In 2022 a post-quantum cryptography competition run by NIST was entering its final round. Among the finalists sat SIKE — a system that had survived seven years of public scrutiny, built on a branch of mathematics so exotic that most cryptographers barely recognized it.
Six weeks before the announcement, two Belgian researchers, Wouter Castryck and Thomas Decru, published a preprint. They had broken SIKE completely: a single-core laptop needed about one hour to recover any private key. No quantum computer required.
The scheme relied on isogeny-based cryptography — a technique for building key-exchange protocols by walking through a vast graph of elliptic curves, where each edge is a structure-preserving map called an isogeny. The hope was that finding the exact path someone took through this graph was computationally hopeless. The reality turned out to be more subtle, and more humbling.
To understand what went wrong, we need to understand what isogenies are, why walks on their graph seemed so safe, and what extra information SIKE accidentally leaked.
Comments
Loading comments...