A Complete Security Proof of SQIsign
Marius A. Aardal, Andrea Basso, Luca De Feo, Sikhar Patranabis, Benjamin Wesolowski
Abstract
. SQIsign is the leading digital signature from isogenies. Despite the many improvements that have appeared in the literature, all its recents variants lack a complete security proof. In this work, we provide the first full security proof of SQIsign, as submitted to the second round of NIST’s on-ramp track for digital signatures. To do so, we introduce a new framework, which we call Fiat–Shamir with hints, that captures all those protocols where the simulator needs additional information to simulate a transcript. Using this framework, we show that SQIsign is EUF-CMA secure in the ROM, assuming the hardness of the One Endomorphism problem with hints , or the hardness of the Full Endomorphism Ring problem with hints together with a hint indistinguishability assumption; all assumptions, unlike previous ones in the literature, are non-interactive. Along the way, we prove several intermediate results that may be of independent interest.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2e4d46a9-9740-4dc4-a623-3a196849bc7bCited by top-tier papers2
- sfqt-sfPegasis: Simpler and Faster Effective Class Group ActionsPierrick Dartois, Jonathan Komada Eriksen, Riccardo Invernizzi, Frederik VercauterenEUROCRYPT 2026 · 2 citations
- The SQInstructor: a Guide to SQIsign and the Deuring Correspondence with Level StructuresGiacomo Borin, Luca De Feo, Guido Maria Lido, Sina SchaefflerCRYPTO 2026
Builds on7
- A Compressed -Protocol Theory for LatticesThomas Attema, Ronald Cramer, Lisa KohlCRYPTO 2021 · 74 citations
- SQIsignHD: New Dimensions in CryptographyPierrick Dartois, Antonin Leroux, Damien Robert, Benjamin WesolowskiEUROCRYPT 2024 · 69 citations
- The supersingular isogeny path and endomorphism ring problems are equivalentBenjamin WesolowskiFOCS 2021 · 61 citations
- New Algorithms for the Deuring Correspondence - Towards Practical and Secure SQISign SignaturesLuca De Feo, Antonin Leroux, Patrick Longa, Benjamin WesolowskiEUROCRYPT 2023 · 46 citations
- Supersingular Curves You Can TrustAndrea Basso, Giulio Codogni, Deirdre Connolly, Luca De Feo et al.EUROCRYPT 2023 · 43 citations
Related papers
- Computing the Endomorphism Ring of a Supersingular Elliptic Curve from a Full Rank SuborderMingjie Chen, Christophe PetitEUROCRYPT 2025 · 2 citations
- The Supersingular Endomorphism Ring and One Endomorphism Problems are EquivalentAurel Page, Benjamin WesolowskiEUROCRYPT 2024 · 28 citations
- The Algebraic Isogeny Model: A General Model with Applications to SQIsign and Key ExchangesMarius A. Aardal, Andrea Basso, Doreen RiepelEUROCRYPT 2026 · 2 citations
- Exclusive Ownership of Fiat-Shamir Signatures: ML-DSA, SQIsign, LESS, and MoreMichael Meyer, Patrick Struck, Maximiliane WeishäuplCRYPTO 2025 · 1 citation
- Tighter Quantum Security for Fiat-Shamir-with-Aborts and Hash-and-Sign-with-Retry SignaturesPouria Fallahpour, Serge Fehr, Yu-Hsuan HuangCRYPTO 2026 · 3 citations
