[Resource Topic] 2021/699: Radical Isogenies on Montgomery Curves

Welcome to the resource topic for 2021/699

Title:
Radical Isogenies on Montgomery Curves

Authors: Hiroshi Onuki, Tomoki Moriya

Abstract:

We work on some open problems in radical isogenies. Radical isogenies are formulas to compute chains of N-isogenies for small N and proposed by Castryck, Decru, and Vercauteren in Asiacrypt 2020. These formulas do not need to generate a point of order N generating the kernel and accelerate some isogeny-based cryptosystems like CSIDH. On the other hand, since these formulas use Tate normal forms, these need to transform Tate normal forms to curves with efficient arithmetic, e.g., Montgomery curves. In this paper, we propose radical-isogeny formulas of degrees 3 and 4 on Montgomery curves. Our formulas compute some values determining Montgomery curves, from which one can efficiently recover Montgomery coefficients. And our formulas are more efficient for some cryptosystems than the original radical isogenies. In addition, we prove a conjecture left open by Castryck et al. that relates to radical isogenies of degree 4.

ePrint: https://eprint.iacr.org/2021/699

Talk: https://www.youtube.com/watch?v=VaJqeoa8EKw

Slides: https://iacr.org/submit/files/slides/2022/pkc/pkc2022/23/slides.pdf

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .