## CryptoDB

### Paper: Séta: Supersingular Encryption from Torsion Attacks

Authors: Péter Kutas , University of Birmingham Christophe Petit , Université Libre de Bruxelles and University of Birmingham Luca de Feo , IBM Research Europe, Zürich, Switzerland Antonin Leroux , DGA, École Polytechnique Tako Boris Fouotsa , Universita Degli Studi Roma Tre, Italy Benjamin Wesolowski , CNRS , Univ. Bordeaux, France Cyprien Delpech de Saint Guilhem , imec-COSIC, KU Leuven, Belgium Javier Silva , Universitat Pompeu Fabra DOI: 10.1007/978-3-030-92068-5_9 Search ePrint Search Google ASIACRYPT 2021 We present Séta, a new family of public-key encryption schemes with post-quantum security based on isogenies of supersingular elliptic curves. It is constructed from a new family of trapdoor one-way functions, where the inversion algorithm uses Petit's so called \emph{torsion attacks} on SIDH to compute an isogeny between supersingular elliptic curves given an endomorphism of the starting curve and images of torsion points. We prove the OW-CPA security of S\'eta and present an IND-CCA variant using the post-quantum OAEP transformation. Several variants for key generation are explored together with their impact on the selection of parameters, such as the base prime of the scheme. We furthermore formalise an uber'' isogeny assumption framework which aims to generalize computational isogeny problems encountered in schemes including SIDH, CSDIH, OSIDH and ours. Finally, we carefully select parameters to achieve a balance between security and run-times and present experimental results from our implementation.
