Benjamin Wesolowski

dblp:162/8958 · DBLP profile ↗
← Back
25ranked-venue papers
4as first author
18since 2021 · last 2026
0000-0003-1249-6077ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 22 · 3 first-author · 15 since 2021Theory of computation · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Average Hardness of SIVP for Module Lattices of Fixed Rank
abstract
The problem of finding short vectors in Euclidean lattices is a central hard problem in complexity theory. The case of module lattices (i.e., lattices which are also modules over a number ring) is of particular interest for cryptography and computational number theory. The hardness of finding short vectors in the asymptotic regime where the rank (as a module) is fixed is supporting the security of quantum-resistant cryptographic standards such as ML-DSA and ML-KEM.
Koen de Boer, Aurel Page, Radu Toma, Benjamin Wesolowski
STOC4
2025 A Complete Security Proof of SQIsign
Marius A. Aardal, Andrea Basso 0002, Luca De Feo, Sikhar Patranabis, Benjamin Wesolowski
CRYPTO (6)5
2025 PEGASIS: Practical Effective Class Group Action using 4-Dimensional Isogenies
Pierrick Dartois, Jonathan Komada Eriksen, Tako Boris Fouotsa, Arthur Herlédan Le Merdy, Riccardo Invernizzi, Damien Robert 0001, Ryan Rueger, Frederik Vercauteren, Benjamin Wesolowski
CRYPTO (1)9
2025 PRISM: Simple and Compact Identification and Signatures from Large Prime Degree Isogenies
Andrea Basso 0002, Giacomo Borin, Wouter Castryck, Maria Corte-Real Santos, Riccardo Invernizzi, Antonin Leroux, Luciano Maino, Frederik Vercauteren, Benjamin Wesolowski
PKC (3)9
2025 Unconditional Foundations for Supersingular Isogeny-Based Cryptography
Arthur Herlédan Le Merdy, Benjamin Wesolowski
TCC (3)2
2024 SQIsign2D-West - The Fast, the Small, and the Safer
Andrea Basso 0002, Pierrick Dartois, Luca De Feo, Antonin Leroux, Luciano Maino, Giacomo Pope, Damien Robert 0001, Benjamin Wesolowski
ASIACRYPT (3)8
2024 Cryptanalysis of Algebraic Verifiable Delay Functions
Alex Biryukov, Ben Fisch, Gottfried Herold, Dmitry Khovratovich, Gaëtan Leurent, María Naya-Plasencia, Benjamin Wesolowski
CRYPTO (3)7
2024 SQIsignHD: New Dimensions in Cryptography
Pierrick Dartois, Antonin Leroux, Damien Robert 0001, Benjamin Wesolowski
EUROCRYPT (1)4
2024 The Supersingular Endomorphism Ring and One Endomorphism Problems are Equivalent
Aurel Page, Benjamin Wesolowski
EUROCRYPT (6)2
2024 Finding orientations of supersingular elliptic curves and quaternion orders
abstract
Abstract An oriented supersingular elliptic curve is a curve which is enhanced with the information of an endomorphism. Computing the full endomorphism ring of a supersingular elliptic curve is a known hard problem, so one might consider how hard it is to find one such orientation. We prove that access to an oracle which tells if an elliptic curve is $$\mathfrak {O}$$ O -orientable for a fixed imaginary quadratic order $$\mathfrak {O}$$ O provides non-trivial information towards computing an endomorphism corresponding to the $$\mathfrak {O}$$ O -orientation. We provide explicit algorithms and in-depth complexity analysis. We also consider the question in terms of quaternion algebras. We provide algorithms which compute an embedding of a fixed imaginary quadratic order into a maximal order of the quaternion algebra ramified at p and $$\infty $$ ∞ . We provide code implementations in Sagemath (in Stein et al. Sage Mathematics Software (Version 10.0), The Sage Development Team, http://www.sagemath.org , 2023) which is efficient for finding embeddings of imaginary quadratic orders of discriminants up to O(p), even for cryptographically sized p.
