{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,17]],"date-time":"2026-08-17T15:07:16Z","timestamp":1786979236722,"version":"3.56.0"},"publisher-location":"Singapore","reference-count":83,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819551125","type":"print"},{"value":"9789819551132","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,12,8]],"date-time":"2025-12-08T00:00:00Z","timestamp":1765152000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,12,8]],"date-time":"2025-12-08T00:00:00Z","timestamp":1765152000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-5113-2_5","type":"book-chapter","created":{"date-parts":[[2025,12,7]],"date-time":"2025-12-07T15:43:35Z","timestamp":1765122215000},"page":"141-173","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Efficient Post-quantum Commutative Group Actions from\u00a0Orientations of\u00a0Large Discriminant"],"prefix":"10.1007","author":[{"given":"Marc","family":"Houben","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,12,8]]},"reference":[{"key":"5_CR1","unstructured":"GitHub repository associated to this paper. https:\/\/github.com\/houbenmr\/LargeDiscriminantOrientations"},{"key":"5_CR2","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"322","DOI":"10.1007\/978-3-030-10970-7_15","volume-title":"Selected Areas in Cryptography - SAC 2018","author":"G Adj","year":"2019","unstructured":"Adj, G., Cervantes-V\u00e1zquez, D., Chi-Dom\u00ednguez, J.J., Menezes, A., Rodr\u00edguez-Henr\u00edquez, F.: On the cost of computing isogenies between supersingular elliptic curves. In: Cid, C., Jacobson, M.J., Jr. (eds.) SAC 2018. LNCS, pp. 322\u2013343. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-10970-7_15"},{"key":"5_CR3","unstructured":"Allombert, B., et al.: PEARL-SCALLOP: parameter extension applicable in real-life SCALLOP. Cryptology ePrint Archive, Report 2024\/1744 (2024). https:\/\/eprint.iacr.org\/2024\/1744"},{"key":"5_CR4","doi-asserted-by":"publisher","unstructured":"Banegas, G., et al.: CTIDH: faster constant-time CSIDH. IACR TCHES 2021(4), 351\u2013387 (2021). https:\/\/doi.org\/10.46586\/tches.v2021.i4.351-387. https:\/\/tches.iacr.org\/index.php\/TCHES\/article\/view\/9069","DOI":"10.46586\/tches.v2021.i4.351-387"},{"key":"5_CR5","doi-asserted-by":"publisher","unstructured":"Banegas, G., et al.: Disorientation faults in CSIDH. In: Hazay, C., Stam, M. (eds.) EUROCRYPT\u00a02023, Part\u00a0V. LNCS, vol. 14008, pp. 310\u2013342. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_11","DOI":"10.1007\/978-3-031-30589-4_11"},{"key":"5_CR6","unstructured":"Basso, A.: POKE: a framework for efficient PKEs, split KEMs, and OPRFs from higher-dimensional isogenies. Cryptology ePrint Archive, Report 2024\/624 (2024). https:\/\/eprint.iacr.org\/2024\/624"},{"key":"5_CR7","unstructured":"Bernstein, D.J., De Feo, L., Leroux, A., Smith, B.: Faster computation of isogenies of large prime degree. Cryptology ePrint Archive, Report 2020\/341 (2020). https:\/\/eprint.iacr.org\/2020\/341"},{"key":"5_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"409","DOI":"10.1007\/978-3-030-17656-3_15","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2019","author":"DJ Bernstein","year":"2019","unstructured":"Bernstein, D.J., Lange, T., Martindale, C., Panny, L.: Quantum Circuits for the CSIDH: optimizing quantum evaluation of isogenies. In: Ishai, Y., Rijmen, V. (eds.) EUROCRYPT 2019, Part II. LNCS, vol. 11477, pp. 409\u2013441. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-17656-3_15"},{"key":"5_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"428","DOI":"10.1007\/978-3-319-13039-2_25","volume-title":"Progress in Cryptology \u2013 INDOCRYPT 2014","author":"J-F Biasse","year":"2014","unstructured":"Biasse, J.