Christophe Petit 0001

dblp:52/2168-1 · DBLP profile ↗
← Back
42ranked-venue papers
5as first author
21since 2021 · last 2026
0000-0003-3482-6743ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 39 · 5 first-author · 19 since 2021Theory of computation · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Another Look at the Quantum Security of the Vectorization Problem with Shifted Inputs
Paul Frixons, Valerie Gilchrist, Péter Kutas, Simon-Philipp Merz, Christophe Petit 0001, Lam L. Pham
EUROCRYPT (1)5
2025 Code-Based Fully Dynamic Accountable Ring Signatures and Group Signatures Using the Helper Methodology
Rishiraj Bhattacharyya, Sreehari Kollath, Christophe Petit 0001
ACISP (2)3
2025 KLPT2: Algebraic Pathfinding in Dimension Two and Applications
Wouter Castryck, Thomas Decru, Péter Kutas, Abel Laval, Christophe Petit 0001, Yan Bo Ti
CRYPTO (1)5
2025 Computing the Endomorphism Ring of a Supersingular Elliptic Curve from a Full Rank Suborder
Christophe Petit 0001
EUROCRYPT (6)2
2025 Radical 2-Isogenies and Cryptographic Hash Functions in Dimensions 1, 2 and 3
Sabrina Kunzweiler, Luciano Maino, Tomoki Moriya, Christophe Petit 0001, Giacomo Pope, Damien Robert 0001, Miha Stopar, Yan Bo Ti
PKC (3)4
2024 Improved Algorithms for Finding Fixed-Degree Isogenies Between Supersingular Elliptic Curves
Benjamin Bencina, Péter Kutas, Simon-Philipp Merz, Christophe Petit 0001, Miha Stopar, Charlotte Weitkämper
CRYPTO (5)4
2024 Solving the Tensor Isomorphism Problem for Special Orbits with Low Rank Points: Cryptanalysis and Repair of an Asiacrypt 2023 Commitment Scheme
Valerie Gilchrist, Laurane Marco, Christophe Petit 0001
CRYPTO (1)3
2024 Failing to Hash Into Supersingular Isogeny Graphs
abstract
Abstract An important open problem in supersingular isogeny-based cryptography is to produce, without a trusted authority, concrete examples of ‘hard supersingular curves’ that is equations for supersingular curves for which computing the endomorphism ring is as difficult as it is for random supersingular curves. A related open problem is to produce a hash function to the vertices of the supersingular $\ell $-isogeny graph, which does not reveal the endomorphism ring, or a path to a curve of known endomorphism ring. Such a hash function would open up interesting cryptographic applications. In this paper, we document a number of (thus far) failed attempts to solve this problem, in the hope that we may spur further research, and shed light on the challenges and obstacles to this endeavour. The mathematical approaches contained in this article include: (i) iterative root-finding for the supersingular polynomial; (ii) gcd’s of specialized modular polynomials; (iii) using division polynomials to create small systems of equations; (iv) taking random walks in the isogeny graph of abelian surfaces, and applying Kummer surfaces and (v) using quantum random walks.
Jeremy Booher, Ross Bowden, Javad Doliskani, Tako Boris Fouotsa, Steven D. Galbraith, Sabrina Kunzweiler, Simon-Philipp Merz, Christophe Petit 0001, Benjamin Smith 0003, Katherine E. Stange, Yan Bo Ti, Christelle Vincent, José Felipe Voloch, Charlotte Weitkämper, Lukas Zobernig
Comput. J.8
2023 Hidden Stabilizers, the Isogeny to Endomorphism Ring Problem and the Cryptanalysis of pSIDH
Muhammad Imran 0022, Gábor Ivanyos, Péter Kutas, Antonin Leroux, Christophe Petit 0001
ASIACRYPT (3)6
2023 M-SIDH and MD-SIDH: Countering SIDH Attacks by Masking Information
Tako Boris Fouotsa, Tomoki Moriya, Christophe Petit 0001
EUROCRYPT (5)3
2023 Proving knowledge of isogenies: a survey
Ward Beullens, Luca De Feo, Steven D. Galbraith, Christophe Petit 0001
Des. Codes Cryptogr.4
2023 Torsion point attacks on 'SIDH-like' cryptosystems
abstract
Abstract Isogeny‐based cryptography is a promising approach for post‐quantum cryptography. The best‐known protocol following that approach is the supersingular isogeny Diffie–Hellman protocol (SIDH); this protocol was turned into the CCA‐secure key encapsulation mechanism SIKE, which was submitted to and remains in the third round of NIST's post‐quantum standardisation process as an ‘alternate’ candidate. Isogeny‐based cryptography generally relies on the conjectured hardness of computing an isogeny between two isogenous elliptic curves, and most cryptanalytic work referenced on SIKE's webpage exclusively focusses on that problem. Interestingly, the hardness of this problem is sufficient for neither SIDH nor SIKE. In particular, these protocols reveal additional information on the secret isogeny, in the form of images of specific torsion points through the isogeny. This paper surveys existing cryptanalysis approaches exploiting this often called ‘torsion point information’, summarises their current impact on SIKE and related algorithms, and suggests some research directions that might lead to further impact.
