Luca De Feo, Nadia El Mrabet, et al.
IACR Transactions on Cryptographic Hardware and Embedded Systems
The problem of computing an isogeny of large prime degree from a supersingular elliptic curve of unknown endomorphism ring is assumed to be hard both for classical as well as quantum computers. In this work, we first build a two-round identification protocol whose security reduces to this problem. The challenge consists of a random large prime~ and the prover simply replies with an efficient representation of an isogeny of degree from its public key. Using the hash-and-sign paradigm, we then derive a signature scheme with a very simple and flexible signing procedure and prove its security in the standard model. Our optimized C implementation of the signature scheme shows that signing is roughly faster than all SQIsign variants, whereas verification is times slower. The sizes of the public key and signature are comparable to existing schemes.
Luca De Feo, Nadia El Mrabet, et al.
IACR Transactions on Cryptographic Hardware and Embedded Systems
Manoj Kumar, Pratap Pattnaik
HPEC 2020
Varun Maram, Daniel Masny, et al.
IACR ToSC
Ward Beullens, Ming-Shing Chen, et al.
IACR Transactions on Cryptographic Hardware and Embedded Systems