CSI -Otter: Isogeny-Based (Partially) Blind Signatures from the Class Group Action with a Twist
Shuichi Katsumata, Yi-Fu Lai, Jason T. LeGrow, Ling Qin
摘要
Abstract In this paper, we construct the first provably-secure isogeny-based (partially) blind signature scheme. While at a high level the scheme resembles the Schnorr blind signature, our work does not directly follow from that construction, since isogenies do not offer as rich an algebraic structure. Specifically, our protocol does not fit into thelinear identification protocolabstraction introduced by Hauck, Kiltz, and Loss (EUROCYRPT’19), which was used to generically construct Schnorr-like blind signatures based on modules such as classical groups and lattices. Consequently, our scheme is provably secure in the random oracle model (ROM) against poly-logarithmically-many concurrent sessions assuming the subexponential hardness of the group action inverse problem. In more detail, our blind signature exploits thequadratic twistof an elliptic curve in an essential way to endow isogenies with a strictly richer structure than abstract group actions (but still more restrictive than modules). The basic scheme has public key size 128 B and signature size 8 KB under the CSIDH-512 parameter sets—these are the smallest among all provably secure post-quantum secure blind signatures. Relying on a newringvariant of the group action inverse problem ( rGAIP ), we can halve the signature size to 4 KB while increasing the public key size to 512 B. We provide preliminary cryptanalysis of rGAIP and show that for certain parameter settings, it is essentially as secure as the standard GAIP . Finally, we show a novel way to turn our blind signature into a partially blind signature, where we deviate from prior methods since they require hashing into the set of public keys while hiding the corresponding secret key—constructing such a hash function in the isogeny setting remains an open problem.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Pairing-Free Blind Signatures from Standard Assumptions in the ROMJulia Kastner, Ky Nguyen, Michael ReichleCRYPTO 2024 · 被引用 11 次
- Another Look at the Quantum Security of the Vectorization Problem with Shifted InputsPaul Frixons, Valerie Gilchrist, Péter Kutas, Simon-Philipp Merz 等EUROCRYPT 2026
它引用的顶会 Paper14
- An Efficient Key Recovery Attack on SIDHWouter Castryck, Thomas DecruEUROCRYPT 2023 · 被引用 284 次
- Breaking SIDH in Polynomial TimeDamien RobertEUROCRYPT 2023 · 被引用 158 次
- A Direct Key Recovery Attack on SIDHLuciano Maino, Chloe Martindale, Lorenz Panny, Giacomo Pope 等EUROCRYPT 2023 · 被引用 136 次
- He Gives C-Sieves on the CSIDHChris PeikertEUROCRYPT 2020 · 被引用 120 次
- Quantum Security Analysis of CSIDHXavier Bonnetain, André SchrottenloherEUROCRYPT 2020 · 被引用 103 次
相关 Paper
- Group Signatures and More from Isogenies and Lattices: Generic, Simple, and EfficientWard Beullens, Samuel Dobson, Shuichi Katsumata, Yi-Fu Lai 等EUROCRYPT 2022 · 被引用 51 次
- Post-Quantum Blind Signature from Standard Group Action Assumptions and MoreLucjan Hanzlik, Yi-Fu Lai, Eugenio Paracucchi, Edoardo PersichettiEUROCRYPT 2026 · 被引用 1 次
- One-Way Functions and Malleability Oracles: Hidden Shift Attacks on Isogeny-Based ProtocolsPéter Kutas, Simon-Philipp Merz, Christophe Petit, Charlotte WeitkämperEUROCRYPT 2021 · 被引用 15 次
- Orientations and the Supersingular Endomorphism Ring ProblemBenjamin WesolowskiEUROCRYPT 2022 · 被引用 34 次
- Practical, Round-Optimal Lattice-Based Blind SignaturesShweta Agrawal, Elena Kirshanova, Damien Stehlé, Anshu YadavCCS 2022 · 被引用 52 次
