Hash functions from superspecial genus-2 curves using Richelot isogenies

Hash functions from superspecial genus-2 curves using Richelot isogenies
复制标题

使用 Richelot 同基因的超特殊 genus-2 曲线的哈希函数

DOI:
--
复制
发表时间:
2019
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
Benjamin A. Smith
Benjamin A. Smith
中科院分区:
--
文献类型:
--
作者:
W. Castryck;Thomas Decru;Benjamin A. Smith

文献摘要

被引文献

相似文献

摘要在2018年,Takashima提出了一个版本的Charles,Goren和劳特的哈希函数,使用Richelot isogenies,从亏格2曲线开始,允许所有后续的算术在二次有限域上执行?P2.在2019年,Flynn和Ti指出,由于存在小的isprone循环,Takashima的哈希函数是不安全的。我们重新审视的建设,并表明,它可以通过施加一个简单的限制,而且澄清了安全分析。所得到的散列函数的运行时间由对消息的每个3位块提取3个平方根来控制,与椭圆曲线情况下的每个位一个平方根相比;然而,在我们的设置中,提取可以并行化,并且在有限域中完成,其位大小减少了3倍。沿着的方式,我们认为,充分的超奇异isgraph是错误的背景下,研究高维类似物的查尔斯,Goren和劳特的哈希函数,并主张使用的superspecial子图,这是自然的框架中,查看高岛的?p2-友好的起始曲线。
Abstract In 2018 Takashima proposed a version of Charles, Goren and Lauter’s hash function using Richelot isogenies, starting from a genus-2 curve that allows for all subsequent arithmetic to be performed over a quadratic finite field ?p2. In 2019 Flynn and Ti pointed out that Takashima’s hash function is insecure due to the existence of small isogeny cycles. We revisit the construction and show that it can be repaired by imposing a simple restriction, which moreover clarifies the security analysis. The runtime of the resulting hash function is dominated by the extraction of 3 square roots for every block of 3 bits of the message, as compared to one square root per bit in the elliptic curve case; however in our setting the extractions can be parallelized and are done in a finite field whose bit size is reduced by a factor 3. Along the way we argue that the full supersingular isogeny graph is the wrong context in which to study higher-dimensional analogues of Charles, Goren and Lauter’s hash function, and advocate the use of the superspecial subgraph, which is the natural framework in which to view Takashima’s ?p2-friendly starting curve.