Sign in

lucianomaino.bsky.social

@lucianomaino.bsky.social
35 followers 43 following 1 posts
PostsRepliesMedia
Reposted by @lucianomaino.bsky.social
spooky Deirdre Connolly¹ ² at a distance @durumcrustulum.com · 01/09/2026
SQIsign has been updated for Round 3 of the NIST PQC signatures on-ramp: - updated params re: eprint 2026/1486 - new full fixed-precision arithmetic with tight size bounds - no more floating point in lattice reduction - new ideal-to-isogeny, gluing algs, speedups sqisign.org/spec/sqisign...
1145
Reposted by @lucianomaino.bsky.social
IEEE European Symposium on Security and Privacy @ieeeeurosp.bsky.social · 07/07/2026
🎤 We're excited to welcome Sofía Celi as the first keynote speaker at IEEE EuroS&P 2026. "Cryptography we want, Cryptography we're given: lessons from analysing and breaking the systems we deploy" #EuroSP26 #IEEEEuroSP #KeynoteSpeakers @claucece.bsky.social
0102
Reposted by @lucianomaino.bsky.social
ePrint Updates @eprint.ing.bot · 08/06/2026
Isogeny-based Signatures with Randomizable Keys (Andrea Basso, Giacomo Borin, Maria Corte-Real Santos, Pierrick Dartois, Riccardo Invernizzi, Luciano Maino, Robi Pedersen, Michel Seck) ia.cr/2026/1169
Abstract. Digital signature schemes based on isogenies are among the most compact signatures achieving post-quantum security. Recent advances, especially those leveraging higher-dimensional isogenies, have also made such schemes practically efficient. However, comparatively little attention has been devoted to endowing these signatures with additional privacy-enhancing properties, such as the re-randomization of keys and the adaptation of signatures to new public keys. Although some results exist in the isogeny group action setting, these signatures suffer from a subexponential quantum attack which renders them rather inefficient.

In this work, we initiate the first systematic study of privacy-enhancing isogeny-based signatures outside the group-action framework. We base our exploration on the notion of signatures with randomizable keys developed by Celi et al. (FC’24), which aims to unify privacy notions related to key updatability and signature adaptation. In particular, we analyze which of their privacy notions can be achieved from the state-of-the-art signatures SQIsign, PRISM and the hash-and-sign signature scheme derived from the Deuring verifiable unpredictable function (DeuringVUF).

To this end, we naturally extend SQIsign to an SWRK scheme that allows key randomization, and enhance both PRISM and the DeuringVUF signature to additionally allow for message adaptation. We show that, due to the deterministic nature of the signatures, the DeuringVUF signature achieves perfect adaptability. We formally prove all three of our modifications achieve unlinkability against unbounded adversaries, and remain unforgeable under the same assumptions as the original schemes.
Image showing part 2 of abstract.
054
Reposted by @lucianomaino.bsky.social
ePrint Updates @eprint.ing.bot · 31/05/2026
Toward zkSNARK-assisted Isogeny-based Cryptography (Yi-Fu Lai, Luciano Maino) ia.cr/2026/1096
Abstract. Zero-knowledge proofs are a fundamental building block of modern privacy-preserving systems. In isogeny-based cryptography, existing zero-knowledge proof constructions are either limited to chains of small-degree isogenies or are quite inefficient. As a result, many relations used in recent cryptosystems lack support in generic proof systems.

In this work, we take a step toward making zkSNARKs practically usable for a broader set of isogeny relations beyond the classical isogeny path knowledge language. Leveraging optimized Vélu-style formulas, we provide an efficient R1CS encoding for 3^(m)- and 4^(n)-isogenies, along with their masked evaluations. We also present an R1CS for non-smooth isogenies of special degree q(2^(e) − q), where q is an odd integer, together with their evaluation. This latter encoding is based on the efficient formulas for (2, 2)-isogenies in the theta model.

Finally, we demonstrate several concrete applications of our tools. We present a compiler that removes the “one-more” evaluation assumption in the signature based on DeuringVRF. We also discuss how to eliminate the hint-based assumption in SQISign and explain how to construct a key-validation mechanism for recent public-key encryption designs, such as POKÉ on the concept level. We provide the experimental results with respect to the constraint numbers under various isogeny NIST-1 primes for reference. Under the setting, the proof sizes considered in this work are bounded by 400 KB by the default setting. We hope our results will inspire further advances in isogeny-based constructions.
Image showing part 2 of abstract.
032
Reposted by @lucianomaino.bsky.social
ePrint Updates @eprint.ing.bot · 24/05/2026
Pushforward Problems and Applications to Isogeny-based Cryptography (Luciano Maino, Christophe Petit) ia.cr/2026/1030
Abstract. Let E and E′ be two supersingular elliptic curves and let φ : E → E′ be an isogeny of known degree d. Given a basis (P, Q) of E[N] together with (φ(P), φ(Q)), it is possible to recover φ provided that N is sufficiently large and smooth, and that the torsion basis can be represented over a small extension of the base field.

