TY - JOUR
T1 - Identification protocols and signature schemes based on supersingular isogeny problems
AU - Galbraith, Steven D.
AU - Petit, Christophe
AU - Silva, Javier
PY - 2020/1
Y1 - 2020/1
N2 - We present signature schemes whose security relies on computational assumptions relating to isogeny graphs of supersingular elliptic curves. We give two schemes, both of them based on interactive identification protocols. The first identification protocol is due to De Feo, Jao and Plût. The second one, and the main contribution of the paper, makes novel use of an algorithm of Kohel, Lauter, Petit and Tignol for the quaternion version of the ℓ-isogeny problem, for which we provide a more complete description and analysis, and is based on a more standard and potentially stronger computational problem. Both identification protocols lead to signatures that are existentially unforgeable under chosen message attacks in the random oracle model using the well-known Fiat-Shamir transform, and in the quantum random oracle model using another transform due to Unruh. A version of the first signature scheme was independently published by Yoo, Azarderakhsh, Jalali, Jao and Soukharev. This is the full version of a paper published at ASIACRYPT 2017.
AB - We present signature schemes whose security relies on computational assumptions relating to isogeny graphs of supersingular elliptic curves. We give two schemes, both of them based on interactive identification protocols. The first identification protocol is due to De Feo, Jao and Plût. The second one, and the main contribution of the paper, makes novel use of an algorithm of Kohel, Lauter, Petit and Tignol for the quaternion version of the ℓ-isogeny problem, for which we provide a more complete description and analysis, and is based on a more standard and potentially stronger computational problem. Both identification protocols lead to signatures that are existentially unforgeable under chosen message attacks in the random oracle model using the well-known Fiat-Shamir transform, and in the quantum random oracle model using another transform due to Unruh. A version of the first signature scheme was independently published by Yoo, Azarderakhsh, Jalali, Jao and Soukharev. This is the full version of a paper published at ASIACRYPT 2017.
KW - isogenies
KW - Public Key Signatures
KW - Post-quantum Cryptography
UR - http://www.scopus.com/inward/record.url?scp=85064513751&partnerID=8YFLogxK
U2 - 10.1007/s00145-019-09316-0
DO - 10.1007/s00145-019-09316-0
M3 - Article
SN - 0933-2790
VL - 33
SP - 130
EP - 175
JO - Journal of Cryptology
JF - Journal of Cryptology
IS - 1
ER -