New Algorithms for the Deuring Correspondence - Towards Practical and Secure SQISign Signatures
Luca De Feo, Antonin Leroux, Patrick Longa, Benjamin Wesolowski
摘要
The Deuring correspondence defines a bijection between isogenies of supersingular elliptic curves and ideals of maximal orders in a quaternion algebra. We present a new algorithm to translate ideals of prime-power norm to their corresponding isogenies --- a central task of the effective Deuring correspondence. The new method improves upon the algorithm introduced in 2021 by De Feo, Kohel, Leroux, Petit and Wesolowski as a building-block of the SQISign signature scheme. SQISign is the most compact post-quantum signature scheme currently known, but is several orders of magnitude slower than competitors, the main bottleneck of the computation being the ideal-to-isogeny translation. We implement the new algorithm and apply it to SQISign, achieving a more than two-fold speedup in key generation and signing with a new choice of parameter. Moreover, after adapting the state-of-the-art multiplication algorithms by Longa to implement SQISign's underlying extension field arithmetic and adding various improvements, we push the total speedups to over three times for signing and four times for verification.
In a second part of the article, we advance cryptanalysis by showing a very simple distinguisher against one of the assumptions used in SQISign. We present a way to impede the distinguisher through a few changes to the generic KLPT algorithm. We formulate a new assumption capturing these changes, and provide an analysis together with experimental evidence for its validity.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- AprèsSQI: Extra Fast Verification for SQIsign Using Extension-Field SigningMaria Corte-Real Santos, Jonathan Komada Eriksen, Michael Meyer, Krijn ReijndersEUROCRYPT 2024 · 被引用 23 次
- Verifiable Random Function from the Deuring Correspondence and Higher Dimensional IsogeniesAntonin LerouxEUROCRYPT 2025 · 被引用 13 次
- A Complete Security Proof of SQIsignMarius A. Aardal, Andrea Basso, Luca De Feo, Sikhar Patranabis 等CRYPTO 2025 · 被引用 11 次
- sfqt-sfPegasis: Simpler and Faster Effective Class Group ActionsPierrick Dartois, Jonathan Komada Eriksen, Riccardo Invernizzi, Frederik VercauterenEUROCRYPT 2026 · 被引用 2 次
- The SQInstructor: a Guide to SQIsign and the Deuring Correspondence with Level StructuresGiacomo Borin, Luca De Feo, Guido Maria Lido, Sina SchaefflerCRYPTO 2026
它引用的顶会 Paper4
- Breaking SIDH in Polynomial TimeDamien RobertEUROCRYPT 2023 · 被引用 158 次
- The supersingular isogeny path and endomorphism ring problems are equivalentBenjamin WesolowskiFOCS 2021 · 被引用 61 次
- Orientations and the Supersingular Endomorphism Ring ProblemBenjamin WesolowskiEUROCRYPT 2022 · 被引用 34 次
- Sieving for Twin Smooth Integers with Solutions to the Prouhet-Tarry-Escott ProblemCraig Costello, Michael Meyer, Michael NaehrigEUROCRYPT 2021 · 被引用 16 次
相关 Paper
- SQIsignHD: New Dimensions in CryptographyPierrick Dartois, Antonin Leroux, Damien Robert, Benjamin WesolowskiEUROCRYPT 2024 · 被引用 69 次
- SQIsign2DPush: Faster Signature Scheme Using 2-Dimensional IsogeniesKohei Nakagawa, Hiroshi OnukiEUROCRYPT 2026 · 被引用 3 次
- WaterSQI and PRISMO: Quaternion Signatures for Supersingular Isogeny Group ActionsTako Boris FouotsaEUROCRYPT 2026 · 被引用 1 次
- Computing the Endomorphism Ring of a Supersingular Elliptic Curve from a Full Rank SuborderMingjie Chen, Christophe PetitEUROCRYPT 2025 · 被引用 2 次
- Improved Algorithms for Finding Fixed-Degree Isogenies Between Supersingular Elliptic CurvesBenjamin Bencina, Péter Kutas, Simon-Philipp Merz, Christophe Petit 等CRYPTO 2024 · 被引用 3 次
