










Giacomo Borin, IBM Research - Zurich
Maria Corte-Real Santos, École Normale Supérieure de Lyon
Riccardo Invernizzi, KU Leuven
Antonin Leroux, Direction Générale de l'Armement
Luciano Maino, University of Birmingham
Frederik Vercauteren, KU Leuven
Benjamin Wesolowski, École Normale Supérieure de Lyon
The problem of computing an isogeny of large prime degree from a supersingular elliptic curve of unknown endomorphism ring is assumed to be hard both for classical as well as quantum computers. In this work, we first build a two-round identification protocol whose security reduces to this problem. The challenge consists of a random large prime $q$ and the prover simply replies with an efficient representation of an isogeny of degree $q$ from its public key. Using the hash-and-sign paradigm, we then derive a signature scheme with a very simple and flexible signing procedure and prove its security in the standard model. The most efficient variant of our signature schemes features a signing which is $1.4\times$ to $1.6\times$ faster than the most recent implementaion of SQIsign, whereas verification ranges from $1.2\times$ slower to $1.01\times$ faster depending on the security level. The sizes of public key and signature are comparable to existing schemes.
BibTeX
@misc{cryptoeprint:2026/443,
author = {Andrea Basso and Giacomo Borin and Wouter Castryck and Maria Corte-Real Santos and Riccardo Invernizzi and Antonin Leroux and Luciano Maino and Frederik Vercauteren and Benjamin Wesolowski},
title = {{PRISM} with a pinch of salt: Simple, Efficient and Strongly Unforgeable Signatures from Isogenies},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/443},
year = {2026},
url = {https://eprint.iacr.org/2026/443}
}
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。