Péter Kutas, Christophe Petit 0001
IET Inf. Secur.2
2023 Guest Editorial: Guest Editorial on Cryptanalysis of (NIST PQC) post-quantum proposals
abstract
SCOPUS: ed.j
Ayoub Otmani, Christophe Petit 0001, Mehdi Tibouchi
IET Inf. Secur.2
2022 A New Adaptive Attack on SIDH
Tako Boris Fouotsa, Christophe Petit 0001
CT-RSA2
2022 Stronger bounds on the cost of computing Gröbner bases for HFE systems
Elisa Gorla, Daniela Müller, Christophe Petit 0001
J. Symb. Comput.3
2021 Cryptanalysis of an Oblivious PRF from Supersingular Isogenies
Andrea Basso 0002, Péter Kutas, Simon-Philipp Merz, Christophe Petit 0001, Antonio Sanso
ASIACRYPT (1)4
2021 Séta: Supersingular Encryption from Torsion Attacks
Luca De Feo, Cyprien Delpech de Saint Guilhem, Tako Boris Fouotsa, Péter Kutas, Antonin Leroux, Christophe Petit 0001, Javier Silva 0001, Benjamin Wesolowski
ASIACRYPT (4)6
2021 SHealS and HealS: Isogeny-Based PKEs from a Key Validation Method for SIDH
Tako Boris Fouotsa, Christophe Petit 0001
ASIACRYPT (4)2
2021 Improved Torsion-Point Attacks on SIDH Variants
Victoria de Quehen, Péter Kutas, Chris Leonardi, Chloe Martindale, Lorenz Panny, Christophe Petit 0001, Katherine E. Stange
CRYPTO (3)6
2021 One-Way Functions and Malleability Oracles: Hidden Shift Attacks on Isogeny-Based Protocols
Péter Kutas, Simon-Philipp Merz, Christophe Petit 0001, Charlotte Weitkämper
EUROCRYPT (1)3
2021 SimS: A Simplification of SiGamal
Tako Boris Fouotsa, Christophe Petit 0001
PQCrypto2
2020 SQISign: Compact Post-quantum Signatures from Quaternions and Isogenies
Luca De Feo, David Kohel, Antonin Leroux, Christophe Petit 0001, Benjamin Wesolowski
ASIACRYPT (1)4
2020 Semi-commutative Masking: A Framework for Isogeny-Based Protocols, with an Application to Fully Secure Two-Round Isogeny-Based OT
Cyprien Delpech de Saint Guilhem, Emmanuela Orsini, Christophe Petit 0001, Nigel P. Smart
CANS3
2020 Another Look at Some Isogeny Hardness Assumptions
Simon-Philipp Merz, Romy M. Minko, Christophe Petit 0001
CT-RSA3
2020 On Index Calculus Algorithms for Subfield Curves
Steven D. Galbraith, Robert Granger, Simon-Philipp Merz, Christophe Petit 0001
SAC4
2020 Trapdoor DDH Groups from Pairings and Isogenies
Péter Kutas, Christophe Petit 0001, Javier Silva 0001
SAC2
2020 Identification Protocols and Signature Schemes Based on Supersingular Isogeny Problems
abstract
We present signature schemes whose security relies on computational assumptions relating to isogeny graphs of supersingular elliptic curves. We give two schemes, both of them based on interactive identification protocols. The first identification protocol is due to De Feo, Jao and Plût. The second one, and the main contribution of the paper, makes novel use of an algorithm of Kohel, Lauter, Petit and Tignol for the quaternion version of the \(\ell \) -isogeny problem, for which we provide a more complete description and analysis, and is based on a more standard and potentially stronger computational problem. Both identification protocols lead to signatures that are existentially unforgeable under chosen message attacks in the random oracle model using the well-known Fiat-Shamir transform, and in the quantum random oracle model using another transform due to Unruh. A version of the first signature scheme was independently published by Yoo, Azarderakhsh, Jalali, Jao and Soukharev. This is the full version of a paper published at ASIACRYPT 2017.
