Paper 2026/2108
$\Delta$-KLPT$^+$: Improved Norm Bounds for the Quaternion Isogeny Path Problem and an Application to Ring Signatures
Abstract
Computing smooth-degree isogenies between supersingular elliptic curves with known endomorphism rings is a fundamental task in isogeny-based cryptography. Via the Deuring correspondence, this task is equivalent to finding a connecting ideal of smooth norm between the corresponding quaternion maximal orders. KLPT-type algorithms address this problem by transforming a known connecting ideal into an equivalent ideal of smooth norm. Although connecting ideals of norm approximately $p$ are expected to exist, the best known such algorithms for general input only achieve norm $\widetilde{O}(p^{4.5})$. In this paper, we propose $\Delta$-KLPT$^+$, a new KLPT-type algorithm that lowers this bound to $\widetilde{O}(p^4)$. Our construction builds on $\Delta$-KLPT, which attains a smaller norm bound but requires two input ideals of the same prime norm. To extend $\Delta$-KLPT to arbitrary inputs, we introduce a new subroutine IdealNormReduce, which reduces the common norm of an ideal pair. By iterating IdealNormReduce, we obtain two ideals with a common norm below $p$. Then we apply $\Delta$-KLPT to the resulting ideal pair to obtain a desired connecting ideal of smooth norm. As an application, we construct Delfar, a fully anonymous isogeny-based ring signature scheme. Compared to Erebor-full, Delfar achieves shorter signatures and lower signing and verification costs for large rings.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- IsogenyQuaternionKLPTSQIsign
- Contact author(s)
-
kohei nakagawa @ ntt com
hiroshi-onuki @ g ecc u-tokyo ac jp - History
- 2026-09-22: approved
- 2026-09-19: received
- See all versions
- Short URL
- https://ia.cr/2026/2108
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2108,
author = {Kohei Nakagawa and Hiroshi Onuki},
title = {$\Delta$-{KLPT}$^+$: Improved Norm Bounds for the Quaternion Isogeny Path Problem and an Application to Ring Signatures},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2108},
year = {2026},
url = {https://eprint.iacr.org/2026/2108}
}