Paper 2024/773
SQIPrime: A dimension 2 variant of SQISignHD with non-smooth challenge isogenies
Abstract
We introduce SQIPrime, a post-quantum digital signature scheme based on the Deuring correspondence and Kani's Lemma.
Compared to its predecessors that are SQISign and especially SQISignHD, SQIPrime further expands the use of high dimensional isogenies, already in use in the verification in SQISignHD, to all its subroutines.
In doing so, it no longer relies on smooth degree isogenies (of dimension 1). Intriguingly, this includes the challenge isogeny which is also a non-smooth degree isogeny, but has an accessible kernel. The fact that the isogenies do not have rational kernel allows to fit more rational power 2 torsion points which are necessary when computing and representing the response isogeny.
SQIPrime operates with prime numbers of the form
Note: Algorithm 3 revisited. Proof of concept implementation provided and timings added in Section 8.4
Metadata
- Available format(s)
- Category
- Public-key cryptography
- Publication info
- A minor revision of an IACR publication in ASIACRYPT 2024
- Keywords
- IsogeniesSQISignSQISignHDKani's LemmaSQIPrime
- Contact author(s)
-
max duparc @ epfl ch
tako fouotsa @ epfl ch - History
- 2024-10-13: last of 2 revisions
- 2024-05-20: received
- See all versions
- Short URL
- https://ia.cr/2024/773
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2024/773, author = {Max Duparc and Tako Boris Fouotsa}, title = {{SQIPrime}: A dimension 2 variant of {SQISignHD} with non-smooth challenge isogenies}, howpublished = {Cryptology {ePrint} Archive, Paper 2024/773}, year = {2024}, url = {https://eprint.iacr.org/2024/773} }