Skip to main content

Cryptographic Smooth Neighbors

  • Conference paper
  • First Online:
Advances in Cryptology – ASIACRYPT 2023 (ASIACRYPT 2023)
  • The original version of the chapter has been revised. The second author name was displayed incorrectly due to a tagging error. This has been corrected. A correction to this chapter can be found at


We revisit the problem of finding two consecutive B-smooth integers by giving an optimised implementation of the Conrey-Holmstrom-McLaughlin “smooth neighbors” algorithm. While this algorithm is not guaranteed to return the complete set of B-smooth neighbors, in practice it returns a very close approximation to the complete set but does so in a tiny fraction of the time of its exhaustive counterparts. We exploit this algorithm to find record-sized solutions to the pure twin smooth problem, and subsequently to produce instances of cryptographic parameters whose corresponding isogeny degrees are significantly smoother than prior works. Our methods seem well-suited to finding parameters for the SQISign signature scheme, especially for instantiations looking to minimise the cost of signature generation. We give a number of examples, among which are the first parameter sets geared towards efficient SQISign instantiations at NIST’s security levels III and V.

Supported by EPSRC grant EP/S022503/1.

Supported by the German Federal Ministry of Education and Research (BMBF) under the project QuantumRISC (ID 16KIS1039).

Supported by EPSRC grant EP/R513350/1.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Subscribe and save

Springer+ Basic
$34.99 /Month
  • Get 10 units per month
  • Download Article/Chapter or eBook
  • 1 Unit = 1 Article or 1 Chapter
  • Cancel anytime
Subscribe now

Buy Now

USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Similar content being viewed by others

Change history

  • 18 December 2023

    A correction has been published.


  1. 1.

    SQISign is instantiated over large primes p such that \(p^2-1\) is divisible by a large, B-smooth factor. If, for example, we find B-smooth twins r and \(r+1\) whose sum is a prime \(p=2r+1\), then \(p^2-1\) is immediately B-smooth.

  2. 2.

    The initial SQISign requirements [16] had \(T \approx p^{3/2}\), but \(T_{1879}\) corresponds to the new requirements.

  3. 3.

    Another alternative is to include both positive and negative values in the inital set \(S^(0)\). Observe that in this case, it does not matter whether one uses \((rs + 1)/(s - r)\) or \((rs - 1)/(s + r)\), as \((rs + 1)/(s - r) = -(s(-r) + 1)/(s + (-r)))\).

  4. 4.

    That satisfy some mild conditions outside of just requiring \(p^2-1\) to be smooth.


  1. Banks, W.D., Shparlinski, I.E.: Integers with a large smooth divisor. arXiv preprint math/0601460 (2006)

    Google Scholar 

  2. Basso, A., Fouotsa, T.B.: New sidh countermeasures for a more efficient key exchange. Cryptology ePrint Archive, Paper 2023/791 (2023).

  3. Basso, A., Maino, L., Pope, G.: FESTA: fast encryption from supersingular torsion attacks. Cryptology ePrint Archive, Paper 2023/660 (2023).

  4. Bernstein, D.J., De Feo, L., Leroux, A., Smith, B.: Faster computation of isogenies of large prime degree. Open Book Series 4(1), 39–55 (2020)

    Article  MathSciNet  Google Scholar 

  5. Bingmann, T.: TLX: collection of sophisticated C++ data structures, algorithms, and miscellaneous helpers (2018). Accessed 7 Oct 2020

  6. Castryck, W., Decru, T.: An efficient key recovery attack on SIDH. In: EUROCRYPT. LNCS, vol. 14008, pp. 423–447. Springer (2023)

    Google Scholar 

  7. Conrey, J.B., Holmstrom, M.A.: Smooth values of quadratic polynomials. Exp. Math. 30(4), 447–452 (2021)

    Article  MathSciNet  Google Scholar 

  8. Conrey, J.B., Holmstrom, M.A., McLaughlin, T.L.: Smooth neighbors. Exp. Math. 22(2), 195–202 (2013)

    Article  MathSciNet  Google Scholar 

  9. Costello, C.: B-SIDH: supersingular isogeny Diffie-Hellman using twisted torsion. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020. LNCS, vol. 12492, pp. 440–463. Springer, Cham (2020).

    Chapter  Google Scholar 

  10. Costello, C., Meyer, M., Naehrig, M.: Sieving for twin smooth integers with solutions to the prouhet-tarry-escott problem. In: Canteaut, A., Standaert, F.-X. (eds.) EUROCRYPT 2021. LNCS, vol. 12696, pp. 272–301. Springer, Cham (2021).

    Chapter  Google Scholar 

  11. Dartois, P., Leroux, A., Robert, D., Wesolowski, B.: SQISignHD: New dimensions in cryptography. Cryptology ePrint Archive, Paper 2023/436 (2023).

