Isogeny-based anonymous ring signature system and method
Patent Information
- Application Number
- PCT/US2024/047340
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-09-19
- Filing Date
- 2024-09-18
- Publication Date
- 2026-01-08
AI Technical Summary
Existing ring signature schemes are vulnerable to quantum attacks, face challenges in managing computational complexity, ensuring signer anonymity in large rings, and maintaining reasonable signature sizes and verification times, necessitating the development of quantum-resistant and efficient isogeny-based solutions.
An isogeny-based ring signature scheme utilizing the SQISign framework, involving a setup algorithm for public parameters, key pair generation, a signing algorithm that computes isogenies and subgroups, and a verification algorithm to determine signature validity, leveraging elliptic curves and isogenies for secure and anonymous authentication.
The proposed scheme provides robust, quantum-resistant anonymous authentication with selfless-CCA security and linear signature growth with ring size, enhancing post-quantum cryptography resilience and efficiency.
Smart Images

Figure US2024047340_08012026_PF_FP_ABST
Abstract
Description
[0001]ISOGENY-BASED ANONYMOUS RINGSIGNATURE SYSTEM AND METHODCROSS-REFERENCE TO RELATED APPLICATIONThis application claims the benefit of U.S. Provisional Application Ser. No. 63 / 583,771filed September 19, 2023, the content of which is incorporated by reference herein in itsentirety.FIELD OF THE INVENTIONThe present disclosure relates to cryptographic systems and methods, and more par-ticularly to isogeny-based anonymous ring signature schemes for secure and privacy-preserving digital authentication.BACKGROUND Ring signature is a promising cryptographic primitive that enables an individual tosign a message on behalf of a group of people without disclosing which member in thering signed the message. Rivest, Shamir, and Tauman were the first to propose the idea ofa ring signature in 2001. In a ring signature, each user generates its own key pair; a secretkey and a public key. To generate a ring signature, the signer first selects a subset of thepublic keys that makes up the ring, which must contain his own public key. The signerwill then sign on behalf of the associated set of users without seeking their assistance.This signature can be verified using the ring of public keys. The intriguing aspect of ringsignatures is that, given such a signature, it is impossible for anyone to determine whichmember of the ring has actually signed the message. This is true even for the insider whoowns all of the secret keys corresponding to the public keys in the ring. The two mainsecurity attributes of a ring signature are: unforgeability and anonymity. Unforgeabilityof a ring signature ensures it is impossible to forge a signature on behalf of an honest ringof signers without the knowledge of the secret key of at least one member of the ring.Anonymity of a ring signature guarantees that (possibly) even with knowledge of all thesecret keys of the ring, it is impossible to determine which member of the ring generatedthe signature.Applications. Ring signatures give a sleek and untraceable means of leaking confidentialinformation in a way that verification is possible only for the intended receiver. Consider,for instance, a scenario where a high-rank government official wants to reveal some sen-sitive information to the media. The official would want to stay anonymous, but themedia would be interested in verifying the credibility of the source. Ring signatures al-low the media to confirm that some government official signed the message but preventthem from identifying the source of the leak. In addition to their use in whistleblowing,ring signatures naturally lend themselves to a variety of applications, including e-voting,anonymous membership authentication for ad hoc groups, non-interactive deniable ringauthentication, and perfect concurrent signature. Interestingly, there are numerous ap-plications that call for merely a two-party ring signature. The use of a ring signaturein conjunction with a designated-verifier signature is one such example, and it is par-ticularly relevant in the context of e-mail. Here, ring signatures enable the sender of ane-mail to sign the message with respect to the ring containing the sender and the re-ceiver; the receiver is then assured that the e-mail originated from the sender but cannotprove this to any third party. A two-party ring signature also serves as a building blockfor primitives such as an optimistic fair exchange and ad-hoc key exchange. In a subse-quent work, Hashimoto et al. demonstrated the application of a two-party ring signaturein Signal-conforming authenticated key exchange (AKE) protocol which is a secure in-stant messaging protocol that underlies the security of numerous applications such asWhatsApp, Facebook Messenger and Skype.Related Work. Since the formalization of ring signatures, there has been a flurry ofwork on ring signatures based on various hardness assumptions such as integer factor-ization, discrete logarithm and pairing-based. However, the onset of quantum computerswill render all these schemes obsolete. Thus, cryptographers have begun devising vari-ous attempts to design quantum-resistant ring signatures from lattice-based assumptions.Beullens et al. were the first to initiate the study of ring signatures in the isogeny world.They proposed a linkable ring signature scheme based on logarithmic OR-proof with bi-nary challenges from Commutative Supersingular Isogeny Diffie-Hellman (CSIDH) basedgroup action and MLWE-based group action. The CSIDH group action is adapted fromthe Couveignes-Rostovtsev-Stolbunov scheme by substituting supersingular elliptic curvesover for ordinary elliptic curves to improve the efficiency of the scheme. Recently, Beul-lens et al. incorporated the accountability feature to the ring signature of prior work byproposing an efficient online-extractable OR-proof that allows to prove the validity of aciphertext. The security of the CSIDH-based ring signature is based on the Group ActionInverse Problem (GAIP) and Squaring Decisional CSIDH (sdCSIDH) Problem. The best-known quantum algorithm to solve GAIP and its variants have subexponential complexity.There has also been a construction of ring signature from SIDH-based assumption. Garjanet al. proposed a sigma protocol for a ring based on the identification scheme proposedby De Feo et al. and then derived their ring signature by applying the Fiat-Shamir trans-form to their proposed sigma protocol. Unfortunately, the SIDH-based ring signature isinvalidated by the recent complete break of SIDH by Castryck and Decru.The current state-of-art depicts that while the SIDH-based ring signature is completelybroken by the Castryck and Decru, the CSIDH-based ring signature can be targeted bya quantum subexponential hidden shift algorithm found by Childs, Jao and Soukharev.To the best of our knowledge, there is by far no construction of ring signatures fromShort Quaternion and Isogeny Signature (SQISign). SQISign is an isogeny-based signaturescheme that uses very rich mathematical knowledge of quaternion algebra. It is, to date,the most compact post-quantum signature, and its speed and functionality have recentlybeen further improved by De Feo et al. Furthermore, it is worth noting that SQISignframework is unaffected by the recent key recovery attack on SIDH by Castryck andDecru as this attack very specifically relies on the auxiliary points involved in SIDHcryptosystem. Combining isogeny-based cryptography with ring signature schemes presents an op-portunity to create anonymous signature systems that are resistant to quantum attacks.However, designing efficient and secure isogeny-based ring signatures poses several chal-lenges. These include managing the computational complexity of isogeny computations,ensuring the anonymity of signers within large rings, and maintaining reasonable signa-ture sizes and verification times.Furthermore, the implementation of isogeny-based cryptosystems requires careful con-sideration of parameter selection, key generation procedures, and protocol design toachieve the desired security properties while maintaining practical performance char-acteristics. As research in this field progresses, there is a growing need for innovativeapproaches that can address these challenges and provide robust, scalable solutions forpost-quantum anonymous authentication.SUMMARY This summary is provided to introduce a selection of concepts in a simplified form thatare further described below in the detailed description. This summary is not intended toidentify key features or essential features of the claimed subject matter, nor is it intendedto be used as an aid in determining the scope of the claimed subject matter.According to an aspect of the present disclosure, a computerized method for generat-ing an isogeny-based ring signature is provided. The method includes executing, by oneor more processors, a setup algorithm to establish public parameters including at leastone base elliptic curve E0 stored in a computer memory. The method further includesgenerating, by the one or more processors, key pairs for a plurality of users, each keypair comprising a signing key SKi and a verification key V Ki stored in the computermemory. The method also includes executing, by the one or more processors, a sign-ing algorithm by a signer. The signing algorithm includes selecting at least one randomisogeny ψs : E0 → E(s)1 . For users in a ring, the signing algorithm iteratively computesand stores in the computer memory: isogenies σi, scalar values ki, basis points {Pi, Qi},subgroups Ki = ^Pi + kiQi^, and isogenies The signing algorithm further computesand stores in the computer memory signer-specific isogenies, subgroups, and kernels. Itthen derives a final isogeny σs : E(s)A → E(s) 2. Finally, the signing algorithm outputs, viaa computer network interface, a ring signature comprising the computed isogenies andbasis points. In this method, E0, E(s)1 , E(s) A, and E(s) 2are elliptic curves, ψs, ϕ̂i, and σsare isogenies, and Pi and Qi are points on the respective elliptic curves.According to other aspects of the present disclosure, the computerized method mayinclude one or more of the following features. At least one isogeny in the signing algorithmmay be cyclic.According to another aspect of the present disclosure, a computerized method forverifying an isogeny-based ring signature is provided. The method includes executing,by one or more processors, a verification algorithm. The verification algorithm includesparsing a ring signature Σ = received via a computer networkinterface. For users in a ring, the verification algorithm retrieves an isogeny σ (i)i : EA →E(i) 2from Σ, verifies properties of σi, computes scalar values ki, computes subgroupsKi = ^Pi+kiQi^ and isogenies ϕ̂i, and verifies if ϕ̂i◦σi is cyclic. The verification algorithmthen determines validity of the ring signature and outputs, via the computer networkinterface, a result of the validity determination. In this method, E(i)(i) Aand E 2 are ellipticcurves, and ϕ̂ are isogenies, and are po (i)i ints on the elliptic curve E2According to another aspect of the present disclosure, a computerized system for gen-erating an isogeny-based ring signature is provided. The system includes one or moreprocessors, a computer memory, a computer network interface, and a non-transitorycomputer-readable medium storing instructions. When executed by the one or more pro-cessors, the instructions cause the system to execute a setup algorithm to establish publicparameters including a base elliptic curve E0 and store the public parameters in the com-puter memory. The system also executes a key generation algorithm to generate key pairsfor users, each key pair comprising a signing key SKi and a verification key V Ki, andstores the key pairs in the computer memory. The system further executes a signing al-gorithm that includes selecting at least one random isogeny ψ (s)s : E0 → E1 . For usersin a ring, the signing algorithm computes and stores in the computer memory: isogeniesσ , scalar values ki, basis points {Pi, Qi}, subgroups Ki = ^Pi + kiQi^, and isogenies The signing algorithm also computes and stores in the computer memory signer-specificisogenies and subgroups, derives a final isogeny σ (s)(s) s: EA → E 2 , and outputs, via thecomputer network interface, a ring signature comprising the computed isogenies and basispoints. In this system, E0, E(s)1 , E(s) A, and E(s) 2are elliptic curves, ψs, σi, ϕ̂i, and σs areisogenies, and Pi and Qi are points on the respective elliptic curves.According to other aspects of the present disclosure, the computerized system mayinclude one or more of the following features. At least one isogeny in the signing algorithmmay be cyclic.According to another aspect of the present disclosure, a computerized system for veri-fying an isogeny-based ring signature is provided. The system includes one or more proces-sors, a computer memory, a computer network interface, and a non-transitory computer-readable medium storing instructions. When executed by the one or more processors,the instructions cause the system to execute a verification algorithm. The verificationalgorithm includes retrieving elements from a ring signature Σ = {{σ N−1 N−1i}i=0 , {Pi, Qi}i=0 }received via the computer network interface and retrieving public parameters from thecomputer memory. For users in a ring, the verification algorithm verifies properties of iso-genies : E(i) → E(i) A2 , computes scalar values computes subgroups Ki = ^Pi + kiQi^and isogenies ϕ̂i, and verifies if is cyclic. The verification algorithm then determinesvalidity of the ring signature and outputs, via the computer network interface, a resultof the validity determination. In this system, E(i) an(i) Ad E 2 are elliptic curves, σi and ϕ̂iare isogenies, (i) are points on the elliptic curve E2 .According to another aspect of the present disclosure, a computerized method forgenerating an isogeny-based ring signature is provided. The method includes executing,by one or more processors, a setup algorithm on a security parameter 1λ by fixing abase elliptic curve E0 in a computer memory and setting public parameters PP = {E0}in the computer memory. The method further includes executing, by the one or moreprocessors, a key generation algorithm to generate a signing and verification key pair(SKi, V Ki) for each user of a plurality of users. This involves selecting a random isogenyτ : E → E(i) , sett(i) 0ing the signing key SKi = and verification key V K = EA incomputer memory, and publishing the user verification key V Ki for each user Ui to acomputer network. The method also includes executing, by the one or more processors, asigning algorithm by a signer Us that employs its signing key SKs. The signing algorithminvolves picking a random isogeny ψ (s)s : E0 → E1 and performing a series of computationsfor users in a ring. These computations include picking random isogenies, storing a ring,computing scalar values, basis points, subgroups, and isogenies. The signing algorithmfurther involves computing signer-specific values and outputting a ring signature to thecomputer network.According to other aspects of the present disclosure, the computerized method mayinclude one or more of the following features. The isogeny ϕ̂s ◦ σs may be cyclic.According to another aspect of the present disclosure, a computerized method for ver-ifying an isogeny-based ring signature is provided. The method includes executing, by oneor more processors, a verification algorithm. The verification algorithm involves parsinga ring signature received from a computer network and performing a series of checks andcomputations for each user in the ring. These operations include retrieving and verifyingisogenies, computing scalar values, subgroups, and isogenies, and checking cyclicity. Theverification algorithm then outputs a validity result to the computer network.According to another aspect of the present disclosure, a computerized system for gen-erating an isogeny-based ring signature is provided. The system includes one or moreprocessors, a computer memory, and a computer network interface. The processors areconfigured to execute instructions for performing a setup algorithm, a key generationalgorithm, and a signing algorithm. These algorithms involve operations similar to thosedescribed in the corresponding method claims, including establishing public parameters,generating key pairs, and executing a signing process that involves various isogeny com-putations. According to other aspects of the present disclosure, the computerized system mayinclude one or more of the following features. The isogeny ϕ̂s ◦ σs may be cyclic.According to another aspect of the present disclosure, a computerized system forverifying an isogeny-based ring signature is provided. The system includes one or moreprocessors, a computer memory, and a computer network interface. The processors areconfigured to execute instructions for performing a verification algorithm. This algorithminvolves retrieving and processing elements of a ring signature, performing various com-putations and checks related to isogenies and subgroups, and determining the validity ofthe ring signature.The foregoing general description of the illustrative embodiments and the followingdetailed description thereof are merely exemplary aspects of the teachings of this disclo-sure and are not restrictive.BRIEF DESCRIPTION OF THE DRAWINGSNon-limiting and non-exhaustive examples are described with reference to the follow-ing figures.FIG. 1 illustrates a system diagram of an isogeny-based cryptographic scheme, ac-cording to aspects of the present disclosure.FIGS. 2A-2B illustrate system diagrams of an isogeny-based ring signature scheme,according to embodiments of the present disclosure.FIG. 3 illustrates a block diagram of an anonymous signature system, in accordancewith example embodiments.FIG. 4 illustrates a block diagram of a computer system, according to an aspect ofthe present disclosure.FIG. 5 illustrates a block diagram of another computer system, according to aspectsof the present disclosure.DETAILED DESCRIPTIONThe present disclosure provides a method and system for generating and verifying anisogeny-based ring signature. This scheme is designed to offer enhanced security in therealm of post-quantum cryptography, where traditional cryptographic methods based oninteger factorization or discrete logarithm problems are vulnerable to attacks by quantumcomputers. The disclosed isogeny-based ring signature scheme leverages the mathematical prop-erties of isogenies between elliptic curves to create cryptographic primitives. Isogeniesare maps between elliptic curves that preserve their group structure, and the difficulty ofcomputing certain isogenies forms the basis for the security of these cryptosystems.The ring signature scheme allows a user to sign a message on behalf of a groupwithout revealing which member of the group actually produced the signature. Thisproperty, known as anonymity, is valuable in various applications where privacy andplausible deniability are important, such as whistleblowing, anonymous voting systems,and confidential transactions in cryptocurrencies.The disclosed method and system involve several key components, including a setupalgorithm, a key generation algorithm, a signing algorithm, and a verification algorithm.The setup algorithm establishes public parameters, including a base elliptic curve. Thekey generation algorithm generates signing and verification key pairs for each user, witheach key pair comprising a signing key derived from a random isogeny mapping from thebase elliptic curve to a user-specific elliptic curve, and a verification key correspondingto the user-specific elliptic curve.The signing algorithm is executed by a signer that employs its signing key. Thisalgorithm involves selecting a random isogeny, iteratively computing various values andisogenies for users in a ring, computing signer-specific isogenies and subgroups, derivinga final isogeny, and outputting a ring signature comprising the computed isogenies andbasis points.The verification algorithm is executed by a verifier and involves parsing the ringsignature, performing a series of verification steps for users in the ring, and determiningthe validity of the ring signature.In summary, the disclosed isogeny-based ring signature scheme provides a robust andquantum-resistant solution for anonymous authentication in cryptographic systems.In this work, we propose the first construction of a ring signature from SQISign. Ourconstruction is inspired by the generic construction of ring signatures from a Three-movetype (Type-T) signature due to Abe et al. We provided a rigorous security analysis of ourring signature and arrived at the following result:Theorem 0.1: (Informal). There exists a ring signature scheme based on the SQISignframework. The scheme is anonymous against partial key exposure and unforgeable withrespect to insider corruption under the hardness assumption underlying the signaturescheme SQISign.We provide a theoretical comparison of our ring signature based on SQISign in termsof signature size, anonymity and security with the existing works on isogeny-based ringsignatures in Table 1. The ring signature scheme by Garjan et al. gives the only construc-tion of ring signature from SIDH. Their signature size increases logarithmically in the sizeof the ring. Nevertheless, their scheme is no longer quantum-resistant due to the recentattack on SIDH. The ring signature schemes of Chung et al. and Lai et al. are basedon CSIDH; however, they only provide CPA anonymity which means the adversary is notprovided with the secret key of any user in the ring. Beullens et al. gives the most efficientisogeny-based ring signature based on CSIDH in terms of signature size and anonymity.They have taken into account the strong model for anonymity and proved their scheme tobe full-CCA secure. In the full-CCA model, the adversary has access to the secret key of allthe users and it gets to choose the signing key used to generate the signature. However, itis important to consider that the CSIDH cryptosystem is susceptible to a subexponentialquantum attack, as indicated in prior work. As a consequence, the proposed scheme byBeullens et al. will necessitate the use of subexponential size parameters. This, in turn,leads to a reduction in the concrete efficiency of their scheme. Our scheme is the firstisogeny-based ring signature that is based on SQISign framework. In contrast to priorwork, we prove the anonymity of our ring signature in a weaker security model intro-duced in the prior work. We prove our scheme to be selfless-CCA secure meaning theadversary is restricted from exposing the signing key used to generate the signature. Thesize of our ring signature grows linear to the size of the ring. However, our ring signaturewill be best suited for applications discussed before which necessitate ring of size two.We believe that our relatively inefficient ring signature serves to advance the state-of-artfor the SQISign-based cryptosystem.Table 1: Comparison with concurrent works in terms of anonymity, signature size andsecurity framework CSIDH = Commutative Supersingular Isogeny Diffie–Hellman, SQISign = Short Quater-nion and Isogeny Signature, N = Size of the ring.Technical overview of SQISign. SQISign gives a new signature scheme for isogeniesthat combines a new one-round, high soundness, interactive identification protocol withthe notion of Fiat-Shamir with aborts. As the identification protocol underlying SQISignhas an exponentially large challenge set, the identification protocol does not have to berepeated thereby yielding the most compact post-quantum signature. A pictorial descrip-tion of the identification protocol underlying SQISign is depicted in FIG. 1.In the identification protocol the prover wishes to prove the knowledge of the isogenyτ : E0 → EA. Here E0 is a base elliptic curve that is publically available. The proverpublishes the codomain elliptic curve EA as its public key and keeps τ secret to itself. Itpicks a random commitment isogeny ψ : E0 → E1 and sends the commitment curve E1to the verifier. Like the secret isogeny τ , the commitment isogeny ψ is also kept secret tothe prover. The verifier computes an exponentially large degree isogeny φ : E1 → E2 andsends φ to the prover as a challenge. The prover employs the Deuring Correspondence tocompute the ideals Īτ , Iψ and Iφ in the quaternion world corresponding to its respectiveisogenies τ̂ , ψ and φ. Leveraging the SigningKLPT algorithm described in Section 1.5,it computes an ideal J equivalent to the ideal I = It computes the isogeny σcorresponding to the ideal J and sends σ to the verifier. The response isogeny σ is offixed degree with appropriate domain and codomain and does not leak any informationabout the secret isogeny τ or commitment isogeny ψ. The signature scheme SQISign isobtained by applying the Fiat-Shamir transformation to this identification protocol. Anexplicit description of the signature scheme SQISign is given herein.Technical overview of our ring signature based on SQISign. To describe the highlevel overview of our ring signature, it is instructive to recall the classical ring signatureapproach proposed by Abe et al. We begin with a Three-move type (Type-T) signatureand then review the generic construction of Abe’s ring signature leveraging the Type-Tsignature. As the name suggests, Type-T signatures are derived from three-move honestverifier zero-knowledge proofs. It comprises of three functions, namely, a commit functionA, a challenge hash function H and a response function Z, each of which is detailed below:– The first move is given by the commit function A that generates a commitment a andwith regard to some randomness r.– The second move is given by the challenge hash function H : {0, 1}∗ → ChSet that oninput a commitment a and a message msg outputs a challenge string c. Here ChSetdenotes the challenge set.– The third move is given by the response function Z that generates a response z to thechallenge c.A Type-T signature is given by σ = (c, z). To check the validity of σ = (c, z), one executesa verification function V that reconstructs the commitment a′ from σ, recomputes thechallenge string c′ = H and checks if c′ = c holds.We now describe the framework for Abe’s ring signature derived from a Type-T signature.Suppose some signer Us wishes to generate a signature on msg on behalf of the ringR = {VK0,VK1, ... ,VKN−1} where VKi is the verification key corresponding to userUi. The signer in possession of its signing key SKs corresponding to VKs performs thefollowing steps to compute a ring signature:– Executes the commit function A on some randomness rs to generate a commitmentas. –Computes the (s + 1)-th challenge string by evaluating the hashfunction H.– For i = s + 1, ... , N − 1, 0, ... , s − 1, samples a random response zi, executes theverification function V on input ci, zi, VKi to reconstruct the i-th commitment andthen computes the (i + 1)-th challenge string ci+1 = H .– Executes the response function Z employing its signing key SKs, challenge string csand randomness rs to compute the response zs.– Sets the ring signature Σ = {c0, z0, ... , zN−1}.The verification of the ring signature Σ = {c0, z0, ... , zN−1} on the message msg involvesthe following steps:– Retrieve c0 from Σ.– For i = 0, ... , N − 1, execute the verification function V on input ci, zi, VKi toreconstruct the i-th commitment and then compute the (i + 1)-th challenge stringci+1 = H(ai,msg).– Check if c0 = cN . If the check succeeds, Σ is valid. Otherwise, its invalid.We are now ready to describe our construction of ring signature scheme from SQISignsignature. For a better illustration of our scheme we set N = 4. We assume that the ringcomprises of four users U0, U1, U2 and U3 and that the index of the signer is 2. At thebeginning of the protocol, each of the four users Ui traverses a random walk τi from abase elliptic curve E leading (i)0 to a random elliptic curve EA . The isogeny τi comprisesthe signing key SK and th (i)i e curve EA comprises the verification key VKi of the user Ui.The signing and verification key pair of each of the users is depicted in FIG. 2A. Thesigner U2 employs its signing key SK2 = τ2 to generate a signature on the message msg onbehalf of the ring R =(1) (2) (3) , E A , E A , E A }. The steps performed by U2 are explicitlydescribed below and are depicted in FIG. 2B for better illustration.– Samples a random isogeny ψ (2)(2) 2: E0 → E1 and sets its commitment curve to E 1. –To compute the commitment curve E(3)1 , the signer picks a random (response) isogenyσ3 : E(3)A → E(3) 2of degree D and then evaluates the hash function H on its commitmentcurve E(2)1 and msg to obtain an integer t3 that determines a path in the ℓ-isogenygraph. Next, it employs E(3) and t to e2 3 deterministically obtain a scalar k3 ∈ Z / ℓ Z.It finds the basis {P , Q } of the t (3) e3 3 orsion subgroup E2 [ℓ ], computes the subgroupK3 = ^P3 + k3Q3^ of E(3)2 and apply Vélu’s formulae to generate the dual of challengeisogeny ϕ̂(3)e E 1 of degree ℓ– Repeating the above step (picking a random response isogeny followed by computingthe dual challenge isogeny) sequentially, the signer computes the commitment curveE(0) 1from E(3) 1and further computes E(1) 1from E(0) 1 . –The signer having its commitment curve E(2)1 , computes the challenge isogeny ϕ2 :E(2) 1→ E(2) 2. It computes the dual isogeny ϕ̂(2) 2: E 2 → and obtains its kernelsubgroup, say, K2.– Evaluates the hash function H on E(1)1 and msg to obtain an integer t2 and employsE(2) 2and t2 to deterministically obtain a scalar k e2 ∈ Z / ℓ Z.– Computes {P , Q2} in that satisfies K2 = ^P2 + k2Q– Performs the SQISign signature to generate its response isogeny σ (2)(2) 2: EA → E 2employing its signing key τ2.– The ring signature Σ comprises of an integer t0, all the four response isogenies σ0, σ1,σ2, σ3 and the basis points {Pi, Qi}3i=0.Basically, for i ̸= 2, the signer picks the response isogeny σi randomly and then com-putes the commitment curves E(i)1 corresponding to non-signers. However, for i = 2, thesigner having its commitment curve E(2)1 , executes the SQISign signature to compute theresponse isogeny σ . To verify the validity of the ring s 32 ignature Σ = {t0, σ0, σ1, σ2, σ3, {Pi, Qi}i=0},the verifier first checks if each of the response isogeny σi is indeed computed correctly. Ifso, it recomputes the integer t0 and checks if the value is same as the one retrieved fromΣ. More precisely, the verifier proceeds as follows:– Retrieves the isogeny σ from Σ and (0)0 checks if σ0 is indeed an isogeny from EA toE(0) 2of degree D.– Employs the curve E(0) e2 and integer t0 to obtain the element k0 ∈ Z / ℓ Z that de-termines the subgroup K = and apply Vélu’s formulae to computeisogeny ϕ̂0 : E(0)2 → E(0) 1with kernel K0.– Checks if ϕ̂ ◦ σ0 is cyclic. If so, computes t1 = –Repeats the above steps sequentially to compute t2 from σ1, t3 from σ2 and finally t0from σ3.– Checks if the recomputed t0 is the same as the one retrieved from Σ.1 PreliminariesNotations. Throughout this disclosure, we use the following notations: Let λ ∈ N denotethe security parameter. We use S∗ to denote the set S \ {0} and to denote thecardinality of the set S. A function negl(·) is negligible if for every integer c, there existsan integer k such that for all λ > k, |negl(λ)| < 1 / λc.1.1 Elliptic curves, isogenies and endomorphismsLet K be a finite field and K̄ be its algebraic closure. An elliptic curve E over K isa smooth projective cubic curve of genus one with a distinguished point OE, called thepoint at infinity. The set of K-rational points E(K) of the elliptic curve E forms anadditive abelian group with OE as the identity element. The j-invariant of an ellipticcurve E : y = x3 + Ax + B over a field K is given Let E1 and E2 be two elliptic curves over a finite field K. An isogeny from E1 to E2is a non-constant morphism φ : E → E2 over K satisfying φ the point at infinity of the curve Ei for i = 1, 2. The degree of the isogeny φ, denotedby deg is its degree as a rational map. A non-zero isogeny φ is called separable if andonly if deg(φ) = #kerf(φ) where kerf(φ) = φ−1(OE2). An isogeny φ is said to be cyclicif its kernel is a cyclic group. For any isogeny φ : E1 → E2, there exists a unique dualisogeny φ̂ : E → E1, satisfying φ ◦ φ̂ = [deg(φ)], the multiplication-by- deg mapE . Similarly, we have φ̂ ◦ φ = [deg the multiplication-by-deg(φ) map on E1.isogeny from a curve E to itself is called an endomorphism. The set of all endomorphismsof E forms a ring under pointwise addition and composition, called the endomorphismring of the elliptic curve E and is denoted by End(E). For a supersingular elliptic curvethe endomorphism ring is isomorphic to an order in a quaternion algebra.Theorem 1.1: (up to K-isomorphism) (φ) = G andE2 := E1 / G and Throughout this disclosure, we will be mainly focused on supersingular elliptic curvesover a finite field K = Fp2 for some prime p.1.2 Quaternion Algebras, Orders and IdealsQuaternion Algebras. For a, b ∈ Q∗, the quaternion algebra over Q denoted byb) = Q + iQ + jQ + kQ is a four-dimensional non-commutative vector space withbasis {1, i, j, k} such that i2 = a, j2 = b, and k = ij = −ji. Every quaternion algebraH(a, b) is associated by a standard convolution g given by g : α = + a2i+ a3j + a4k →a1−a2i−a3j−a4k = ᾱ. The reduced trace tr : H(a, b) → Q of a standard convolution g isthe map tr : α → α+ g(α). The reduced norm nr : H(a, b) → Q of a standard convolutiong is the map nr : α → αg(α). In this work, we shall be interested in the quaternion algebra some prime p.Ideals and Orders. Let us consider the quaternion algebra Bp,∞. A fractional idealI = α1Z + α2Z + α3Z + α4Z is a Z-lattice of rank four with ^α1, α2, α3, α4^ a basis ofBp,∞. The norm of I denoted by nr(I) is defined as the largest rational number such thatnr(α) ∈ nr(I)Z for any α ∈ I. The conjugate ideal Ī is given by Ī = {ᾱ |α ∈ I}. Anorder O is a subring of Bp,∞ that is also a fractional ideal. A maximal order O is an orderthat is not properly contained in any other order. The left order of a fractional ideal I,denoted by OL(I) is defined as OL(I) = {α ∈ Bp,∞ |αI ⊆ I}. Similarly, right order ofa fractional ideal I, denoted by OR(I) is defined as OR(I) = {α ∈ Bp,∞ | Iα ⊆ I}. HereI is said to be a left OL(I)-ideal or a right OR(I)-ideal or an (OL(I),OR(I))-ideal. AnEichler order is the intersection of two maximal orders inside Bp,∞. A fractional ideal Iis called integral if I ⊆ OL(I) or I ⊆ OR(I). Two left O-ideals I and J are equivalent ifthere exists β ∈ B∗p,∞ such that I = Jβ and is denoted by I ∼ J . A special extremal orderis an order O in Bp,∞ which contains a suborder of the form R + jR where R = Z[ω] ⊂Q[i] is a quadratic order and ω has smallest norm in O.1.3 Deuring’s correspondence:Deuring’s correspondence establishes a one-to-one correspondence between the set ofisomorphism classes of supersingular curves over Fp2 and the set of ideal classes of agiven maximal order. Under this correspondence, we look into the connection betweenideals in maximal orders of quaternions and separable isogenies between supersingularcurves over Fp2.Given a separable isogeny φ : E0 → E1 with finite kernel H where O0 = End(E0) andO1 = End(E1) be the maximal orders corresponding to the endomorphism rings of E0 andE1 in Bp,∞, we can define the left O0-ideal Iφ := {α ∈ O0 |α(P ) = OE0 for allP ∈ H}corresponding to φ. Conversely, given a left O0-ideal I, we can define the kernel groupE1[I] := (P ) = OE0 for allα ∈ I} and computes the isogenyφI : E0 → E0 / E0[I] that corresponds to I.Under this Deuring correspondence, deg(φ) corresponds to nr(Iφ) and the dual isogenyφ̂ corresponds to the conjugate ideal Īφ.Lemma 1. Let O be a maximal order, I be a left O-ideal and β ∈ I \{0}. Then χI(β) =nr(β) nr(I).1.4 Pushforward and pullback isogeny.Consider three elliptic curves E0, E1, E2 over Fp2 and two separable isogenies φ1 : E0 →E1 and φ2 : E0 → E2 of coprime degrees N1 and N2 respectively. The pushforward of φ1by φ2 is denoted by [φ2]∗φ1 and is defined as the separable isogeny [φ2]∗φ1 from E2 tosome new curve E3 such that ker([φ2]∗φ1) = φ2(ker(φ1)) and deg([φ2]∗φ1) = N1. Similarly,the pushforward of φ2 by φ1 is denoted by [φ1]∗φ2 and is defined as the separable isogeny[φ1]∗φ2 : E1 → E3 such that ker([φ1]∗φ2) = φ1(ker(φ2)) and deg([φ1]∗φ2) = N2. Pullbackisogeny is the dual notion of pushforward isogeny. Consider two separable isogeniersφ : E0 → E1 and ρ2 : E1 → E3 of coprime degrees. The pullback of ρ2 by isby [φ1]∗ρ2 and is defined as the separable isogeny [φ1]∗ρ2 from E0 to a new curve E4satisfying The pushforward and pullback terms can be extended to ideals as well. Consider a(O0,O1)-ideal J and a (O0,O2)-ideal K where O0 = End(E0), O1 = End(E1) and O2 =End(E ). The pushforward of J by K, denoted by [K]∗J is the ideal Jto the pushforward isogeny [φK ]∗φJ . Consider a (O1,O3)-ideal L where O1 = End(E1),O3 = End(E3), then the pullback of L by J , denoted by [J ]∗L is defined as [J ]∗L = [J̄ ]∗L.Lemma 2. Let I is an ideal with left order O0 and right order O and J1, J2 be O0-ideals with J1 ∼ J2 and gcd(nr(J1), nr(J2), nr(I)) = 1. Suppose that J1 = χJ2(β) andβ ∈ J2 ∩ O0 ∩ O. Then [I]∗J1 ∼ [I]∗J2 and [I]∗J1 = χ[I]∗J2(β).1.5 SigningKLPT algorithmWe briefly review below the sub-algorithms invoked by the algorithm SigningKLPT. Thedetails of which can be found in the work of De Feo et al.Cornacchia(M) → (x, y): This algorithm on input M ∈ Z either outputs ⊥ if M cannotbe represented as f(x, y) or returns a solution (x, y) to f(x, y) = M .EquivalentPrimeIdeal(I) → L ∼ I: This algorithm takes as input a left O0-ideal I repre-sented by Minkowski reduced basis . It chooses an integer m, generatesrandom element δ = Σixiδi with xi ∈ [−m,m] and checks if is a prime number. Ifnot, it continues to generate random δ until it finds a δ ∈ I for which nr(δ)nr(I) is a