Paper 2026/364
SPRINT: New Isogeny Proofs of Knowledge and Isogeny-Based Signatures
Abstract
Zero-knowledge proofs of knowledge are a fundamental building block in many isogeny-based cryptographic protocols, such as signature schemes based on identification-to-signature transformations, or multi-party ceremonies that avoid a trusted setup, in particular for generating supersingular elliptic curves with unknown endomorphism rings. In this paper, we construct SPRINT, an efficient polynomial IOP-based proof system that encodes the radical $2$-isogeny formulas into a system of multivariate polynomials. When combined with the recent polynomial commitment scheme (PCS) DeepFold, our construction yields substantial improvements over state-of-the-art isogeny proofs of knowledge. For the SQIsign prime $p=5 \cdot 2^{248}-1$ (giving NIST security level I), our implementation takes only a few milliseconds for proving and verification, with proof sizes around 80 kB. Compared to the previous state-of-the-art proof system by den Hollander et. al (PQCrypto'26), we achieve speedups ranging from $1.1\times$ to $22.7\times$ for the prover and from $4.4\times$ to $109\times$ for the verifier, while achieving proof sizes that are $1.4\times$ to $17.5\times$ smaller, across different instantiations and parameter sets. Moreover, we study the weak simulation extractability of our proof system, which we can use as a starting point for a modular construction of signatures. We show that any Fiat–Shamir compiled interactive proof with a so-called canonical simulator is weakly simulation-extractable. We expect this general result to be applicable to other proof systems and thus of independent interest. Building on SPRINT and our wSE result, we introduce a new family of signature schemes whose security solely relies on the $\ell$-isogeny path problem, a foundational problem in isogeny-based cryptography. As a concrete instantiation, we construct a signature scheme using DeepFold as the PCS. Across the different NIST security levels, a prototype implementation of our scheme achieves performance on par with the highly optimized NIST specification for SQIsign. Meanwhile our signature scheme relies on weaker assumptions and is constant-time when instantiated with a suitable PCS. Even though our signatures are relatively large, the framework offers flexibility for tradeoffs and optimizations -- both within a given PCS and by switching to alternative PCS constructions. In particular, it will naturally inherit efficiency gains from future advances in plausibly post-quantum secure PCS constructions.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- Isogeny Proofs of KnowledgeIsogeny-based SignaturesSimulation Extractability
- Contact author(s)
-
thomasdh @ unibw de
shai levin @ chalmers se
marzio mula @ unibw de
robi pedersen @ protonmail com
daniel slamanig @ unibw de
s spindler @ unibw de - History
- 2026-06-04: last of 2 revisions
- 2026-02-23: received
- See all versions
- Short URL
- https://ia.cr/2026/364
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/364,
author = {Thomas den Hollander and Shai Levin and Marzio Mula and Robi Pedersen and Daniel Slamanig and Sebastian A. Spindler},
title = {{SPRINT}: New Isogeny Proofs of Knowledge and Isogeny-Based Signatures},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/364},
year = {2026},
url = {https://eprint.iacr.org/2026/364}
}