Paper 2025/376

Another Look at the Quantum Security of the Vectorization Problem with Shifted Inputs

Paul Frixons, Université Libre de Bruxelles
Valerie Gilchrist, Université Libre de Bruxelles
Péter Kutas, University of Birmingham, Eötvös Loránd University
Simon-Philipp Merz, ETH Zurich
Christophe Petit, Université Libre de Bruxelles, University of Birmingham
Lam L. Pham, Ghent University
Abstract

Cryptographic group actions provide a basis for simple post-quantum generalizations of many cryptographic protocols based on the discrete logarithm problem (DLP). However, many advanced group action-based protocols do not solely rely on the core group action problem (the so called vectorization problem), but also on variants of this problem, to either improve efficiency or enable new functionalities. For example, the security of the CSI-SharK threshold signature protocol relies on the hardness of the Vectorization Problem with Shifted Inputs where (in DLP formalism) the adversary not only receives g and g^x, but also g^(x^c) for multiple known values of c. A natural open question is whether the additional data allows adversaries to solve the underlying problem more efficiently. We revisit the concrete quantum security of this problem. We start from a quantum multiple hidden shift algorithm of Childs and van Dam, which to the best of our knowledge was never applied in cryptography before. We describe and analyze a variant of this algorithm, and we specify and analyze all its subroutines to provide concrete complexity estimates. We then apply our analysis to the CSI-SharK protocol. In prior analyses based on Kuperberg’s algorithms, group action evaluations contributed to a significant part of the overall T-gate cost. For CSI-SharK’s suggested parameters, our new approach requires significantly fewer calls to the group action evaluation subroutine, leading to significant complexity improvements overall. We describe two instances of our approach, one minimizing the T-gate complexity, and the other one keeping qubit requirements small, both of them resulting in significant complexity improvements over previous works. More generally, we quantify the quantum security degradation resulting from additional published data in the CSI-SharK protocol.

Note: Includes full proofs and appendices. Small changes made to probability of success proof in Section 3, and qubit counts in Table 1. Publication info updated.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
A major revision of an IACR publication in EUROCRYPT 2026
Keywords
post-quantumquantumcryptanalysisisogenygroup actionvectorizationhidden shiftcsi-shark
Contact author(s)
paul frixons @ gmail com
gilchrist valerie @ gmail com
kutasp @ gmail com
merz @ simon-philipp com
christophe petit @ ulb be
lam @ lamlaurentpham com
History
2026-02-23: last of 3 revisions
2025-02-27: received
See all versions
Short URL
https://ia.cr/2025/376
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/376,
      author = {Paul Frixons and Valerie Gilchrist and Péter Kutas and Simon-Philipp Merz and Christophe Petit and Lam L. Pham},
      title = {Another Look at the Quantum Security of the Vectorization Problem with Shifted Inputs},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/376},
      year = {2025},
      url = {https://eprint.iacr.org/2025/376}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.