EdSIDH: Supersingular Isogeny Die-Hellman Key Exchange on Edwards Curves

EdSIDH: Supersingular Isogeny Die-Hellman Key Exchange on Edwards Curves
复制标题

EdSIDH:Edwards 曲线上的超奇异同源 Die-Hellman 密钥交换

DOI:
10.1007/978-3-030-05072-6_8
复制
发表时间:
2018
期刊:
and Applied Cryptography Engineering
影响因子:
--
通讯作者:
Koziel, Brian
Koziel, Brian
中科院分区:
--
文献类型:
--
作者:
Azarderakhsh, Reza;Lang, B Elena;Jao, David;Koziel, Brian

文献摘要

相似文献

关于有限域上椭圆曲线同构计算的问题已经研究了很长时间。超奇异椭圆曲线上的同构是量子安全密钥交换协议的候选者,因为用于解决同构问题的良构实例的最著名的经典和量子算法是指数的。我们提出了一个实现超奇异的isoprotic Diffie-Hellman(SIDH)密钥交换完整的爱德华兹曲线。我们的工作的动机是使用爱德华兹曲线,以加快许多密码协议和提高安全性。我们的工作实际上并没有提供一个更快的实现SIDH,但使用完整的爱德华兹曲线和完整的加法公式提供了安全的好处,对侧信道攻击。我们提供运行时的复杂度分析和操作计数的基础上爱德华兹曲线沿着与比较的蒙哥马利形式的建议的密钥交换。
Problems relating to the computation of isogenies between elliptic curves defined over finite fields have been studied for a long time. Isogenies on supersingular elliptic curves are a candidate for quantum-safe key exchange protocols because the best known classical and quantum algorithms for solving well-formed instances of the isogeny problem are exponential. We propose an implementation of supersingular isogeny Diffie-Hellman (SIDH) key exchange for complete Edwards curves. Our work is motivated by the use of Edwards curves to speed up many cryptographic protocols and improve security. Our work does not actually provide a faster implementation of SIDH, but the use of complete Edwards curves and their complete addition formulae provides security benefits against side-channel attacks. We provide run time complexity analysis and operation counts for the proposed key exchange based on Edwards curves along with comparisons to the Montgomery form.