Sign in

kutasp89.bsky.social

@kutasp89.bsky.social
61 followers 45 following 15 posts
PostsRepliesMedia
Reposted by @kutasp89.bsky.social
ePrint Updates @eprint.ing.bot · 23/07/2026
The supersingular isogeny problem in time and memory p^(1/3 + o(1)) (Benjamin Wesolowski) ia.cr/2026/1486
Abstract. We prove that under a plausible heuristic assumption (on the smoothness of certain random integers), the supersingular isogeny problem can be solved in time and memory p^(1/3 + o(1)). This improves upon the previous best complexity of p^(1/2) ⋅ (log p)^(O(1)). This problem is arguably the central hard problem underlying isogeny-based cryptography, and the cost of its resolution is a major (and often the only) factor in the choice of secure parameters. The impact on concrete parameter sets remains to be clarified, as the asymptotic advantage of the new algorithm is mitigated by a superpolynomial overhead hiding in the o(1) exponent, and by its high memory requirement.
01511
Reposted by @kutasp89.bsky.social
ePrint Updates @eprint.ing.bot · 21/07/2026
Identity-Based Encryption from Isogenies (Shweta Agrawal, Andrea Basso, Sikhar Patranabis) ia.cr/2026/1457
Abstract. We provide the first construction of identity-based encryption from isogeny-based assumptions. Security of our construction relies on a novel assumption called the “CDH with Mismatched Torsion” (CD-HwMT) assumption, which we introduce. At a high level, the assumption posits the hardness of solving a CDH-like problem even when the adversary is given some additional “safe” leakage. We justify our assumption by showing that, in the Algebraic Isogeny Model, our assumption reduces to well-known assumptions from the literature.

As a bonus feature, our identity-based encryption enjoys anonymity, which means that the ciphertexts hide not only the message but also the target identity. We additionally obtain the first isogeny based constructions of laconic oblivious transfer, as well as public-key encryption that simultaneously satisfies security against high-rate key leakage and key-dependent message/circular security from the CDHwMT assumption. All our constructions can be conjectured to be post-quantum secure.

At the heart of our results lie several new techniques, which we believe will help in building even more advanced cryptography in isogeny-land.
Image showing part 2 of abstract.
022
Reposted by @kutasp89.bsky.social
Krijn Reijnders @krijn.isogeni.es · 16/07/2026
Excited about isogenies? Wanna claim some rewards? Solve one of the seven Isogeny Problems, the hardest open problems in isogeny-based cryptography! Full write-up now on ePrint: ia.cr/2026/1431 Webpage: isogeni.es/problems Now with EVEN MORE REWARDS!!
isogeni.es
The Isogeny Problems
A list of foremost unsolved problems in isogeny-based cryptography, with expositions by leading experts.
1105
Reposted by @kutasp89.bsky.social
Damien Robert @damienrobert.bsky.social · 05/07/2026
It's been a while since I last posted about MIKE, but a lot of exciting stuff happened meanwhile. MIKE is described in more details in this 4 part thread: - CSIDH bsky.app/profile/dami... - SIDH bsky.app/profile/dami... - MIKE bsky.app/profile/dami... - Speculations: bsky.app/profile/dami...
1104
Reposted by @kutasp89.bsky.social
Nils Fleischhacker @cryptomaeher.bsky.social · 02/07/2026
I'm looking for a job! I'm an experienced researcher in cryptography. My focus is on the transition to post-quantum cryptographic protocols and protocols related to blockains. If that sounds like someone you might want to hire or you know someone who might, let's talk!
11412
Reposted by @kutasp89.bsky.social
Andrea Basso @andreavbasso.bsky.social · 21/05/2026
New paper out 🎉 We introduce a new UPKE based on FESTA that supports unbounded updates and whose security is equivalent to FESTA! Our main result: a (four-dimensional) variant of FESTA has uniformly random public keys, which means that any random walk is a valid pk update.
062
Reposted by @kutasp89.bsky.social
Andrea Basso @andreavbasso.bsky.social · 14/05/2026
Round 3 of the NIST additional signatures process announced! 🎉 And SQIsign is part of it!! ⛷️⛷️
Screenshot of email announcement saying:

Nine Candidates Advance to the Third Round of the Additional Digital Signatures for the PQC Standardization Process

 After 18 months of evaluation, NIST has selected nine candidates for the third round of the Additional Digital Signatures for the Post-Quantum Cryptography (PQC) Standardization Process. The advancing digital signature algorithms are:

FAEST
HAWK
MAYO
MQOM
QR-UOV
SDitH
SNOVA
SQIsign
UOV
02613
Reposted by @kutasp89.bsky.social
Luca De Feo @bsky.defeo.lu · 12/04/2026
Looking forward to AM-PQC 2026, the Workshop on Algebraic Methods in Post-Quantum Cryptography this August in Macedonia! pqcrypto.cs.ru.nl/ampqc/ Stipends for students are available. Apply before May 4th!
pqcrypto.cs.ru.nl
Workshop on Algebraic Methods in Post-Quantum Cryptography 2026
084
Reposted by @kutasp89.bsky.social
Krijn Reijnders @krijn.isogeni.es · 13/03/2026
Thomas and I looked at directed isogeny graphs! In dim 1, we often ignore directedness, as there are only 2 "problematic" curves. Not so in dim 2: we analyze the action of automorphisms on level structures and the resulting directed graphs. Crucial: Directed (2,2)-graphs looks Ramanujan after all!
184
Reposted by @kutasp89.bsky.social
ePrint Updates @eprint.ing.bot · 07/03/2026
The principal ideal problem for endomorphism rings of superspecial abelian varieties (Wouter Castryck, Jonathan Komada Eriksen, Riccardo Invernizzi, Frederik Vercauteren) ia.cr/2026/454
Abstract. We describe a Las Vegas algorithm for the principal ideal problem in matrix rings M_(g)(O) for g ≥ 2, over maximal orders O in the rational quaternion algebra B_(p, ∞) ramified at ∞ and a prime number p. Under plausible heuristic assumptions, the method has expected polynomial runtime. An implementation in SageMath shows that it runs very efficiently in practice, with compact output. Our main auxiliary result is a method for finding endomorphisms of superspecial abelian varieties (i.e., powers of supersingular elliptic curves) with a prescribed kernel.
053
Reposted by @kutasp89.bsky.social
Maria Corte-Real Santos @maria.isogeny.club · 06/03/2026
New PRISM improvements 🥳 We extended our PRISM paper to present two new variants: one that achieves strong unforgeability, and another that allows for smaller parameters and therefore faster signatures! eprint.iacr.org/2026/443.pdf
eprint.iacr.org
195
Reposted by @kutasp89.bsky.social
Tjerand Silde @tjesi.bsky.social · 05/02/2026
I am co-organising (with @drl3c7er.bsky.social and Lucjan Hanzlik) a workshop on Privacy-Enhancing Cryptography in Rome on May 10 as an affiliated event to IACR Eurocrypt. Submit your best PEC-work (3-page extended abstract) for presentation by February 25th: privcryptworkshop.github.io
privcryptworkshop.github.io
PrivCrypt 2026
1119
Reposted by @kutasp89.bsky.social
Tanja Lange @hyperelliptic.bsky.social · 14/01/2026
Bit of a last-minute announcement: school on isogenies 9 - 13 Feb at Okinawa Institute of Science and Technology (OIST) groups.oist.jp/tsvp/event/s... Registration deadline is tomorrow (15 Jan).
groups.oist.jp
School: Introduction to Isogeny-based Cryptography (TSVP-TP25IC)
Title: "Introduction to Isogeny-based Cryptography" Abstract: Isogeny-based cryptography is a fast-moving field, and recent developments have introduced several new techniques, making the barrier of e...
025
Reposted by @kutasp89.bsky.social
ePrint Updates @eprint.ing.bot · 02/01/2026
The Cokernel Pairing (Krijn Reijnders) ia.cr/2026/001
Abstract. We study a new pairing, beyond the Weil and Tate pairing. The Weil pairing is a non-degenerate pairing E[m] × E[m] → μ_(m), which operates on the kernel of [m]. Similarly, when μ_(m) ⊆ 𝔽_(q)^(*), the Tate pairing is a non-degenerate pairing E[m](𝔽_(q)) × E(𝔽_(q))/[m]E(𝔽_(q)) → μ_(m), which connects the kernel and the rational cokernel of [m]. We define a pairing
⟨  ⟩_(m) : E(𝔽_(q))/[m]E(𝔽_(q)) × E(𝔽_(q))/[m]E(𝔽_(q)) → μ_(m)
on the rational cokernels of [m], filling the gap left by the Weil and Tate pairing. When E[m] ⊆ E(𝔽_(q)), this pairing is non-degenerate, and can be computed using three Tate pairings, and two discrete logarithms in μ_(m), assuming a basis for E[m]. For m = ℓ prime, this pairing allows us to study E(𝔽_(q))/[ℓ]E(𝔽_(q)) directly and to simplify the computation for a basis of E[ℓ^(k)], and more generally the Sylow ℓ-torsion. This finds natural applications in isogeny-based cryptography when computing ℓ^(k)-isogenies.
043
kutasp89.bsky.social @kutasp89.bsky.social · 29/11/2025
scottaaronson.blog?p=9344 I think this is an incredibly insightful blogpost, I highly recommend reading it, especially the last paragraph.
scottaaronson.blog
Quantum Investment Bros: Have you no shame?
Near the end of my last post, I made a little offhand remark: [G]iven the current staggering rate of hardware progress, I now think it’s a live possibility that we’ll have a fault-tolerant quantum …
010
Reposted by @kutasp89.bsky.social
mccurley.bsky.social @mccurley.bsky.social · 15/11/2025
While I can understand how some reviewers in cryptography research are frustrated with the process, I cannot imagine how bad it is in machine learning. ncfrey.substack.com/p/publishing...
ncfrey.substack.com
Publishing and communicating research in AI/ML is fundamentally broken
Why researchers should care, and four proposals for how to fix it
022
Reposted by @kutasp89.bsky.social
Tibor Jager @tiborj.bsky.social · 25/09/2025
The call for papers for PKC 2026 is out: pkc.iacr.org/2026/callfor...
pkc.iacr.org
PKC 2026 call for papers
Public Key Cryptography
0810
Reposted by @kutasp89.bsky.social
ePrint Updates @eprint.ing.bot · 22/09/2025
Bribers, Bribers on The Chain, Is Resisting All in Vain? Trustless Consensus Manipulation Through Bribing Contracts (Bence Soóki-Tóth, István András Seres, Kamilla Kara, Ábel Nagy, Balázs Pejó, Gergely Biczók) ia.cr/2025/1719
Abstract. The long-term success of cryptocurrencies largely depends on the incentive compatibility provided to the validators. Bribery attacks, facilitated trustlessly via smart contracts, threaten this foundation. This work introduces, implements, and evaluates three novel and efficient bribery contracts targeting Ethereum validators. The first bribery contract enables a briber to fork the blockchain by buying votes on their proposed blocks. The second contract incentivizes validators to voluntarily exit the consensus protocol, thus increasing the adversary’s relative staking power. The third contract builds a trustless bribery market that enables the briber to auction off their manipulative power over the RANDAO, Ethereum’s distributed randomness beacon. Finally, we provide an initial game-theoretical analysis of one of the described bribery markets.
011
Reposted by @kutasp89.bsky.social
Maria Corte-Real Santos @maria.isogeny.club · 12/09/2025
TL;DR: we solve norm equations in a better way and get around a 2x improvement to IdealToIsogeny routines crucial in both SQIsign and PRISM.
2125
Reposted by @kutasp89.bsky.social
ePrint Updates @eprint.ing.bot · 11/09/2025
Qlapoti: Simple and Efficient Translation of Quaternion Ideals to Isogenies (Giacomo Borin, Maria Corte-Real Santos, Jonathan Komada Eriksen, Riccardo Invernizzi, Marzio Mula, Sina Schaeffler, Frederik Vercauteren) ia.cr/2025/1604
Abstract. The main building block in isogeny-based cryptography is an algorithmic version of the Deuring correspondence, called IdealToIsogeny. This algorithm takes as input left ideals of the endomorphism ring of a supersingular elliptic curve and computes the associated isogeny. Building on ideas from QFESTA, the Clapoti framework by Page and Robert reduces this problem to solving a certain norm equation. The current state of the art is however unable to efficiently solve this equation, and resorts to a relaxed version of it instead. This impacts not only the efficiency of the IdealToIsogeny procedure, but also its success probability. The latter issue has to be mitigated with complex and memory-heavy rerandomization procedures, but still leaves a gap between the security analysis and the actual implementation of cryptographic schemes employing IdealToIsogeny as a subroutine. For instance, in SQIsign the failure probability is still 2⁻⁶⁰ which is not cryptographically negligible.

