Extended supersingular isogeny Diffie–Hellman key exchange protocol: Revenge of the SIDH

Daniel Cervantes-Vázquez, Eduardo Ochoa‐Jiménez, Francisco Rodríguez‐Henríquez · IET Information Security · 2021

Abstract The supersingular isogeny Diffie–Hellman key exchange protocol (SIDH) was introduced by Jao and De Feo in 2011. SIDH operates on supersingular elliptic curves defined over , where p is a large prime number of the form and e A and e B are positive integers such that . A variant of the SIDH protocol, dubbed extended SIDH (eSIDH), is presented. The eSIDH makes use of primes of the form . Here ℓ B and ℓ C are two small prime numbers; f is a cofactor; and e A , e B , and e C are positive integers such that . It is shown that for many relevant instantiations of the SIDH protocol, this new family of primes enjoys faster field arithmetic than the one associated with traditional SIDH primes. Furthermore, its richer opportunities for parallelism yield a noticeable speed‐up factor when implemented on multicore platforms. A supersingular isogeny key encapsulation (SIKE) instantiation using the prime eSIDH‐ p 765 yields an acceleration factor of 1.06, 1.15 and 1.14 over a SIKE instantiation with the prime SIKE‐ p 757 when implemented on k = {1, 2, 3}‐core processors. To the authors’ knowledge, this work reports the first multicore implementation of SIDH and SIKE.

Read the paper · More papers on PaperTik