Sign in

Boris Fouotsa

@borisfouotsa.bsky.social
116 followers 61 following 10 posts

Postdoc at EPFL, isogenies, and more... borisfouotsa.com

PostsRepliesMedia
Reposted by Boris Fouotsa
ePrint Updates @eprint.ing.bot · 21/05/2026
Updatable Public-Key Encryption from FESTA (Andrea Basso, Tako Boris Fouotsa, Fatna Kouider, Péter Kutas, Luciano Maino, Laurane Marco) ia.cr/2026/1014
Abstract. Updatable public-key encryption (UPKE) is a cryptographic primitive that was proposed for secure messaging to provide forward secrecy in public-key settings. It extends standard public-key encryption with a key-update mechanism that lets anyone update a receiver’s public key and issue a corresponding token for updating the secret key. Unlike traditional forward secrecy where all past messages should remain secure after a key leakage, UPKEs guarantee security only as long as at least one honest update has occurred.
While classically-secure efficient instantiations of UPKE are known from Diffie-Hellman assumptions, constructing an UPKE scheme with updates remains an open problem. In this work, we propose an isogeny-based UPKE that relies on a dimension-four version of the FESTA public-key encryption scheme. It is practically efficient and supports an unbounded amount of updates. Moreover, we provide a formal security proof based on a problem in isogeny-based cryptography that has received considerable scrutiny.
062
Reposted by Boris Fouotsa
COSIC @cosic.bsky.social · 03/11/2025
Valerio Ardizio is the newest member of Frederik Vercauteren's team! "I chose COSIC because of its welcoming, inspiring, and stimulating research environment, as well as the outstanding expertise of the researchers who are part of this group." #choosecosic
022
Reposted by Boris Fouotsa
mccurley.bsky.social @mccurley.bsky.social · 25/10/2025
I spent two years building a piece of infrastructure for open access publishing in CS arxiv.org/abs/2504.10424. I've gotten positive feedback from authors, but most are quite ignorant about how publishing works (even in computer science). Thankfully we don't have to accept Microsoft Word.😁
arxiv.org
Lowering the Cost of Diamond Open Access Journals
Many scholarly societies face challenges in adapting their publishing to an open access model where neither authors nor readers pay any fees. Some have argued that one of the main barriers is the actu...
194
Reposted by Boris Fouotsa
spooky Deirdre Connolly¹ ² at a distance @durumcrustulum.com · 10/10/2025
let's read some legal agreements www.youtube.com/watch?v=nmvf...
youtube.com
Is ML-KEM Patent-Encumbered?
YouTube video by Deirdre Connolly
162
Reposted by Boris Fouotsa
Tibor Jager @tiborj.bsky.social · 25/09/2025
The call for papers for PKC 2026 is out: pkc.iacr.org/2026/callfor...
pkc.iacr.org
PKC 2026 call for papers
Public Key Cryptography
0810
Reposted by Boris Fouotsa
ePrint Updates @eprint.ing.bot · 24/09/2025
WaterSQI and PRISMO: Quaternion Signatures for Supersingular Isogeny Group Actions (Tako Boris Fouotsa) ia.cr/2025/1737
Abstract. Isogeny group action based signatures are obtained from a sigma protocol with high soundness error, say $\frac{1}{2}$ for its most basic variant. One needs to independently repeat the sigma protocol O(λ) times to reduce the soundness error to negligible (with λ being the security parameter). These repetitions come with a considerable efficiency and size overhead. On the other hand, quaternion isogeny-based signatures such as SQIsign and PRISM are directly obtained from a sigma protocol with a negligible soundness error. The secret key in the SQIsign and PRISM is a random supersingular isogeny, and both schemes are insecure when the secret isogeny arises from the supersingular isogeny group action setting.

