{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T11:07:44Z","timestamp":1775732864814,"version":"3.50.1"},"publisher-location":"Cham","reference-count":95,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032226976","type":"print"},{"value":"9783032226983","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-22698-3_3","type":"book-chapter","created":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T10:24:14Z","timestamp":1775730254000},"page":"74-104","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["On the Active Security of the PEARL-SCALLOP Group Action"],"prefix":"10.1007","author":[{"given":"Tako Boris","family":"Fouotsa","sequence":"first","affiliation":[]},{"given":"Marc","family":"Houben","sequence":"additional","affiliation":[]},{"given":"Gioella","family":"Lorenzon","sequence":"additional","affiliation":[]},{"given":"Ryan","family":"Rueger","sequence":"additional","affiliation":[]},{"given":"Parsa","family":"Tasbihgou","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2026,4,10]]},"reference":[{"key":"3_CR1","unstructured":"Aardal, M.A., et al.: SQIsign. Tech. Rep., National Institute of Standards and Technology (2024), available at https:\/\/csrc.nist.gov\/Projects\/pqc-dig-sig\/round-2-additional-signatures"},{"key":"3_CR2","doi-asserted-by":"publisher","unstructured":"Abdalla, M., Eisenhofer, T., Kiltz, E., Kunzweiler, S., Riepel, D.: Password-authenticated key exchange from group actions. In: Dodis, Y., Shrimpton, T. (eds.) CRYPTO\u00a02022, Part\u00a0II. LNCS, vol. 13508, pp. 699\u2013728. Springer, Cham (Aug 2022). https:\/\/doi.org\/10.1007\/978-3-031-15979-4_24","DOI":"10.1007\/978-3-031-15979-4_24"},{"key":"3_CR3","doi-asserted-by":"publisher","unstructured":"Alamati, N., De Feo, L., Montgomery, H., Patranabis, S.: Cryptographic group actions and applications. In: Moriai, S., Wang, H. (eds.) ASIACRYPT\u00a02020, Part\u00a0II. LNCS, vol. 12492, pp. 411\u2013439. Springer, Cham (Dec 2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_14","DOI":"10.1007\/978-3-030-64834-3_14"},{"key":"3_CR4","doi-asserted-by":"publisher","unstructured":"Allombert, B., et al.: Faster SCALLOP from non-prime conductor suborders in medium sized quadratic fields. In: Jager, T., Pan, J. (eds.) PKC\u00a02025, Part\u00a0III. LNCS, vol. 15676, pp. 333\u2013363. Springer, Cham (May 2025). https:\/\/doi.org\/10.1007\/978-3-031-91826-1_11","DOI":"10.1007\/978-3-031-91826-1_11"},{"key":"3_CR5","doi-asserted-by":"publisher","unstructured":"Atapoor, S., Baghery, K., Cozzo, D., Pedersen, R.: CSI-SharK: CSI-FiSh with sharing-friendly keys. In: Simpson, L., Baee, M.A.R. (eds.) ACISP 23. LNCS, vol. 13915, pp. 471\u2013502. Springer, Cham (Jul 2023). https:\/\/doi.org\/10.1007\/978-3-031-35486-1_21","DOI":"10.1007\/978-3-031-35486-1_21"},{"key":"3_CR6","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1007\/978-3-030-92641-0_9","volume-title":"Cryptography and Coding","author":"K Baghery","year":"2021","unstructured":"Baghery, K., Cozzo, D., Pedersen, R.: An isogeny-based id protocol using structured public keys. In: Paterson, M.B. (ed.) Cryptography and Coding, pp. 179\u2013197. Springer International Publishing, Cham (2021)"},{"key":"3_CR7","doi-asserted-by":"publisher","unstructured":"Banegas, G., et al.: CTIDH: faster constant-time CSIDH. IACR TCHES 2021(4), 351\u2013387 (2021). https:\/\/doi.org\/10.46586\/tches.v2021.i4.351-387, https:\/\/tches.iacr.org\/index.php\/TCHES\/article\/view\/9069","DOI":"10.46586\/tches.v2021.i4.351-387"},{"key":"3_CR8","doi-asserted-by":"publisher","unstructured":"Banegas, G., et al.: Disorientation faults in CSIDH. In: Hazay, C., Stam, M. (eds.) EUROCRYPT\u00a02023, Part\u00a0V. LNCS, vol. 14008, pp. 310\u2013342. Springer, Cham (Apr 2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_11","DOI":"10.1007\/978-3-031-30589-4_11"},{"key":"3_CR9","doi-asserted-by":"publisher","unstructured":"Basso, A., Kutas, P., Merz, S.P., Petit, C., Weitk\u00e4mper, C.: On adaptive attacks against jao-urbanik\u2019s isogeny-based protocol. In: Nitaj, A., Youssef, A.M. (eds.) AFRICACRYPT 20. LNCS, vol. 12174, pp. 195\u2013213. Springer, Cham (Jul 2020). https:\/\/doi.org\/10.1007\/978-3-030-51938-4_10","DOI":"10.1007\/978-3-030-51938-4_10"},{"key":"3_CR10","doi-asserted-by":"publisher","unstructured":"Bernstein, D.J., Lange, T., Martindale, C., Panny, L.: Quantum circuits for the CSIDH: Optimizing quantum evaluation of isogenies. In: Ishai, Y., Rijmen, V. (eds.) EUROCRYPT\u00a02019, Part\u00a0II. LNCS, vol. 11477, pp. 409\u2013441. Springer, Cham (May 2019). https:\/\/doi.org\/10.1007\/978-3-030-17656-3_15","DOI":"10.1007\/978-3-030-17656-3_15"},{"key":"3_CR11","doi-asserted-by":"publisher","unstructured":"Beullens, W., Dobson, S., Katsumata, S., Lai, Y.F., Pintore, F.: Group signatures and more from isogenies and lattices: Generic, simple, and efficient. In: Dunkelman, O., Dziembowski, S. (eds.) EUROCRYPT\u00a02022, Part\u00a0II. LNCS, vol. 13276, pp. 95\u2013126. Springer, Cham (May\/Jun 2022). https:\/\/doi.org\/10.1007\/978-3-031-07085-3_4","DOI":"10.1007\/978-3-031-07085-3_4"},{"key":"3_CR12","doi-asserted-by":"publisher","unstructured":"Beullens, W., Katsumata, S., Pintore, F.: Calamari and Falafl: logarithmic (linkable) ring signatures from isogenies and lattices. In: Moriai, S., Wang, H. (eds.) ASIACRYPT\u00a02020, Part\u00a0II. LNCS, vol. 12492, pp. 464\u2013492. Springer, Cham (Dec 2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_16","DOI":"10.1007\/978-3-030-64834-3_16"},{"key":"3_CR13","doi-asserted-by":"publisher","unstructured":"Beullens, W., Kleinjung, T., Vercauteren, F.: CSI-FiSh: efficient isogeny based signatures through class group computations. In: Galbraith, S.D., Moriai, S. (eds.) ASIACRYPT\u00a02019, Part\u00a0I. LNCS, vol. 11921, pp. 227\u2013247. Springer, Cham (Dec 2019). https:\/\/doi.org\/10.1007\/978-3-030-34578-5_9","DOI":"10.1007\/978-3-030-34578-5_9"},{"key":"3_CR14","unstructured":"Bisson, G., Sutherland, A.V.: Computing the endomorphism ring of an ordinary elliptic curve over a finite field. Cryptology ePrint Archive, Report 2009\/100 (2009). https:\/\/eprint.iacr.org\/2009\/100"},{"key":"3_CR15","doi-asserted-by":"publisher","unstructured":"Boneh, D., Kogan, D., Woo, K.: Oblivious pseudorandom functions from isogenies. In: Moriai, S., Wang, H. (eds.) ASIACRYPT\u00a02020, Part\u00a0II. LNCS, vol. 12492, pp. 520\u2013550. Springer, Cham (Dec 2020).https:\/\/doi.org\/10.1007\/978-3-030-64834-3_18","DOI":"10.1007\/978-3-030-64834-3_18"},{"key":"3_CR16","doi-asserted-by":"publisher","unstructured":"Bonnetain, X., Schrottenloher, A.: Quantum security analysis of CSIDH. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT\u00a02020, Part\u00a0II. LNCS, vol. 12106, pp. 493\u2013522. Springer, Cham (May 2020). https:\/\/doi.org\/10.1007\/978-3-030-45724-2_17","DOI":"10.1007\/978-3-030-45724-2_17"},{"issue":"1","key":"3_CR17","doi-asserted-by":"publisher","first-page":"5","DOI":"10.62056\/anjbksdja","volume":"1","author":"F Campos","year":"2024","unstructured":"Campos, F., et al.: Optimizations and practicality of high-security CSIDH. CiC 1(1), 5 (2024). https:\/\/doi.org\/10.62056\/anjbksdja","journal-title":"CiC"},{"key":"3_CR18","doi-asserted-by":"crossref","unstructured":"Campos, F., Hellenbrand, A., Meyer, M., Reijnders, K.: dCTIDH: Fast and deterministic CTIDH. Cryptology ePrint Archive, Report 2025\/107 (2025). https:\/\/eprint.iacr.org\/2025\/107","DOI":"10.46586\/tches.v2025.i3.516-541"},{"key":"3_CR19","doi-asserted-by":"crossref","unstructured":"Campos, F., Kannwischer, M.J., Meyer, M., Onuki, H., St\u00f6ttinger, M.: Trouble at the CSIDH: protecting CSIDH with dummy-operations against fault injection attacks. Cryptology ePrint Archive, Report 2020\/1005 (2020). https:\/\/eprint.iacr.org\/2020\/1005","DOI":"10.1109\/FDTC51366.2020.00015"},{"key":"3_CR20","doi-asserted-by":"publisher","unstructured":"Campos, F., Meyer, M., Reijnders, K., St\u00f6ttinger, M.: Patient zero and patient six: zero-value and correlation attacks on CSIDH and SIKE. In: Smith, B., Wu, H. (eds.) SAC 2022. LNCS, vol. 13742, pp. 234\u2013262. Springer, Cham (Aug 2024). https:\/\/doi.org\/10.1007\/978-3-031-58411-4_11","DOI":"10.1007\/978-3-031-58411-4_11"},{"key":"3_CR21","doi-asserted-by":"publisher","unstructured":"Castryck, W., Decru, T.: CSIDH on the surface. In: Ding, J., Tillich, J.P. (eds.) Post-Quantum Cryptography - 11th International Conference, PQCrypto 2020. pp. 111\u2013129. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-44223-1_7","DOI":"10.1007\/978-3-030-44223-1_7"},{"key":"3_CR22","doi-asserted-by":"publisher","unstructured":"Castryck, W., Houben, M., Merz, S.P., Mula, M., van Buuren, S., Vercauteren, F.: Weak instances of class group action based cryptography via self-pairings. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO\u00a02023, Part\u00a0III. LNCS, vol. 14083, pp. 762\u2013792. Springer, Cham (Aug 2023). https:\/\/doi.org\/10.1007\/978-3-031-38548-3_25","DOI":"10.1007\/978-3-031-38548-3_25"},{"issue":"4","key":"3_CR23","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1007\/s40993-022-00399-6","volume":"8","author":"W Castryck","year":"2022","unstructured":"Castryck, W., Houben, M., Vercauteren, F., Wesolowski, B.: On the decisional Diffie-Hellman problem for class group actions on oriented elliptic curves. Res. Number Theor. 8(4), 99 (2022). https:\/\/doi.org\/10.1007\/s40993-022-00399-6","journal-title":"Res. Number Theor."},{"key":"3_CR24","doi-asserted-by":"crossref","unstructured":"Castryck, W., Invernizzi, R., Lorenzon, G., Meers, J., Vercauteren, F.: Orient express: using frobenius to express oriented isogenies. Cryptology ePrint Archive, Paper 2025\/1047 (2025). https:\/\/eprint.iacr.org\/2025\/1047","DOI":"10.1007\/978-3-032-06754-8_6"},{"key":"3_CR25","doi-asserted-by":"publisher","unstructured":"Castryck, W., Lange, T., Martindale, C., Panny, L., Renes, J.: CSIDH: an efficient post-quantum commutative group action. In: Peyrin, T., Galbraith, S. (eds.) ASIACRYPT\u00a02018, Part\u00a0III. LNCS, vol. 11274, pp. 395\u2013427. Springer, Cham (Dec 2018). https:\/\/doi.org\/10.1007\/978-3-030-03332-3_15","DOI":"10.1007\/978-3-030-03332-3_15"},{"issue":"4","key":"3_CR26","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1007\/s00145-022-09435-1","volume":"35","author":"W Castryck","year":"2022","unstructured":"Castryck, W., Sot\u00e1kov\u00e1, J., Vercauteren, F.: Breaking the decisional Diffie-Hellman problem for class group actions using genus theory: Extended version. J. Cryptol. 35(4), 24 (2022). https:\/\/doi.org\/10.1007\/s00145-022-09435-1","journal-title":"J. Cryptol."},{"key":"3_CR27","doi-asserted-by":"publisher","unstructured":"Cervantes-V\u00e1zquez, D., et al.: Stronger and faster side-channel protections for CSIDH. In: Schwabe, P., Th\u00e9riault, N. (eds.) LATINCRYPT\u00a02019. LNCS, vol. 11774, pp. 173\u2013193. Springer, Cham (Oct 2019). https:\/\/doi.org\/10.1007\/978-3-030-30530-7_9","DOI":"10.1007\/978-3-030-30530-7_9"},{"issue":"3","key":"3_CR28","doi-asserted-by":"publisher","first-page":"349","DOI":"10.1007\/s13389-021-00271-w","volume":"12","author":"J Ch\u00e1vez-Saab","year":"2022","unstructured":"Ch\u00e1vez-Saab, J., Chi-Dom\u00ednguez, J.J., Jaques, S., Rodr\u00edguez-Henr\u00edquez, F.: The SQALE of CSIDH: sublinear V\u00e9lu quantum-resistant isogeny action with low exponents. J. Cryptogr. Eng. 12(3), 349\u2013368 (2022). https:\/\/doi.org\/10.1007\/s13389-021-00271-w","journal-title":"J. Cryptogr. Eng."},{"key":"3_CR29","doi-asserted-by":"publisher","unstructured":"Chen, M., Lai, Y.F., Laval, A., Marco, L., Petit, C.: Malleable commitments from group actions and zero-knowledge proofs for circuits based on isogenies. In: Chattopadhyay, A., Bhasin, S., Picek, S., Rebeiro, C. (eds.) INDOCRYPT\u00a02023, Part\u00a0I. LNCS, vol. 14459, pp. 221\u2013243. Springer, Cham (Dec 2023). https:\/\/doi.org\/10.1007\/978-3-031-56232-7_11","DOI":"10.1007\/978-3-031-56232-7_11"},{"key":"3_CR30","doi-asserted-by":"publisher","unstructured":"Chen, M., Leroux, A., Panny, L.: SCALLOP-HD: group action from 2-dimensional isogenies. In: Tang, Q., Teague, V. (eds.) PKC\u00a02024, Part\u00a0II. LNCS, vol. 14603, pp. 190\u2013216. Springer, Cham (Apr 2024). https:\/\/doi.org\/10.1007\/978-3-031-57725-3_7","DOI":"10.1007\/978-3-031-57725-3_7"},{"key":"3_CR31","unstructured":"Chenu, M., Smith, B.: Higher-degree supersingular group actions. Cryptology