primenumber. The algorithm outputs the ideal L = χ (δ) = equivalent to I andprime norm.EquivalentRandomEichlerIdeal(I, N) → L ∼ I: This algorithm takes as input a left O0-ideal I and an integer N and finds a random equivalent leftO0-ideal L of norm coprimeto N . This algorithm takes input an integer M ∈ Z with M >and outputs an element γ = x1 + ωy1 + j(x2 + ωy2) ∈ O0 with nr(γ) = M . Itcontinues to samples random integer M′ = M − pf(x2, y2) and run Cornacchia on M ′ until Cornaccia returns a solutiony ) to the equation ′1 f(x1, y1) = MIdealModConstraint(I, γ) → (C0 : D0): On input a left O0-ideal I of norm N and anelement γ ∈ O0 of norm Nn, this algorithm outputs a projective point (C0 : D0) ∈P1(Z / NZ) satisfying γµ0 ∈ I with µ0 = (C0 + ωD0)j ∈ Rj.EichlerModConstraint(I, γ, δ) → (C0 : D0): This algorithm takes input a left O0-ideal Iof norm N , elements γ, δ ∈ O0 of norms coprime to N and outputs a projective point(C0 : D0) ∈ P1(Z / NZ) satisfying γµ0δ ∈ I where µ0 = (C0 + ωD0)j ∈ Rj.StrongApproximationS(N,C,D) → µ: Taking as input a prime N , integers C, D anda subset S ⊂ N, this algorithm outputs µ ∈ O0 of smallest norm in S satisfying When S{d ∈ N : d|D} for some D ∈ N, we simply write StrongApproximationD.CRTM,N(x, y) → z: This is the algorithm for Chinese Remainder Theorem which takesas input x ∈ ZM , y ∈ ZN and returns z ∈ ZMN satisfying z ≡ x (mod M) and z ≡ y(mod N) where M and N are coprime to each other.We now describe the algorithm I) which takes as input a prime l,fixed e ∈ N, a left O0 and a right O-ideal Iτ of norm Nτ and a left O-ideal I and outputsan ideal J ∼ I of norm ℓe. The steps involved in the algorithm SigningKLPT are explicitlydescribed below.1. Runs the algorithm EquivalentRandomEichlerIdeal(I,Nτ ) to generate a random idealK ∼ I with gcd(nr(K), Nτ ) = 1. We denote the right order of the ideal K (or I) byO2.2. Performs the pullback of the (O,O2)- ideal K by the (O0,O)-ideal Iτ to obtain a (O0,O′)-ideal K ′ = [Iτ ]∗K where O′ = End(E ′) for some curve E ′.3. Computes an ideal L = χK′(δ′) ← EquivalentPrimeIdeal(K ′) equivalent toK ′ but of prime norm N for some δ′ ∈ K ′. (See Lemma 1)4. Chooses e0 ∈ N and runs the algorithm RepresentInteger e0O0(Nℓ ) to obtain an elementγ ∈ O0 such that nr(γ) = Nℓe0. Sets e1 = e− e0 ∈ N.5. Finds the projective point (C0 : D0) ∈ P1(Z / NZ) ← IdealModConstraint(L, γ) satisfy-ing γµ0 ∈ L where µ0 = (C0 + ωD0)j ∈ Rj.6. Chooses δ ∈ O0 with gcd(nr(δ), Nτ ) = 1 and runs the algorithm EichlerModConstraint(Z+Iτ , γ, δ) on input the ideal Z+Iτ of norm Nτ and elements γ, δ ∈ O0 of norms coprimeto Nτ to find the projective point (C1 : D1) ∈ P1(Z / NτZ) satisfying γµ1δ ∈ Z + Iτwhere µ1 = (C1 + ωD1)j ∈ Rj.7. Computes C ← CRTN,Nτ (C0, C1) where C is the solution modulo NNτ to the systemof congruences C ≡ C0 (mod N) and C ≡ C1 (mod Nτ ) and D ← CRTN,Nτ (D0, D1)where D is the solution modulo NNτ to the system of congruences D ≡ D0 (mod N)and D ≡ D1 (mod Nτ ). If ℓep(C2 + D2) is not a quadratic residue, go back to Step 4and repeat the process.8. Executes the algorithm StrongApproximationℓ⋆(NNτ , C,D) to generate µ ∈ O0 of normℓe1 where ℓ⋆ = {ℓα : α ∈ N}.9. Sets β = γµ, obtains the (O ,O )-ideal χL(β) = (See Lemma 1) andthe (O,O2)- ideal J = [Iτ ]∗χL(β) by using pushforward of the ideal χL(β) by the(O0,O)-ideal Iτ .0. The algorithm then returns the ideal J ∼ I.Correctness. Step 5 and Step 8 ensure β ∈ L whereas Step 6 ensures β ∈ Z + Iτ . Also,we have, which implies nr(J) = nr([Iτ ]∗χL(β)) =nr(β) Nℓe= ℓe. Also, Lemma 2 app β̄ ′′ ′ β̄ ′ δ̄β̄nr(L)= Nlied to χL(β) = Lnr(L) = χK (δ )nr(L) = Knr(K′) nr(L) βδ′= χ ( nr(L)) implies that ∼ [Iτ ]∗K . This proves J ∼ K and we alsoK ∼ I, which implies J ∼ I.Remark 1.1: Taking into account an attack on the security of SQISign, a few changeshave been made to the SigningKLPT algorithm to mitigate the attack. They have pre-sented a variant of RepresentInteger algorithm (which they call it FullRepresentInteger) thatis believed to return well-distributed solutions in O0, unlike the algorithm RepresentIntegerthat solves norm equations inside a suborder Z^i, j^ of O0 thereby excluding many poten-tial solutions. They have also modified the StrongApproximation algorithm to FullStrongApproximationthat returns well-distributed solutions in O0.2 The Proposed Ring Signature SchemeIn this section, we propose our isogeny-based ring signature based on SQISign.Setup(1λ) → PP: A trusted authority runs this algorithm on input a security parameter1λ and performs the following steps:– Chooses a prime p and fixes a base supersingular elliptic curve E0 given by y2 = x3 +xover with endomorphism ring O0 = ^1, i, –Picks a smooth number D = 2e where 2e > p3.– Picks an odd smooth number D = ℓe where e−1c ℓ is a prime and µ(Dc) = (ℓ + 1) · ℓ .– Samples a cryptographic hash function H : {0, –Samples an arbitrary function mapping the elliptic curve E and an integert ∈ [1, µ(D )] to ec a member of Z / ℓ Z.– Sets the public parameter PP = {p, E0, Dc, D,H, f}.KeyGen(PP) → (SKi,VKi): On input PP, each user Ui for i ∈ [N−1] executes the followingsteps to generate its signing and verification key pair (SKi,VKi):– Picks a random isogeny walk τ (i)i : E0 → EA .– Sets the signing key SK = τ and verificatio (i)i i n key VKi = EA . The user publishes itsverification key VKi while keeps SKi secret to itself.Sign(PP, SKs, R,msg) → Σ: The signing algorithm is executed by some signer Us thatemploys its signing key SKs = τs to generate a signature on the message msg with respectto the ring R = {VK0,VK1, ... ,VKN−1}. It proceeds as follows:– Picks a random (secret) isogeny ψ (s)s : E0 → E1 .– For i = s, ... , N − 1, 0, ... , s− 2, the signer executes the following steps:• i′ = i + 1 (mod N).• Picks a random isogeny (i′) (i′) : E A → E 2 of degree D, leading to a randomcurve E(i′) 2 . •Evaluates the hash function H to obtain ti′ = H(R, j(E(i)1 ),msg).• Computes •Computes the canonical basis {Pi′ , Qi′} that generates E(i′) 2 [ℓe]. •Computes the subgroup ′ = ^Pi′ +ki′Qi′^ of E(i′) 2and then computes theϕ̂′ : E(i′) (i′) 2 E 1 with kernel ′ using Vélu’s– Evaluates the hash function H to obtain t ),msg)– Samples an element k′ random es ly from Z / ℓ Z.– Computes the canonical basis {P ′, Q′s} that generates the subgroup [ℓe] –Computes the subgroup K ′ = and then computes the isogenyϕ with kernel K ′s using Vélu’s– Computes the dual isogeny ϕ̂ (s)(s) s: E2 → E 1 and then computes its kernel Ks, asubgroup of E(s)2 .– Computes f(E(s)2 , t es) = ks ∈ Z / ℓ Z.– Computes {Ps, Qs} in E(s)2 [ℓe] that satisfies Ks = ^Ps + ksQs^.– Employs its signing key SK = τ (s)(s) ss to compute an isogeny σs : EA → E 2 of degreeD leveraging the SigningKLPT algorithm described in Section 1.5 such that ϕ̂s ◦ σs iscyclic. –Outputs the ring signature Σ = {t N−10, σ0, σ1, ... , σN−1, {Pi, Qi}i=0 }.Verify(PP, R,msg, Σ) → Valid / Invalid: The verification algorithm on input the publicparameter PP, a set of verification key R = {VK0,VK1, ... ,VKN−1}, a message msg and aring signature Σ = } verifies the validity of the signatureΣ on the message msg with respect to the ring R. The steps involved are detailed below:– Retrieves the element t from Σ N−10 = {t0, σ0, σ1, ... , σN−1, {Pi, Qi}i=0 }.– For i = ... , N − 1, the verifier executes the following steps:• Retrieves the isogeny σ (i)(i) i: EA → E 2 from the ring signature Σ.• Checks if σ is an iso (i)(i) igeny from EA → E 2 of degree D. If not, outputs Invalid.• Computes •Computes the subgroup K (i)i = ^Pi + kiQi^ of E2 and then computes the isogenyϕ̂ : E(i) → E(i) i2 1 with kernel Ki.• Checks if ϕ̂i ◦ σi is cyclic. If not, outputs Invalid.• Evaluates the hash function to obtain (i) = H(R, j(E1 ),msg)– Check if tN computed by the verifier is same as the t0 retrieved from the ring signatureΣ. If the check succeeds, outputs Valid, else outputs Invalid.Correctness. To show the correctness of our ring signature RSig it is enough to show thatthe commitment curves E(i)1 computed by the verifier is the same as the ones computedby the signer for all i ∈ [N − 1].– For i ̸= s, this follows immediately as both the signer and the verifier perform thesame steps to compute the commitment curve E(i)1 .– For i = s, this follows from the correctness of computing the unique dual isogeny.Since the points {Ps, Qs} are computed in a manner that it uniquely determines thekernel K = ^Ps + ksQs^ of the dual isogeny this leads the verifier to computesame commitment curve E(s)1 of the signer.A Ring signatureDefinition A.1: A ring signature RSig = (Setup,KeyGen, Sign,Verify) is a tuple of fourprobabilistic polynomial-time algorithms associated with the message space M satisfyingthe following requirements:Setup(1λ) → PP: On input the security parameter 1λ, the setup algorithm outputs thepublic parameter PP and makes it available to all the users.KeyGen(PP) → (SKi,VKi): Each potential user Ui executes this randomized algorithmto generate his pair of signing-verification keys (SKi,VKi).Sign(PP, SKs, R,msg) → Σ: This randomized algorithm is run by some signer Us whowants to compute a signature on behalf of the ring R = {VK0,VK1, ... ,VKN−1}. It takes input the public parameter PP, its signing key SKs, a set of ver-ification keys R and a message msg ∈ M and outputs a ring signature Σ. We requirethat (SKs,VKs) is a valid key-pair output by KeyGen and that VKs ∈ R.Verify(PP, R,msg, Σ) → Valid / Invalid: This deterministic algorithm takes as input thepublic parameter PP, a set of verification keys R that constitutes the ring, a messagemsg and a signature Σ and outputs Valid if the signature is valid, or Invalid otherwise.Correctness. For all PP ← Setup(1λ), all (SKi,VKi) ← KeyGen(PP), all message msg ∈M, it must hold that Verify(PP, R,msg, Sign(PP, SKs, R,msg)) = 1.A.1 Security ModelWe review the security model of a ring signature introduced in the prior work. A ringsignature must satisfy two independent notions of security: namely Anonymity and Un-forgeability which are explicitly defined below:Anonymity against partial key exposure: This security attribute ensures that norelevant information about the identity of the signer is revealed to an adversary possessingall the randomness used to generate the secret keys except the one used to generate thesignature. The adversary can only check if a signature is generated by a member of a ringbut cannot learn who the actual signer is. More formally, anonymity is described belowin the experiment ExpP.Anon−bRSig,A between a challenger C and an adversary A:– The challenger C generates the public parameter PP ← Setup(1λ) and executes thealgorithm KeyGen to generate the key pairs (SKi,VKi) for all i ∈ [N−1]. Additionally,it records the random coins used in generating each key pair (SKi,VKi).– The challenger C provides the public parameter PP and verification keys {VK N−1i}i=0 tothe adversary A.– The adversary A outputs a challenge (R,msg, i0, i1) to C where the ring R can includeadversarially generated public keys but it must include VKi0 and VKi1.– The challenger C flips a random bit b ←− $ {0, 1}, computes the signature Σ∗ Sign(PP, SKib , R,msg) and outputs Σ∗ along with the randomness to A.– The adversary A eventually outputs a guess bit b∗. If b∗ = b, C outputs 1, otherwise0.Definition A.2: A ring signature scheme RSig is anonymous against partial key expo-sure if for all PPT adversary A, there exists a negligible function negl(λ) such that forany security parameter λ, negl(λ).Unforgeability with respect to insider corruption: Unforgeability with respectto insider corruption captures the idea that an adversary cannot generate a valid ringsignature without a signing key, even if he can adaptively corrupt some honest membersof a ring and obtain their signing keys. More formally, unforgeability is described belowin the experiment ExpUnfRSig,A between a challenger C and an adversary A:– The challenger C generates the public parameter PP ← Setup(1λ) and executes thealgorithm KeyGen to generate the key pairs (SKi,VKi) for all i ∈ [N − 1]. It alsoinitializes the list Slist of signing queries and the list Clist of corrupted users as Slist ←∅, Clist ← ∅.– The challenger C provides the public parameter PP and verification keys {VK N−1i}i=0 tothe adversary A.– The challenger C responds to polynomial many adaptive queries made by A in thefollowing manner:• Sign queries to (i,msg, R): Upon receiving a signing query on (i,msg, R),C checks if VKi ∈ R. If the check succeeds, it computes the signature Σ ←Sign(PP, SKi, R,msg) and provides Σ to A. Moreover, C adds (i,msg, R) to Slistto maintain a list of signing queries made by A.• Corrupt queries to oracle OCorrupt(i): Upon receiving a corrupt query on some indexi, the challenger adds i to Clist and outputs the signing key SKi corresponding tothe index i to A.