The main contribution of this paper is a very simple and efficient algorithm called Qlapoti which approaches the norm equation from Clapoti directly, solving all the aforementioned problems at once. First, it makes the IdealToIsogeny subroutine between 2.2 and 2.6 times faster. This signigicantly improves the speed of schemes using this subroutine, including notably SQIsign and . On top of that, Qlapoti has a cryptographically negligible failure probability. This eliminates the need for rerandomization, drastically reducing memory consumption, and allows for cleaner security reductions.
Image showing part 2 of abstract.
064
kutasp89.bsky.social @kutasp89.bsky.social · 03/09/2025
Can someone provide me with an explanation how TCHES ended up on some Norwegian list for predatory journals?
110
Reposted by @kutasp89.bsky.social
COSIC @cosic.bsky.social · 21/08/2025
Proud moment at #CRYPTO 2025! “KLPT²: Algebraic Pathfinding in Dimension Two and Applications” received the Best Paper Award. 🏆 Co-authored by COSIC’s Wouter Castryck & Thomas Decru (presenter). Read it here: eprint.iacr.org/2025/372
073
kutasp89.bsky.social @kutasp89.bsky.social · 31/07/2025
Very sad news
010
Reposted by @kutasp89.bsky.social
Janne Hämäläinen @janne.hamalainen.social · 06/07/2025
This exactly. And it's not just theoretical, it can happen for real. "The Chinese state-sponsored cyberattack threat managed to infiltrate the "lawful intercept" network connections that police use in criminal investigations." www.darkreading.com/cyber-risk/s...
darkreading.com
Sat Typhoon APT Subverts Law Enforcement Wiretapping
The Chinese state-sponsored cyberattack threat managed to infiltrate the "lawful intercept" network connections that police use in criminal investigations.
092
Reposted by @kutasp89.bsky.social
Krijn Reijnders @krijn.isogeni.es · 16/06/2025
Yessss!!!
041
Reposted by @kutasp89.bsky.social
David Picard @davidpicard.eurosky.social · 06/06/2025
Reminder that the MSCA postdoctoral program exists. If you have a PhD and want to work in a European lab, you have until September to apply. Just contact them now. ec.europa.eu/info/funding...
ec.europa.eu
03024
Reposted by @kutasp89.bsky.social
ePrint Updates @eprint.ing.bot · 05/06/2025
Orient Express: Using Frobenius to Express Oriented Isogenies (Wouter Castryck, Riccardo Invernizzi, Gioella Lorenzon, Jonas Meers, Frederik Vercauteren) ia.cr/2025/1047
Abstract. In this paper we study supersingular elliptic curves primitively oriented by an imaginary quadratic order, where the orientation is determined by an endomorphism that factors through the Frobenius isogeny. In this way, we partly recycle one of the main features of CSIDH, namely the fact that the Frobenius orientation can be represented for free. This leads to the most efficient family of ideal-class group actions in a range where the discriminant is significantly larger than the field characteristic p. Moreover, if we orient with a non-maximal order $\mathcal{O} \subset \mathbb{Q}(\sqrt{-p})$ and we assume that it is feasible to compute the ideal-class group of the maximal order, then also the ideal-class group of 𝒪 is known and we recover the central feature of SCALLOP-like constructions.