In this paper, we propose WaterSQI and PRISMO, variants of SQIsign and PRISM respectively, suited for secret isogenies that arise from the supersingular isogeny group action setting. They use a sigma protocol whose soundness error is negligible without requiring parallel repetitions. They are hence more compact and O(λ) times more efficient compared to Generalised CSI-FiSh (the generalisation of CSI-FiSh to large parameters using generic isogeny group action evaluation algorithms such as Clapotis/KLaPoTi/PEGASIS). For example, for our proof of concept implementation with a 2000 bits prime in sagemath, PRISMO, when compared to Generalised CSI-FiSh with the same public key size, is about 3x faster for key generation, 273x faster for signing and 4900x faster for verification, while also being 29x more compact (signature size).
Image showing part 2 of abstract.
021
Boris Fouotsa @borisfouotsa.bsky.social · 24/09/2025
Quaternion signatures for isogeny group actions: showing how to adapt SQIsign and PRISM to the group actions setting, unleashing WaterSQI and PRISMO signatures that come with a tremendous speed-up over CSI-FiSh style signatures.
130
Reposted by Boris Fouotsa
Sofia Celi @claucece.bsky.social · 25/06/2025
Come to the ASCrypto school, affiliated with Latincrypt2025! 🗓️ Sept 29–30 | Medellín, Colombia 👨‍🏫 Learn 𝐦𝐨𝐝𝐞𝐫𝐧 𝐩𝐫𝐨𝐯𝐢𝐧𝐠 𝐬𝐲𝐬𝐭𝐞𝐦𝐬 from top experts 💥 2 days, 3 modules: IVC, STARKs, MPC 👥 With Benedikt Bünz, Sophia Yakoubov, Alan Szepieniec Organised by the amazing Arantxa Zapico and Javier Verbel.
064
Reposted by Boris Fouotsa
COSIC @cosic.bsky.social · 16/06/2025
Registration for the Leuven Isogeny Days 6 is now open! 📅 10–12 Sept 2025 @ KU Leuven Morning: research talks Afternoon: brainstorming sessions More info: www.esat.kuleuven.be/cosic/projec... #isogeny #isocrypt #erc #postquantum
0119
Boris Fouotsa @borisfouotsa.bsky.social · 22/05/2025
AFRICACRYPT'25 accepted papers (africacrypt2025.sciencesconf.org/resource/page/…) & invited speakers (africacrypt2025.sciencesconf.org/re…) are online. Early registration deadline is May 30th (africacrypt2025.sciencesconf.org/resource/page/���). See you in Rabat 🇲🇦 in July! 😉
101
Boris Fouotsa @borisfouotsa.bsky.social · 03/05/2025
Isogenies @ Eurocrypt 2025 in Madrid!
080
Reposted by Boris Fouotsa
Luca De Feo @bsky.defeo.lu · 25/04/2025
The SQIparty starts on Monday, but it's still time to register! We prepared an exciting program for you with a balanced mix of talks, coding sprints, skillshares and other activities! www.cig.udl.cat/SQIparty2025... See you in Lleida!
299
Reposted by Boris Fouotsa
Maria Corte-Real Santos @maria.isogeny.club · 23/04/2025
Good news is that we're still accepting brainstorm topics!! If you have a brainstorm idea, send us a short description by email !
034
Reposted by Boris Fouotsa
Maria Corte-Real Santos @maria.isogeny.club · 23/04/2025
Season 6 of the Isogeny Club is officially done! You can catch up with all the talks here: isogeny.club If, like us, you haven't had enough isogenies for the term, be sure to join us at the Brainstorm Sessions affiliated with Eurocrypt: isogeny.club/eurocrypt
isogeny.club
The Isogeny Club
163
Reposted by Boris Fouotsa
Nigel Smart @smartcryptology.bsky.social · 14/04/2025
Congratulations to the new IACR fellows.... Joan Daemen, Thomas Johansson, Anna Lysyanskaya, Pascal Paillier, J.R. Rao, Alon Rosen, Elaine Shi, Bo-Yin Yang. iacr.org/fellows/ #cryptography
iacr.org
IACR Fellows
03511
Boris Fouotsa @borisfouotsa.bsky.social · 07/04/2025
Higher dimensions everywhere ! #isogenies
0111
Reposted by Boris Fouotsa
Luca De Feo @bsky.defeo.lu · 25/03/2025
Registration to the SQIparty is open, free, and we have a first sketch of a program! www.cig.udl.cat/SQIparty2025... Register and plan your travel quickly: the rooms are reserved only until Thursday! See you in Lleida!