– Eventually, A outputs a tuple (R∗,msg∗, Σ∗). The challenger outputs 1 if the tuple(R∗,msg∗, Σ∗) satisfies (i) R∗ ⊆ {VK N−1 ∗ ∗i}i=0 \ Clist, (ii) (i,msg , R ) Slist for anyindex i, (iii) Verify(PP, R∗,msg∗, Σ∗) = 1. Otherwise, it outputs 0.Definition A.3: A ring signature scheme RSig is unforgeable with respect to insidercorruption if for all PPT adversary A, there exists a negligible function negl(λ) such thatfor any security parameter λ, negl(λ)B SQISign: an isogeny-based signature schemeWe shall now discuss how one can build the signature scheme SQISign based on secretknowledge of the endomorphism ring leveraging SigningKLPT algorithm. The signaturescheme comprises of four PPT algorithms Setup, KeyGen, Sign, Verify that works as fol-lows:Setup(1λ) → PP: A trusted authority runs this algorithm on input a security parameter1λ and performs the following steps:– Chooses a prime p and fixes a base supersingular elliptic curve E 2 30 given by y = x +xover Fp2. This elliptic curve is known to have special extremal endomorphism ringO0 = ^1, i, i+j1+k 2, 2^. –Picks a smooth number D = 2e where 2e > p3.– Picks an odd smooth number D = ℓe where ℓ is a prime and µ(D ) = (ℓ + 1) · e−1c c ℓ .– Samples a cryptographic hash function H : {0, 1}∗ → [1, µ(Dc)].– Samples an arbitrary function ΦDc(E, s) that maps integers s ∈ [1, µ(Dc)] to a non-backtracking isogeny of degree Dc from E.– Sets the public parameter PP = {p, E0, Dc, D,H, ΦDc}.KeyGen(PP) → (SK,VK): On input the public parameter PP, the key generation algorithmgenerates a signing-verification key pair (SK,VK) as follows:– Picks a random isogeny walk τ : E0 → EA, leading to a random elliptic curve EA.– Sets the signing key SK = τ and verification key VK = EA.Sign(PP, SK,msg) → Σ: Taking input the public parameter PP, signing key SK and amessage msg, the signer generates a signature Σ on msg by following the steps givenbelow: –Picks a random isogeny ψ : E0 → E1.– Evaluate the hash function to obtain s = H(j(E1),msg) and compute the challengeisogeny ΦDc(E1, s) = φ : E1 → E2.– Computes the idea Īτ , Iψ, Iφ corresponding to their respective isogenies τ̂ , ψ, φ.– The signer having the knowledge of O = End(EA) through τ and O2 = End(E2)through φ ◦ ψ, executes the SigningKLPT2e I) algorithm described in Section 1.5on input the (O0,O) connecting ideal Iτ and a left O-ideal I = IφIψ Īτ to obtain a(O,O2) connecting ideal J ∼ I of norm D = 2e.– It constructs the isogeny σ : EA → E2 corresponding to the ideal J , of degree D suchthat φ̂ ◦ σ is cyclic. The signature is the pair Σ = (E1, σ).Verify(PP,VK,msg, Σ) → Valid / Invalid: This is a deterministic algorithm in which theverifier verifies the validity of signature Σ = (E1, σ) on the message msg. It proceeds asfollows: –Evaluates the hash function to compute s = H(j(E1),msg) and then recover theisogeny ΦDc(E1, s) = φ : E1 → E2.– Checks if σ is an isogeny from EA to E2 and that φ̂ ◦ σ is cyclic.– If all the check succeeds return Valid, otherwise return Invalid.B.1 Security Aspect of SQISign.The SQISign signature scheme is obtained by applying the Fiat–Shamir transformationto an interactive identification scheme. De Feo et al. proved the soundness of their identi-fication scheme under the hardness of the Supersingular Smooth Endomorphism Problemdefined below:Problem 1: Given a prime p and a supersingular elliptic curve E over Fp2 , find a (non-trivial) cyclic endomorphism of E of smooth degree.In the prior work, this Supersingular Smooth Endomorphism Problem is shown to beequivalent to the Endomorphism Ring Problem defined below:Problem 2: Given an elliptic curve E over Fp2 , compute endomorphisms forming aZ-basis of End(E).In order to prove the zero knowledge of the identification scheme underlying SQISign,the authors resort to a computational assumption that formalises the idea that the isogenyσ corresponding to the ideal J returned by the SigningKLPT algorithm is indistinguishablefrom a random isogeny of the same degree. Before defining the problem formally, we shallanalyze the structure of the isogeny σ.Lemma B.1: Consider the ideal L and element β ∈ L computed as in steps 3, 9 respec-tively of the algorithm SigningKLPT described in Section 1.5. The isogeny σ correspondingto the output J of SigningKLPT algorithm is equal to σ = [τ ]∗ι where ι is an isogeny ofdegree ℓe satisfying β = ι̂ ◦ φL.We recall the following notations before defining the (computationally) indistinguishableproblem underlying the security of SQISign.: For a given ideal L of norm N , UL,Nτ denotes the set of all isogenies ι computed inLemma B.1 from elements β = γµ ∈ L where γ is any possible output of the algorithmRepresentIntegerO0 and µ is computed by algorithm StrongApproximation in Step 8 ofSigningKLPT. PNτ : We define PNτ =⋃ C∈Cl(O) UC,Nτ where we write UC,Nτ for UL,Nτ where L ←EquivalentPrimeIdeal(C) for an equivalence class C in the ideal class group Cl(O0) ofO0. IsoD,j(E): Denotes the set of cyclic isogenies of degree D whose domain is a curve insidethe isomorphism class of E.[τ ]∗P : Denotes the subset | φ ∈ P} of IsoD,j(E0) where P is a subset of and τ : E → E0 is an isogeny with gcd(deg(τ), D) = 1.K: a probability distribution on the set of cyclic isogenies whose domain is E0, repre-senting the distribution of SQISign private keys.Problem 3: Let p be a prime and D be a smooth integer. Let τ : E0 → EA be a randomisogeny drawn from K and let Nτ be its degree. Let Oracleτ be an oracle sampling randomelements in . Let σ be an isogeny of degree D whose domain curve is E. Givenp,D,K, EA, η and a polynomial number of queries to Oracleτ , it is hard to determinewhere1. whether σ is uniformly random in 2. or σ is uniformly random Informally speaking, the problem states that the ideals output by the quaternion-path-finding algorithm SigningKLPT are indistinguishable from uniformly random idealsof the same norm. They provided evidence for the assumption by showing that the outputof SigningKLPT is uniformly distributed in an exponentially large set whose size does notdepend on the secret.The security of SQISign signature was further investigated in a recent paper by De Feoet. al. They designed a distinguisher against the computational assumption (Problem 3)used in SQISign. To impede the distinguisher they have incorporated a few modificationsto the SigningKLPT highlighted in Remark 1.1.SYSTEM IMPLEMENTATIONSReferring to FIG. 1, the isogeny-based cryptographic scheme involves several key com-ponents, including elliptic curves and isogenies. The elliptic curves include a base ellipticcurve, a commitment curve, and a challenge curve. The isogenies include a commitmentisogeny, a challenge isogeny, a secret isogeny, and a response isogeny.In some aspects, the base elliptic curve E0 serves as the starting point for the scheme.From E0, the commitment isogeny leads to the commitment curve E1. The challengeisogeny then connects E1 to the challenge curve E2. Separately, the secret isogeny connectsthe base curve E0 to an unlabeled curve EA. The response isogeny then connects EA tothe challenge curve E2, completing the cryptographic operation.The layout of the diagram emphasizes the relationships between the different curvesand isogenies, illustrating the flow of the cryptographic process from the base curve tothe challenge curve through various intermediate steps. The isogenies are maps betweenelliptic curves that preserve their group structure, and the difficulty of computing certainisogenies forms the basis for the security of these cryptosystems.SETUP ALGORITHM AND PUBLIC PARAMETERSIn the disclosed method and system, a setup algorithm is executed on a securityparameter to establish public parameters. The public parameters include at least onebase elliptic curve E0. The base elliptic curve E0 is fixed by the setup algorithm and isincluded in the public parameters. The public parameters are denoted as PublicParamsand are set to E0. The base elliptic curve E0 serves as the starting point for the isogeny-based cryptographic scheme and is used in the generation of key pairs for each user.KEY GENERATION FOR THE ISOGENY-BASED RING SIGNATURE SCHEMEReferring to FIGS. 2A-2B, the key generation process for the isogeny-based ring sig-nature scheme is depicted. In this process, each user in the system generates a uniquekey pair, which consists of a signing key and a verification key. The signing key and veri-fication key are derived from isogenies and elliptic curves, providing a strong foundationfor the security of the ring signature scheme.In some aspects, the key generation algorithm selects a random isogeny from the baseelliptic curve E0 to a user-specific elliptic curve E(i)A . This random isogeny walk from E0to E(i)A forms the basis for the signing key SKi for each user. The signing key SKi is setto τ , capturing the information ab (i)i out the isogeny walk from E0 to EA . This signingkey is kept secret by the user and is used in the signing algorithm to generate the ringsignature. In addition to the signing key, the key generation algorithm also generates a verifi-cation key V Ki for each user. The verification key V Ki corresponds to the user-specificelliptic curve E(i)A , which is the endpoint of the isogeny walk from E0. The verificationkey V Ki is made public and is used in the verification algorithm to verify the validity ofthe ring signature.In summary, the key generation process in the isogeny-based ring signature schemeinvolves the generation of signing and verification key pairs for each user, with eachkey pair comprising a signing key derived from a random isogeny walk from the baseelliptic curve to a user-specific elliptic curve, and a verification key corresponding to theuser-specific elliptic curve. This process provides a robust and secure foundation for thegeneration and verification of ring signatures in the system.SIGNING ALGORITHM FOR THE ISOGENY-BASED RING SIGNATURE SCHEMEContinuing with the description of the signing algorithm for the isogeny-based ringsignature scheme, the signer, denoted as Us, employs its signing key SKs to generate aring signature. The signing algorithm involves several steps, including the selection of arandom isogeny, the computation of various values and isogenies for each user in the ring,and the computation of signer-specific isogenies and subgroups.In some aspects, the signer selects a random isogeny ψs : E0 This isogenymaps the base elliptic curve E0 to an intermediate elliptic curve E(s)1 . The selection ofthis random isogeny forms the first step in the signing algorithm and sets the stage forthe subsequent computations.For each user in the ring, denoted by i = s, ... , N −1, 0, ... , s−2, the signer executea series of computations. First, the signer picks a random isogeny′ ′s(i) (i ) : E A → E 2offixed degree. This isogeny maps the user-specific elliptic curve E(i′)to another ellipticurve E i′A c() 2 . Next, the signer computes a scalar value ki′ based on the message msg, the elcurve E i)1 , and the elliptic curve E(i′liptic() 2. This scalar value is computed using a functionf(E, t), which maps the elliptic curve E and an additional input to a scalar from Z / ℓeZ.The signer then computes a canonical basis {Pi′ , Qi′} that generates the torsion sub-group of E(i′). This basis consists of two points P ′ and on the e(i′) 2i lliptic curve E 2. Using the computed scalar value and the basis points Pi′ and Qi′ , the signercomputes the subgroup = ^P ′ + k ′ ′ (i′) i i Qi ^ of E 2 . This subgroup is generated bylinear combination of the basis points Pi′ and Qi′ with the scalar value ki′ .Finally, the signer computes the isogeny ϕ̂i′ : E(i′) (i′) 2→ E 1 with kernel Ki′s the elliptic curve E′. This isogenymap (i) (i′) 2to the elliptic curve E 1 and its kernel is the computedsubgroup Ki′ .In summary, the signing algorithm for the isogeny-based ring signature scheme involvesthe selection of a random isogeny, the computation of various isogenies, scalar values, basispoints, and subgroups for each user in the ring. These computations form the basis for thegeneration of the ring signature, providing a robust and secure method for anonymousauthentication in cryptographic systems.SIGNING ALGORITHM: COMPUTATION OF SIGNER-SPECIFIC ISOGENIES,SUBGROUPS, AND KERNELSContinuing with the description of the signing algorithm for the isogeny-based ringsignature scheme, the signer computes additional isogenies, subgroups, and kernels thatare specific to the signer. These computations can be used for the generation of the ringsignature and contribute to the security and anonymity of the scheme.In some aspects, the signer evaluates the hash function H on the message msg, theelliptic curve and the ring R to obtain a scalar value ts. This scalar