Paper 2026/1775
A Note on the Security Proof of SQIsign
Abstract
Aardal et al. (CRYPTO 2025) provided the first complete security proof of SQIsign; however, their reduction incurs a square-root loss in the prime characteristic due to the application of a loose bound on the min-entropy. For instance, at NIST security level I, an adversary making $2^{64}$ signing queries renders the security proof vacuous. In this note, we show that the min-entropy of SQIsign is optimal, namely $\mathcal{O}(1/p)$. Although this improvement does not yield full $\lambda$-bit security, we show that it preserves two-thirds of the expected bit-security. We show that this artifact comes from an information-theoretic loss in the zero-knowledge simulation of SQIsign, suggesting a new proof technique is needed to achieve full $\lambda$-bit security at the current parameters.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- Isogeny-based cryptographySQIsignSecurity proof
- Contact author(s)
-
mmamah @ uwaterloo ca
djao @ uwaterloo ca - History
- 2026-08-24: approved
- 2026-08-22: received
- See all versions
- Short URL
- https://ia.cr/2026/1775
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1775,
author = {Maher Mamah and David Jao},
title = {A Note on the Security Proof of {SQIsign}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1775},
year = {2026},
url = {https://eprint.iacr.org/2026/1775}
}