[Resource Topic] 2022/847: A note on key control in CSIDH

Welcome to the resource topic for 2022/847

A note on key control in CSIDH

Authors: Antonio Sanso


In this short note we explore a particular behaviour of the CSIDH key exchange that leads to a very special form of (shared) key control via the use of the quadratic twists. This peculiarity contained in CSIDH with regard to quadratic twists was already noted in the original CSDIH work and used in several subsequent papers but we believe spelling out this in the form of an attack might be useful to the wider community.

ePrint: https://eprint.iacr.org/2022/847

