### Paper: CSIDH: An Efficient Post-Quantum Commutative Group Action

Authors: Wouter Castryck Tanja Lange Chloe Martindale Lorenz Panny Joost Renes DOI: 10.1007/978-3-030-03332-3_15 Search ePrint Search Google ASIACRYPT 2018 We propose an efficient commutative group action suitable for non-interactive key exchange in a post-quantum setting. Our construction follows the layout of the Couveignes–Rostovtsev–Stolbunov cryptosystem, but we apply it to supersingular elliptic curves defined over a large prime field $\mathbb F_p$, rather than to ordinary elliptic curves. The Diffie–Hellman scheme resulting from the group action allows for public-key validation at very little cost, runs reasonably fast in practice, and has public keys of only 64 bytes at a conjectured AES-128 security level, matching NIST’s post-quantum security category I.