-F., Jao, D., Sankar, A.: A quantum algorithm for computing isogenies between supersingular elliptic curves. In: Meier, W., Mukhopadhyay, D. (eds.) INDOCRYPT 2014. LNCS, vol. 8885, pp. 428\u2013442. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-13039-2_25"},{"key":"5_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"493","DOI":"10.1007\/978-3-030-45724-2_17","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2020","author":"X Bonnetain","year":"2020","unstructured":"Bonnetain, X., Schrottenloher, A.: Quantum security analysis of CSIDH. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT 2020, Part II. LNCS, vol. 12106, pp. 493\u2013522. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45724-2_17"},{"key":"5_CR11","doi-asserted-by":"publisher","unstructured":"Bruno, G., et al.: Cryptographic smooth neighbors. In: Guo, J., Steinfeld, R. (eds.) ASIACRYPT\u00a02023, Part\u00a0VII. LNCS, vol. 14444, pp. 190\u2013221. Springer, Singapore (2023). https:\/\/doi.org\/10.1007\/978-981-99-8739-9_7","DOI":"10.1007\/978-981-99-8739-9_7"},{"key":"5_CR12","doi-asserted-by":"publisher","unstructured":"Campos, F., et al.: Optimizations and practicality of high-security CSIDH. CiC 1(1), 5 (2024). https:\/\/doi.org\/10.62056\/anjbksdja","DOI":"10.62056\/anjbksdja"},{"key":"5_CR13","doi-asserted-by":"crossref","unstructured":"Campos, F., Hellenbrand, A., Meyer, M., Reijnders, K.: dCTIDH: fast & deterministic CTIDH. Cryptology ePrint Archive, Report 2025\/107 (2025). https:\/\/eprint.iacr.org\/2025\/107","DOI":"10.46586\/tches.v2025.i3.516-541"},{"key":"5_CR14","doi-asserted-by":"crossref","unstructured":"Campos, F., Kannwischer, M.J., Meyer, M., Onuki, H., St\u00f6ttinger, M.: Trouble at the CSIDH: protecting CSIDH with dummy-operations against fault injection attacks. Cryptology ePrint Archive, Report 2020\/1005 (2020). https:\/\/eprint.iacr.org\/2020\/1005","DOI":"10.1109\/FDTC51366.2020.00015"},{"key":"5_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1007\/978-3-030-44223-1_7","volume-title":"Post-Quantum Cryptography","author":"W Castryck","year":"2020","unstructured":"Castryck, W., Decru, T.: CSIDH on the surface. In: Ding, J., Tillich, J.-P. (eds.) PQCrypto 2020. LNCS, vol. 12100, pp. 111\u2013129. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-44223-1_7"},{"key":"5_CR16","doi-asserted-by":"publisher","unstructured":"Castryck, W., Decru, T.: An efficient key recovery attack on SIDH. In: Hazay, C., Stam, M. (eds.) EUROCRYPT\u00a02023, Part\u00a0V. LNCS, vol. 14008, pp. 423\u2013447. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_15","DOI":"10.1007\/978-3-031-30589-4_15"},{"key":"5_CR17","doi-asserted-by":"publisher","unstructured":"Castryck, W., Decru, T., Houben, M., Vercauteren, F.: Horizontal racewalking using radical isogenies. In: Agrawal, S., Lin, D. (eds.) ASIACRYPT\u00a02022, Part\u00a0II. LNCS, vol. 13792, pp. 67\u201396. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-22966-4_3","DOI":"10.1007\/978-3-031-22966-4_3"},{"key":"5_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"493","DOI":"10.1007\/978-3-030-64834-3_17","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"W Castryck","year":"2020","unstructured":"Castryck, W., Decru, T., Vercauteren, F.: Radical isogenies. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020, Part II. LNCS, vol. 12492, pp. 493\u2013519. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_17"},{"key":"5_CR19","doi-asserted-by":"publisher","unstructured":"Castryck, W., Houben, M., Merz, S.P., Mula, M., van Buuren, S., Vercauteren, F.: Weak instances of class group action based cryptography via self-pairings. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO\u00a02023, Part\u00a0III. LNCS, vol. 14083, pp. 762\u2013792. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38548-3_25","DOI":"10.1007\/978-3-031-38548-3_25"},{"issue":"4","key":"5_CR20","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1007\/s40993-022-00399-6","volume":"8","author":"W Castryck","year":"2022","unstructured":"Castryck, W., Houben, M., Vercauteren, F., Wesolowski, B.: On the decisional Diffie-Hellman problem for class group actions on oriented elliptic curves. Res. Number Theory 8(4), 99 (2022)","journal-title":"Res. Number Theory"},{"key":"5_CR21","doi-asserted-by":"crossref","unstructured":"Castryck, W., Invernizzi, R., Lorenzon, G., Meers, J., Vercauteren, F.: Orient express: using frobenius to express oriented isogenies. Cryptology ePrint Archive, Paper 2025\/1047 (2025). https:\/\/eprint.iacr.org\/2025\/1047","DOI":"10.1007\/978-3-032-06754-8_6"},{"key":"5_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"395","DOI":"10.1007\/978-3-030-03332-3_15","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2018","author":"W Castryck","year":"2018","unstructured":"Castryck, W., Lange, T., Martindale, C., Panny, L., Renes, J.: CSIDH: an efficient post-quantum commutative group action. In: Peyrin, T., Galbraith, S. (eds.) ASIACRYPT 2018, Part III. LNCS, vol. 11274, pp. 395\u2013427. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03332-3_15"},{"key":"5_CR23","unstructured":"Castryck, W., Meeren, N.V.: Two remarks on the vectorization problem. Cryptology ePrint Archive, Report 2022\/1366 (2022). https:\/\/eprint.iacr.org\/2022\/1366"},{"key":"5_CR24","doi-asserted-by":"publisher","unstructured":"Castryck, W., Sot\u00e1kov\u00e1, J., Vercauteren, F.: Breaking the decisional Diffie-Hellman problem for class group actions using genus theory: extended version. J. Cryptol. 35(4), 24 (2022). https:\/\/doi.org\/10.1007\/s00145-022-09435-1","DOI":"10.1007\/s00145-022-09435-1"},{"key":"5_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"173","DOI":"10.1007\/978-3-030-30530-7_9","volume-title":"Progress in Cryptology \u2013 LATINCRYPT 2019","author":"D Cervantes-V\u00e1zquez","year":"2019","unstructured":"Cervantes-V\u00e1zquez, D., Chenu, M., Chi-Dom\u00ednguez, J.-J., De Feo, L., Rodr\u00edguez-Henr\u00edquez, F., Smith, B.: Stronger and faster side-channel protections for CSIDH. In: Schwabe, P., Th\u00e9riault, N. (eds.) LATINCRYPT 2019. LNCS, vol. 11774, pp. 173\u2013193. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-30530-7_9"},{"key":"5_CR26","doi-asserted-by":"publisher","unstructured":"Ch\u00e1vez-Saab, J., Chi-Dom\u00ednguez, J.J., Jaques, S., Rodr\u00edguez-Henr\u00edquez, F.: The SQALE of CSIDH: sublinear V\u00e9lu quantum-resistant isogeny action with low exponents. J. Cryptogr. Eng. 12(3), 349\u2013368 (2022). https:\/\/doi.org\/10.1007\/s13389-021-00271-w","DOI":"10.1007\/s13389-021-00271-w"},{"key":"5_CR27","doi-asserted-by":"publisher","unstructured":"Chen, M., Leroux, A., Panny, L.: SCALLOP-HD: group action from 2-dimensional isogenies. In: Tang, Q., Teague, V. (eds.) PKC\u00a02024, Part\u00a0II. LNCS, vol. 14603, pp. 190\u2013216. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-57725-3_7","DOI":"10.1007\/978-3-031-57725-3_7"},{"key":"5_CR28","doi-asserted-by":"publisher","unstructured":"Cheng, H., Fotiadis, G., Gro\u00dfsch\u00e4dl, J., Ryan, P.Y.A., R\u00f8nne, P.B.: Batching CSIDH group actions using AVX-512. IACR TCHES 2021(4), 618\u2013649 (2021). https:\/\/doi.org\/10.46586\/tches.v2021.i4.618-649. https:\/\/tches.iacr.org\/index.php\/TCHES\/article\/view\/9077","DOI":"10.46586\/tches.v2021.i4.618-649"},{"key":"5_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1007\/978-3-030-95312-6_4","volume-title":"Topics in Cryptology \u2013 CT-RSA 2022","author":"J-J Chi-Dom\u00ednguez","year":"2022","unstructured":"Chi-Dom\u00ednguez, J.-J., Reijnders, K.: Fully projective radical isogenies in constant-time. In: Galbraith, S.D. (ed.) CT-RSA 2022. LNCS, vol. 13161, pp. 73\u201395. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-030-95312-6_4"},{"key":"5_CR30","unstructured":"Chi-Dom\u00ednguez, J.J., Rodr\u00edguez-Henr\u00edquez, F.: Optimal strategies for CSIDH. Cryptology ePrint Archive, Report 2020\/417 (2020). https:\/\/eprint.iacr.org\/2020\/417"},{"issue":"1","key":"5_CR31","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1103\/RevModPhys.82.1","volume":"82","author":"AM Childs","year":"2010","unstructured":"Childs, A.M., Van Dam, W.: Quantum algorithms for algebraic problems. Rev. Mod. Phys. 82(1), 1\u201352 (2010)","journal-title":"Rev. Mod. Phys."},{"key":"5_CR32","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/BFb0099440","volume-title":"Number Theory Noordwijkerhout 1983","author":"H Cohen","year":"1984","unstructured":"Cohen, H., Lenstra, H.W.: Heuristics on class groups of number fields. In: Jager, H. (ed.) Number Theory Noordwijkerhout 1983, pp. 33\u201362. Springer, Heidelberg (1984). https:\/\/doi.org\/10.1007\/BFb0099440"},{"key":"5_CR33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-02945-9","volume-title":"A Course in Computational Algebraic Number Theory","author":"H Cohen","year":"2010","unstructured":"Cohen, H.: A Course in Computational Algebraic Number Theory. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-662-02945-9"},{"key":"5_CR34","doi-asserted-by":"publisher","first-page":"414","DOI":"10.1515\/jmc-2019-0034","volume":"14","author":"L Col\u00f2","year":"2020","unstructured":"Col\u00f2, L., Kohel, D.: Orienting supersingular isogeny graphs. J. Math. Cryptol. 14, 414\u2013437 (2020). https:\/\/doi.org\/10.1515\/jmc-2019-0034","journal-title":"J. Math. Cryptol."},{"issue":"2","key":"5_CR35","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1080\/10586458.2013.768483","volume":"22","author":"JB Conrey","year":"2013","unstructured":"Conrey, J.B., Holmstrom, M.A., McLaughlin, T.L.: Smooth neighbors. Exp. Math. 22(2), 195\u2013202 (2013)","journal-title":"Exp. Math."},{"key":"5_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"428","DOI":"10.1007\/978-3-030-03332-3_16","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2018","author":"C Costello","year":"2018","unstructured":"Costello, C.: Computing supersingular isogenies on Kummer surfaces. In: Peyrin, T., Galbraith, S. (eds.) ASIACRYPT 2018, Part III. LNCS, vol. 11274, pp. 428\u2013456. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03332-3_16"},{"key":"5_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"440","DOI":"10.1007\/978-3-030-64834-3_15","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"C Costello","year":"2020","unstructured":"Costello, C.: B-SIDH: supersingular isogeny Diffie-Hellman using twisted torsion. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020, Part II. LNCS, vol. 12492, pp. 440\u2013463. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_15"},{"key":"5_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"272","DOI":"10.1007\/978-3-030-77870-5_10","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2021","author":"C Costello","year":"2021","unstructured":"Costello, C., Meyer, M., Naehrig, M.: Sieving for twin smooth integers with solutions to the Prouhet-Tarry-Escott problem. In: Canteaut, A., Standaert, F.-X. (eds.) EUROCRYPT 2021, Part I. LNCS, vol. 12696, pp. 272\u2013301. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-77870-5_10"},{"key":"5_CR39","unstructured":"Couveignes, J.M.: Hard homogeneous spaces. Cryptology ePrint Archive, Report 2006\/291 (2006). https:\/\/eprint.iacr.org\/2006\/291"},{"key":"5_CR40","doi-asserted-by":"publisher","unstructured":"Dartois, P., De Feo, L.: On the security of OSIDH. In: Hanaoka, G., Shikata, J., Watanabe, Y. (eds.) PKC\u00a02022, Part\u00a0I. LNCS, vol. 13177, pp. 52\u201381. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-030-97121-2_3","DOI":"10.1007\/978-3-030-97121-2_3"},{"key":"5_CR41","doi-asserted-by":"publisher","unstructured":"De Feo, L., et al.: SCALLOP: scaling the CSI-FiSh. In: Boldyreva, A., Kolesnikov, V. (eds.) PKC\u00a02023, Part\u00a0I. LNCS, vol. 13940, pp. 345\u2013375. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-31368-4_13","DOI":"10.1007\/978-3-031-31368-4_13"},{"key":"5_CR42","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-3-030-64837-4_3","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"L De Feo","year":"2020","unstructured":"De Feo, L., Kohel, D., Leroux, A., Petit, C., Wesolowski, B.: SQISign: compact post-quantum signatures from quaternions and isogenies. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020, Part I. LNCS, vol. 12491, pp. 64\u201393. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64837-4_3"},{"key":"5_CR43","doi-asserted-by":"crossref","unstructured":"De\u00a0Feo, L., Leroux, A., Longa, P., Wesolowski, B.: New algorithms for the deuring correspondence: towards practical and secure sqisign signatures. In: Annual International Conference on the Theory and Applications of Cryptographic Techniques, pp. 659\u2013690. Springer (2023)","DOI":"10.1007\/978-3-031-30589-4_23"},{"key":"5_CR44","doi-asserted-by":"publisher","unstructured":"Decru, T.: Radical \n\n                  \n                  \n                  \n                    The image shows a mathematical expression with a square root symbol. The expression is: sqrt[]{\u00e9lu}.\n                  \n                 isogeny formulae. In: Reyzin, L., Stebila, D. (eds.) CRYPTO\u00a02024, Part\u00a0V. LNCS, vol. 14924, pp. 107\u2013128. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-68388-6_5","DOI":"10.1007\/978-3-031-68388-6_5"},{"issue":"1","key":"5_CR45","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1007\/BF01393993","volume":"92","author":"W Duke","year":"1988","unstructured":"Duke, W.: Hyperbolic distribution problems and half-integral weight Maass forms. Invent. Math. 92(1), 73\u201390 (1988). https:\/\/doi.org\/10.1007\/BF01393993","journal-title":"Invent. Math."},{"key":"5_CR46","doi-asserted-by":"publisher","first-page":"2695","DOI":"10.1155\/IMRN.2005.2695","volume":"44","author":"N Elkies","year":"2005","unstructured":"Elkies, N., Ono, K., Yang, T.: Reduction of CM elliptic curves and modular function congruences. Int. Math. Res. Not. 44, 2695\u20132707 (2005). https:\/\/doi.org\/10.1155\/IMRN.2005.2695","journal-title":"Int. Math. Res. Not."},{"key":"5_CR47","doi-asserted-by":"publisher","unstructured":"Eriksen, J.K., Panny, L., Sot\u00e1kov\u00e1, J., Veroni, M.: Deuring for the people: supersingular elliptic curves with prescribed endomorphism ring in general characteristic. In: LuCaNT: LMFDB, Computation, and Number Theory, Contemp. Math., vol.\u00a0796, pp. 339\u2013373 (2024). https:\/\/doi.org\/10.1090\/conm\/796\/16008","DOI":"10.1090\/conm\/796\/16008"},{"key":"5_CR48","unstructured":"Gajland, P., de\u00a0Kock, B., Quaresma, M., Malavolta, G., Schwabe, P.: SWOOSH: efficient lattice-based non-interactive key exchange. In: Balzarotti, D., Xu, W. (eds.) USENIX Security 2024. USENIX Association (2024)"},{"key":"5_CR49","unstructured":"Houben, M.: Deterministic algorithms for class group actions. Cryptology ePrint Archive, Report 2025\/847 (2025). https:\/\/eprint.iacr.org\/2025\/847"},{"key":"5_CR50","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"481","DOI":"10.1007\/978-3-030-57808-4_24","volume-title":"Applied Cryptography and Network Security","author":"A Hutchinson","year":"2020","unstructured":"Hutchinson, A., LeGrow, J., Koziel, B., Azarderakhsh, R.: Further optimizations of CSIDH: a systematic approach to efficient strategies, permutations, and bound vectors. In: Conti, M., Zhou, J., Casalicchio, E., Spognardi, A. (eds.) ACNS 2020. LNCS, vol. 12146, pp. 481\u2013501. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-57808-4_24"},{"key":"5_CR51","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-642-25405-5_2","volume-title":"Post-Quantum Cryptography","author":"D Jao","year":"2011","unstructured":"Jao, D., De Feo, L.: Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies. In: Yang, B.-Y. (ed.) PQCrypto 2011. LNCS, vol. 7071, pp. 19\u201334. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25405-5_2"},{"key":"5_CR52","doi-asserted-by":"crossref","unstructured":"Jaques, S., Schanck, J.M.: Quantum cryptanalysis in the RAM model: claw-finding attacks on SIKE. Cryptology ePrint Archive, Report 2019\/103 (2019). https:\/\/eprint.iacr.org\/2019\/103","DOI":"10.1007\/978-3-030-26948-7_2"},{"key":"5_CR53","doi-asserted-by":"publisher","unstructured":"Kohel, D., Lauter, K., Petit, C., Tignol, J.P.: On the quaternion $$\\ell $$-isogeny path problem. LMS J. Comput. Math. 17, 418\u2013432 (2014). https:\/\/doi.org\/10.1112\/S1461157014000151","DOI":"10.1112\/S1461157014000151"},{"issue":"1","key":"5_CR54","doi-asserted-by":"publisher","first-page":"170","DOI":"10.1137\/S0097539703436345","volume":"35","author":"G Kuperberg","year":"2005","unstructured":"Kuperberg, G.: A subexponential-time quantum algorithm for the dihedral hidden subgroup problem. SIAM J. Comput. 35(1), 170\u2013188 (2005)","journal-title":"SIAM J. Comput."},{"key":"5_CR55","doi-asserted-by":"publisher","unstructured":"Kuperberg, G.: Another subexponential-time quantum algorithm for the dihedral hidden subgroup problem. In: 8th Conference on the Theory of Quantum Computation, Communication and Cryptography (TQC 2013). Leibniz International Proceedings in Informatics (LIPIcs), vol.\u00a022, pp. 20\u201334. Schloss Dagstuhl\u2013Leibniz-Zentrum fuer Informatik (2013). https:\/\/doi.org\/10.4230\/LIPIcs.TQC.2013.20. http:\/\/drops.dagstuhl.de\/opus\/volltexte\/2013\/4321","DOI":"10.4230\/LIPIcs.TQC.2013.20"},{"issue":"1","key":"5_CR56","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1007\/s40993-024-00606-6","volume":"11","author":"S Leem","year":"2025","unstructured":"Leem, S., Jacobson, M.J., Jr., Scheidler, R.: Solving norm equations in global function fields. Res. Number Theory 11(1), 17 (2025)","journal-title":"Res. Number Theory"},{"key":"5_CR57","unstructured":"LeGrow, J., Hutchinson, A.: An analysis of fault attacks on CSIDH. Cryptology ePrint Archive, Report 2020\/1006 (2020). https:\/\/eprint.iacr.org\/2020\/1006"},{"key":"5_CR58","doi-asserted-by":"publisher","unstructured":"LeGrow, J.T.: A faster method for fault attack resistance in static\/ephemeral CSIDH. J. Cryptogr. Eng. 13(3), 283\u2013294 (2023). https:\/\/doi.org\/10.1007\/s13389-023-00318-0","DOI":"10.1007\/s13389-023-00318-0"},{"key":"5_CR59","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"216","DOI":"10.1007\/978-3-030-85987-9_12","volume-title":"Advances in Information and Computer Security","author":"JT LeGrow","year":"2021","unstructured":"LeGrow, J.T., Hutchinson, A.: (Short Paper) analysis of a strong fault attack on static\/ephemeral CSIDH. In: Nakanishi, T., Nojima, R. (eds.) IWSEC 2021. LNCS, vol. 12835, pp. 216\u2013226. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-85987-9_12"},{"key":"5_CR60","unstructured":"Leonardi, C.: A note on the ending elliptic curve in SIDH. Cryptology ePrint Archive, Report 2020\/262 (2020). https:\/\/eprint.iacr.org\/2020\/262"},{"key":"5_CR61","doi-asserted-by":"publisher","unstructured":"Leroux, A.: An effective lower bound on the number of orientable supersingular elliptic curves. In: Smith, B., Wu, H. (eds.) SAC 2022. LNCS, vol. 13742, pp. 263\u2013281. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-58411-4_12","DOI":"10.1007\/978-3-031-58411-4_12"},{"key":"5_CR62","doi-asserted-by":"publisher","unstructured":"Maino, L., Martindale, C., Panny, L., Pope, G., Wesolowski, B.: A direct key recovery attack on SIDH. In: Hazay, C., Stam, M. (eds.) EUROCRYPT\u00a02023, Part\u00a0V. LNCS, vol. 14008, pp. 448\u2013471. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_16","DOI":"10.1007\/978-3-031-30589-4_16"},{"key":"5_CR63","doi-asserted-by":"publisher","unstructured":"Meyer, M., Campos, F., Reith, S.: On lions and elligators: an efficient constant-time implementation of CSIDH. In: Ding, J., Steinwandt, R. (eds.) Post-Quantum Cryptography - 10th International Conference, PQCrypto 2019, pp. 307\u2013325. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-25510-7_17","DOI":"10.1007\/978-3-030-25510-7_17"},{"key":"5_CR64","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1007\/978-3-030-05378-9_8","volume-title":"Progress in Cryptology \u2013 INDOCRYPT 2018","author":"M Meyer","year":"2018","unstructured":"Meyer, M., Reith, S.: A faster way to the CSIDH. In: Chakraborty, D., Iwata, T. (eds.) INDOCRYPT 2018. LNCS, vol. 11356, pp. 137\u2013152. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-05378-9_8"},{"key":"5_CR65","doi-asserted-by":"publisher","unstructured":"Michel, P.: The subconvexity problem for Rankin-Selberg $$L$$-functions and equidistribution of Heegner points. Ann. of Math. (2) 160(1), 185\u2013236 (2004). https:\/\/doi.org\/10.4007\/annals.2004.160.185","DOI":"10.4007\/annals.2004.160.185"},{"key":"5_CR66","unstructured":"Morrison, T., Panny, L., Sot\u00e1kov\u00e1, J., Wills, M.: The sea algorithm for endomorphisms of supersingular elliptic curves (2025). https:\/\/arxiv.org\/abs\/2501.16321"},{"key":"5_CR67","doi-asserted-by":"crossref","unstructured":"Onuki, H.: On oriented supersingular elliptic curves. Finite Fields and Their Applications (2021). https:\/\/doi.org\/10.1016\/j.ffa.2020.101777","DOI":"10.1016\/j.ffa.2020.101777"},{"key":"5_CR68","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1007\/978-3-030-26834-3_2","volume-title":"Advances in Information and Computer Security","author":"H Onuki","year":"2019","unstructured":"Onuki, H., Aikawa, Y., Yamazaki, T., Takagi, T.: (Short Paper) a faster constant-time algorithm of CSIDH keeping two points. In: Attrapadung, N., Yagi, T. (eds.) IWSEC 2019. LNCS, vol. 11689, pp. 23\u201333. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-26834-3_2"},{"key":"5_CR69","doi-asserted-by":"publisher","unstructured":"van Oorschot, P.C., Wiener, M.J.: Parallel collision search with cryptanalytic applications. J. Cryptol. 12(1), 1\u201328 (1999). https:\/\/doi.org\/10.1007\/PL00003816","DOI":"10.1007\/PL00003816"},{"key":"5_CR70","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"463","DOI":"10.1007\/978-3-030-45724-2_16","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2020","author":"C Peikert","year":"2020","unstructured":"Peikert, C.: He Gives C-Sieves on the CSIDH. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT 2020, Part II. LNCS, vol. 12106, pp. 463\u2013492. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45724-2_16"},{"key":"5_CR71","unstructured":"Pope, G.: An implementation of isogenies between Kummer Lines of Montgomery curves using $$x$$-only arithmetic. https:\/\/github.com\/GiacomoPope\/KummerIsogeny"},{"key":"5_CR72","unstructured":"Regev, O.: A subexponential time algorithm for the dihedral hidden subgroup problem with polynomial space (2004). https:\/\/arxiv.org\/pdf\/quant-ph\/0406151"},{"key":"5_CR73","doi-asserted-by":"publisher","unstructured":"Robert, D.: Breaking SIDH in polynomial time. In: Hazay, C., Stam, M. (eds.) EUROCRYPT\u00a02023, Part\u00a0V. LNCS, vol. 14008, pp. 472\u2013503. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_17","DOI":"10.1007\/978-3-031-30589-4_17"},{"key":"5_CR74","unstructured":"Robert, D.: The module action for isogeny based cryptography. Cryptology ePrint Archive, Paper 2024\/1556 (2024). https:\/\/eprint.iacr.org\/2024\/1556"},{"key":"5_CR75","unstructured":"Rostovtsev, A., Stolbunov, A.: Public-key cryptosystem based on isogenies. Cryptology ePrint Archive, Report 2006\/145 (2006). https:\/\/eprint.iacr.org\/2006\/145"},{"key":"5_CR76","doi-asserted-by":"publisher","unstructured":"Santos, M.C.R., Eriksen, J.K., Meyer, M., Reijnders, K.: Apr\u00e8sSQI: extra fast verification for SQIsign using extension-field signing. In: Joye, M., Leander, G. (eds.) EUROCRYPT\u00a02024, Part\u00a0I. LNCS, vol. 14651, pp. 63\u201393. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-58716-0_3","DOI":"10.1007\/978-3-031-58716-0_3"},{"key":"5_CR77","doi-asserted-by":"publisher","unstructured":"Santos, M.C.R., Eriksen, J.K., Meyer, M., Rodr\u00edguez-Henr\u00edquez, F.: Finding practical parameters for isogeny-based cryptography. CiC 1(3), 39 (2024). https:\/\/doi.org\/10.62056\/ayojbhey6b","DOI":"10.62056\/ayojbhey6b"},{"key":"5_CR78","unstructured":"Sterner, B.: Towards optimally small smoothness bounds for cryptographic-sized twin smooth integers and their isogeny-based applications. Cryptology ePrint Archive, Report 2023\/1576 (2023). https:\/\/eprint.iacr.org\/2023\/1576"},{"key":"5_CR79","unstructured":"St\u00f8rmer, C.: Quelques th\u00e9or\u00e8mes sur l\u2019\u00e9quation de pell x2- dy2=$$\\pm $$1 et leurs applications. Christiania Videnskabens Selskabs Skrifter, Math. Nat. Kl(2) 48 (1897)"},{"issue":"50","key":"5_CR80","doi-asserted-by":"publisher","first-page":"5285","DOI":"10.1016\/j.tcs.2009.08.030","volume":"410","author":"S Tani","year":"2009","unstructured":"Tani, S.: Claw finding algorithms using quantum walk. Theoret. Comput. Sci. 410(50), 5285\u20135297 (2009)","journal-title":"Theoret. Comput. Sci."},{"key":"5_CR81","unstructured":"The Sage Developers: SageMath, the Sage Mathematics Software System (Version 10.6) (2025). https:\/\/www.sagemath.org"},{"key":"5_CR82","first-page":"238","volume":"273","author":"J V\u00e9lu","year":"1971","unstructured":"V\u00e9lu, J.: Isog\u00e9nies entre courbes elliptiques. Comptes-Rendus de l\u2019Acad\u00e9mie des Sciences 273, 238\u2013241 (1971)","journal-title":"Comptes-Rendus de l\u2019Acad\u00e9mie des Sciences"},{"key":"5_CR83","doi-asserted-by":"publisher","unstructured":"Wesolowski, B.: Orientations and the supersingular endomorphism ring problem. In: Dunkelman, O., Dziembowski, S. (eds.) EUROCRYPT\u00a02022, Part\u00a0III. LNCS, vol. 13277, pp. 345\u2013371. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-07082-2_13","DOI":"10.1007\/978-3-031-07082-2_13"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 ASIACRYPT 2025"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-5113-2_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,7]],"date-time":"2025-12-07T15:43:39Z","timestamp":1765122219000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-5113-2_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,8]]},"ISBN":["9789819551125","9789819551132"],"references-count":83,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-5113-2_5","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12,8]]},"assertion":[{"value":"8 December 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ASIACRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on the Theory and Application of Cryptology and Information Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Melbourne, VIC","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 December 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12 December 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"31","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"asiacrypt2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/asiacrypt.iacr.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}