Cryptography Reference
In-Depth Information
works with only small (but noticeable) probability then it is possible to have a CDH
instance on an elliptic curve
E
for which the oracle does not work for any twist of
E
.
By moving around the isogeny class they claim that the probability of success increases.
However, it is still possible to have a CDH instance on an elliptic curve
E
for which the
oracle does not work for any elliptic curve in the isogeny class of
E
.