ePrint Archive, Report 2021\/955 (2021). https:\/\/eprint.iacr.org\/2021\/955"},{"key":"3_CR32","doi-asserted-by":"publisher","unstructured":"Chi-Dom\u00ednguez, J.J., Reijnders, K.: Fully projective radical isogenies in constant-time. In: Galbraith, S.D. (ed.) CT-RSA\u00a02022. LNCS, vol. 13161, pp. 73\u201395. Springer, Cham (Mar 2022). https:\/\/doi.org\/10.1007\/978-3-030-95312-6_4","DOI":"10.1007\/978-3-030-95312-6_4"},{"key":"3_CR33","doi-asserted-by":"publisher","first-page":"414","DOI":"10.1515\/jmc-2019-0034","volume":"14","author":"L Col\u00f2","year":"2020","unstructured":"Col\u00f2, L., Kohel, D.: Orienting supersingular isogeny graphs. J. Math. Cryptol. 14, 414\u2013437 (2020). https:\/\/doi.org\/10.1515\/jmc-2019-0034","journal-title":"J. Math. Cryptol."},{"key":"3_CR34","unstructured":"Conrad, K.: The conductor ideal of an order. https:\/\/kconrad.math.uconn.edu\/blurbs\/gradnumthy\/conductor.pdf"},{"key":"3_CR35","unstructured":"Couveignes, J.M.: Hard homogeneous spaces. Cryptology ePrint Archive, Report 2006\/291 (2006). https:\/\/eprint.iacr.org\/2006\/291"},{"key":"3_CR36","unstructured":"Cox, D.A.: Primes of the form $$x^2+ny^2$$: Fermat, Class Field Theory, and Complex Multiplication, Pure and Applied Mathematics, vol.\u00a0116. Wiley, 2nd edn. (2013)"},{"key":"3_CR37","doi-asserted-by":"publisher","unstructured":"Cozzo, D., Smart, N.P.: Sashimi: cutting up CSI-FiSh secret keys to produce an actively secure distributed signing protocol. In: Ding, J., Tillich, J.P. (eds.) Post-Quantum Cryptography - 11th International Conference, PQCrypto 2020, pp. 169\u2013186. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-44223-1_10","DOI":"10.1007\/978-3-030-44223-1_10"},{"key":"3_CR38","unstructured":"Dartois, P.: Fast computation of 2-isogenies in dimension 4 and cryptographic applications. Cryptology ePrint Archive, Report 2024\/1180 (2024). https:\/\/eprint.iacr.org\/2024\/1180"},{"key":"3_CR39","doi-asserted-by":"publisher","unstructured":"Dartois, P., De Feo, L.: On the security of OSIDH. In: Hanaoka, G., Shikata, J., Watanabe, Y. (eds.) PKC\u00a02022, Part\u00a0I. LNCS, vol. 13177, pp. 52\u201381. Springer, Cham (Mar 2022). https:\/\/doi.org\/10.1007\/978-3-030-97121-2_3","DOI":"10.1007\/978-3-030-97121-2_3"},{"key":"3_CR40","unstructured":"Dartois, P., Duparc, M.: Chasing rabbits through hypercubes: better algorithms for higher dimensional 2-isogeny computations. Cryptology ePrint Archive, Paper 2026\/114 (2026). https:\/\/eprint.iacr.org\/2026\/114"},{"key":"3_CR41","doi-asserted-by":"publisher","unstructured":"Dartois, P., et al.: PEGASIS: practical effective class group action using 4-dimensional isogenies. In: Kalai, Y.T., Kamara, S.F. (eds.) CRYPTO\u00a02025, Part\u00a0I. LNCS, vol. 16000, pp. 67\u201399. Springer, Cham (Aug 2025). https:\/\/doi.org\/10.1007\/978-3-032-01855-7_3","DOI":"10.1007\/978-3-032-01855-7_3"},{"key":"3_CR42","unstructured":"Dartois, P., Leroux, A., Robert, D., Wesolowski, B.: SQISignHD: new dimensions in cryptography. Cryptology ePrint Archive, Report 2023\/436 (2023). https:\/\/eprint.iacr.org\/2023\/436"},{"key":"3_CR43","doi-asserted-by":"publisher","unstructured":"De Feo, L., et al.: SCALLOP: scaling the CSI-FiSh. In: Boldyreva, A., Kolesnikov, V. (eds.) PKC\u00a02023, Part\u00a0I. LNCS, vol. 13940, pp. 345\u2013375. Springer, Cham (May 2023). https:\/\/doi.org\/10.1007\/978-3-031-31368-4_13","DOI":"10.1007\/978-3-031-31368-4_13"},{"key":"3_CR44","doi-asserted-by":"publisher","unstructured":"De Feo, L., Leroux, A., Longa, P., Wesolowski, B.: New algorithms for the deuring correspondence - towards practical and secure SQISign signatures. In: Hazay, C., Stam, M. (eds.) EUROCRYPT\u00a02023, Part\u00a0V. LNCS, vol. 14008, pp. 659\u2013690. Springer, Cham (Apr 2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_23","DOI":"10.1007\/978-3-031-30589-4_23"},{"key":"3_CR45","doi-asserted-by":"publisher","unstructured":"De Feo, L., Meyer, M.: Threshold schemes from isogeny assumptions. In: Kiayias, A., Kohlweiss, M., Wallden, P., Zikas, V. (eds.) PKC\u00a02020, Part\u00a0II. LNCS, vol. 12111, pp. 187\u2013212. Springer, Cham (May 