Sarah Arpin, James Clements, Pierrick Dartois, Jonathan Komada Eriksen, Péter Kutas, Benjamin Wesolowski
Des. Codes Cryptogr.6
2023 Supersingular Curves You Can Trust
Andrea Basso 0002, Giulio Codogni, Deirdre Connolly, Luca De Feo, Tako Boris Fouotsa, Guido Maria Lido, Travis Morrison, Lorenz Panny, Sikhar Patranabis, Benjamin Wesolowski
EUROCRYPT (2)10
2023 New Algorithms for the Deuring Correspondence - Towards Practical and Secure SQISign Signatures
Luca De Feo, Antonin Leroux, Patrick Longa, Benjamin Wesolowski
EUROCRYPT (5)4
2023 A Direct Key Recovery Attack on SIDH
Luciano Maino, Chloe Martindale, Lorenz Panny, Giacomo Pope, Benjamin Wesolowski
EUROCRYPT (5)5
2023 Ideal-SVP is Hard for Small-Norm Uniform Prime Ideals
Joël Felderhoff, Alice Pellet-Mary, Damien Stehlé, Benjamin Wesolowski
TCC (4)4
2022 Orientations and the Supersingular Endomorphism Ring Problem
Benjamin Wesolowski
EUROCRYPT (3)1
2021 Séta: Supersingular Encryption from Torsion Attacks
Luca De Feo, Cyprien Delpech de Saint Guilhem, Tako Boris Fouotsa, Péter Kutas, Antonin Leroux, Christophe Petit 0001, Javier Silva 0001, Benjamin Wesolowski
ASIACRYPT (4)8
2021 The supersingular isogeny path and endomorphism ring problems are equivalent
abstract
We prove that the path-finding problem in isogeny graphs and the endomorphism ring problem for supersingular elliptic curves are equivalent under reductions of polynomial expected time, assuming the generalised Riemann hypothesis. The presumed hardness of these problems is foundational for isogeny-based cryptography. As an essential tool, we develop a rigorous algorithm for the quaternion analog of the path-finding problem, building upon the heuristic method of Kohel, Lauter, Petit and Tignol. This problem, and its (previously heuristic) resolution, are both a powerful cryptanalytic tool and a building-block for cryptosystems. This is an extended abstract of the full article available at http://arxiv.org/abs/2111.01481. This full article will be referred to as “the full version” throughout the text.
Benjamin Wesolowski
FOCS1
2021 Mildly Short Vectors in Cyclotomic Ideal Lattices in Quantum Polynomial Time
abstract
In this article, we study the geometry of units and ideals of cyclotomic rings and derive an algorithm to find a mildly short vector in any given cyclotomic ideal lattice in quantum polynomial time, under some plausible number-theoretic assumptions. More precisely, given an ideal lattice of the cyclotomic ring of conductor m , the algorithm finds an approximation of the shortest vector by a factor exp (Õ(√ m )). This result exposes an unexpected hardness gap between these structured lattices and general lattices: The best known polynomial time generic lattice algorithms can only reach an approximation factor exp (Õ(m)). Following a recent series of attacks, these results call into question the hardness of various problems over structured lattices, such as Ideal-SVP and Ring-LWE, upon which relies the security of a number of cryptographic schemes. N OTE . This article is an extended version of a conference paper [11]. The results are generalized to arbitrary cyclotomic fields. In particular, we also extend some results of Reference [10] to arbitrary cyclotomic fields. In addition, we prove the numerical stability of the method of Reference [10]. These extended results appeared in the Ph.D. dissertation of the third author [46].
Ronald Cramer, Léo Ducas, Benjamin Wesolowski
J. ACM3
2020 SQISign: Compact Post-quantum Signatures from Quaternions and Isogenies
Luca De Feo, David Kohel, Antonin Leroux, Christophe Petit 0001, Benjamin Wesolowski
ASIACRYPT (1)5
2020 Random Self-reducibility of Ideal-SVP via Arakelov Random Walks
Koen de Boer, Léo Ducas, Alice Pellet-Mary, Benjamin Wesolowski
CRYPTO (2)4
2020 Efficient Verifiable Delay Functions
Benjamin Wesolowski
J. Cryptol.1
2019 On the Shortness of Vectors to Be Found by the Ideal-SVP Quantum Algorithm
Léo Ducas, Maxime Plançon, Benjamin Wesolowski
CRYPTO (1)3
2019 Efficient Verifiable Delay Functions
Benjamin Wesolowski
EUROCRYPT (3)1
2017 Short Stickelberger Class Relations and Application to Ideal-SVP
Ronald Cramer, Léo Ducas, Benjamin Wesolowski
EUROCRYPT (1)3
2017 Loop-Abort Faults on Supersingular Isogeny Cryptosystems
Alexandre Gélin, Benjamin Wesolowski
PQCrypto2