033
Boris Fouotsa @borisfouotsa.bsky.social · 29/03/2025
It saddens to spend time reviewing a paper, then to neither be able to see the other reviews nor take part in the discussion on that paper! Program Chairs should always enable this (and choose a reviewing platform that allows them to).
140
Reposted by Boris Fouotsa
Martin R. Albrecht @malb.bsky.social · 21/03/2025
Update on crypto.iacr.org/2025/
 Given recent instances of US visa holders and residents being detained or deported by US immigration authorities, we understand that some members of our community may not feel safe traveling to the US for Crypto this year. We want to assure everyone that we will provide the option to present and attend remotely.
26639
Reposted by Boris Fouotsa
Krijn Reijnders @krijn.isogeni.es · 14/03/2025
> claims no new results > adds in a tiny new result anyway > ??? anyway, enjoy the read!
0134
Reposted by Boris Fouotsa
Andrea Basso @andreavbasso.bsky.social · 13/03/2025
This workshop is gonna be great: cool people, interesting talks, and lots of great research on SQIsign and isogeny-based crypto. Mark it in your calendars! And if you’re going to Eurocrypt, this is going to be convenient: the workshop is just the week before, and it’s not too far from Madrid
022
Reposted by Boris Fouotsa
Nigel Smart @smartcryptology.bsky.social · 13/03/2025
Looking forward to speaking at this event. Come and enjoy an autumn day in Rome talking #cryptography.... www.decifris.it/fcir25
decifris.it
Financial Cryptography in Rome 2025
L'associazione De Componendis Cifris si propone di animare la comunità crittografica italiana, favorendo lo studio, la ricerca e la divulgazione della crittografia.
042
Reposted by Boris Fouotsa
Luca De Feo @bsky.defeo.lu · 13/03/2025
Fancy some isogeny crypto? Join us for a 3-day workshop on isogeny-based cryptography in Lleida, Catalonia, April 28-30 www.cig.udl.cat/icrypto2025_... Brought to you by ULleida's Cryptography+Graphs group, the SQIsign team and friends! Registration and program coming soon Registration is free!
Cathedral of La Seu Vella in Lleida
289
Reposted by Boris Fouotsa
Ignacio Cascudo @icascudo.bsky.social · 12/03/2025
Registration for Eurocrypt 2025 is open!! Register at eurocrypt.iacr.org/2025/registr... Early bird registration deadline is 4th of April. Note that registration will be temporarily closed between the 29th and the 31st of March, and we'll have to cancel previous invoices left unpaid by March 30th.
187
Reposted by Boris Fouotsa
Luca De Feo @bsky.defeo.lu · 13/03/2025
And why not pair that with an isogeny workshop in Catalonia just before? bsky.app/profile/bsky...