2020). https:\/\/doi.org\/10.1007\/978-3-030-45388-6_7","DOI":"10.1007\/978-3-030-45388-6_7"},{"key":"3_CR46","doi-asserted-by":"publisher","unstructured":"Delpech de Saint Guilhem, C., Pedersen, R.: New proof systems and an OPRF from CSIDH. In: Tang, Q., Teague, V. (eds.) PKC\u00a02024, Part\u00a0II. LNCS, vol. 14603, pp. 217\u2013251. Springer, Cham (Apr 2024). https:\/\/doi.org\/10.1007\/978-3-031-57725-3_8","DOI":"10.1007\/978-3-031-57725-3_8"},{"issue":"4","key":"3_CR47","doi-asserted-by":"publisher","first-page":"387","DOI":"10.1080\/23799927.2021.2018115","volume":"6","author":"S Dobson","year":"2021","unstructured":"Dobson, S., Galbraith, S.D., LeGrow, J., Ti, Y.B., Zobernig, L.: An adaptive attack on 2-SIDH. Int. J. Comput. Math. Comput. Syst. Theor. 6(4), 387\u2013404 (2021). https:\/\/doi.org\/10.1080\/23799927.2021.2018115","journal-title":"Int. J. Comput. Math. Comput. Syst. Theor."},{"key":"3_CR48","unstructured":"Dobson, S., Li, T., Zobernig, L.: A note on a static SIDH protocol. Cryptology ePrint Archive, Report 2019\/1244 (2019). https:\/\/eprint.iacr.org\/2019\/1244"},{"issue":"3","key":"3_CR49","doi-asserted-by":"publisher","first-page":"5","DOI":"10.62056\/ae0fhbmo","volume":"1","author":"JK Eriksen","year":"2024","unstructured":"Eriksen, J.K., Leroux, A.: Computing orientations from the endomorphism ring of supersingular curves and applications. CiC 1(3), 5 (2024). https:\/\/doi.org\/10.62056\/ae0fhbmo","journal-title":"CiC"},{"key":"3_CR50","doi-asserted-by":"publisher","unstructured":"Fouotsa, T.B., Petit, C.: SHealS and HealS: isogeny-based PKEs from a key validation method for SIDH. In: Tibouchi, M., Wang, H. (eds.) ASIACRYPT\u00a02021, Part\u00a0IV. LNCS, vol. 13093, pp. 279\u2013307. Springer, Cham (Dec 2021). https:\/\/doi.org\/10.1007\/978-3-030-92068-5_10","DOI":"10.1007\/978-3-030-92068-5_10"},{"key":"3_CR51","doi-asserted-by":"publisher","unstructured":"Fouotsa, T.B., Petit, C.: A new adaptive attack on SIDH. In: Galbraith, S.D. (ed.) CT-RSA\u00a02022. LNCS, vol. 13161, pp. 322\u2013344. Springer, Cham (Mar 2022). https:\/\/doi.org\/10.1007\/978-3-030-95312-6_14","DOI":"10.1007\/978-3-030-95312-6_14"},{"key":"3_CR52","unstructured":"Gajland, P., de\u00a0Kock, B., Quaresma, M., Malavolta, G., Schwabe, P.: SWOOSH: efficient lattice-based non-interactive key exchange. In: Balzarotti, D., Xu, W. (eds.) USENIX Security 2024. USENIX Association (Aug 2024). https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/gajland"},{"key":"3_CR53","unstructured":"Galbraith, S., Gilchrist, V., Robert, D.: Improved algorithms for ascending isogeny volcanoes, and applications. Cryptology ePrint Archive, Paper 2025\/1243 (2025). https:\/\/eprint.iacr.org\/2025\/1243"},{"key":"3_CR54","unstructured":"Galbraith, S., Panny, L., Smith, B., Vercauteren, F.: Quantum equivalence of the DLP and CDHP for group actions. Cryptology ePrint Archive, Report 2018\/1199 (2018). https:\/\/eprint.iacr.org\/2018\/1199"},{"key":"3_CR55","doi-asserted-by":"publisher","unstructured":"Galbraith, S.D., Hess, F., Smart, N.P.: Extending the GHS Weil descent attack. In: Knudsen, L.R. (ed.) EUROCRYPT\u00a02002. LNCS, vol.\u00a02332, pp. 29\u201344. Springer, Berlin, Heidelberg (Apr\/May 2002). https:\/\/doi.org\/10.1007\/3-540-46035-7_3","DOI":"10.1007\/3-540-46035-7_3"},{"key":"3_CR56","doi-asserted-by":"publisher","unstructured":"Galbraith, S.D., Lai, Y.F.: Attack on SHealS and HealS: the second wave of GPST. In: Cheon, J.H., Johansson, T. (eds.) Post-Quantum Cryptography - 13th International Workshop, PQCrypto 2022. pp. 399\u2013421. Springer, Cham (Sep 2022). https:\/\/doi.org\/10.1007\/978-3-031-17234-2_19","DOI":"10.1007\/978-3-031-17234-2_19"},{"key":"3_CR57","doi-asserted-by":"publisher","unstructured":"Galbraith, S.D., Petit, C., Shani, B., Ti, Y.B.: On the security of supersingular isogeny cryptosystems. In: Cheon, J.H., Takagi, T. (eds.) ASIACRYPT\u00a02016, Part\u00a0I. LNCS, vol. 10031, pp. 63\u201391. Springer, Heidelberg (Dec 2016). https:\/\/doi.org\/10.1007\/978-3-662-53887-6_3","DOI":"10.1007\/978-3-662-53887-6_3"},{"key":"3_CR58","doi-asserted-by":"publisher","unstructured":"Grover, L.K.: A