Efficient Theta-Based Algorithms for Computing \((\ell , \ell )\) -Isogenies on Kummer Surfaces for Arbitrary Odd \(\ell \)
摘要
Isogeny-based cryptography is one of the candidates for post-quantum cryptography. Recently, several isogeny-based cryptosystems using isogenies between Kummer surfaces were proposed. Most of those cryptosystems use (2, 2)-isogenies. However, to enhance the possibility of cryptosystems, higher degree isogenies, i.e., \((\ell ,\ell )\) -isogenies for an odd \(\ell \) , are also crucial. For an odd \(\ell \) , Lubicz–Robert proposed a formula to compute \((\ell )^g\) -isogenies in general dimensions g. In this paper, we propose explicit and efficient algorithms to compute \((\ell ,\ell )\) -isogenies between Kummer surfaces, based on the Lubicz–Robert formula. In particular, we propose two algorithms for computing the codomain of the isogeny and two algorithms for evaluating the image of a point under the isogeny. Then, we count the number of arithmetic operations required for each proposed algorithm and determine the most efficient algorithm in terms of the number of operations for each algorithm for each \(\ell \) . As an application, we implemented the SIDH attack on B-SIDH in SageMath using the most efficient algorithm. In a setting that originally claimed 128-bit security, our implementation was able to recover the secret key in approximately 11 h.