Pushforward Problems and Applications to Isogeny-based Cryptography

Christophe Petit
Let $E$ and $E'$ be two supersingular elliptic curves and let $\varphi: E\to E'$ be an isogeny of known degree $d$. Given a basis $(P, Q)$ of $E[N]$ together with $(\varphi(P), \varphi(Q))$, it is possible to recover $\varphi$ provided that $N$ is sufficiently large and smooth, and that the torsion basis can be represented over a small extension of the base field. In this work, we consider the more general setting where the $N$-torsion may not be efficiently representable. To address this sett