Paper 2025/1853

Compact, Efficient and CCA-Secure Updatable Encryption from Isogenies

Antonin Leroux, Direction Générale de l'Armement, IRMAR
Maxime Roméas, ANSSI
Abstract

Updatable Encryption (UE) allows ciphertexts to be updated under new keys without decryption, enabling efficient key rotation. Constructing post-quantum UE with strong security guarantees is challenging: the only known CCA-secure scheme, COM-UE, uses bitwise encryption, resulting in large ciphertexts and high computational costs. We introduce $\mathsf{DINE}_\ell$, a family of compact and efficient CCA-secure isogeny-based post-quantum UE schemes parametrized by an integer $\ell$, achieving increasing security levels for $\ell = 3,4,8$. Each encryption, decryption, or update requires only a few power-of-2 isogeny computations in dimension 2. At NIST security level 1, $\mathsf{DINE}_\ell$ supports 28B messages, 480B ciphertexts, and $\ell\times336$B update tokens, significantly smaller than prior constructions. Our C implementation demonstrates practical performance, with updates in $\ell \times 15$ms, encryptions in 65ms, and decryptions in 155ms. Our design combines high-dimensional isogeny representations with the Deuring correspondence. We also introduce new algorithms for the Deuring correspondence which may be of independent interest. Moreover, the security of our scheme relies on new problems that might open interesting perspectives in isogeny-based cryptography.

Note: latest update, correct some errors in the security proof, takes into account the latest attacks against isogeny-based cryptography

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Updatable EncryptionIsogeniesDeuring CorrespondencePost-Quantum Cryptography
Contact author(s)
antonin leroux @ polytechnique org
maxime romeas @ ssi gouv fr
History
2026-09-22: last of 2 revisions
2025-10-07: received
See all versions
Short URL
https://ia.cr/2025/1853
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1853,
      author = {Antonin Leroux and Maxime Roméas},
      title = {Compact, Efficient and {CCA}-Secure Updatable Encryption from Isogenies},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1853},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1853}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.