fast quantum mechanical algorithm for database search. In: 28th ACM STOC. pp. 212\u2013219. ACM Press (May 1996). https:\/\/doi.org\/10.1145\/237814.237866","DOI":"10.1145\/237814.237866"},{"key":"3_CR59","doi-asserted-by":"crossref","unstructured":"Hanzlik, L., Lai, Y.F., Mula, M., Paracucchi, E., Slamanig, D., Tang, G.: Tanuki: new frameworks for (concurrently secure) blind signatures from post-quantum groups actions. Cryptology ePrint Archive, Paper 2025\/1100 (2025). https:\/\/eprint.iacr.org\/2025\/1100","DOI":"10.1007\/978-981-95-5113-2_2"},{"key":"3_CR60","doi-asserted-by":"publisher","unstructured":"Heimberger, L., Hennerbichler, T., Meisingseth, F., Ramacher, S., Rechberger, C.: OPRFs from isogenies: designs and analysis. In: Zhou, J., Quek, T.Q.S., Gao, D., C\u00e1rdenas, A.A. (eds.) ASIACCS 24. ACM Press (Jul 2024). https:\/\/doi.org\/10.1145\/3634737.3645010","DOI":"10.1145\/3634737.3645010"},{"key":"3_CR61","doi-asserted-by":"publisher","unstructured":"Houben, M.: Deterministic algorithms for class group actions. In: Kalai, Y.T., Kamara, S.F. (eds.) CRYPTO\u00a02025, Part\u00a0I. LNCS, vol. 16000, pp. 100\u2013130. Springer, Cham (Aug 2025). https:\/\/doi.org\/10.1007\/978-3-032-01855-7_4","DOI":"10.1007\/978-3-032-01855-7_4"},{"key":"3_CR62","unstructured":"Houben, M.: Efficient post-quantum commutative group actions from orientations of large discriminant. Cryptology ePrint Archive, Paper 2025\/1098 (2025). https:\/\/eprint.iacr.org\/2025\/1098"},{"key":"3_CR63","doi-asserted-by":"publisher","unstructured":"Katsumata, S., Lai, Y.F., LeGrow, J.T., Qin, L.: CSI-Otter: isogeny-based (partially) blind signatures from the class group action with a twist. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO\u00a02023, Part\u00a0III. LNCS, vol. 14083, pp. 729\u2013761. Springer, Cham (Aug 2023). https:\/\/doi.org\/10.1007\/978-3-031-38548-3_24","DOI":"10.1007\/978-3-031-38548-3_24"},{"key":"3_CR64","unstructured":"Kopp, G.S., Lagarias, J.C.: Class field theory for orders of number fields (2022). https:\/\/arxiv.org\/abs\/2212.09177"},{"key":"3_CR65","doi-asserted-by":"publisher","unstructured":"Kunzweiler, S., Ti, Y.B., Weitk\u00e4mper, C.: Secret keys in genus-2 SIDH. In: AlTawy, R., H\u00fclsing, A. (eds.) SAC 2021. LNCS, vol. 13203, pp. 483\u2013507. Springer, Cham (Sep\/Oct 2022). https:\/\/doi.org\/10.1007\/978-3-030-99277-4_23","DOI":"10.1007\/978-3-030-99277-4_23"},{"issue":"1","key":"3_CR66","doi-asserted-by":"publisher","first-page":"170","DOI":"10.1137\/S0097539703436345","volume":"35","author":"G Kuperberg","year":"2005","unstructured":"Kuperberg, G.: A subexponential-time quantum algorithm for the dihedral hidden subgroup problem. SIAM J. Comput. 35(1), 170\u2013188 (2005)","journal-title":"SIAM J. Comput."},{"key":"3_CR67","doi-asserted-by":"publisher","unstructured":"Kuperberg, G.: Another subexponential-time quantum algorithm for the dihedral hidden subgroup problem. In: 8th Conference on the Theory of Quantum Computation, Communication and Cryptography (TQC 2013). Leibniz International Proceedings in Informatics (LIPIcs), vol.\u00a022, pp. 20\u201334. Schloss Dagstuhl\u2013Leibniz-Zentrum fuer Informatik (2013). https:\/\/doi.org\/10.4230\/LIPIcs.TQC.2013.20, http:\/\/drops.dagstuhl.de\/opus\/volltexte\/2013\/4321","DOI":"10.4230\/LIPIcs.TQC.2013.20"},{"key":"3_CR68","doi-asserted-by":"publisher","unstructured":"Lai, Y.F., Galbraith, S.D., Delpech de Saint Guilhem, C.: Compact, efficient and UC-secure isogeny-based oblivious transfer. In: Canteaut, A., Standaert, F.X. (eds.) EUROCRYPT\u00a02021, Part\u00a0I. LNCS, vol. 12696, pp. 213\u2013241. Springer, Cham (Oct 2021). https:\/\/doi.org\/10.1007\/978-3-030-77870-5_8","DOI":"10.1007\/978-3-030-77870-5_8"},{"key":"3_CR69","unstructured":"LeGrow, J., Hutchinson, A.: An analysis of fault attacks on CSIDH. Cryptology ePrint Archive, Report 2020\/1006 (2020). https:\/\/eprint.iacr.org\/2020\/1006"},{"issue":"3","key":"3_CR70","doi-asserted-by":"publisher","first-page":"283","DOI":"10.1007\/s13389-023-00318-0","volume":"13","author":"JT LeGrow","year":"2023","unstructured":"LeGrow, J.T.: A faster method for fault attack resistance in static\/ephemeral CSIDH. J. Cryptogr. Eng. 13(3), 283\u2013294 (2023). https:\/\/doi.org\/10.1007\/s13389-023-00318-0","journal-title":"J. Cryptogr. Eng."