value iscomputed using the hash function H, which takes as input the message msg, the ellipticcurve E(s−1)1 , and the ring R. The scalar value ts is used in subsequent computations inthe signing algorithm.Next, the signer samples an element k′s randomly from the set Z / ℓeZ. This randomelement k′s is used in the computation of a subgroup of the elliptic curve E(s) 1 . The signer then computes a canonical basis {P ′ ′s, Qs} that generates the torsion sub-group of the elliptic curve E(s)1 . This basis consists of two points P ′s and Q′s on the ellipticcurve E(s)1 . The computation of this canonical basis can be used for the generation of asubgroup of the elliptic curve E(s)1 .Using the computed random element k′ and the bas ′ ′s is points Ps and Qs, the signercomputes the subgroup K ′ = ^P ′ + k′Q′^ of the elliptic cu(s) ss s s rve E 1 . This subgroup isgenerated by the linear combination of the basis points P ′ a ′s nd Qs with the randomelement k′s.The signer then computes the isogeny ϕs : E(s)1 → E(s) 2with kernel K ′s. This isogenymaps the elliptic curve E(s)1 to another elliptic curve E(s) 2, and its kernel is the computedsubgroup K ′s.In summary, the signing algorithm for the isogeny-based ring signature scheme involvesthe computation of signer-specific isogenies, subgroups, and kernels. These computationscan form a part of the signing algorithm and contribute to the generation of the ring sig-nature. The resulting ring signature provides a robust and secure method for anonymousauthentication in cryptographic systems.SIGNING ALGORITHM: DERIVATION OF THE FINAL ISOGENY AND OUT-PUT OF THE RING SIGNATUREContinuing with the description of the signing algorithm for the isogeny-based ringsignature scheme, the signer performs additional computations to derive the final isogenyand output the ring signature. These computations involve the use of the signer’s signingkey and the previously computed values, and they contribute to the generation of thering signature, which provides a robust and secure method for anonymous authenticationin cryptographic systems.In some aspects, the signer computes a dual isogeny ϕ̂ (s)s : E2 This dualisogeny maps the elliptic curve E(s) bac(s) 2k to the elliptic curve E 1 . The computation ofthis dual isogeny can be a step in the signing algorithm, as it allows the signer to derivethe kernel of the isogeny, which is used in subsequent computations.Next, the signer computes the kernel Ks of the dual isogeny ϕ̂s. The kernel Ks isa subgroup of the elliptic curve E(s)2 that is annihilated by the dual isogeny ϕ̂s. Thecomputation of this kernel is a key step in the signing algorithm, as it provides thenecessary information for the computation of the final isogeny.The signer then computes a scalar value ks from the message msg, the elliptic curveE(s−1) 1, and the elliptic curve E(s) 2. This scalar value is computed using a function f(E, t),which maps the elliptic curve E and an additional input to a scalar from Z / ℓeZ. Thecomputation of this scalar value can be used for the generation of the final isogeny, as itdetermines the structure of the isogeny.The signer then computes a set of points {Ps, Qs} in E(s)2 that satisfies the equationKs = ^Ps + ksQs^. This set of points forms a basis for the subgroup Ks of the ellipticcurve E(s)2 . The computation of this basis is a key step in the signing algorithm, as itprovides the necessary information for the computation of the final isogeny.Finally, the signer computes the isogeny σ(s) s E 2 . This isogeny maps theuser-specific elliptic curve E(s)(s) Ato the elliptic curve E 2 . The computation of this isogenyforms the final step in the signing algorithm and results in the generation of the ringsignature. In summary, the signing algorithm for the isogeny-based ring signature scheme involvesthe computation of a dual isogeny, the computation of a kernel of the dual isogeny, thecomputation of a scalar value, the computation of a basis for a subgroup of an ellipticcurve, and the computation of a final isogeny. The output of the signing algorithm is aring signature comprising the computed isogenies and basis points. This ring signatureprovides a robust and secure method for anonymous authentication in cryptographicsystems. VERIFICATION ALGORITHM FOR THE ISOGENY-BASED RING SIGNATURESCHEME The disclosed method and system also include a verification algorithm for the isogeny-based ring signature scheme. This algorithm is executed by a verifier and involves parsingthe ring signature, performing a series of verification steps for users in the ring, anddetermining the validity of the ring signature. The verification algorithm provides a robustand secure method for verifying the authenticity of the ring signature, thereby ensuringthe integrity of the cryptographic system.In some aspects, the verifier retrieves an element t0 from a ring signature constructedas Σ = This ring signature comprises computed isogenies σi andbasis points {Pi, Qi} for each user in the ring. The element t0 is a scalar value that isused in subsequent computations in the verification algorithm.The verifier also retrieves and stores the function f and the hash function H from thepublic parameters PP = {p, E0,H, f}. These functions are used in the computation ofscalar values and the evaluation of the hash function in the verification algorithm.For each user in the ring, denoted by i = 0, 1, ... , N − 1, the verifier executes a seriesof verification steps. First, the verifier retrieves an isogeny E(i) from thesignature Σ. This isogeny maps the user-specific elliptic curve E(i)A to another ellipticcurve E(i)2 .The verifier then checks if σi is an isogeny from E(i)A → E(i) 2of fixed degree. If σi is notan isogeny of fixed degree, the verifier outputs Invalid, indicating that the ring signatureis not valid.Next, the verifier computes a scalar value ki from the message msg, the elliptic curveE(i−1) 1, and the elliptic curve E(i) 2. This scalar value is computed using the function f(E, t),which maps the elliptic curve E and an additional input to a scalar from Z / ℓeZ.The verifier then computes the subgroup K = ^P + (i)i i kiQi^ of the elliptic curve E2 .This subgroup is generated by the linear combination of the basis points P and the scalar value ki.The verifier also computes the isogeny ϕ̂ (i)(i) i: E2 → E 1 with kernel Ki. This isogenymaps the elliptic curve E(i) back to the elliptic curve , and its kernel is thesubgroup Ki.The verifier then checks if is cyclic. ◦ σi is not cyclic, the verifierInvalid, indicating that the ring signature is not valid.Finally, the verifier evaluates the hash function H on the message msg, the ellipticcurve E(i)1 , and the ring R to obtain a scalar value ti+1. This scalar value is used insubsequent computations in the verification algorithm.After performing these verification steps for each user in the ring, the verifier checksif tN , as computed by the verifier, is the same as the t0 retrieved from the ring signatureΣ. If the check succeeds, the verifier outputs Valid, indicating that the ring signatureis valid. Otherwise, the verifier outputs Invalid, indicating that the ring signature is notvalid. In summary, the verification algorithm for the isogeny-based ring signature schemeinvolves parsing the ring signature, performing a series of verification steps for each userin the ring, and determining the validity of the ring signature. This algorithm providesa robust and secure method for verifying the authenticity of the ring signature, therebyensuring the integrity of the cryptographic system.SIGNING ALGORITHM: COMPUTATION OF IDEALS AND FINAL ISOGENYContinuing with the description of the signing algorithm for the isogeny-based ringsignature scheme, the signer performs additional computations involving ideals and iso-genies. These computations can be used for the generation of the final isogeny and thering signature, contributing to the security and anonymity of the scheme.In some aspects, the signer computes ideals corresponding to the isogenies τŝ, ψs, andThese ideals, denoted as Īτs , Iψs , and Iφs , are mathematical constructs in the realm ofquaternion algebras that correspond to the isogenies in the elliptic curve world. The com-putation of these ideals forms a key step in the signing algorithm, as it provides a bridgebetween the geometric world of elliptic curves and the arithmetic world of quaternionalgebras. Next, the signer computes an ideal J that is equivalent to the ideal I = ĪτsIψsIφs .This ideal J is computed using the properties of quaternion algebras and the ideals Īτs ,Iψs , and Iφs . The computation of this ideal can be a step in the signing algorithm, as itprovides the necessary information for the computation of the final isogeny.Finally, the signer computes the isogeny σ :(s) s → E 2 corresponding to the idealJ . This isogeny maps the user-specific elliptic curve E(s)(s) Ato the elliptic curve E 2 . Thecomputation of this isogeny forms the final step in the signing algorithm and results inthe generation of the ring signature.In summary, the signing algorithm for the isogeny-based ring signature scheme in-volves the computation of ideals corresponding to isogenies, the computation of an idealequivalent to the product of other ideals, and the computation of a final isogeny corre-sponding to the computed ideal. The output of the signing algorithm is a ring signaturecomprising the computed isogenies and basis points. This ring signature provides a robustand secure method for anonymous authentication in cryptographic systems.VERIFICATION ALGORITHM: COMPUTATION OF SUBGROUPS, ISOGENIES,AND CYCLICITY CHECKSContinuing with the description of the verification algorithm for the isogeny-basedring signature scheme, the verifier performs additional computations involving subgroups,isogenies, and cyclicity checks. These computations can be used for the verification of thering signature and contribute to the security and integrity of the cryptographic system.In some aspects, the verifier computes the subgroup Ki = ^Pi + kiQi^ of the ellipticcurve E(i)2 . This subgroup is generated by the linear combination of the basis points Piand Qi with the scalar value ki. The computation of this subgroup forms a key step inthe verification algorithm, as it provides the necessary information for the computationof the isogeny Next, the verifier computes the isogeny : E(i)2 → E(i) 1with kernel Ki. Thismaps the elliptic curve E(i)2 back to the elliptic curve E(i) 1, and its kernel is the computedsubgroup Ki. The computation of this isogeny can be a step in the verification algorithm,as it allows the verifier to check the cyclicity of the composition of the isogenies ϕ̂i andσi. Finally, the verifier checks if is cyclic. If ϕ̂i ◦σi is not cyclic, the verifier outputsInvalid, indicating that the ring signature is not valid. If ϕ̂i ◦ σi is cyclic, the verifiercontinues with the next steps of the verification algorithm.In summary, the verification algorithm for the isogeny-based ring signature schemeinvolves the computation of subgroups of elliptic curves, the computation of isogenieswith specific kernels, and the verification of the cyclicity of the composition of isogenies.These computations provide a robust and secure method for verifying the authenticity ofthe ring signature, thereby ensuring the integrity of the cryptographic system.VERIFICATION ALGORITHM: COMPUTATION OF SCALAR VALUES AND FI-NAL VALIDITY CHECKContinuing with the description of the verification algorithm for the isogeny-based ringsignature scheme, the verifier performs additional computations involving scalar valuesand a final validity check. These computations can be used for the verification of the ringsignature and contribute to the security and integrity of the cryptographic system.In some aspects, the verifier evaluates the hash function H on the message msg, theelliptic curve E(i)1 , and the ring R to obtain a scalar value ti + 1. This scalar value iscomputed using the hash function H, which takes as input the message msg, the ellipticcurve E(i)1 , and the ring R. The computation of this scalar value is a key step in theverification algorithm, as it provides the necessary information for the final validity checkof the ring signature.Finally, the verifier checks if as computed by the verifier, is the same as the t0retrieved from the ring signature Σ. If the check succeeds, the verifier outputs Valid, indi-cating that the ring signature is valid. Otherwise, the verifier outputs Invalid, indicatingthat the ring signature is not valid.In summary, the verification algorithm for the isogeny-based ring signature schemeinvolves the computation of scalar values based on the message, elliptic curves, and thering, and a final validity