Paper 2026/1157

A Simple and Unified Approach for Proving Knowledge of Isogenies between Abelian Varieties

Jonathan Komada Eriksen, KU Leuven
Riccardo Invernizzi, KU Leuven
Jannik Spiessens, KU Leuven
Frederik Vercauteren, KU Leuven
Abstract

In this paper we introduce a simple and unified approach, based on generic proof systems, to prove knowledge of any isogeny between two principally polarized abelian varieties in any dimension, assuming that the $2^m$-torsion is accessible for sufficiently large $m$. Previous generic proof approaches were only able to prove knowledge of a smooth degree isogeny between elliptic curves, where for each small prime factor $\ell$ of the degree, bespoke constraints had to be derived, typically from (a variant of) the $\ell$-th modular polynomial. Our approach is much simpler in that it relies on proving knowledge of a $2^n$-isogeny between two principally polarized abelian varieties in any dimension. Furthermore, our approach is unified in that the constraints are essentially the same for each dimension, resulting in a simpler and easier-to-optimize algorithm. Our construction has immediate applications to proving knowledge of an isogeny of any degree between two elliptic curves, by using a higher dimensional representation. Indeed, by a result of Robert, any isogeny can be embedded in a $2^n$-isogeny by increasing the dimension, and conversely, the knowledge of a $2^n$-isogeny between products of varieties implies the knowledge of an isogeny of degree $\leq 2^n$ between a factor of the domain and codomain. Our generic proof does not disclose the degree of the secret isogeny, nor does it rely on knowing the endomorphism ring, thereby solving an open problem posed by Beullens, De Feo, Galbraith, and Petit in 2023. Two use cases are immediate. First, if one wants to prove knowledge of any isogeny between two supersingular curves over $\mathbb{F}_{p^2}$, e.g. during the generation of an elliptic curve with unknown endomorphism ring. Second, to prove knowledge of a secret isogeny coming from the class group action on oriented supersingular elliptic curves, e.g. CSIDH with curves defined over $\mathbb{F}_p$. Computing such group actions is typically done using qt-Pegasis, which naturally results in a 4-dimensional representation of the isogeny. Lastly, we propose two tailored zero-knowledge proof systems that improve proving time and proof size without loss of generality and provide the first implementation in dimension 2 and 4 by implementing both proof systems in Rust.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
post-quantum cryptographyisogenieszero-knowledge proofs
Contact author(s)
jonathan eriksen97 @ gmail com
riccardo invernizzi @ esat kuleuven be
jannik spiessens @ esat kuleuven be
frederik vercauteren @ gmail com
History
2026-06-08: approved
2026-06-03: received
See all versions
Short URL
https://ia.cr/2026/1157
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1157,
      author = {Jonathan Komada Eriksen and Riccardo Invernizzi and Jannik Spiessens and Frederik Vercauteren},
      title = {A Simple and Unified Approach for Proving Knowledge of Isogenies between Abelian Varieties},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1157},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1157}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.