021
Reposted by Boris Fouotsa
ePrint Updates @eprint.ing.bot · 04/03/2025
A Note on Zero-Knowledge Simulator of the CROSS Identification Protocol (Shai Levin) ia.cr/2025/359
Abstract. We point out flaw in zero-knowledge of the CROSS identification protocol, CROSS-ID, which allows a distinguisher to distinguish real and simulated transcripts given access to the witness. Moreover, we show that the real and simulated transcripts are not statistically indistinguishable, and therefore the protocol can only satisfy weak computational (rather than strong, statistical or perfect) Honest Verifier Zero-knowledge. This issue is still present in version 2.0 updated on January 31, 2025, which resolves the security losses attained via the attacks of [BLP+25]
011
Reposted by Boris Fouotsa
ePrint Updates @eprint.ing.bot · 04/03/2025
KLPT²: Algebraic Pathfinding in Dimension Two and Applications (Wouter Castryck, Thomas Decru, Péter Kutas, Abel Laval, Christophe Petit, Yan Bo Ti) ia.cr/2025/372
Abstract. Following Ibukiyama, Katsura and Oort, all principally polarized superspecial abelian surfaces over $\overline{\mathbb{F}}_p$ can be represented by a certain type of 2 × 2 matrix g, having entries in the quaternion algebra B_(p, ∞). We present a heuristic polynomial-time algorithm which, upon input of two such matrices g₁, g₂, finds a “connecting matrix” representing a polarized isogeny of smooth degree between the corresponding surfaces. Our algorithm should be thought of as a two-dimensional analog of the KLPT algorithm from 2014 due to Kohel, Lauter, Petit and Tignol for finding a connecting ideal of smooth norm between two given maximal orders in B_(p, ∞).

The KLPT algorithm has proven to be a versatile tool in isogeny-based cryptography, and our analog has similar applications; we discuss two of them in detail. First, we show that it yields a polynomial-time solution to a two-dimensional analog of the so-called constructive Deuring correspondence: given a matrix g representing a superspecial principally polarized abelian surface, realize the latter as the Jacobian of a genus-2 curve (or, exceptionally, as the product of two elliptic curves if it concerns a product polarization). Second, we show that, modulo a plausible assumption, Charles-Goren-Lauter style hash functions from superspecial principally polarized abelian surfaces require a trusted set-up. Concretely, if the matrix g associated with the starting surface is known then collisions can be produced in polynomial time. We deem it plausible that all currently known methods for generating a starting surface indeed reveal the corresponding matrix. As an auxiliary tool, we present an explicit table for converting (2,2)-isogenies into the corresponding connecting matrix, a step for which a previous method by Chu required super-polynomial (but sub-exponential) time.
Image showing part 2 of abstract.
043
Reposted by Boris Fouotsa
ePrint Updates @eprint.ing.bot · 04/03/2025
A Complete Security Proof of SQIsign (Marius A. Aardal, Andrea Basso, Luca De Feo, Sikhar Patranabis, Benjamin Wesolowski) ia.cr/2025/379
Abstract. SQIsign is the leading digital signature from isogenies. Despite the many improvements that have appeared in the literature, all its recents variants lack a complete security proof. In this work, we provide the first full security proof of SQIsign, as submitted to the second round of NIST’s on-ramp track for digital signatures.

To do so, we introduce a new framework, which we call Fiat-Shamir with hints, that captures all those protocols where the simulator needs additional information to simulate a transcript. Using this framework, we show that SQIsign is EUF-CMA secure in the ROM, assuming the hardness of the One Endomorphism problem with hints, or the hardness of the Full Endomorphism Ring problem with hints together with a hint indistinguishability assumption; all assumptions, unlike previous ones in the literature, are non-interactive. Along the way, we prove several intermediate results that may be of independent interest.
071
Reposted by Boris Fouotsa
Andrea Basso @andreavbasso.bsky.social · 04/03/2025
As part of the round-2 NIST submission, we developed a complete proof of security of SQIsign!
1105
Reposted by Boris Fouotsa
Jonathan Komada Eriksen @jonathan.isogeny.club · 04/03/2025
At the right level pf abstraction, we present an effective group action: Its so efficient, that frob is sufficient; another win for the isogeny-faction! 🥳
0123
Reposted by Boris Fouotsa
ePrint Updates @eprint.ing.bot · 04/03/2025
PEGASIS: Practical Effective Class Group Action using 4-Dimensional Isogenies (Pierrick Dartois, Jonathan Komada Eriksen, Tako Boris Fouotsa, Arthur Herlédan Le Merdy, Riccardo Invernizzi, Damien Robert, Ryan Rueger, Frederik Vercauteren, Benjamin Wesolowski) ia.cr/2025/401
Abstract. In this paper, we present the first practical algorithm to compute an effective group action of the class group of any imaginary quadratic order 𝒪 on a set of supersingular elliptic curves primitively oriented by 𝒪. Effective means that we can act with any element of the class group directly, and are not restricted to acting by products of ideals of small norm, as for instance in CSIDH. Such restricted effective group actions often hamper cryptographic constructions, e.g. in signature or MPC protocols.

