Paper 2026/1305

Auxiliary Isogeny Freedom in SQIsign's Two-Dimensional Representation

Dustin Ray, Anchor Labs
Abstract

SQIsign encodes its response isogeny via a two-dimensional representation on a product of elliptic curves, using the Kani construction. We analyze the algebraic structure of this encoding in detail, with a focus on the role of the auxiliary isogeny and its implications for strong unforgeability. We show that the anti-isometry $\psi$ determining the Kani kernel is publicly computable from the torsion-point images of the component and auxiliary isogenies alone, that the automorphism orbit $\{\psi, -\psi\}$ is the only torsion-level source of encoding non-uniqueness on a fixed product surface, and that every auxiliary of the correct degree is commitment-compatible by Kani's theorem. The sole barrier to producing an alternative encoding is the construction of a new auxiliary isogeny of the required (generically non-smooth) degree from the challenge curve. We demonstrate that this barrier falls whenever a single small prime divides the auxiliary degree $2^f - q$: the adversary reroutes the terminal $\ell$-isogeny step at the codomain of the honest auxiliary, preserving the total degree exactly. Since generic odd integers possess small prime factors with overwhelming probability, this establishes that canonicalization of the basis change matrix does not suffice for strong unforgeability. We analyze the signing algorithm's dependency structure to show that the auxiliary cannot be bound into the Fiat-Shamir hash without a protocol redesign, and conclude with a structural comparison of ECDSA (where canonicalization suffices), SQIsign (where it does not), and salt-PRISM (which achieves strong unforgeability via a salted hash-to-prime mechanism that eliminates the auxiliary freedom entirely).

Note: Changes in v5: Complete rewrite. Versions 1-4 attempted a SUF-CMA proof for canonicalized SQIsign; following an observation by De Feo (Section 6), the proof's barrier identification was incorrect. This version pivots to a technical note analyzing the auxiliary isogeny freedom: why canonicalization eliminates the sign ambiguity (Section 3) but does not suffice for strong unforgeability (Sections 4-6), and what structural property a scheme needs to close the gap (Section 8). The M vs -M finding and canonical encoding fix are unchanged from v1.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
SQIsignpost-quantum signaturesstrong unforgeabilitySUF-CMAisogeny-based cryptographyKani's lemma
Contact author(s)
dustin ray @ anchorlabs com
History
2026-07-08: last of 5 revisions
2026-06-23: received
See all versions
Short URL
https://ia.cr/2026/1305
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1305,
      author = {Dustin Ray},
      title = {Auxiliary Isogeny Freedom in {SQIsign}'s Two-Dimensional Representation},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1305},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1305}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.