[Paper Review] Higher-degree supersingular group actions
This paper introduces $(d,\epsilon)$-structures—supersingular elliptic curves over $\FF_{p^2}$ equipped with a $d$-isogeny to their Galois conjugate—for $d > 1$, generalizing the $\FF_p$-subgraph used in CSIDH. It establishes a free and transitive action of ideal class groups on these structures, enabling new isogeny-based cryptosystems and generalizing the Delfs–Galbraith algorithm. The key contribution is a framework for constructing secure, efficient isogeny-based cryptosystems beyond $d=1$, with potential for optimized key exchange and cryptanalysis.
We investigate the isogeny graphs of supersingular elliptic curves over $\mathbb{F}_{p^2}$ equipped with a $d$-isogeny to their Galois conjugate. These curves are interesting because they are, in a sense, a generalization of curves defined over $\mathbb{F}_p$, and there is an action of the ideal class group of $\mathbb{Q}(\sqrt{-dp})$ on the isogeny graphs. We investigate constructive and destructive aspects of these graphs in isogeny-based cryptography, including generalizations of the CSIDH cryptosystem and the Delfs-Galbraith algorithm.
Motivation & Objective
- To generalize the $\FF_p$-subgraph of supersingular isogeny graphs, which underlies CSIDH, to higher-degree $d$-isogeny structures for $d > 1$.
- To investigate the existence and structure of subgraphs of supersingular isogeny graphs defined by curves with a $d$-isogeny to their Galois conjugate.
- To establish a free and transitive action of ideal class groups of $\QQ(\sqrt{-dp})$ on these $(d,\epsilon)$-structures, enabling new cryptographic constructions.
- To extend the Delfs–Galbraith isogeny-finding algorithm to multiple $d$ values, improving path-finding efficiency in isogeny graphs.
- To analyze the feasibility and security of generalized CSIDH-like systems and their resistance to cryptanalytic attacks based on random walks into these subgraphs.
Proposed method
- Define $(d,\epsilon)$-structures as supersingular elliptic curves over $\FF_{p^2}$ equipped with a $d$-isogeny to their Galois conjugate, where $d$ is squarefree and $\gcd(d,p)=1$.
- Show that such curves have $j$-invariants in $\FF_p$, and provide explicit parameterizations for $d=2$ and $d=3$ using modular polynomials.
- Use the theory of orientations and endomorphism rings to establish a free and transitive action of the ideal class group of $\QQ(\sqrt{-dp})$ on the set of $(d,\epsilon)$-structures.
- Construct isogeny graphs $\Gamma(\mathcal{D}_{d,\epsilon}(p))$ for each $d$, where vertices are $(d,\epsilon)$-structures and edges are isogenies compatible with the $d$-isogeny to the conjugate.
- Generalize the Delfs–Galbraith algorithm by performing random walks into a union of subgraphs $\sqcup_{d \in D} \mathcal{D}_{d,\epsilon}(p)$ for small, coprime $d$, reducing expected path length in Phase 1.
- Analyze the trade-off between shorter walks (Phase 1) and more expensive isogeny steps (Phase 2), showing that small $d$ values like $d=5$ can yield speedups when membership testing is efficient.
Experimental results
Research questions
- RQ1Can the $\FF_p$-subgraph of supersingular isogeny graphs be generalized to higher-degree $d$-isogeny structures for $d > 1$, preserving a group action?
- RQ2What is the structure and size of the subgraph of supersingular curves over $\FF_{p^2}$ that admit a $d$-isogeny to their Galois conjugate?
- RQ3How does the ideal class group of $\QQ(\sqrt{-dp})$ act on these $(d,\epsilon)$-structures, and can this action be used to build new isogeny-based cryptosystems?
- RQ4Can the Delfs–Galbraith isogeny-finding algorithm be generalized to multiple $d$ values, and what is the performance trade-off between shorter walks and more expensive isogeny steps?
- RQ5What is the probability and expected number of steps for a random walk in the full supersingular isogeny graph to reach a $(d,\epsilon)$-structure, and how does this vary with $d$?
Key findings
- The subgraph of $(d,\epsilon)$-structures forms a free and transitive $\operatorname{Cl}(\mathcal{O}_{-dp})$-set, generalizing the class group action in CSIDH.
- For $d=2$ and $d=3$, explicit parameterizations of $(d,\epsilon)$-structures are derived using modular polynomials, enabling efficient construction.
- The size of $\mathcal{D}_{d,\epsilon}(p)$ is asymptotically $O(\sqrt{d} \sqrt{p})$, with $\kappa(d,p) \approx \sqrt{d}$ for large $d$, but for small $d$ like $d=5$, $\kappa(5,p) \approx 4.916$ for the toy prime $p = 2^{52} \cdot 3^{33} - 1$, indicating a significant deviation from $\sqrt{d}$.
- Generalized Delfs–Galbraith attacks can be faster when $d$-isogeny membership testing is efficient: for $p = 2^{52} \cdot 3^{33} - 1$, testing for a 5-isogeny to the conjugate may be faster than computing six 2-isogenies, enabling faster Phase 1 walks.
- The $2$-isogeny graph of SIKEp434 contains paths through $\Gamma_2(\mathcal{D}_{17,\epsilon}(p))$ and $\Gamma_2(\mathcal{D}_{41,\epsilon}(p))$, suggesting a potential cryptanalytic shortcut for a small fraction of keys if such paths can be found efficiently.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.