},{"key":"3_CR71","doi-asserted-by":"publisher","unstructured":"LeGrow, J.T., Hutchinson, A.: (Short paper) analysis of a strong fault attack on static\/ephemeral CSIDH. In: Nakanishi, T., Nojima, R. (eds.) IWSEC 21. LNCS, vol. 12835, pp. 216\u2013226. Springer, Cham (Sep 2021). https:\/\/doi.org\/10.1007\/978-3-030-85987-9_12","DOI":"10.1007\/978-3-030-85987-9_12"},{"key":"3_CR72","doi-asserted-by":"publisher","unstructured":"Leroux, A., Rom\u00e9as, M.: Updatable encryption from group actions. In: Saarinen, M.J., Smith-Tone, D. (eds.) Post-Quantum Cryptography - 15th International Workshop, PQCrypto 2024, Part\u00a0II. pp. 20\u201353. Springer, Cham (Jun 2024). https:\/\/doi.org\/10.1007\/978-3-031-62746-0_2","DOI":"10.1007\/978-3-031-62746-0_2"},{"key":"3_CR73","unstructured":"Levin, S., Pedersen, R.: Faster proofs and VRFs from isogenies. Cryptology ePrint Archive, Report 2024\/1626 (2024). https:\/\/eprint.iacr.org\/2024\/1626"},{"key":"3_CR74","unstructured":"Lim, D., Ti, Y.B.: Adaptive attack on static POK\u00c9 keys. Cryptology ePrint Archive, Paper 2025\/1541 (2025). https:\/\/eprint.iacr.org\/2025\/1541"},{"key":"3_CR75","doi-asserted-by":"publisher","unstructured":"Meers, J., Riepel, D.: CCA secure updatable encryption from non-mappable group actions. In: Saarinen, M.J., Smith-Tone, D. (eds.) Post-Quantum Cryptography - 15th International Workshop, PQCrypto 2024, Part\u00a0I. pp. 137\u2013169. Springer, Cham (Jun 2024). https:\/\/doi.org\/10.1007\/978-3-031-62743-9_5","DOI":"10.1007\/978-3-031-62743-9_5"},{"key":"3_CR76","doi-asserted-by":"publisher","unstructured":"Meyer, M., Campos, F., Reith, S.: On lions and elligators: an efficient constant-time implementation of CSIDH. In: Ding, J., Steinwandt, R. (eds.) Post-Quantum Cryptography - 10th International Conference, PQCrypto 2019. pp. 307\u2013325. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-25510-7_17","DOI":"10.1007\/978-3-030-25510-7_17"},{"key":"3_CR77","doi-asserted-by":"publisher","unstructured":"Meyer, M., Reith, S.: A faster way to the CSIDH. In: Chakraborty, D., Iwata, T. (eds.) INDOCRYPT\u00a02018. LNCS, vol. 11356, pp. 137\u2013152. Springer, Cham (Dec 2018). https:\/\/doi.org\/10.1007\/978-3-030-05378-9_8","DOI":"10.1007\/978-3-030-05378-9_8"},{"key":"3_CR78","doi-asserted-by":"publisher","unstructured":"Montgomery, H., Sharif, S.: Quantum money from class group actions on elliptic curves. In: Chung, K.M., Sasaki, Y. (eds.) ASIACRYPT\u00a02024, Part\u00a0IX. LNCS, vol. 15492, pp. 33\u201364. Springer, Singapore (Dec 2024). https:\/\/doi.org\/10.1007\/978-981-96-0947-5_2","DOI":"10.1007\/978-981-96-0947-5_2"},{"key":"3_CR79","unstructured":"Moriya, T., Onuki, H.: The wrong use of FESTA trapdoor functions leads to an adaptive attack. Cryptology ePrint Archive, Report 2023\/1092 (2023). https:\/\/eprint.iacr.org\/2023\/1092"},{"key":"3_CR80","doi-asserted-by":"publisher","unstructured":"Moriya, T., Onuki, H., Takagi, T.: SiGamal: a supersingular isogeny-based PKE and its application to a PRF. In: Moriai, S., Wang, H. (eds.) ASIACRYPT\u00a02020, Part\u00a0II. LNCS, vol. 12492, pp. 551\u2013580. Springer, Cham (Dec 2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_19","DOI":"10.1007\/978-3-030-64834-3_19"},{"key":"3_CR81","doi-asserted-by":"publisher","unstructured":"Moriya, T., Onuki, H., Xu, M., Zhou, G.: Adaptive attacks against FESTA without input validation or constant-time implementation. In: Saarinen, M.J., Smith-Tone, D. (eds.) Post-Quantum Cryptography - 15th International Workshop, PQCrypto 2024, Part\u00a0II. pp. 3\u201319. Springer, Cham (Jun 2024). https:\/\/doi.org\/10.1007\/978-3-031-62746-0_1","DOI":"10.1007\/978-3-031-62746-0_1"},{"key":"3_CR82","unstructured":"Morrison, T., Panny, L., Sot\u00e1kov\u00e1, J., Wills, M.: The sea algorithm for endomorphisms of supersingular elliptic curves (2025). https:\/\/arxiv.org\/abs\/2501.16321"},{"key":"3_CR83","doi-asserted-by":"publisher","DOI":"10.1016\/j.ffa.2020.101777","volume":"69","author":"H Onuki","year":"2021","unstructured":"Onuki, H.: On oriented supersingular elliptic curves. Finite Fields Appl. 69, 101777 (2021). https:\/\/doi.org\/10.1016\/j.ffa.2020.101777","journal-title":"Finite Fields Appl."