In the realm of post-quantum cryptography, the Commutative Supersingular Isogeny Diffie-Hellman (CSIDH) has drawn considerable attention since its proposal at Asiacrypt 2018. This paper introduces a new batching strategy for computing multiple group actions in CSIDH, which is essential for constructing cryptographic schemes such as zero-knowledge proofs and signature schemes. Two variants of the batching strategy are presented in this work, suited to different security requirements and application contexts. In the first scenario, we focus on situations where group actions are public, aiming to reduce CSIDH’s computational cost. Using our strategy, we show that computational costs can be significantly reduced, making it a viable option for schemes in which efficiency is critical. This variant reduces the computational requirements of group actions by roughly up to \( 14\%\) when compared to non-batched action evaluation. The second variant is towards constant-time group actions, and it reduces computational costs while maintaining resilience to side-channel timing attacks. This article also introduces a new constant-time implementation of CSIDH that, when combined with the second variant, reduces the computation costs of secret action sets by roughly up to \(8\%\) compared to individual computation using state-of-the-art constant-time algorithms, while the new constant time alone reduces computation by approximately up to \(4\%\) .

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Streamlining CSIDH: Cost-Effective Strategies for Group Actions Evaluation

  • Ahmed Zawia,
  • M. Anwar Hasan

摘要

In the realm of post-quantum cryptography, the Commutative Supersingular Isogeny Diffie-Hellman (CSIDH) has drawn considerable attention since its proposal at Asiacrypt 2018. This paper introduces a new batching strategy for computing multiple group actions in CSIDH, which is essential for constructing cryptographic schemes such as zero-knowledge proofs and signature schemes. Two variants of the batching strategy are presented in this work, suited to different security requirements and application contexts. In the first scenario, we focus on situations where group actions are public, aiming to reduce CSIDH’s computational cost. Using our strategy, we show that computational costs can be significantly reduced, making it a viable option for schemes in which efficiency is critical. This variant reduces the computational requirements of group actions by roughly up to \( 14\%\) when compared to non-batched action evaluation. The second variant is towards constant-time group actions, and it reduces computational costs while maintaining resilience to side-channel timing attacks. This article also introduces a new constant-time implementation of CSIDH that, when combined with the second variant, reduces the computation costs of secret action sets by roughly up to \(8\%\) compared to individual computation using state-of-the-art constant-time algorithms, while the new constant time alone reduces computation by approximately up to \(4\%\) .