SCALLOP: scaling the CSI-FiSh

LD Feo, TB Fouotsa, P Kutas, A Leroux…�- …�conference on public�…, 2023 - Springer
… We present SCALLOP, a new isogeny-based group action on supersingular curves. … In
an attempt to solve the scaling issue of CSI-FiSh, we explore the situation where the quadratic …

[PDF][PDF] SCALLOP: a somewhat scalable effective group action from isogenies

LDFTB Fouotsa, P Kutas, A Leroux, SP Merz, L Panny… - 2024 - simon-philipp.com
… group action that solves the scaling issue of CSI-FiSh … Introduce group action that solves the
scaling issue of CSI-FiShCSI-FiSh: efficient isogeny based signatures through class group …

SCALLOP-HD: group action from 2-dimensional isogenies

M Chen, A Leroux, L Panny�- IACR International Conference on Public�…, 2024 - Springer
… the orientation is what renders the efficiency of SCALLOP bad in comparison to CSI-FiSh. …
security level of SCALLOP. In this line of research, CSI-FiSh was only able to scale to achieve …

[PDF][PDF] A curved path to post-quantum: cryptanalysis and design of isogeny-based cryptography

SP Merz - 2023 - core.ac.uk
… The index-calculus algorithm used in CSI-FiSh to compute … the development of large-scale
quantum computers, the danger … to the parameter generation for the SCALLOP group action. …

A Tightly Secure Identity-Based Signature Scheme from Isogenies

J Chen, H Jo, S Sato, J Shikata�- International Conference on Post�…, 2023 - Springer
… based on the lossy CSI-FiSh signature scheme and give a … , due to the properties of lossy
CSI-FiSh. Moreover, we show that … for SCALLOP is needed, we utilize the lossy CSI-FiSh as the …

Practical robust DKG protocols for CSIDH

S Atapoor, K Baghery, D Cozzo, R Pedersen�- International Conference on�…, 2023 - Springer
… parties can sample a PK of size 4 kB, for CSI-FiSh and CSI-SharK, respectively, 3.4 and 1.7
… while extended DKGs scale linearly with k in every term, structured DKGs only scale with k in …

OPRFs from isogenies: designs and analysis

L Heimberger, T Hennerbichler, F Meisingseth…�- Proceedings of the 19th�…, 2024 - dl.acm.org
… Of independent interest, we report that the Naor-Reingold PRF is nearly constant-time with
respect to the input length when using the lattice reductions of CSI-FiSh. Based on the work …

Efficient Post-Quantum Secure Deterministic Threshold Wallets from Isogenies

P Das, A Erwig, M Meyer, P Struck�- Proceedings of the 19th ACM Asia�…, 2024 - dl.acm.org
… We then instantiate our construction from the isogeny-based signature scheme CSI-FiSh
A potential alternative is SCALLOP [22], which allows for larger parameter sets equivalent to …

Performance Evaluation of Isogeny-Based Digital Signature Algorithms: Introducing FIBS--Fast Isogeny Based Digital Signature

S Kim, Y Lee, K Yoon - 2023 - researchsquare.com
… Recently, SCALLOP was proposed, which tackled the problem of CSI-FiSh, although it requires
… choice of log p, ℓ, and r, the cost per bit of evaluating the CGL hash function is scaled as …

Generating Supersingular Elliptic Curves over� with�Unknown Endomorphism Ring

Y Mokrani, D Jao�- International Conference on Cryptology in India, 2023 - Springer
… using a signature scheme such as CSI-FiSh or SeaSign for proof of … On the other hand,
CSI-FiSh can potentially be both zero-… While recent results presented in the SCALLOP paper [12] …