← Back to Blog

SIDH: Supersingular Isogeny Diffie-Hellman History

SIDH: Supersingular Isogeny Diffie-Hellman History - QNSQY post-quantum encryption guide

SIDH, Supersingular Isogeny Diffie-Hellman, was a post-quantum key exchange protocol proposed in 2011 by Luca De Feo and David Jao. It became the most studied isogeny-based scheme of the 2010s, the basis for the SIKE submission to NIST's post-quantum competition, and a prominent candidate for tight-bandwidth deployments. In July 2022, eleven years after its introduction, Wouter Castryck and Thomas Decru published a polynomial-time attack that completely broke SIDH. By August 2022, SIKE had withdrawn from the NIST competition.

This article tells the SIDH story: where it came from, what made it appealing, why it lasted so long despite its flaws, and what isogeny cryptography looks like in 2026 after the catastrophic break.

The Hidden Path

Imagine a maze with billions of intersections, where the only way through is to take a long sequence of turns. Two people each walk a different path through the maze, ending at different exits. They publish their exits but keep their paths secret. Then each one walks their secret path through the other's exit, and they end up at the same final intersection. That is supersingular isogeny Diffie-Hellman in metaphor.

The "intersections" are supersingular elliptic curves. The "paths" are sequences of isogenies (structure-preserving maps between curves). The hardness assumption is that recovering the secret path, given only the start and end curves, is computationally hard. SIDH made this idea concrete and added the auxiliary points that the protocol needed to function. Those auxiliary points were also what enabled the eventual break.

The Origin: 2011, De Feo and Jao

Luca De Feo (then at INRIA) and David Jao (University of Waterloo) published "Towards Quantum-Resistant Cryptosystems from Supersingular Elliptic Curve Isogenies" in 2011. The paper described a Diffie-Hellman-style key exchange where Alice and Bob each compute a secret isogeny, exchange enough public information for the other to translate, and arrive at a shared curve.

The protocol's headline numbers in the original paper:

  • Field prime: ~768 bits at the original proposal's 80-bit security level, giving public keys far smaller than other post-quantum candidates of the time.
  • Quantum security: No known polynomial-time attack on quantum computers.
  • Computation cost: Significant, but tolerable for batch operations.

For comparison, the most efficient post-quantum schemes at the time had public keys of several kilobytes. SIDH's sub-kilobyte keys made it the small-key champion of the post-quantum field.

Why Small Keys Mattered

The PQC community in 2011 had a fundamental size problem. McEliece's public keys were over a megabyte. Lattice schemes were several kilobytes. Hash-based signatures were tens of kilobytes. SIDH's sub-kilobyte keys were genuinely revolutionary, opening the door to PQC deployment in bandwidth-tight scenarios that other schemes could not reach: satellite communications, embedded radios, RFID-tier devices.

SIDH's Decade of Refinement

From 2011 to 2022, the SIDH research community refined the scheme:

  • Compressed public keys: Researchers showed how to compress SIDH public keys further, getting them under 200 bytes for some parameter sets.
  • Faster implementations: Optimisation work brought SIDH performance into the same range as elliptic curve Diffie-Hellman on modern CPUs.
  • CCA security wrapper: SIKE (Supersingular Isogeny Key Encapsulation) was the IND-CCA2-secure KEM built around SIDH, submitted to NIST in 2017.
  • Side-channel hardening: Constant-time implementations were developed and refined.

Throughout this period, SIDH was studied for cryptanalytic weaknesses. Various partial attacks emerged (active attacks, attacks on weak parameter sets), but the core scheme survived. The cryptographic community grew confident that SIDH would be safe to standardise.

The Auxiliary Point Problem

A subtle feature of SIDH was that each party published not just their final curve but two auxiliary points on it. The auxiliary points let the other party "translate" their secret isogeny kernel onto the partner's curve, which was necessary for the protocol to compute a shared secret.

The auxiliary points were studied carefully. Several papers verified that they did not leak the secret isogeny in any obvious way. The community concluded the auxiliary points were structurally safe.

That conclusion was wrong, and the discovery would come from an unexpected direction.

The 2022 Break

Wouter Castryck and Thomas Decru (KU Leuven) posted "An efficient key recovery attack on SIDH" on the IACR ePrint server on July 30, 2022. The attack used Kani's theorem, a 1997 result on isogenies between abelian surfaces, to construct a 2-dimensional isogeny that revealed the secret kernel given only the auxiliary points and the public curves.