We propose two variants of our scheme. In the first one, the orientation is by a suborder of the form $\mathbb{Z}[f\sqrt{-p}]$ for some f coprime to p, so this is similar to SCALLOP. In the second one, inspired by the work of Chenu and Smith, the orientation is by an order of the form $\mathbb{Z}[\sqrt{-dp}]$ where d is square-free and not a multiple of p. We give practical ways of generating parameters, together with a proof-of-concept SageMath implementation of both variants, which shows the effectiveness of our construction.
Image showing part 2 of abstract.
053
Reposted by @kutasp89.bsky.social
Andrea Basso @andreavbasso.bsky.social · 17/05/2025
Next week @lucianomaino.bsky.social and I will teach a week-long course on SQIsign at the University of Trento. The course will be both in-person and online: if you're interested, you can tune in Monday morning at 10:30 at unitn.zoom.us/j/88902079708 (details and full schedule in the image below)
Title of the PhD course: Advances in Cryptography and Codes - Part 1: SQIsign

Lecturers: Andrea Basso (IBM Research Zurich, CH),
Luciano Maino (University of Bristol, UK)

The course in short: The course offers a comprehensive and rigorous introduction
to SQIsign, an advanced isogeny-based digital signature scheme designed to resist
attacks from quantum computers. The course will present the mathematical
foundations on which SQIsign is based and the algorithmic background necessary to
understand and evaluate the security of SQIsign and other isogeny-based protocols.
Complementing the theoretical material, the course also includes a practical
laboratory where students will use SageMath to study and implement various
aspects of SQIsign.

