{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T03:09:39Z","timestamp":1787022579936,"version":"3.56.0"},"reference-count":35,"publisher":"Walter de Gruyter GmbH","issue":"1","license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,8,7]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>\n                    In 2018 Takashima proposed a version of Charles, Goren and Lauter\u2019s hash function using Richelot isogenies, starting from a genus-2 curve that allows for all subsequent arithmetic to be performed over a quadratic finite field \ud835\udd3d\n                    <jats:sub>\n                      <jats:italic>p<\/jats:italic>\n                      <jats:sup>2<\/jats:sup>\n                    <\/jats:sub>\n                    . In 2019 Flynn and Ti pointed out that Takashima\u2019s hash function is insecure due to the existence of small isogeny cycles. We revisit the construction and show that it can be repaired by imposing a simple restriction, which moreover clarifies the security analysis. The runtime of the resulting hash function is dominated by the extraction of 3 square roots for every block of 3 bits of the message, as compared to one square root per bit in the elliptic curve case; however in our setting the extractions can be parallelized and are done in a finite field whose bit size is reduced by a factor 3. Along the way we argue that the full supersingular isogeny graph is the wrong context in which to study higher-dimensional analogues of Charles, Goren and Lauter\u2019s hash function, and advocate the use of the superspecial subgraph, which is the natural framework in which to view Takashima\u2019s \ud835\udd3d\n                    <jats:sub>\n                      <jats:italic>p<\/jats:italic>\n                      <jats:sup>2<\/jats:sup>\n                    <\/jats:sub>\n                    -friendly starting curve.\n                  <\/jats:p>","DOI":"10.1515\/jmc-2019-0021","type":"journal-article","created":{"date-parts":[[2020,8,17]],"date-time":"2020-08-17T06:30:07Z","timestamp":1597645807000},"page":"268-292","source":"Crossref","is-referenced-by-count":34,"title":["Hash functions from superspecial genus-2 curves using Richelot isogenies"],"prefix":"10.1515","volume":"14","author":[{"given":"Wouter","family":"Castryck","sequence":"first","affiliation":[{"name":"imec-COSIC, Department of Electrical Engineering , KU Leuven , France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thomas","family":"Decru","sequence":"additional","affiliation":[{"name":"imec-COSIC, Department of Electrical Engineering , KU Leuven , France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Benjamin","family":"Smith","sequence":"additional","affiliation":[{"name":"Inria and \u00c9cole Polytechnique, Institut Polytechnique de Paris , Palaiseau , France"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"374","published-online":{"date-parts":[[2020,8,7]]},"reference":[{"key":"2025120600172399530_j_jmc-2019-0021_ref_001_w2aab3b7d965b1b6b1ab2b1b1Aa","unstructured":"J.-M. Couveignes, \u201cHard homogeneous spaces.\u201d Cryptology ePrint Archive, Report 2006\/291, 2006."},{"key":"2025120600172399530_j_jmc-2019-0021_ref_002_w2aab3b7d965b1b6b1ab2b1b2Aa","unstructured":"A. Stolbunov, \u201cPublic-key encryption based on cycles of isogenous elliptic curves,\u201d Master\u2019s thesis, Saint-Petersburg State Polytechnical University, 2004. In Russian."