check comparing the computed scalar value with the scalarvalue retrieved from the ring signature. These computations provide a robust and securemethod for verifying the authenticity of the ring signature, thereby ensuring the integrityof the cryptographic system.DESCRIPTION OF THE ANONYMOUS SIGNATURE SYSTEMReferring to FIG. 3, the anonymous signature system 1 is depicted. The system 1comprises several interconnected apparatuses that communicate through a communica-tion network 50. These apparatuses include a signature generation apparatus 10, ananonymous signature generation apparatus 20, a signature verification apparatus 30, anda system parameter generation apparatus 40. Each of these apparatuses includes key unitsthat perform specific functions in the generation and verification of the isogeny-based ringsignature. The signature generation apparatus 10 includes a key generation unit 110 and asignature generation unit 120. The key generation unit 110 is responsible for generatingsigning and verification key pairs for each user in the system. The signature generationunit 120 uses the signing key to generate a ring signature on behalf of a user.The anonymous signature generation apparatus 20 contains a setup unit 210 and ananonymization unit 220. The setup unit 210 executes the setup algorithm to establishpublic parameters, including the base elliptic curve E0. The anonymization unit 220processes the ring signature generated by the signature generation unit 120 to producean anonymous ring signature.The signature verification apparatus 30 includes a verification unit 310. The verifica-tion unit 310 verifies the anonymous ring signature generated by the anonymous signaturegeneration apparatus 20. It checks the validity of the ring signature by performing a seriesof computations and checks as described in the verification algorithm.The system parameter generation apparatus 40 includes a system parameter gen-eration unit 410. This unit generates system parameters used by other components ofthe system. These parameters include the base elliptic curve E0 and other parametersrequired for the isogeny-based ring signature scheme.All these components are connected via the communication network 50, allowing forthe exchange of information between the different apparatuses. The network 50 enablesthe system parameter generation apparatus 40 to distribute parameters, the signaturegeneration apparatus 10 to send signatures, the anonymous signature generation appara-tus 20 to process and anonymize signatures, and the signature verification apparatus 30to receive and verify signatures.In some aspects, the anonymous signature system 1 may be implemented on a com-puter system or a network of computer systems. The system 1 may be used in variousapplications where anonymous authentication is required, such as in blockchain systems,secure voting systems, and confidential transactions in cryptocurrencies.FUNCTIONALITY AND INTERACTIONS OF THE SIGNATURE GENERATIONAPPARATUS Referring to FIG. 3, the signature generation apparatus 10 is a key component ofthe anonymous signature system 1. The signature generation apparatus 10 includes akey generation unit 110 and a signature generation unit 120. These units work togetherto generate a ring signature on behalf of a user, contributing to the functionality andsecurity of the system.In some aspects, the key generation unit 110 is responsible for generating signing andverification key pairs for each user in the system. The key pairs are generated basedon the public parameters established by the setup algorithm, including the base ellipticcurve E0. The key generation process involves selecting a random isogeny walk from thebase elliptic curve E0 to a user-specific elliptic curve EA(i), setting the signing key SK(i)to the random isogeny, and setting the verification key VK(i) to the user-specific ellipticcurve EA(i). The generated key pairs are then published for each user.The signature generation unit 120 uses the signing key SK(i) to generate a ring signa-ture on behalf of a user. The signature generation process involves several steps, includingthe selection of a random isogeny, the computation of various isogenies, scalar values, ba-sis points, and subgroups for each user in the ring, and the computation of signer-specificisogenies and subgroups. The output of the signature generation unit 120 is a ring signa-ture comprising the computed isogenies and basis points.The signature generation apparatus 10 interfaces with other components of the anony-mous signature system 1 via the communication network 50. The communication network50 enables the exchange of information between the different apparatuses, allowing thesystem parameter generation apparatus 40 to distribute parameters, the signature gen-eration apparatus 10 to send signatures, the anonymous signature generation apparatus20 to process and anonymize signatures, and the signature verification apparatus 30 toreceive and verify signatures.In summary, the signature generation apparatus 10 can play a role in the anonymoussignature system 1 by generating signing and verification key pairs for each user andgenerating a ring signature on behalf of a user. The functionality and interactions ofthe signature generation apparatus 10 contribute to the robustness and security of theisogeny-based ring signature scheme.COMPUTER SYSTEM FOR EXECUTING ISOGENY-BASED RING SIGNATUREALGORITHMS Referring to FIG. 4, a computer system 500 is depicted, which is configured to executethe isogeny-based ring signature algorithms. The computer system 500 includes severalkey components that enable the execution of these algorithms, including a processor 504,a main memory 508, and a communication infrastructure 506.The processor 504 is a central component of the computer system 500. In some aspects,the processor 504 is a computing entity capable of executing instructions to perform aspecific set of operations. The processor 504 may be implemented in hardware, firmware,software, or any combination thereof. The processor 504 is configured to execute in-structions for generating an isogeny-based ring signature. These instructions may includeexecuting a setup algorithm to establish public parameters, generating key pairs for aplurality of users, and executing a signing algorithm by a signer.The main memory 508 is another component of the computer system 500. The mainmemory 508 is a storage device that provides a workspace for the processor 504 to readand write data during the execution of the isogeny-based ring signature algorithms. Themain memory 508 may store the instructions that the processor 504 executes, as well asthe data that the processor 504 processes.The communication infrastructure 506 interconnects the various components of thecomputer system 500, allowing them to communicate and exchange data. The communi-cation infrastructure 506 may include various types of communication links, such as buslines, data lines, address lines, control lines, or any other types of communication linksknown in the art.In some aspects, the processor 504 is also configured to execute instructions for verify-ing an isogeny-based ring signature. These instructions may include executing a verifica-tion algorithm that involves parsing the ring signature, performing a series of verificationsteps for users in the ring, and determining the validity of the ring signature.In summary, the computer system 500 provides a robust platform for executing theisogeny-based ring signature algorithms. The processor 504, the main memory 508, andthe communication infrastructure 506 work together to enable the generation and ver-ification of isogeny-based ring signatures, providing enhanced security in cryptographicsystems. SECONDARY MEMORY AND COMMUNICATION INTERFACES IN THE COM-PUTER SYSTEMReferring to FIG. 4, the computer system 500 includes a secondary memory 510 anda communications interface 524, which play roles in the implementation of the isogeny-based ring signature scheme.The secondary memory 510 is connected to the communication infrastructure 506and provides additional storage capacity for the computer system 500. The secondarymemory 510 includes a hard disk memory 512 and a removable storage drive 514. Thehard disk memory 512 provides a large-capacity, non-volatile storage solution for thecomputer system 500. It can store the instructions for executing the isogeny-based ringsignature algorithms, as well as the data processed by these algorithms.The removable storage drive 514 interacts with a removable storage unit 518, providinga flexible and portable storage solution. The removable storage unit 518 can store theinstructions for executing the isogeny-based ring signature algorithms, allowing theseinstructions to be easily transferred between different computer systems. This featurecan be particularly useful in distributed cryptographic systems, where the isogeny-basedring signature algorithms may need to be executed on multiple computer systems.An interface 520 is also part of the secondary memory 510, which interacts withanother removable storage unit 522. This interface 520 allows the computer system 500to read from and write to the removable storage unit 522, further enhancing the flexibilityand portability of the storage solutions in the computer system 500.The communications interface 524 is connected to the communication infrastructure506 and provides network connectivity for the computer system 500. The communicationsinterface 524 is linked to a communications path 526, which enables communication withremote devices or network entities 528. This feature can be used for the operation ofthe isogeny-based ring signature scheme in a networked environment, as it allows thecomputer system 500 to send and receive ring signatures, as well as to exchange publicparameters and verification keys with other computer systems.In summary, the secondary memory 510 and the communications interface 524 in thecomputer system 500 enable storage, data transfer, and interaction with external devicesfor implementing the isogeny-based ring signature scheme. These components contributeto the robustness and versatility of the computer system 500, making it a suitable platformfor executing the isogeny-based ring signature algorithms.SPECIALIZED PROCESSING UNITS IN THE COMPUTER SYSTEMReferring to FIG. 5, the computer system 900 includes several specialized processingunits that enhance its computational capabilities. These specialized processing units in-clude a graphics processing unit 922, a video processing unit 928, and an audio processingunit 932. These units are connected to a bus 930, which facilitates data and control signaltransmission between the various elements of the computer system 900.The graphics processing unit 922 is a specialized electronic circuit designed to rapidlymanipulate and alter memory to accelerate the creation of images in a frame bufferintended for output to a display device. In some aspects, the graphics processing unit922 may be used to perform computations related to the isogeny-based ring signaturescheme, such as the computation of isogenies, scalar values, basis points, and subgroups.The use of the graphics processing unit 922 for these computations can significantly speedup the execution of the isogeny-based ring signature algorithms, thereby enhancing theefficiency of the system.The video processing unit 928 is a specialized circuit for manipulating video signals.In some cases, the video processing unit 928 may be used to process video data that isinvolved in the isogeny-based ring signature scheme. For instance, the video processingunit 928 may be used to generate visual representations of the elliptic curves and isogeniesused in the scheme, aiding in the understanding and analysis of the cryptographic process.The audio processing unit 932 is a specialized circuit for processing audio signals. Insome aspects, the audio processing unit 932 may be used to process audio data that isinvolved in the isogeny-based ring signature scheme. For example, the audio processingunit 932 may be used to generate audio signals corresponding to the computations per-formed in the isogeny-based ring signature scheme, providing an additional layer of userinteraction and feedback.In summary, the specialized processing units in the computer system 900, includingthe graphics processing unit 922, the video processing unit 928, and the audio processingunit 932, enhance the computational capabilities of the system. These units enable theefficient execution of the isogeny-based ring signature algorithms, providing a robust andhigh-performance platform for the implementation of the isogeny-based ring signaturescheme.