Where (in presence): Department of Mathematics, University of Trento (IT)
Via Sommarive, 5, 38123, Trento
(online): https://unitn.zoom.us/j/88902079708 (Passcode: 532383)
When: From May 19, 2025 to May 28, 2025

Detailed Program:
Monday 19/05 10:30 - 12:30 (Room A205) & 14:30 - 16:30 (Room A221)
Tuesday 20/05 10:30 - 12:30 (Room A215) & 14:30 - 16:30 (Room A213)
Wednesday 21/05 10:30 - 12:30 (Room A218) & 14:30 - 16:30 (Room A215)
Thursday 22/05 10:30 - 12:30 (Room A209) & 14:30 - 16:30 (Room A220)
Friday 23/05 10:30 - 12:30 (Room A215) & 14:30 - 16:30 (Room A215)
Tuesday 27/05 11:30 - 12:30 – Q&A, optional (Room A218)
Wednesday 28/05 11:30 - 12:30 – Q&A, optional (Room A218)
1188
kutasp89.bsky.social @kutasp89.bsky.social · 10/05/2025
CECC 2025 will accept posters, submission deadline is the 23rd May (more details can be found at cecc2025.inf.elte.hu). Also we have great invited speakers (Carla Rafols, Thomas Decru, Stefan Dziembowski), so hope to see you in Budapest!
cecc2025.inf.elte.hu
Central European Conference on Cryptology 2025
Central European Conference on Cryptology 2025
031
Reposted by @kutasp89.bsky.social
Martin R. Albrecht @malb.bsky.social · 08/05/2025
This is cool heimberger.xyz/oprfs.html
heimberger.xyz
PQ-OPRF table
0136
Reposted by @kutasp89.bsky.social
Luca De Feo @bsky.defeo.lu · 25/04/2025
The SQIparty starts on Monday, but it's still time to register! We prepared an exciting program for you with a balanced mix of talks, coding sprints, skillshares and other activities! www.cig.udl.cat/SQIparty2025... See you in Lleida!
299
Reposted by @kutasp89.bsky.social
Krijn Reijnders @krijn.isogeni.es · 15/04/2025
New work: we explain cubical arithmetic in simple terms to show you how easy it is to compute pairings. Essentially, you only need to know the Montgomery ladder! As a bonus, pairings from cubical arithmetic are faster than those from Miller's loop for applications in isogeny-based cryptography.
1169
Reposted by @kutasp89.bsky.social
Maria Corte-Real Santos @maria.isogeny.club · 03/04/2025
Really excited to share the Decrypting Diversity Summit happening in Montpellier, France from 17-20 June! The goal of the summit is to promote diversity, inclusivity, and gender equality within the cryptography community. For more info: decryptingdiversity.com
decryptingdiversity.com
Decrypting Diversity Summit
Decrypting Diversity Summit
196
kutasp89.bsky.social @kutasp89.bsky.social · 31/03/2025
Deadline to submit to this conference is today!
021
Reposted by @kutasp89.bsky.social
Real World Crypto Symposium @rwc.iacr.org · 26/03/2025
The second Levchin Prize goes to the CADO-NFS team: Emmanuel Thomé, Pierrick Gaudry, and Paul Zimmerman! Congratulations! #realworldcrypto
0175
Reposted by @kutasp89.bsky.social
Andrea Basso @andreavbasso.bsky.social · 24/03/2025
Registration is now open! www.cig.udl.cat/SQIparty2025...
034
Reposted by @kutasp89.bsky.social
Luca De Feo @bsky.defeo.lu · 13/03/2025
Fancy some isogeny crypto? Join us for a 3-day workshop on isogeny-based cryptography in Lleida, Catalonia, April 28-30 www.cig.udl.cat/icrypto2025_... Brought to you by ULleida's Cryptography+Graphs group, the SQIsign team and friends! Registration and program coming soon Registration is free!
Cathedral of La Seu Vella in Lleida
289
Reposted by @kutasp89.bsky.social
Maria Corte-Real Santos @maria.isogeny.club · 06/03/2025
Next week (Tuesday 5pm CET) at The Isogeny Club we'll have Laurane Marco (EPFL) who will talk to us about computing modular polynomials modulo a generic prime! More details at isogeny.club
isogeny.club
The Isogeny Club
094
Reposted by @kutasp89.bsky.social
ePrint Updates @eprint.ing.bot · 05/03/2025
On the Soundness of Algebraic Attacks against Code-based Assumptions (Miguel Cueto Noval, Simon-Philipp Merz, Patrick Stählin, Akin Ünal) ia.cr/2025/415
Abstract. We study recent algebraic attacks (Briaud-Øygarden EC’23) on the Regular Syndrome Decoding (RSD) problem and the assumptions underlying the correctness of their attacks’ complexity estimates. By relating these assumptions to interesting algebraic-combinatorial problems, we prove that they do not hold in full generality. However, we show that they are (asymptotically) true for most parameter sets, supporting the soundness of algebraic attacks on RSD. Further, we prove—without any heuristics or assumptions—that RSD can be broken in polynomial time whenever the number of error blocks times the square of the size of error blocks is larger than 2 times the square of the dimension of the code.

