IACR News item: 30 November 2022
Jesús-Javier Chi-Domínguez
ePrint Report
This paper illustrates that masking the torsion point images does not guarantee Castryck-Decru attack does not apply.
Our experiments over SIDH primes hint that any square root concerning the Weil pairing on the masked public key helps to recover Bob's private key via the Castryck-Decru attack.
Additional news items may be found on the IACR news page.