Claims
CLAIMS 1. A computerized method for generating an isogeny-based ring signature, comprising:executing, by one or more processors, a setup algorithm to establish public parametersincluding at least one base elliptic curve E0 stored in a computer memory;generating, by the one or more processors, key pairs for a plurality of users, each keypair comprising a signing key SKi and a verification key V Ki stored in the computermemory; executing, by the one or more processors, a signing algorithm by a signer, comprising:(a) selecting at least one random isogeny ψ (s)s : E0 → E1 ;(b) for users in a ring, iteratively computing and storing in the computer memory:(i) isogenies σi,(ii) scalar values ki,(iii) basis points {Pi, Qi},(iv) subgroups Ki = ^Pi + kiQi^,(v) isogenies ϕ̂i;(c) computing and storing in the computer memory signer-specific isogenies, subgroups,and kernels;(d) deriving a final isogeny σ (s)s : EA(e) outputting, via a computer network interface, a ring signature comprising the com-puted isogenies and basis points;wherein E , E(s) , E(s) A, and E(s) 2are elliptic curves, ψs, σi,and σ areand Pi and Qi are points on the respective elliptic curves.
2. The computerized method of claim 1, wherein at least one isogeny in the signingalgorithm is cyclic.
3. A computerized method for verifying an isogeny-based ring signature, comprising:executing, by one or more processors, a verification algorithm by:(a) parsing a ring signature Σ =received via a computerinterface;(b) for users in a ring:(i) retrieving an isogeny σ (i)(i) i: EA → E 2 from Σ,(ii) verifying properties of σi,(iii) computing scalar values ki,(iv) computing subgroups Ki = ^Pi + kiQi^ and isogenies ϕ̂i,(v) verifying if ϕ̂i ◦ σi is cyclic;(c) determining validity of the ring signature;(d) outputting, via the computer network interface, a result of the validity determination;wherein E(i)A and E(i) 2are elliptic curves, σi and ϕ̂i are isogenies, and Pi and Qi arepoints on the elliptic curve E(i)2 .
4. A computerized system for generating an isogeny-based ring signature, comprising:one or more processors;a computer memory;a computer network interface; anda non-transitory computer-readable medium storing instructions that, when executedby the one or more processors, cause the system to:execute a setup algorithm to establish public parameters including a base elliptic curveE0 and store the public parameters in the computer memory;execute a key generation algorithm to generate key pairs for users, each key paircomprising a signing key SKi and a verification key V Ki, and store the key pairs in thecomputer memory;execute a signing algorithm comprising:(a) selecting at least one random isogeny ψ (s)s : E0 → E1 ;(b) for users in a ring, computing and storing in the computer memory:(i) isogenies<img src='' class="img-anchor img-center" img-id="IMGF000037_0001" / >(ii) scalar values ki,(iii) basis points {Pi, Qi},(iv) subgroups Ki = ^Pi + kiQi^,(v) isogenies ϕ̂i;(c) computing and storing in the computer memory signer-specific isogenies and sub-groups;(d) deriving a final isogeny σ : E(s)<img src='' class="img-anchor img-center" img-id="IMGF000037_0002" / >(e) outputting, via the computer network interface, a ring signature comprising the com-puted isogenies and basis points;wherein E , E(s) , E(s), and E(s) 01 A 2 are elliptic curves, ψs, σi, ϕ̂i, and σs are isogenies,and P and are points on the respective elliptic5. The computerized system of claim 4, wherein at least one isogeny in the signing algo-rithm is cyclic.
6. A computerized system for verifying an isogeny-based ring signature, comprising:one or more processors;a computer memory;a computer network interface; anda non-transitory computer-readable medium storing instructions that, when executedby the one or more processors, cause the system to:execute a verification algorithm comprising:(a) retrieving elements from a ring signature Σ =received via thecomputer network interface;(b) retrieving public parameters from the computer memory;(c) for users in a ring:(i) verifying properties of isogenies σ : E(i)<img src='' class="img-anchor img-center" img-id="IMGF000038_0002" / >(ii) computing scalar values ki,(iii) computing subgroups Ki = ^Pi + kiQi^ and isogenies ϕ̂i,(iv) verifying<img src='' class="img-anchor img-center" img-id="IMGF000038_0003" / >(d) determining validity of the ring signature;(e) outputting, via the computer network interface, a result of the validity determination;wherein E(i)A and E(i) 2are elliptic curves, σ andare isogenies, and Pi and Qipoints on the elliptic curve E(i)<sub>2 .
7. A computerized method for generating an isogeny-based ring signature, the methodcomprising: executing, by one or more processors, a setup algorithm on a security parameter 1λby: fixing a base elliptic curve E0 in a computer memory;setting public parameters PP = {E0} in the computer memory;executing, by the one or more processors, a key generation algorithm to generate asigning and verification key pair (SKi,VKi) for each user of a plurality of users by:selecting a random isogeny τsetting the signing key SK (i)i = τi and verification key VKi = EA in the computermemory; publishing the user verification key VKi for each user Ui to a computer network;executing, by the one or more processors, a signing algorithm by a signer Us thatemploys its signing key SKs by:picking a random isogeny ψ (s)s : E0 → E1 ;for i = s, ... , N − 1, 0, ... , s− 2, the signer executing the steps:i′ = i + 1 (mod N);picking a random isogeny (i′) (i′): E A → E 2storing a ring R as {VK0,VK1, ... ,VKN−1} in the computer memory;computing k ′ based on a message msg, E(i)1 , andcomputing a basis {Pi′ , Qi′} that generates a torsion subgroup of E(i′) 2 ;computing a subgroup Ki = ^Pi′ + ki′ ′^ of E(i′′ ) 2 ; computing an isogeny ϕ̂ (i′< / sup>i′ : E) 2→ with kernel Ki′ ;sampling k′s randomly;computing a basis {P ′, Q′} that generat(s) ss es a torsion subgroup of E 1; computing a subgroup K ′ ′ ′ ′(s) s= ^Ps + ksQs^ of E 1; computing an isogeny ϕ : E(s)(s)′s 1 → E 2 with kernel Ks;computing a dual isogeny ϕ̂ : (s)(s) sE2 → E 1; computing a kernel Ks of ϕ̂s;computing ks from msg,computing {P , Q } in E(s)s s 2 that satisfies Ks = ^Ps + ksQs^;computing an isogeny σ (s)s : EAandoutp a ring signature Σ ={Pi, Q }i=0 } to the computer8. The computerized method of claim 7, wherein the isogeny ϕ̂s ◦ σs is cyclic.
9. A computerized method for verifying an isogeny-based ring signature, the methodcomprising: executing, by one or more processors, a verification algorithm by:parsing a ring signature Σ = {{σ N−1i}i=0 , {Pi, Qi}N−1i=0 } received from a computer net-work; for i = 0, 1, ... , N − 1, executing at a verifier:retrieving an isogeny σ : E(i)(i) iA → E 2 from the ring signature Σ;checking if σ is a (i)(i) in isogeny from EA → E 2 ; if not, outputting Invalid to the computernetwork; computing k from a message msg, , an(i)d E 2computing a subgroupcomputing an isogeny ϕ̂ (i)(i) i: E2 → E 1 with kernel Ki;checking if ϕ̂i ◦ σi is cyclic; if not, outputting Invalid to the computer network; andoutputting Valid to the computer network if all checks passed.
10. A computerized system for generating an isogeny-based ring signature, the systemcomprising: one or more processors;a computer memory; anda computer network interface;wherein the one or more processors are configured to execute instructions for:executing a setup algorithm on a security parameter 1λ by:choosing a prime p;fixing a base supersingular elliptic curve E0 in the computer memory;sampling a cryptographic hash function H;sampling an arbitrary function f(E, t) mapping an elliptic curve E and an additionalinput to a scalar from Z / ℓeZ;setting public parameters PP = {p, E0,H, f} in the computer memory;executing a key generation algorithm to generate a signing and verification key pair(SKi,VKi) for each user of a plurality of users by:selecting a random isogeny walk τ (i)i : E0 → EA ;setting the signing key SK (i)i =and verification key VKi = EA in the computermemory; publishing the user verification key VKi for each user Ui to the computer networkinterface; executing a signing algorithm by a signer Us that employs its signing key SKs by:picking a random isogeny ψ (s)s : E0 → E1 ;for i = s, ... , N − 1, 0, ... , s− 2, the signer executing the steps:i′ = i + 1 (mod N);picking a random isogeny σ (i′< / sup>i′ : E) Aof fixed degree;storing a ring R as {VK0,VK1, ... ,VKN−1} in the computer memory;evaluating the hash function H on a message msg, elliptic curve E(i)1 and ring R toobtain ti′ ;computingcomputing a canonical basis {P (′i′ , Qi′} that generates a torsion subgroup of E i) 2 ; computing a subgroup ′ ′ (i′′ )= ^Pi + ki Qi ^ of E 2computing an isogeny (i′) (i′): E 2 → E 1 with kernel Ki′evaluating the hash function H on msg, elliptic curve E(s−1)1 and ring R to obtain ts;sampling an element k′ ra es ndomly from Z / ℓ Z;computing a canonical basis {P ′s, Q′s} that generates a subgroup E(s) 1 [ℓe]; computing a subgroup K ′s = ^P ′s + k′sQ′s^ of E(s) 1and then computing an isogenykernel K ′s;computing a dual isogeny ϕ̂ (s)(s) s: E2 → E 1 and then computing its kernel Ks;computing= kcomputing {Ps, Qs} in E(s)2 that satisfies Ks = ^Ps + ksQs^;computing ideals Īτs , Iψs and Iφs corresponding to their respective isogenies τŝ, ψsand φs;computing an ideal J equivalent to an ideal I = ĪτsIψsIφs ;computing an isogeny σ : E(s) →(s) sA E 2 corresponding to the ideal J ; andoutputting a ring signature Σ = {t , σ0, σ1,to thenetwork interface.
11. The computerized system of claim 10, wherein the isogeny ϕ̂s ◦ σs is cyclic.
12. A computerized system for verifying an isogeny-based ring signature, the systemcomprising: one or more processors;a computer memory; anda computer network interface;wherein the one or more processors are configured to execute instructions for:executing a verification algorithm by:retrieving an element t0 from a ring signature constructed as Σ =received from the computer network interface;retrieving and storing a function f and a hash function H from public parametersPP = {p, E0,H, f} in the computer memory;for i = 0, 1, ... , N − 1, executing at a verifier:retrieving an isogenyE(i) 2from the ring signature Σ;checking if σ (i)(i) iis an isogeny from EA → E 2 of fixed degree; if not, outputting Invalidto the computer network interface;computing f(E(i)2 , ti) = ki;computing a subgroup K = (i)i ^Pi + kiQi^ of E2 and then computing an isogenykernel Ki;is cyclic; if not, outputting Invalid to the computer network interface;evaluating the hash function H on a message msg, elliptic curve E(i)1 and ring R toobtain ti+1; andchecking if tN as computed by the verifier is same as the t0 retrieved from the ringsignature Σ such that if the check succeeds, the verifier outputs Valid to the computernetwork interface, else the verifier outputs Invalid to the computer network interface.
Citation Information
Patent Citations
Processing batches of point evaluations in a supersingular isogeny-based cryptosystem
US10805081B1
Cryptographically concealing amounts and asset types for independently verifiable transactions
US11080665B1
Elliptic curve random number generation
US20070189527A1
Elliptic curve isogeny-based cryptographic scheme
US20180323973A1
Elliptic curve isogeny based key agreement protocol
US20200014534A1