Additionally, we use our methodology to attack a variant of the Learning With Errors problem where each error term lies in a fixed set of constant size. We prove that this problem can be broken in polynomial time, given a sufficient number of samples. This result improves on the seminal work by Arora and Ge (ICALP’11), as the attack’s time complexity is independent of the LWE modulus.
Image showing part 2 of abstract.
011
Reposted by @kutasp89.bsky.social
Boris Fouotsa @borisfouotsa.bsky.social · 03/03/2025
16th International Conference on Cryptology AFRICACRYPT 2025 July 21-23, 2025 – Rabat, Morocco 🇲🇦 Extended submission deadline in 1 week: africacrypt2025.sciencesconf.org Submit your best results ! See you in Rabat 🇲🇦 in July 2025.
africacrypt2025.sciencesconf.org
16th International Conference on Cryptology, Africacrypt 2025 - Sciencesconf.org
Africacrypt 2025 is organized by the ENSIAS College of Mohammed V University in Rabat with partnership of the General Directorate of Information Systems Security (DGSSI), Morocco.
186
Reposted by @kutasp89.bsky.social
ePrint Updates @eprint.ing.bot · 04/03/2025
PEGASIS: Practical Effective Class Group Action using 4-Dimensional Isogenies (Pierrick Dartois, Jonathan Komada Eriksen, Tako Boris Fouotsa, Arthur Herlédan Le Merdy, Riccardo Invernizzi, Damien Robert, Ryan Rueger, Frederik Vercauteren, Benjamin Wesolowski) ia.cr/2025/401
Abstract. In this paper, we present the first practical algorithm to compute an effective group action of the class group of any imaginary quadratic order 𝒪 on a set of supersingular elliptic curves primitively oriented by 𝒪. Effective means that we can act with any element of the class group directly, and are not restricted to acting by products of ideals of small norm, as for instance in CSIDH. Such restricted effective group actions often hamper cryptographic constructions, e.g. in signature or MPC protocols.

Our algorithm is a refinement of the Clapoti approach by Page and Robert, and uses 4-dimensional isogenies. As such, it runs in polynomial time, does not require the computation of the structure of the class group, nor expensive lattice reductions, and our refinements allows it to be instantiated with the orientation given by the Frobenius endomorphism. This makes the algorithm practical even at security levels as high as CSIDH-4096. Our implementation in SageMath takes 1.5s to compute a group action at the CSIDH-512 security level, 21s at CSIDH-2048 level and around 2 minutes at the CSIDH-4096 level. This marks the first instantiation of an effective cryptographic group action at such high security levels. For comparison, the recent KLaPoTi approach requires around 200s at the CSIDH-512 level in SageMath and 2.5s in Rust.
Image showing part 2 of abstract.
0136
Reposted by @kutasp89.bsky.social
Andrea Basso @andreavbasso.bsky.social · 04/03/2025
As part of the round-2 NIST submission, we developed a complete proof of security of SQIsign!
1105
kutasp89.bsky.social @kutasp89.bsky.social · 04/03/2025
Happy to share this work with Paul Frixons, Valerie Gilchrist, Simon-Philipp Merz and Christophe Petit. We show that you have to be careful with new assumptions for cryptographic group actions. Namely for the CSI-SHARK assumption one can significantly beat Kuperberg using Childs-Van Dam
042
kutasp89.bsky.social @kutasp89.bsky.social · 04/03/2025
Excited to share this work on 2-dimensional KLPT which is joint work with Wouter Castryck, Thomas Decru, Abel Laval, Christophe Petit and Yan Bo Ti. This could pave the way for a 2-dimensional SQIsign and potentially other applications.
053