Our algorithm is a refinement of the Clapoti approach by Page and Robert, and uses 4-dimensional isogenies. As such, it runs in polynomial time, does not require the computation of the structure of the class group, nor expensive lattice reductions, and our refinements allows it to be instantiated with the orientation given by the Frobenius endomorphism. This makes the algorithm practical even at security levels as high as CSIDH-4096. Our implementation in SageMath takes 1.5s to compute a group action at the CSIDH-512 security level, 21s at CSIDH-2048 level and around 2 minutes at the CSIDH-4096 level. This marks the first instantiation of an effective cryptographic group action at such high security levels. For comparison, the recent KLaPoTi approach requires around 200s at the CSIDH-512 level in SageMath and 2.5s in Rust.
Image showing part 2 of abstract.
0136
Reposted by Boris Fouotsa
Helger Lipmaa @helger.bsky.social · 03/03/2025
Recommend, if you did not manage to submit to Crypto
031
Boris Fouotsa @borisfouotsa.bsky.social · 03/03/2025
16th International Conference on Cryptology AFRICACRYPT 2025 July 21-23, 2025 – Rabat, Morocco 🇲🇦 Extended submission deadline in 1 week: africacrypt2025.sciencesconf.org Submit your best results ! See you in Rabat 🇲🇦 in July 2025.
africacrypt2025.sciencesconf.org
16th International Conference on Cryptology, Africacrypt 2025 - Sciencesconf.org
Africacrypt 2025 is organized by the ENSIAS College of Mohammed V University in Rabat with partnership of the General Directorate of Information Systems Security (DGSSI), Morocco.
186
Reposted by Boris Fouotsa
ePrint Updates @eprint.ing.bot · 01/09/2024
Attacking trapdoors from matrix products (Thomas Decru, Tako Boris Fouotsa, Paul Frixons, Valerie Gilchrist, Christophe Petit) ia.cr/2024/1332
Abstract. Recently, Geraud-Stewart and Naccache proposed two trapdoors based on matrix products. In this paper, we answer the call for cryptanalysis. We explore how using the trace and determinant of a matrix can be used to attack their constructions. We fully break their first construction in a polynomial-time attack. We show an information leak in the second construction using characteristic polynomials, and provide an attack using traces that decreases the bit security by about half.
011
Reposted by Boris Fouotsa
ePrint Updates @eprint.ing.bot · 22/05/2024
SQIPrime: A dimension 2 variant of SQISignHD with non-smooth challenge isogenies (Max Duparc, Tako Boris Fouotsa) ia.cr/2024/773
Abstract. We introduce SQIPrime, a post-quantum digital signature scheme based on the Deuring correspondence and Kani’s Lemma. Compared to its predecessors that are SQISign and especially SQISignHD, SQIPrime further expands the use of high dimensional isogenies, already in use in the verification in SQISignHD, to both key generation and commitment. In doing so, it no longer relies on smooth degree isogenies (of dimension 1). SQIPrime operates with a prime number of the form p = 2^(α)f − 1, as opposed to SQISignHD that uses SIDH primes.

The most intriguing novelty in SQIPrime is the use of non-smooth degree isogenies as challenge isogeny. In fact, in the SQISign family identification scheme, the challenge isogeny is computed by the verifier, who is not well-equipped to compute an isogeny of large non-smooth degree. To overcome this obstacle, the verifier samples the kernel of the challenge isogeny and the task of computing this isogeny is accomplished by the prover. The response is modified in such a way that the verifier can check that his challenge isogeny was correctly computed by the prover, on top of verifying the usual response in the SQISign family.

