Another Look at the Quantum Security of the Vectorization Problem with Shifted Inputs
Paul Frixons, Valerie Gilchrist, Péter Kutas, Simon-Philipp Merz, Christophe Petit, Lam L. Pham
Abstract
. Cryptographic group actions provide a basis for simple post-quantum generalizations of many cryptographic protocols based on the discrete logarithm problem (DLP). However, many advanced group action-based protocols do not solely rely on the core group action problem (the so-called vectorization problem), but also on variants of this problem, to either improve efficiency or enable new functionalities. In particular, the security of the CSI-SharK threshold signature protocol relies on the hardness of the Vectorization Problem with Shifted Inputs where (in DLP formalism) the adversary not only receives g and g x , but also g x c for multiple known values of c . A natural open question is whether the extra data provided to the adversary in this variant allows them to solve the underlying problem more efficiently. In this paper, we revisit the concrete quantum security of this problem. We start from a quantum multiple hidden shift algorithm of Childs and van Dam, which to the best of our knowledge was never applied in cryptography before. We specify algorithms for its subroutines and we provide concrete complexity estimates for both these subroutines and the overall algorithm. We apply our analysis to the CSI-SharK protocol. In prior analyses based on Kuperberg’s algorithms, group action evaluations contributed to a significant part of the overall T-gate cost. For CSI-SharK suggested parameters, our new approach requires significantly fewer calls to the group action evaluation subroutine, leading to significant complexity improvements overall
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 67ddced6-a7c3-491a-8ecd-82c0ec6b2145Builds on7
- He Gives C-Sieves on the CSIDHChris PeikertEUROCRYPT 2020 · 120 citations
- Quantum Security Analysis of CSIDHXavier Bonnetain, André SchrottenloherEUROCRYPT 2020 · 103 citations
- Tower: data structures in Quantum superpositionCharles Yuan, Michael CarbinOOPSLA 2022 · 26 citations
- PEGASIS: Practical Effective Class Group Action using 4-Dimensional IsogeniesPierrick Dartois, Jonathan Komada Eriksen, Tako Boris Fouotsa, Arthur Herlédan Le Merdy et al.CRYPTO 2025 · 25 citations
- Finding Many Collisions via Reusable Quantum Walks - Application to Lattice SievingXavier Bonnetain, André Chailloux, André Schrottenloher, Yixin ShenEUROCRYPT 2023 · 22 citations
Related papers
- Quantum State Group ActionsSaachi Mutreja, Mark ZhandryCRYPTO 2025 · 2 citations
- CORAL Faster Isogeny Group Action for Post-Quantum NIKEAndrea Basso, Giacomo Borin, Ryan Rueger, Sina SchaefflerCRYPTO 2026 · 2 citations
- Post-Quantum Blind Signature from Standard Group Action Assumptions and MoreLucjan Hanzlik, Yi-Fu Lai, Eugenio Paracucchi, Edoardo PersichettiEUROCRYPT 2026 · 1 citation
- One-Way Functions and Malleability Oracles: Hidden Shift Attacks on Isogeny-Based ProtocolsPéter Kutas, Simon-Philipp Merz, Christophe Petit, Charlotte WeitkämperEUROCRYPT 2021 · 15 citations
- On the Quantum Complexity of the Continuous Hidden Subgroup ProblemKoen de Boer, Léo Ducas, Serge FehrEUROCRYPT 2020 · 7 citations