},{"key":"2025120600172399530_j_jmc-2019-0021_ref_003_w2aab3b7d965b1b6b1ab2b1b3Aa","doi-asserted-by":"crossref","unstructured":"D. X. Charles, K. E. Lauter, and E. Z. Goren, \u201cCryptographic hash functions from expander graphs,\u201d Journal of Cryptology, vol. 22, no. 1, pp. 93\u2013113, 2009.","DOI":"10.1007\/s00145-007-9002-x"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_004_w2aab3b7d965b1b6b1ab2b1b4Aa","doi-asserted-by":"crossref","unstructured":"D. Jao and L. De Feo, \u201cTowards quantum-resistant cryptosystems from supersingular elliptic curve isogenies,\u201d in International Workshop on Post-Quantum Cryptography, pp. 19\u201334, Springer, 2011.","DOI":"10.1007\/978-3-642-25405-5_2"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_005_w2aab3b7d965b1b6b1ab2b1b5Aa","doi-asserted-by":"crossref","unstructured":"L. De Feo, D. Jao, and J. Pl\u00fbt, \u201cTowards quantum-resistant cryptosystems from supersingular elliptic curve isogenies,\u201d Journal of Mathematical Cryptology, vol. 8, no. 3, pp. 209\u2013247, 2014.","DOI":"10.1515\/jmc-2012-0015"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_006_w2aab3b7d965b1b6b1ab2b1b6Aa","doi-asserted-by":"crossref","unstructured":"L. De Feo, J. Kieffer, and B. Smith, \u201cTowards practical key exchange from ordinary isogeny graphs,\u201d in Advances in Cryptology \u2013 ASIACRYPT 2018, Part III (T. Peyrin and S. Galbraith, eds.), pp. 365\u2013394, Springer International Publishing, 2018.","DOI":"10.1007\/978-3-030-03332-3_14"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_007_w2aab3b7d965b1b6b1ab2b1b7Aa","doi-asserted-by":"crossref","unstructured":"W. Castryck, T. Lange, C. Martindale, L. Panny, and J. Renes, \u201cCSIDH: An efficient post-quantum commutative group action,\u201d in Advances in Cryptology \u2013 ASIACRYPT 2018, Part III (T. Peyrin and S. Galbraith, eds.), pp. 395\u2013427, Springer International Publishing, 2018.","DOI":"10.1007\/978-3-030-03332-3_15"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_008_w2aab3b7d965b1b6b1ab2b1b8Aa","doi-asserted-by":"crossref","unstructured":"L. De Feo and S. D. Galbraith, \u201cSeaSign: Compact isogeny signatures from class group actions,\u201d in Advances in Cryptology \u2013 EUROCRYPT 2019 (Y. Ishai and V. Rijmen, eds.), pp. 759\u2013789, Springer International Publishing, 2019.","DOI":"10.1007\/978-3-030-17659-4_26"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_009_w2aab3b7d965b1b6b1ab2b1b9Aa","doi-asserted-by":"crossref","unstructured":"T. Decru, L. Panny, and F. Vercauteren, \u201cFaster SeaSign signatures through improved rejection sampling,\u201d in Post-Quantum Cryptography (J. Ding and R. Steinwandt, eds.), pp. 271\u2013285, Springer International Publishing, 2019.","DOI":"10.1007\/978-3-030-25510-7_15"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_010_w2aab3b7d965b1b6b1ab2b1c10Aa","doi-asserted-by":"crossref","unstructured":"W. Beullens, T. Kleinjung, and F. Vercauteren, \u201cCSI-FiSh: Efficient isogeny based signatures through class group computations,\u201d in Advances in Cryptology \u2013 ASIACRYPT 2019 (S. D. Galbraith and S. Moriai, eds.), (Cham), pp. 227\u2013247, Springer International Publishing, 2019.","DOI":"10.1007\/978-3-030-34578-5_9"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_011_w2aab3b7d965b1b6b1ab2b1c11Aa","doi-asserted-by":"crossref","unstructured":"L. De Feo, S. Masson, C. Petit, and A. Sanso, \u201cVerifiable delay functions from supersingular isogenies and pairings,\u201d in Advances in Cryptology \u2013 ASIACRYPT 2019 (S. D. Galbraith and S. Moriai, eds.), (Cham), pp. 248\u2013277, Springer International Publishing, 2019.","DOI":"10.1007\/978-3-030-34578-5_10"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_012_w2aab3b7d965b1b6b1ab2b1c12Aa","unstructured":"R. Azarderakhsh, B. Koziel, M. Campagna, B. LaMacchia, C. Costello, P. Longa, L. De Feo, M. Naehrig, B. Hess, J. Renes, A. Jalali, V. Soukharev, D. Jao, and D. Urbanik, \u201cSupersingular isogeny key encapsulation.\u201d http:\/\/sike.org, 2017."