We describe two variants of SQIPrime: SQIPrime4D which uses dimension 4 isogenies to represent the response isogeny, and SQIPrime2D which solely uses dimension 2 isogenies to represent the response isogeny and hence is more efficient compared to SQIPrime4D and to SQISignHD.
Image showing part 2 of abstract.
022
Reposted by Boris Fouotsa
ePrint Updates @eprint.ing.bot · 06/04/2024
Avoiding Trusted Setup in Isogeny-based Commitments (Gustave Tchoffo Saah, Tako Boris Fouotsa, Emmanuel Fouotsa, Célestin Nkuimi-Jugnia) ia.cr/2024/531
Abstract. In 2021, Sterner proposed a commitment scheme based on supersingular isogenies. For this scheme to be binding, one relies on a trusted party to generate a starting supersingular elliptic curve of unknown endomorphism ring. In fact, the knowledge of the endomorphism ring allows one to compute an endomorphism of degree a power of a given small prime. Such an endomorphism can then be split into two to obtain two different messages with the same commitment. This is the reason why one needs a curve of unknown endomorphism ring, and the only known way to generate such supersingular curves is to rely on a trusted party or on some expensive multiparty computation. We observe that if the degree of the endomorphism in play is well chosen, then the knowledge of the endomorphism ring is not sufficient to efficiently compute such an endomorphism and in some particular cases, one can even prove that endomorphism of a certain degree do not exist. Leveraging these observations, we adapt Sterner’s commitment scheme in such a way that the endomorphism ring of the starting curve can be known and public. This allows us to obtain isogeny-based commitment schemes which can be instantiated without trusted setup requirements.
Image showing part 2 of abstract.
011
Reposted by Boris Fouotsa
Martin R. Albrecht @malb.bsky.social · 25/03/2024
Slides for my talk "An Update on Lattice Cryptanalysis Vol. 1" at the Real World Post Quantum Cryptography workshop yesterday: github.com/malb/talks/b... Yes, there was a Vol 2, it was given by John Schanck and his talk was way better.
076
Reposted by Boris Fouotsa
ePrint Updates @eprint.ing.bot · 22/03/2024
Isogeny problems with level structure (Luca De Feo, Tako Boris Fouotsa, Lorenz Panny) ia.cr/2024/459
Abstract. Given two elliptic curves and the degree of an isogeny between them, finding the isogeny is believed to be a difficult problem—upon which rests the security of nearly any isogeny-based scheme. If, however, to the data above we add information about the behavior of the isogeny on a large enough subgroup, the problem can become easy, as recent cryptanalyses on SIDH have shown. Between the restriction of the isogeny to a full N-torsion subgroup and no ’’torsion information” at all lies a spectrum of interesting intermediate problems, raising the question of how easy or hard each of them is. Here we explore modular isogeny problems where the torsion information is masked by the action of a group of 2 × 2 matrices. We give reductions between these problems, classify them by their difficulty, and link them to security assumptions found in the literature.
031
Reposted by Boris Fouotsa
ePrint Updates @eprint.ing.bot · 05/03/2024
SILBE: an Updatable Public Key Encryption Scheme from Lollipop Attacks (Max Duparc, Tako Boris Fouotsa, Serge Vaudenay) ia.cr/2024/400
Abstract. We present a new post-quantum Public Key Encryption scheme (PKE) named Supersingular Isogeny Lollipop Based Encryption or SILBE. SILBE is obtained by leveraging the generalized lollipop attack of Castryck and Vercauteren on the M-SIDH Key exchange by Fouotsa, Moriya and Petit. Doing so, we can in fact make of SILBE a post-quantum secure Updatable Public Key Encryption scheme (UPKE). SILBE is the first isogeny-based UPKE which is not based on group actions. In its core, SILBE extensively uses both the Deuring Correspondence and Kani’s Lemma, two central concepts in Isogeny-Based Cryptography.
