras. Springer, Cham (2021)"},{"key":"8_CR69","doi-asserted-by":"crossref","unstructured":"Waterhouse, W.C.: Abelian varieties over finite fields. In: Annales scientifiques de l\u2019\u00c9cole Normale Sup\u00e9rieure, vol.\u00a02, pp. 521\u2013560 (1969)","DOI":"10.24033\/asens.1183"},{"key":"8_CR70","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"345","DOI":"10.1007\/978-3-031-07082-2_13","volume-title":"Advances in Cryptology","author":"B Wesolowski","year":"2022","unstructured":"Wesolowski, B.: Orientations and the supersingular endomorphism ring problem. In: Dunkelman, O., Dziembowski, S. (eds.) EUROCRYPT 2022, Part III. LNCS, vol. 13277, pp. 345\u2013371. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-07082-2_13"},{"key":"8_CR71","doi-asserted-by":"crossref","unstructured":"Wesolowski, B.: The supersingular isogeny path and endomorphism ring problems are equivalent. In: 2021 IEEE 62nd Annual Symposium on Foundations of Computer Science (FOCS), pp. 1100\u20131111. IEEE (2022)","DOI":"10.1109\/FOCS52979.2021.00109"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-68388-6_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,26]],"date-time":"2024-11-26T19:37:39Z","timestamp":1732649859000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-68388-6_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031683879","9783031683886"],"references-count":71,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-68388-6_8","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"17 August 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRYPTO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Cryptology Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Santa Barbara, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 August 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 August 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"44","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crypto2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crypto.iacr.org\/2024\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}