},{"key":"2025120600172399530_j_jmc-2019-0021_ref_013_w2aab3b7d965b1b6b1ab2b1c13Aa","doi-asserted-by":"crossref","unstructured":"D. X. Charles, E. Z. Goren, and K. E. Lauter, \u201cFamilies of Ramanujan graphs and quaternion algebras,\u201d Groups and symmetries: from Neolithic Scots to John McKay, vol. 47, pp. 53\u201363, 2009.","DOI":"10.1090\/crmp\/047\/05"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_014_w2aab3b7d965b1b6b1ab2b1c14Aa","doi-asserted-by":"crossref","unstructured":"K. Takashima, \u201cEfficient algorithms for isogeny sequences and their cryptographic applications,\u201d in Mathematical Modelling for Next-Generation Cryptography. Mathematics for Industry (T. T. et al., ed.), vol. 29, (Singapore), pp. 97\u2013114, Springer, 2018.","DOI":"10.1007\/978-981-10-5065-7_6"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_015_w2aab3b7d965b1b6b1ab2b1c15Aa","doi-asserted-by":"crossref","unstructured":"K. Takashima and R. Yoshida, \u201cAn algorithm for computing a sequence of Richelot isogenies,\u201d Bull. Korean Math. Soc, vol. 46, no. 4, pp. 789\u2013802, 2009.","DOI":"10.4134\/BKMS.2009.46.4.789"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_016_w2aab3b7d965b1b6b1ab2b1c16Aa","doi-asserted-by":"crossref","unstructured":"E. V. Flynn and Y. B. Ti, \u201cGenus two isogeny cryptography,\u201d in Post-Quantum Cryptography (J. Ding and R. Steinwandt, eds.), pp. 286\u2013306, Springer International Publishing, 2019.","DOI":"10.1007\/978-3-030-25510-7_16"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_017_w2aab3b7d965b1b6b1ab2b1c17Aa","unstructured":"K.-Z. Li and F. Oort, Moduli of supersingular abelian varieties, vol. 1680 of Lecture Notes in Mathematics. Springer-Verlag, Berlin, 1998."},{"key":"2025120600172399530_j_jmc-2019-0021_ref_018_w2aab3b7d965b1b6b1ab2b1c18Aa","unstructured":"B. W. Brock, Superspecial curves of genera two and three. PhD thesis, Princeton University, 1994."},{"key":"2025120600172399530_j_jmc-2019-0021_ref_019_w2aab3b7d965b1b6b1ab2b1c19Aa","doi-asserted-by":"crossref","unstructured":"E. W. Howe, \u201cConstructing distinct curves with isomorphic Jacobians,\u201d J. Number Theory, vol. 56, pp. 381\u2013390, 1996.","DOI":"10.1006\/jnth.1996.0026"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_020_w2aab3b7d965b1b6b1ab2b1c20Aa","unstructured":"T. Ibukiyama and T. Katsura, \u201cOn the field of definition of superspecial polarized abelian varieties and type numbers,\u201d Compositio Mathematica, vol. 91, no. 1, pp. 37\u201346, 1994."},{"key":"2025120600172399530_j_jmc-2019-0021_ref_021_w2aab3b7d965b1b6b1ab2b1c21Aa","unstructured":"T. Ibukiyama, T. Katsura, and F. Oort, \u201cSupersingular curves of genus two and class numbers,\u201d Compositio Mathematica, vol. 57, no. 2, pp. 127\u2013152, 1986."},{"key":"2025120600172399530_j_jmc-2019-0021_ref_022_w2aab3b7d965b1b6b1ab2b1c22Aa","doi-asserted-by":"crossref","unstructured":"G. Cardona and J. Quer, \u201cField of moduli and field of definition for curves of genus 2,\u201d in Computational aspects of algebraic curves, pp. 71\u201383, World Scientific, 2005.","DOI":"10.1142\/9789812701640_0006"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_023_w2aab3b7d965b1b6b1ab2b1c23Aa","unstructured":"B. Smith, Explicit endomorphisms and correspondences. PhD thesis, University of Sydney, 2005."},{"key":"2025120600172399530_j_jmc-2019-0021_ref_024_w2aab3b7d965b1b6b1ab2b1c24Aa","doi-asserted-by":"crossref","unstructured":"E. W. Howe, F. Lepr\u00e9vost, and B. Poonen, \u201cLarge torsion subgroups of split jacobians of curves of genus two or three,\u201d Forum Mathematicum, vol. 12, no. 3, pp. 315 \u2013 364, 2000.","DOI":"10.1515\/form.2000.008"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_025_w2aab3b7d965b1b6b1ab2b1c25Aa","doi-asserted-by":"crossref","unstructured":"E. Kani, \u201cThe number of curves of genus two with elliptic differentials,\u201d Journal f\u00fcr die reine und angewandte Mathematik, vol. 485, pp. 93\u2013122, 1997.","DOI":"10.1515\/crll.1997.485.93"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_026_w2aab3b7d965b1b6b1ab2b1c26Aa","doi-asserted-by":"crossref","unstructured":"N. Bruin and K. Doerksen, \u201cThe arithmetic of genus two curves with (4, 4)-split Jacobians,\u201d Canadian Journal of Mathematics, vol. 63, no. 5, pp. 992\u20131024, 2011.","DOI":"10.4153\/CJM-2011-039-3"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_027_w2aab3b7d965b1b6b1ab2b1c27Aa","doi-asserted-by":"crossref","unstructured":"J. H. Silverman, The arithmetic of elliptic curves, vol. 106. Springer Science & Business Media, 2009.","DOI":"10.1007\/978-0-387-09494-6"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_028_w2aab3b7d965b1b6b1ab2b1c28Aa","unstructured":"T. Katsura and K. Takashima, \u201cCounting superspecial Richelot isogenies and its cryptographic application.