In this work, we consider the more general setting where the N-torsion may not be efficiently representable. To address this setting, we introduce a new framework for encoding torsion information via an oracle that computes pushforwards of N-isogenies under φ. We then show that there exist instances for which access to the pushforward oracle allows for an efficient isogeny recovery.

Beyond their theoretical interest, these instances have direct cryptographic implications. We show a practical attack against the threshold signature scheme recently proposed by Kim, Kim, and Lee. We also identify weak instances for Basso’s oblivious pseudorandom function, and we refine the security discussion for Leroux and Roméas’s updatable encryption scheme.
Image showing part 2 of abstract.
011
Reposted by @lucianomaino.bsky.social
Sofia Celi @claucece.bsky.social · 14/05/2026
Go MAYO!! Moving to the third round of the PQC NIST process!
0115
Reposted by @lucianomaino.bsky.social
Andrea Basso @andreavbasso.bsky.social · 14/05/2026
Round 3 of the NIST additional signatures process announced! 🎉 And SQIsign is part of it!! ⛷️⛷️
Screenshot of email announcement saying:

Nine Candidates Advance to the Third Round of the Additional Digital Signatures for the PQC Standardization Process

 After 18 months of evaluation, NIST has selected nine candidates for the third round of the Additional Digital Signatures for the Post-Quantum Cryptography (PQC) Standardization Process. The advancing digital signature algorithms are:

FAEST
HAWK
MAYO
MQOM
QR-UOV
SDitH
SNOVA
SQIsign
UOV
02613
Reposted by @lucianomaino.bsky.social
Andrea Basso @andreavbasso.bsky.social · 10/06/2025
We (finally) published all the material from this course on SQIsign, including lecture slides and exercise sheets for the Sage laboratory. Available here: github.com/andreavico/S...
github.com
GitHub - andreavico/SQIsign_summer_school: Slides and worksheets for the introductory course on SQIsign held in Trento in May 2025
Slides and worksheets for the introductory course on SQIsign held in Trento in May 2025 - andreavico/SQIsign_summer_school
11616
Reposted by @lucianomaino.bsky.social
Andrea Basso @andreavbasso.bsky.social · 17/05/2025
Next week @lucianomaino.bsky.social and I will teach a week-long course on SQIsign at the University of Trento. The course will be both in-person and online: if you're interested, you can tune in Monday morning at 10:30 at unitn.zoom.us/j/88902079708 (details and full schedule in the image below)
Title of the PhD course: Advances in Cryptography and Codes - Part 1: SQIsign

Lecturers: Andrea Basso (IBM Research Zurich, CH),
Luciano Maino (University of Bristol, UK)

The course in short: The course offers a comprehensive and rigorous introduction
to SQIsign, an advanced isogeny-based digital signature scheme designed to resist
attacks from quantum computers. The course will present the mathematical
foundations on which SQIsign is based and the algorithmic background necessary to
understand and evaluate the security of SQIsign and other isogeny-based protocols.
Complementing the theoretical material, the course also includes a practical
laboratory where students will use SageMath to study and implement various
aspects of SQIsign.

Where (in presence): Department of Mathematics, University of Trento (IT)
Via Sommarive, 5, 38123, Trento
(online): https://unitn.zoom.us/j/88902079708 (Passcode: 532383)
When: From May 19, 2025 to May 28, 2025

Detailed Program:
Monday 19/05 10:30 - 12:30 (Room A205) & 14:30 - 16:30 (Room A221)
Tuesday 20/05 10:30 - 12:30 (Room A215) & 14:30 - 16:30 (Room A213)
Wednesday 21/05 10:30 - 12:30 (Room A218) & 14:30 - 16:30 (Room A215)
Thursday 22/05 10:30 - 12:30 (Room A209) & 14:30 - 16:30 (Room A220)
Friday 23/05 10:30 - 12:30 (Room A215) & 14:30 - 16:30 (Room A215)
Tuesday 27/05 11:30 - 12:30 – Q&A, optional (Room A218)
Wednesday 28/05 11:30 - 12:30 – Q&A, optional (Room A218)
1188
Reposted by @lucianomaino.bsky.social
Luca De Feo @bsky.defeo.lu · 13/03/2025
Fancy some isogeny crypto? Join us for a 3-day workshop on isogeny-based cryptography in Lleida, Catalonia, April 28-30 www.cig.udl.cat/icrypto2025_... Brought to you by ULleida's Cryptography+Graphs group, the SQIsign team and friends! Registration and program coming soon Registration is free!
Cathedral of La Seu Vella in Lleida
289