Evidence that XTR is more secure than supersingular elliptic curve cryptosystems

ER Verheul - Journal of Cryptology, 2004 - Springer
… problem in many supersingular elliptic curves is … elliptic curve cryptosystem in disguise. We
did not yet succeed in fully generalizing them to other classes of (supersingular) elliptic curves

Evidence that XTR is more secure than supersingular elliptic curve cryptosystems

ER Verheul - … on the Theory and Applications of Cryptographic …, 2001 - Springer
… in many supersingular elliptic curves is efficiently … an elliptic curve cryptosystem in disguise.
We did not attempt to fully generalize them to other classes of (supersingular) elliptic curves, …

Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies

D Jao, L De Feo - … -Quantum Cryptography: 4th International Workshop …, 2011 - Springer
supersingular or all ordinary. Traditionally, most elliptic curve cryptography uses ordinary
curves; however, for this work we will be interested in supersingular curves. We assume for the …

Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies

L De Feo, D Jao, J Plût - Journal of Mathematical Cryptology, 2014 - degruyter.com
cryptosystems based on the conjectured difficulty of finding isogenies between supersingular
elliptic curves… previous isogeny-based cryptosystems over ordinary curves. This paper is an …

Non supersingular elliptic curves for public key cryptosystems

T Beth, F Schaefer - … on the Theory and Application of of Cryptographic …, 1991 - Springer
… choose elliptic curves over finite fields with respect to application for such cryptosystems. The
… Menezes, Okamoto and Vanstone propose to use some other supersingular elliptic curves

Supersingular curves in cryptography

SD Galbraith - International Conference on the Theory and …, 2001 - Springer
elliptic curves, supersingular curves always have small k. Of course, there are lots of non-…
supersingular elliptic curve. In this section we show that the use of other supersingular curves

Implementation of elliptic Curve cryptosystems

A Menezes, A Menezes - Elliptic Curve Public Key Cryptosystems, 1993 - Springer
… scheme, similar in spirit to the RSA cryptosystem, which uses elliptic curves over the ring '!In. …
discussion to non-supersingular elliptic curves. However, supersingular curves may also be …

Computational problems in supersingular elliptic curve isogenies

SD Galbraith, F Vercauteren - Quantum Information Processing, 2018 - Springer
… We present an overview of supersingular isogeny cryptography and how it fits into the broad
… tutorial of elliptic curve isogenies and the computational problems relevant for supersingular

Theoretical foundations of cryptosystems based on isogenies of supersingular elliptic curves

J Oupický - 2022 - dspace.cuni.cz
Cryptographic algorithms built on isogenies between supersingular elliptic curves have, for
… go to achieve post-quantum cryptographic algorithms ie, cryptographic algorithms that do not …

Constructing elliptic curve cryptosystems in characteristic 2

N Koblitz - Advances in Cryptology-CRYPTO'90: Proceedings 10, 1991 - Springer
… logarithm on an elliptic curve to the discrete logarithm in a finite field, a reduction which
leads to a subexponential algorithm for the discrete log on a supersingular elliptic curve but not …