022
Reposted by Boris Fouotsa
ePrint Updates @eprint.ing.bot · 15/12/2023
Exploring SIDH-based Signature Parameters (Andrea Basso, Mingjie Chen, Tako Boris Fouotsa, Péter Kutas, Abel Laval, Laurane Marco, Gustave Tchoffo Saah) ia.cr/2023/1906
Abstract. Isogeny-based cryptography is an instance of post-quantum cryptography whose fundamental problem consists of finding an isogeny between two (isogenous) elliptic curves E and E′. This problem is closely related to that of computing the endomorphism ring of an elliptic curve. Therefore, many isogeny-based protocols require the endomorphism ring of at least one of the curves involved to be unknown. In this paper, we explore the design of isogeny based protocols in a scenario where one assumes that the endomorphism ring of all the curves are public. In particular, we identify digital signatures based on proof of isogeny knowledge from SIDH squares as such a candidate. We explore the design choices for such constructions and propose two variants with practical instantiations. We analyze their security according to three lines, the first consists of attacks based on KLPT with both polynomial and superpolynomial adversary, the second consists of attacks derived from the SIDH attacks
and finally we study the zero-knowledge property of the underlying proof of knowledge.
021
Reposted by Boris Fouotsa
ePrint Updates @eprint.ing.bot · 29/01/2024
K-Waay: Fast and Deniable Post-Quantum X3DH without Ring Signatures (Daniel Collins, Loïs Huguenin-Dumittan, Ngoc Khanh Nguyen, Nicolas Rolin, Serge Vaudenay) ia.cr/2024/120
Abstract. The Signal protocol and its X3DH key exchange core are regularly used by billions of people in applications like WhatsApp but are unfortunately not quantum-secure. Thus, designing an efficient and post-quantum secure X3DH alternative is paramount. Notably, X3DH supports asynchronicity, as parties can immediately derive keys after uploading them to a central server, and deniability, allowing parties to plausibly deny having completed key exchange. To satisfy these constraints, existing post-quantum X3DH proposals use ring signatures (or equivalently a form of designated-verifier signatures) to provide authentication without compromising deniability as regular signatures would. Existing ring signature schemes, however, have some drawbacks. Notably, they are not generally proven secure in the quantum random oracle model (QROM) and so the quantum security of parameters that are proposed is unclear and likely weaker than claimed. In addition, they are generally slower than standard primitives like KEMs.

In this work, we propose an efficient, deniable and post-quantum X3DH-like protocol that we call K-Waay, that does not rely on ring signatures. At its core, K-Waay uses a split-KEM, a primitive introduced by Brendel et al. [SAC 2020], to provide Diffie-Hellman-like implicit authentication and secrecy guarantees. Along the way, we revisit the formalism of Brendel et al. and identify that additional security properties are required to prove a split-KEM-based protocol secure. We instantiate split-KEM by building a protocol based on the Frodo key exchange protocol relying on the plain LWE assumption: our proofs might be of independent interest as we show it satisfies our novel unforgeability and deniability security notions. Finally, we complement our theoretical results by thoroughly benchmarking both K-Waay and existing X3DH protocols. Our results show even when using plain LWE and a conservative choice of parameters that K-Waay is significantly faster than previous work.
Image showing part 2 of abstract.
042
Reposted by Boris Fouotsa
ePrint Updates @eprint.ing.bot · 07/08/2023
Towards a Quantum-resistant Weak Verifiable Delay Function (Thomas Decru, Luciano Maino, Antonio Sanso) ia.cr/2023/1197
Abstract. In this paper, we present a new quantum-resistant weak Verifiable Delay Function based on a purely algebraic construction. Its delay depends on computing a large-degree isogeny between elliptic curves, whereas its verification relies on the computation of isogenies between products of two elliptic curves. One of its major advantages is its expected fast verification time. However, it is important to note that the practical implementation of our theoretical framework poses significant challenges. We examine the strengths and weaknesses of our construction, analyze its security and provide a proof-of-concept implementation.
011