Within hours of the paper's appearance, multiple research teams verified the attack. Within days, Damien Robert showed how to extend it to break SIDH at every standardised parameter set. Maino, Martindale, Pope, and others contributed further refinements that made the attack run in minutes on a single laptop for SIKEp434, the smallest NIST parameter set.

By the end of August 2022, the SIKE submission had been withdrawn from NIST's Round 4 evaluation. SIDH was dead as a deployable cryptographic primitive.

For more on the attack itself, see SIKE Broken Explained.

Why the Attack Was Possible

The attack's mathematical core relies on Kani's theorem, which gives a way to construct an isogeny between products of elliptic curves (an abelian surface) given enough information about the underlying isogenies. The auxiliary points that SIDH published turned out to provide exactly enough information. Castryck and Decru's contribution was recognising the connection and turning it into an efficient algorithm.

In hindsight, the auxiliary points were the load-bearing weakness. Schemes that do not publish such points (like CSIDH, see below) are not affected.

The Aftermath: NIST's Response

NIST IR 8528 (March 2025) confirmed that SIKE had been withdrawn and that no isogeny-based KEM remained in the standardisation process. The Round 4 KEM standard went to HQC, with Classic McEliece and BIKE as remaining alternates for future consideration.

The lesson NIST drew was diversity. Their post-quantum portfolio (ML-KEM lattice, HQC code, ML-DSA lattice, SLH-DSA hash, FN-DSA lattice) explicitly avoids putting all its security on any single mathematical family. If isogenies had been the only PQC option, the SIDH break would have been catastrophic. Because lattices and codes were also in the portfolio, the cryptographic ecosystem absorbed the loss without crisis.

What Survives in Isogeny Cryptography

SIDH is dead, but isogeny cryptography is not entirely extinct. Several variants survived because they do not have the auxiliary-point structure that Castryck and Decru exploited.

  • CSIDH (Castryck-Lange-Martindale-Panny-Renes, 2018): Commutative supersingular isogeny Diffie-Hellman. Uses a different mathematical structure (commutative class group action). Does not publish auxiliary points. The Castryck-Decru attack does not apply. CSIDH is much slower than SIDH was, but it remains a candidate for non-interactive key exchange.
  • SQIsign (De Feo-Kohel-Leroux-Petit-Wesolowski, 2020): An isogeny-based digital signature with extremely small signatures (about 200 bytes). NIST's additional-signatures on-ramp (Round 1 announced in July 2023) included SQIsign as a candidate. Slow signing but compact signatures make it interesting for niche scenarios.
  • FESTA (Basso-Maino-Pope, 2023): A trapdoor-isogeny KEM that learned from SIDH's mistakes by carefully avoiding the auxiliary-point structure. Still in research stages.

The Field Today

Isogeny cryptography in 2026 is a smaller, more cautious research community than it was in 2021. The major candidates (CSIDH, SQIsign, FESTA) are designed with explicit awareness of how SIDH fell. NIST's signature on-ramp keeps isogeny-based proposals in the research pipeline. But isogeny KEMs are not on any near-term standardisation track.

For production deployment in 2026, isogenies are not a viable choice. ML-KEM (lattice) and HQC (code) are the standardised KEMs. Researchers continue to explore isogeny variants for the future.

SIDH's Legacy

SIDH's place in cryptographic history is unique. It was:

  • The most-studied isogeny scheme in the 2010s.
  • The smallest-key post-quantum KEM during its active years.
  • The basis for SIKE, a NIST Round 4 alternate.
  • The most spectacular cryptographic break of the modern era.

The lessons from SIDH's fall shape the post-quantum field today:

  1. Diversity is not optional. Putting too many eggs in one mathematical basket is dangerous.
  2. Old math can suddenly become weaponised. Kani's 1997 theorem sat in the abelian-variety literature for 25 years before anyone applied it to cryptography. Cryptographic schemes are vulnerable to math that has not yet been pointed at them.
  3. Auxiliary information is dangerous. Any "extra" data published alongside a public key is a potential attack surface. Newer designs (CSIDH, FESTA) deliberately minimise auxiliary information.
  4. Cryptanalysis can be sudden. Eleven years of research on SIDH did not surface the vulnerability. The community went from "SIDH is approaching standardisation" to "SIDH is dead" in less than a month.

SIDH and SIKE in QNSQY

QNSQY does not ship SIDH or SIKE. The product was designed in 2023, after the Castryck-Decru attack, so isogeny KEMs were never on the table. QNSQY's KEM portfolio is ML-KEM (lattice) and HQC (code, Business tier). For signatures, QNSQY ships ML-DSA, SLH-DSA, FN-DSA, and LMS in Business tier.

If we had launched in 2021 with SIKE in the suite (some pre-NIST projects did), the August 2022 break would have forced a complete re-encryption of every file. Customers' files encrypted under broken SIKE between 2021 and 2022 would have been retroactively vulnerable to anyone who captured them, which under the harvest-now-decrypt-later threat model is a worst-case outcome.

The conservative approach is to ship algorithms NIST has standardised or formally selected. SIDH was never standardised, SIKE was withdrawn before standardisation, and isogeny KEMs are not in the FIPS 203 standard. QNSQY's portfolio reflects that.

The Lesson For Early Adopters

The SIDH story has a clear lesson for any organisation considering early-stage post-quantum schemes: do not commit production data to a candidate algorithm. Wait for standardisation. SIKE was a Round 4 alternate, the closest thing to "almost standardised" without actually being standardised, and it still fell. Pre-standardisation deployment of post-quantum cryptography should be reserved for experimentation, with hybrid wrappers that ensure classical primitives still protect the data even if the post-quantum half is broken.

QNSQY's hybrid envelope (X25519 with ML-KEM) is exactly this pattern, applied to a standardised scheme. If the unthinkable happened and ML-KEM fell tomorrow, the X25519 half would still protect the data against classical adversaries. Of course, X25519 falls to a sufficiently large quantum computer, so the hybrid is a transitional measure. But during the transition period, layering classical and post-quantum is what the SIDH lesson teaches us to do.

For more on related history, see SIKE Broken Explained and HQC Explained.

Frequently Asked Questions

Did the SIDH break affect any production systems?

Very few. SIDH and SIKE were never NIST-standardised. Cloudflare and Google ran an experimental hybrid SIKE TLS deployment (CECPQ2b, 2019) that was long finished before the attack, and remaining experimental uses were retired immediately after it. Most production post-quantum deployments waited for ML-KEM standardisation. The break was a research crisis but had a small operational footprint.

Could a similar attack break ML-KEM or HQC?

The Castryck-Decru attack is specific to SIDH's auxiliary-point structure. It does not apply to lattice or code-based schemes. ML-KEM and HQC have their own attack surfaces (BKZ reduction for lattices, decoding-based attacks for codes), but neither has had a comparable catastrophic break in over a decade of intensive cryptanalysis.

Are isogeny-based schemes completely abandoned?

No. CSIDH (key exchange), SQIsign (signatures), and FESTA (KEM) are active research. None are production-ready in 2026, but the field continues. NIST's signature on-ramp evaluates isogeny-based candidates. The community is much more cautious now than before the SIDH break.

Why did SIDH publish auxiliary points if they were dangerous?

Because the protocol mathematically required them. SIDH worked by having Alice and Bob each compute a secret isogeny, then exchange the necessary information for the other to "translate" their isogeny kernel onto the partner's curve. The translation needs the auxiliary points. The community studied these points for over a decade and concluded they were safe; the conclusion turned out to be wrong because it had not considered Kani's theorem.

Sources

  1. Jao, D., De Feo, L. "Towards Quantum-Resistant Cryptosystems from Supersingular Elliptic Curve Isogenies." PQCrypto 2011. https://eprint.iacr.org/2011/506
  2. Castryck, W., Decru, T. "An efficient key recovery attack on SIDH." IACR ePrint 2022/975. https://eprint.iacr.org/2022/975
  3. NIST. "Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process." NIST IR 8528, March 2025. https://csrc.nist.gov/pubs/ir/8528/final
  4. Robert, D. "Breaking SIDH in polynomial time." IACR ePrint 2022/1038. https://eprint.iacr.org/2022/1038
  5. Maino, L., Martindale, C., Panny, L., Pope, G., Wesolowski, B. "A direct key recovery attack on SIDH." IACR ePrint 2022/1026. https://eprint.iacr.org/2022/1026
  6. NIST. "PQC Standardization Process: Announcing Four Candidates to be Standardized, Plus Fourth Round Candidates." July 5, 2022. https://csrc.nist.gov/News/2022/pqc-candidates-to-be-standardized-and-round-4

Related Articles

Protect Your Data Before Q-Day Arrives

QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.

Try QNSQY