  12. de Bruijn, N.G.: On the number of positive integers \(\le \) x and free of prime factors \(> y\), ii. Indag. Math. 38, 239–247 (1966)

    Article  MathSciNet  Google Scholar 

  13. De Feo, L., Delpech de Saint Guilhem, C., Fouotsa, T.B., Kutas, P., Leroux, A., Petit, C., Silva, J., Wesolowski, B.: Séta: supersingular encryption from torsion attacks. In: Tibouchi, M., Wang, H. (eds.) ASIACRYPT 2021. LNCS, vol. 13093, pp. 249–278. Springer, Cham (2021).

    Chapter  Google Scholar 

  14. Dickman, K.: On the frequency of numbers containing prime factors of a certain relative magnitude. Arkiv for matematik, astronomi och fysik 22(10), A-10 (1930)

    Google Scholar 

  15. Komada Eriksen, J., Panny, L., Sotáková, J., Veroni, M.: Deuring for the people: Supersingular elliptic curves with prescribed endomorphism ring in general characteristic. Cryptology ePrint Archive (2023)

    Google Scholar 

  16. De Feo, L., Kohel, D., Leroux, A., Petit, C., Wesolowski, B.: SQISign: Compact Post-quantum Signatures from Quaternions and Isogenies. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020. LNCS, vol. 12491, pp. 64–93. Springer, Cham (2020).

    Chapter  Google Scholar 

  17. De Feo, L., Leroux, A., Longa, P., Wesolowski, B.: New algorithms for the deuring correspondence - towards practical and secure sqisign signatures. In: EUROCRYPT, vol. 14008, pp. 659–690. Springer (2023)

    Google Scholar 

  18. T. B. Fouotsa, T. Moriya, and C. Petit. M-SIDH and MD-SIDH: Countering sidh attacks by masking information. In: EUROCRYPT, vol. 14008, pp. 282–309. Springer (2023). doi:

  19. Jao, D., De Feo, L.: Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies. In: Yang, B.-Y. (ed.) PQCrypto 2011. LNCS, vol. 7071, pp. 19–34. Springer, Heidelberg (2011).

    Chapter  Google Scholar 

  20. Lehmer, D.H.: On a problem of Störmer. Ill. J. Math. 8(1), 57–79 (1964)

    Google Scholar 

  21. Luca, F., Najman, F.: On the largest prime factor of \(x^2\)-1. Math. Comput. 80(273), 429–435 (2011)

    Article  Google Scholar 

  22. Maino, L., Martindale, C., Panny, L., Pope, G., Wesolowski, B.: A direct key recovery attack on SIDH. In: EUROCRYPT. LNCS, vol. 14008, pp. 448–471. Springer (2023).

  23. Robert, D.: Breaking SIDH in polynomial time. In: EUROCRYPT. LNCS, vol. 14008, pp. 472–503. Springer (2023).

  24. Størmer, C.: Quelques théorèmes sur l’équation de Pell \(x^2-dy^2=\pm 1\) et leurs applications. Christiania Videnskabens Selskabs Skrifter, Math. Nat. Kl (2), 48 (1897)

    Google Scholar 

  25. Tenenbaum, G.: Integers with a large friable component. Acta Arith 124, 287–291 (2006)

    Article  MathSciNet  Google Scholar 

  26. Tenenbaum, G.: Introduction to analytic and probabilistic number theory, volume 163. American Mathematical Soc. (2015)

    Google Scholar 

  27. The National Institute of Standards and Technology (NIST). Submission requirements and evaluation criteria for the post-quantum cryptography standardization process, December 2016

    Google Scholar 

  28. The National Institute of Standards and Technology (NIST). Call for additional digital signature schemes for the post-quantum cryptography standardization process, October 2022

    Google Scholar 

Download references


We thank Joost Renes for several helpful discussions about the CHM algorithm, and Luca De Feo for helpful comments on SQISign prime requirements during the preparation of this work as well as the anonymous reviewers for their constructive feedback.

Author information

Authors and Affiliations


Corresponding author

Correspondence to Giacomo Bruno .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2023 International Association for Cryptologic Research

About this paper

Check for updates. Verify currency and authenticity via CrossMark

Cite this paper

Bruno, G. et al. (2023). Cryptographic Smooth Neighbors. In: Guo, J., Steinfeld, R. (eds) Advances in Cryptology – ASIACRYPT 2023. ASIACRYPT 2023. Lecture Notes in Computer Science, vol 14444. Springer, Singapore.

Download citation

  • DOI:

  • Published:

  • Publisher Name: Springer, Singapore

  • Print ISBN: 978-981-99-8738-2

  • Online ISBN: 978-981-99-8739-9

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics