Sign in

Damien Robert

@damienrobert.bsky.social
298 followers 176 following 249 posts

Researcher in algorithmic number theory, notably on abelian varieties and their moduli spaces, and their applications to elliptic and isogeny based cryptography

PostsRepliesMedia
Damien Robert @damienrobert.bsky.social · 11h
See also this mail: groups.google.com/a/list.nist.... And this older bluesky thread: bsky.app/profile/dami...
groups.google.com
MIKE (Module Isogeny Key Exchange): a fast and compact post-quantum NIKE
051
Damien Robert @damienrobert.bsky.social · 11h
I am happy to announce that our new post-quantum NIKE (non interactive key exchange) called MIKE (module isogeny key exchange) got released today: mike.isogeni.es
mike.isogeni.es
MIKE - PQ NIKE
1176
Reposted by Damien Robert
Gro-Tsen @gro-tsen.bsky.social · 10/11/2025
“Dear mathematician, can you explain to me what mass is?” “Very simple, dear: the mass of a dynamical system is the cohomology class of the Galilean group representing lack of equivariance of the moment map on the symplectic manifold that is the phase space of the system.”
3303
Reposted by Damien Robert
Maria Corte-Real Santos @maria.isogeny.club · 23/09/2026
On 29 September, Benjamin Wesolowski will give a talk at The Isogeny Club on his recent p^{1/3+o(1)} attack on the isogeny problem! See you all there 🥳 isogeny.club
isogeny.club
The Isogeny Club
155
Reposted by Damien Robert
pianocktailiste @pianocktailiste.bsky.social · 24/07/2026
Les scientifiques et ingénieurs, en particulier les mathématiciens : font un effort énorme, mondial, sur plusieurs générations, visant à automatiser la pensée. La pensée : commence à être automatisée. Les scientifiques et ingénieurs, en particulier les mathématiciens :
static.klipy.com
Pikachu Shocked Face Stunned - Surprised Meme
Alt: Pikachu Shocked Face Stunned - Surprised Meme
6173
Reposted by Damien Robert
Maria Corte-Real Santos @maria.isogeny.club · 03/09/2026
Rise and shine, it's time for the Isogeny Club Season Nine! isogeny.club
isogeny.club
The Isogeny Club
185
Reposted by Damien Robert
COSIC @cosic.bsky.social · 17/08/2026
We’re excited to announce the 7th edition of the Leuven Isogeny Days (Sept 16–18, 2026)! Registration is open until 22 August, join us! More info & signup: www.esat.kuleuven.be/cosic/projec... #LID #Isogeny #IsogenyDays
033
Damien Robert @damienrobert.bsky.social · 28/07/2026
No, the proof will be in the upcoming, serious, version.
010
Damien Robert @damienrobert.bsky.social · 28/07/2026
I also wonder if an AI could have found the p^{1/3} attack: 1) without the recently published p^{1/3} bound on the minimal degree between E and E^{(p)} 2) with it (My random guesses: yes with 2), and probably yes too even with 1))
010
Damien Robert @damienrobert.bsky.social · 28/07/2026
I am mentioning this because apparently AI are working on the seven isogeny problems. So at least problems 1 and 7 fell to humans first. Take that AI!
111
Damien Robert @damienrobert.bsky.social · 28/07/2026
To be fair, I think problem 7 did fall earlier than problem 1: I think that we had a proof that MIKE's security reduce to the endomorphism ring problem in the AIM before Benjamin found the p^{1/3} attack. He just was quicker in publishing :) (Not our fault, the MIKE paper is over 100 pages long!)
310
Damien Robert @damienrobert.bsky.social · 24/07/2026
Exactly what I was thinking! Predicts problem 1 is the hardest... Problem 1 falls one week later!
110
Damien Robert @damienrobert.bsky.social · 05/07/2026
We are in the process of finalizing the paper, which is quite long, since there are a lot of cool maths there. We aim to have it public by the end of August.
210
Damien Robert @damienrobert.bsky.social · 05/07/2026
We won the prize for best song at Eurocrypt's 2026 Rump Session! (Well my colleagues won it, I was not there...). Unfortunately the rump session videos do not seem to be available yet.
110
Damien Robert @damienrobert.bsky.social · 05/07/2026
In dimension 1, this is typically done via the $j$-invariant. But we don't really have good modular invariants in dimension 4 (this is a hard problem). Thankfully for MIKE, we land in a special subvariety of the moduli space, on which we managed to build specific modular invariants.
110
Damien Robert @damienrobert.bsky.social · 05/07/2026
We have modular invariants! The MIKE key exchange gives a dimension four abelian fourfold. Alice and Bob ends up with isomorphic abelian varieties. But for key agreement, they need to extract a common shared information.
110
Damien Robert @damienrobert.bsky.social · 05/07/2026
We have a security proof! MIKE's security relies on the (module version of the) CDH problem. We have a proof that, in the (HD version of) the Algebraic Isogeny Model (introduced here: eprint.iacr.org/2026/032), the CDH problem is equivalent to the supersingular endomorphism ring problem.
eprint.iacr.org
The Algebraic Isogeny Model: A General Model with Applications to SQIsign and Key Exchanges
We introduce the Algebraic Isogeny Model (AIM): an algebraic model, akin to the Algebraic Group Model in the group setting, for isogenies and supersingular elliptic curves. This model is significantly...
110
Damien Robert @damienrobert.bsky.social · 05/07/2026
So what's new compared to last time? Well we have a Rust implementation, and as illustrated above very nice timings! On my laptop the key exchange is at <3ms for NIST level 1.
110
Damien Robert @damienrobert.bsky.social · 05/07/2026
*Provable security:* We prove MIKE's security (in the algebraic isogeny model) as a passively-secure NIKE or a KEM assuming only the supersingular endomorphism ring problem (the core assumption in isogeny-based cryptography).
120
Damien Robert @damienrobert.bsky.social · 05/07/2026
*Active security:* It is an actively-secure NIKE. The timings above include public key validation, which is a supersingularity test over $\mathbb{F}_{p^2}$.
110
Damien Robert @damienrobert.bsky.social · 05/07/2026
*Simple Implementation:* Our implementation is simple (~4200 LoC, excluding finite field arithmetic) and constant time
110
Damien Robert @damienrobert.bsky.social · 05/07/2026
*Fast key exchange:* For NIST Level 1, our Rust implementation requires <1 ms for key generation and <5 ms for the full key exchange (benchmarked on an AMD Ryzen 7 PRO 7840U @ 3.3GHz).
110
Damien Robert @damienrobert.bsky.social · 05/07/2026
*Compact keys:* 64B for NIST Level 1, and 128B for NIST Level 5.
110
Damien Robert @damienrobert.bsky.social · 05/07/2026
So what is MIKE? It is a post-quantum NIKE (non interactive key exchange) which has many nice properties:
111
Damien Robert @damienrobert.bsky.social · 05/07/2026
It's been a while since I last posted about MIKE, but a lot of exciting stuff happened meanwhile. MIKE is described in more details in this 4 part thread: - CSIDH bsky.app/profile/dami... - SIDH bsky.app/profile/dami... - MIKE bsky.app/profile/dami... - Speculations: bsky.app/profile/dami...
1104
Reposted by Damien Robert
Gro-Tsen @gro-tsen.bsky.social · 01/07/2026
A long thread about variants of Kőnig's lemma in relation to computability theory, because this caused me a lot of headaches yesterday and today, so maybe this will clarify things for other people. 🧵⤵️ •1/32
162
Reposted by Damien Robert
Gro-Tsen @gro-tsen.bsky.social · 27/06/2026
I posted a question of MathOverflow asking whether the line of research that sought to relate higher-order computability with computability on large countable ordinals died out post 1980, and if so, why. (I give several examples of such results.) mathoverflow.net/q/512688/17064
mathoverflow.net
Relating higher-order computability and computably large countable ordinals
In the period going roughly from the late 1960's to early 1980's, a number of results appeared in computability that have roughly the following flavor, relating higher-order computability with
132
Reposted by Damien Robert
Pierre Beyssac @pierreb.bsky.social · 18/06/2026
Volé sur le fédivers.
Capitaine Haddock : "deux canicules en 1 mois, quel été, hein ?"
Tintin : "On est au printemps, capitaine"
16120
Reposted by Damien Robert
Gro-Tsen @gro-tsen.bsky.social · 01/06/2026
“How can we construct a non-Borel set explicitly?” is a fascinating question by @arula-ratnakar.bsky.social, and in fact we can do this by a diagonal argument that is deeply analogous to how we construct a noncomputable subset of ℕ, but sadly nowhere written clearly AFAICT.🧵⤵️ •1/17
1124
Reposted by Damien Robert
Andrea Basso @andreavbasso.bsky.social · 21/05/2026
New paper out 🎉 We introduce a new UPKE based on FESTA that supports unbounded updates and whose security is equivalent to FESTA! Our main result: a (four-dimensional) variant of FESTA has uniformly random public keys, which means that any random walk is a valid pk update.
062
Reposted by Damien Robert
Gro-Tsen @gro-tsen.bsky.social · 19/05/2026
Despite this proof, I don't have much intuition about what this (or Scott's formula) really “means”. But it certainly shows that there are important differences between these two models of computability in higher types. See also this previous thread: 🔽
021
Reposted by Damien Robert
Matthew Green @matthewdgreen.bsky.social · 17/05/2026
A good primer on the new Bitlocker exploit. solcyber.com/bitlocker-in...
solcyber.com
BitLocker in crisis? The "YellowKey" zero-day in plain English - SolCyber
Nightmare Eclipse hates Microsoft, loves dropping 0-days.
25822
Reposted by Damien Robert
Andrea Basso @andreavbasso.bsky.social · 14/05/2026
Round 3 of the NIST additional signatures process announced! 🎉 And SQIsign is part of it!! ⛷️⛷️
Screenshot of email announcement saying:

Nine Candidates Advance to the Third Round of the Additional Digital Signatures for the PQC Standardization Process

 After 18 months of evaluation, NIST has selected nine candidates for the third round of the Additional Digital Signatures for the Post-Quantum Cryptography (PQC) Standardization Process. The advancing digital signature algorithms are:

FAEST
HAWK
MAYO
MQOM
QR-UOV
SDitH
SNOVA
SQIsign
UOV
02613
Reposted by Damien Robert
Luca De Feo @bsky.defeo.lu · 12/04/2026
Looking forward to AM-PQC 2026, the Workshop on Algebraic Methods in Post-Quantum Cryptography this August in Macedonia! pqcrypto.cs.ru.nl/ampqc/ Stipends for students are available. Apply before May 4th!
pqcrypto.cs.ru.nl
Workshop on Algebraic Methods in Post-Quantum Cryptography 2026
084
Damien Robert @damienrobert.bsky.social · 04/04/2026
I am pretty sure this explains the "semi-reduced Tate pairing" from eprint.iacr.org/2023/549.pdf. See eq.(6) p.13. I am happy because I was wondering about a more conceptual explanation of this semi-reduced pairing for 3 years!
eprint.iacr.org
010
Damien Robert @damienrobert.bsky.social · 04/04/2026
But $2nq(x)|A[n]$ is always trivial! So this time for $P \in A[n]$ we get a $\mu_{2n}$-torsor as the obstruction, not necessarily induced by a $\mu_n$-torsor, and not coming from a self Tate pairing. (We can recover the self Tate pairing from this $\mu_{2n}$-torsor, but not the other way around.)
110
Damien Robert @damienrobert.bsky.social · 04/04/2026
This is just (up to a square root), the self Tate pairing $T_n(P,P)$, because the Tate pairing is also defined as a $\mu_n$-torsor encoding the descent of trivialisations induced by $nb(x,y)=0$ over $A[n]xA$. What's interesting is when $n$ is even. Then $nq(x)|A[n]$ is non trivial in general...
110
Damien Robert @damienrobert.bsky.social · 04/04/2026
Then on the $n$-torsion, for $n$ odd, $nq(x) |A[n]=0$ means that for P in A[n], we can define an etale $\mu_n$-torsor, as the obstruction of the descent of the rigidification of L^n above P induced by "nq=0" to a trivialisation of L above P.
110
Damien Robert @damienrobert.bsky.social · 04/04/2026
Ohh, and I have just realized that this "trivial quadratic form" has another cool application. This time I'll assume we have the roots of unity in the base field, unlike in the monodromy leak. Let q:A->BGm be the quadratic form associated to an ample line bundle L.
110
Damien Robert @damienrobert.bsky.social · 04/04/2026
(I know I already made this joke in our other discussion channel, but I am very proud of it, so let me do it again here...)
020
Damien Robert @damienrobert.bsky.social · 04/04/2026
No, of course not! An ∞-category is a category enriched in ∞-groupoids. That's perfectly non circular. Ok, so then what is an ∞-groupoid? Well its simply a groupoid enriched in ∞-groupoids...
120
Damien Robert @damienrobert.bsky.social · 04/04/2026
:-) Here is a link to the paper by the way: eprint.iacr.org/2026/640
eprint.iacr.org
MIKE (Module Isogeny Key Exchange): An ἰχθύς introduction
We give a down to earth and elementary introduction to the isogeny based cryptography protocol MIKE.
010
Reposted by Damien Robert
Gro-Tsen @gro-tsen.bsky.social · 02/04/2026
I'm beginning to feel more and more that the meaning of the ‘∞’ in “∞-categories” is that you can only explain what an ∞-category is to someone who already knows what an ∞-category is.
253
Damien Robert @damienrobert.bsky.social · 02/04/2026
=> this gives explicit algorithms to compute isogenies 7) As I mentioned above, if n is odd, then Q(x):=nq(x) is trivial over A[n] => this gives the monodromy leak.
110
Damien Robert @damienrobert.bsky.social · 02/04/2026
6) If f: A -> B is linear with kernel K, a quadratic form Q on A is of the form Q=f^* q for a quadratic form q on B, iff Q(k+x)=0 for all x in A and k in K, i.e. a) Q(k)=Q(0) for each k in K and b) If B is the symmetric bilinear form associated to Q, B(k,x)=0 for all k in K and x in A.
110
Damien Robert @damienrobert.bsky.social · 02/04/2026
5) A quadratic form q is linear iff the associated bilinear form b is 0 => this gives the theta group arithmetic
110
Damien Robert @damienrobert.bsky.social · 02/04/2026
4) If b is bilinear, B_1(x,y)=b(nx,y) and B_2(x,y)=b(x,ny) are both trivial on A[n]xA[n] => this gives the Weil pairing
110
Damien Robert @damienrobert.bsky.social · 02/04/2026
3) If b is bilinear, B(x,y):=b(nx, y) is trivial on A[n] x A => this gives the Tate pairing
110
Damien Robert @damienrobert.bsky.social · 02/04/2026
2) q quadratic gives a symmetric bilinear form b(x,y)=q(x+y)+q(0)-q(x)-q(y) => this gives the polarisation associated to a line bundle
130