\u201d Cornell University arXiv, Report 2003.00633, 2020."},{"key":"2025120600172399530_j_jmc-2019-0021_ref_029_w2aab3b7d965b1b6b1ab2b1c29Aa","doi-asserted-by":"crossref","unstructured":"C. Costello and B. Smith, \u201cThe supersingular isogeny problem in genus 2 and beyond,\u201d in PQCrypto 2020 (J. Ding and J.-P. Tillich, eds.), Springer International Publishing, 2020.","DOI":"10.1007\/978-3-030-44223-1_9"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_030_w2aab3b7d965b1b6b1ab2b1c30Aa","doi-asserted-by":"crossref","unstructured":"S. Tani, \u201cClaw finding algorithms using quantum walk,\u201d Theoretical Computer Science, vol. 410, no. 50, pp. 5285\u20135297, 2009.","DOI":"10.1016\/j.tcs.2009.08.030"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_031_w2aab3b7d965b1b6b1ab2b1c31Aa","doi-asserted-by":"crossref","unstructured":"S. Jaques and J. M. Schanck, \u201cQuantum cryptanalysis in the RAM model: Claw-finding attacks on SIKE,\u201d in Advances in Cryptology \u2013 CRYPTO 2019 (A. Boldyreva and D. Micciancio, eds.), (Cham), pp. 32\u201361, Springer International Publishing, 2019.","DOI":"10.1007\/978-3-030-26948-7_2"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_032_w2aab3b7d965b1b6b1ab2b1c32Aa","unstructured":"J. Doliskani, G. C. Pereira, and P. S. Barreto, \u201cFaster cryptographic hash function from supersingular isogeny graphs.\u201d Cryptology ePrint Archive, Report 2017\/1202, 2017."},{"key":"2025120600172399530_j_jmc-2019-0021_ref_033_w2aab3b7d965b1b6b1ab2b1c33Aa","doi-asserted-by":"crossref","unstructured":"D. Kohel, K. Lauter, C. Petit, and J.-P. Tignol, \u201cOn the quaternion \u2113-isogeny path problem,\u201d LMS J. Comput. Math., vol. 17, no. suppl. A, pp. 418\u2013432, 2014.","DOI":"10.1112\/S1461157014000151"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_034_w2aab3b7d965b1b6b1ab2b1c34Aa","doi-asserted-by":"crossref","unstructured":"K. Eisentr\u00e4ger, S. Hallgren, K. Lauter, T. Morrison, and C. Petit, \u201cSupersingular isogeny graphs and endomorphism rings: reductions and solutions,\u201d in Advances in cryptology\u2014EUROCRYPT 2018. Part III (J. B. Nielsen and V. Rijmen, eds.), pp. 329\u2013368, Springer International Publishing, 2018.","DOI":"10.1007\/978-3-319-78372-7_11"},{"key":"2025120600172399530_j_jmc-2019-0021_ref_035_w2aab3b7d965b1b6b1ab2b1c35Aa","unstructured":"B. W. Jordan and Y. Zaytman, \u201cIsogeny graphs of superspecial abelian varieties and generalized Brandt matrices,\u201d arXiv preprint arXiv:2005.09031, 2020."}],"container-title":["Journal of Mathematical Cryptology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.degruyter.com\/view\/journals\/jmc\/14\/1\/article-p268.xml","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.degruyterbrill.com\/document\/doi\/10.1515\/jmc-2019-0021\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.degruyterbrill.com\/document\/doi\/10.1515\/jmc-2019-0021\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,6]],"date-time":"2025-12-06T00:17:36Z","timestamp":1764980256000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.degruyterbrill.com\/document\/doi\/10.1515\/jmc-2019-0021\/html"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,1,1]]},"references-count":35,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2020,8,7]]},"published-print":{"date-parts":[[2020,8,7]]}},"alternative-id":["10.1515\/jmc-2019-0021"],"URL":"https:\/\/doi.org\/10.1515\/jmc-2019-0021","relation":{},"ISSN":["1862-2984","1862-2976"],"issn-type":[{"value":"1862-2984","type":"electronic"},{"value":"1862-2976","type":"print"}],"subject":[],"published":{"date-parts":[[2020,1,1]]}}}