},{"key":"3_CR84","unstructured":"Page, A., Robert, D.: Introducing clapoti(s): evaluating the isogeny class group action in polynomial time. Cryptology ePrint Archive, Report 2023\/1766 (2023). https:\/\/eprint.iacr.org\/2023\/1766"},{"key":"3_CR85","doi-asserted-by":"crossref","unstructured":"Panny, L., Petit, C., Stopar, M.: KLaPoTi: an asymptotically efficient isogeny group action from 2-dimensional isogenies. Cryptology ePrint Archive, Report 2024\/1844 (2024). https:\/\/eprint.iacr.org\/2024\/1844","DOI":"10.62056\/ahp2wakrz"},{"key":"3_CR86","doi-asserted-by":"publisher","unstructured":"Peikert, C.: He gives C-sieves on the CSIDH. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT\u00a02020, Part\u00a0II. LNCS, vol. 12106, pp. 463\u2013492. Springer, Cham (May 2020). https:\/\/doi.org\/10.1007\/978-3-030-45724-2_16","DOI":"10.1007\/978-3-030-45724-2_16"},{"key":"3_CR87","unstructured":"Regev, O.: A subexponential time algorithm for the dihedral hidden subgroup problem with polynomial space (2004). https:\/\/arxiv.org\/pdf\/quant-ph\/0406151"},{"key":"3_CR88","unstructured":"Robert, D.: The module action for isogeny based cryptography. Cryptology ePrint Archive, Report 2024\/1556 (2024). https:\/\/eprint.iacr.org\/2024\/1556"},{"key":"3_CR89","unstructured":"Robert, D.: On the efficient representation of isogenies (a survey). Cryptology ePrint Archive, Report 2024\/1071 (2024). https:\/\/eprint.iacr.org\/2024\/1071"},{"key":"3_CR90","unstructured":"Rostovtsev, A., Stolbunov, A.: Public-key cryptosystem based on isogenies. Cryptology ePrint Archive, Report 2006\/145 (2006). https:\/\/eprint.iacr.org\/2006\/145"},{"key":"3_CR91","doi-asserted-by":"crossref","unstructured":"Siegel, C.: \u00dcber die classenzahl quadratischer zahlk\u00f6rper. Acta Arith 1(1), 83\u201386 (1935). https:\/\/doi.org\/eudml.org\/doc\/205054","DOI":"10.4064\/aa-1-1-83-86"},{"issue":"1","key":"3_CR92","doi-asserted-by":"publisher","first-page":"507","DOI":"10.2140\/obs.2013.1.507","volume":"1","author":"A Sutherland","year":"2013","unstructured":"Sutherland, A.: Isogeny volcanoes. Open Book Ser. 1(1), 507\u2013530 (2013). https:\/\/doi.org\/10.2140\/obs.2013.1.507","journal-title":"Open Book Ser."},{"key":"3_CR93","unstructured":"Sutherland, A.: Lecture notes for MIT course 18.783: Elliptic Curves (2023). https:\/\/math.mit.edu\/classes\/18.783\/2023\/LectureNotes17.pdf"},{"key":"3_CR94","doi-asserted-by":"publisher","unstructured":"Wesolowski, B.: Orientations and the supersingular endomorphism ring problem. In: Dunkelman, O., Dziembowski, S. (eds.) EUROCRYPT\u00a02022, Part\u00a0III. LNCS, vol. 13277, pp. 345\u2013371. Springer, Cham (May\u00a0\/\u00a0Jun 2022). https:\/\/doi.org\/10.1007\/978-3-031-07082-2_13","DOI":"10.1007\/978-3-031-07082-2_13"},{"key":"3_CR95","unstructured":"Zhou, G., Xu, M.: An efficient adaptive attack against FESTA. Cryptology ePrint Archive, Report 2024\/345 (2024). https:\/\/eprint.iacr.org\/2024\/345"}],"container-title":["Lecture Notes in Computer Science","Post-Quantum Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-22698-3_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T10:24:28Z","timestamp":1775730268000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-22698-3_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032226976","9783032226983"],"references-count":95,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-22698-3_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"10 April 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"PQCrypto","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Post-Quantum Cryptography","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Saint-Malo","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 April 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 April 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"pqcrypto2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}