Steven D. Galbraith, Christophe Petit 0001, Javier Silva 0001
J. Cryptol.2
2019 Verifiable Delay Functions from Supersingular Isogenies and Pairings
Luca De Feo, Simon Masson, Christophe Petit 0001, Antonio Sanso
ASIACRYPT (1)3
2018 Supersingular Isogeny Graphs and Endomorphism Rings: Reductions and Solutions
Kirsten Eisenträger, Sean Hallgren, Kristin E. Lauter, Travis Morrison, Christophe Petit 0001
EUROCRYPT (3)5
2017 Identification Protocols and Signature Schemes Based on Supersingular Isogeny Problems
Steven D. Galbraith, Christophe Petit 0001, Javier Silva 0001
ASIACRYPT (1)2
2017 Faster Algorithms for Isogeny Problems Using Torsion Point Images
Christophe Petit 0001
ASIACRYPT (2)1
2016 On the Security of Supersingular Isogeny Cryptosystems
Steven D. Galbraith, Christophe Petit 0001, Barak Shani, Yan Bo Ti
ASIACRYPT (1)2
2016 Efficient Zero-Knowledge Arguments for Arithmetic Circuits in the Discrete Log Setting
Jonathan Bootle, Andrea Cerulli, Pyrros Chaidos, Jens Groth, Christophe Petit 0001
EUROCRYPT (2)5
2016 A Generalised Successive Resultants Algorithm
James H. Davenport, Christophe Petit 0001, Benjamin Pring
WAIFI2
2015 Short Accountable Ring Signatures Based on DDH
abstract
Ring signatures and group signatures are prominent cryptographic primitives offering a combination of privacy and authentication. They enable individual users to anonymously sign messages on behalf of a group of users. In ring signatures, the group, i.e. the ring, is chosen in an ad hoc manner by the signer. In group signatures, group membership is controlled by a group manager. Group signatures additionally enforce accountability by providing the group manager with a secret tracing key that can be used to identify the otherwise anonymous signer when needed. Accountable ring signatures, introduced by Xu and Yung (CARDIS 2004), bridge the gap between the two notions. They provide maximal flexibility in choosing the ring, and at the same time maintain accountability by supporting a designated opener that can identify signers when needed. We revisit accountable ring signatures and offer a formal security model for the primitive. Our model offers strong security definitions incorporating protection against maliciously chosen keys and at the same time flexibility both in the choice of the ring and the opener. We give a generic construction using standard tools. We give a highly efficient instantiation of our generic construction in the random oracle model by meticulously combining Camenisch’s group signature scheme (CRYPTO 1997) with a generalization of the one-out-of-many proofs of knowledge by Groth and Kohlweiss (EUROCRYPT 2015). Our instantiation yields signatures of logarithmic size (in the size of the ring) while relying solely on the well-studied decisional Diffie-Hellman assumption. In the process, we offer a number of optimizations for the recent Groth and Kohlweiss one-out-of-many proofs, which may be useful for other applications. Accountable ring signatures imply traditional ring and group signatures. We therefore also obtain highly efficient instantiations of those primitives with signatures shorter than all existing ring signatures as well as existing group signatures relying on standard assumptions.
Jonathan Bootle, Andrea Cerulli, Pyrros Chaidos, Essam Ghadafi, Jens Groth, Christophe Petit 0001
ESORICS (1)6
2014 Towards factoring in $${SL(2, \, \mathbb{F}_{2^n})}$$
Christophe Petit 0001
Des. Codes Cryptogr.1
2012 On Polynomial Systems Arising from a Weil Descent
Christophe Petit 0001, Jean-Jacques Quisquater
ASIACRYPT1
2012 Improving the Complexity of Index Calculus Algorithms in Elliptic Curves over Binary Fields
Jean-Charles Faugère, Ludovic Perret, Christophe Petit 0001, Guénaël Renault
EUROCRYPT3
2011 Fresh Re-keying II: Securing Multiple Parties against Side-Channel and Fault Attacks
Marcel Medwed, Christophe Petit 0001, Francesco Regazzoni 0001, Mathieu Renauld, François-Xavier Standaert
CARDIS2
2010 One-Time Trapdoor One-Way Functions
Julien Cathalo, Christophe Petit 0001
ISC2
2009 Hard and Easy Components of Collision Search in the Zémor-Tillich Hash Function: New Attacks and Reduced Variants with Equivalent Security
Christophe Petit 0001, Jean-Jacques Quisquater, Jean-Pierre Tillich, Gilles Zémor
CT-RSA1
2008 A block cipher based pseudo random number generator secure against side-channel key recovery
abstract
We study the security of a block cipher-based pseudorandom number generator (PRNG), both in the black box world and in the physical world, separately. We first show that the construction is a secure PRNG in the ideal cipher model. Then, we demonstrate its security against a Bayesian side-channel key recovery adversary. As a main result, we show that our construction guarantees that the success rate of the adversary does not increase with the number of physical observations, but in a limited and controlled way. Besides, we observe that, under common assumptions on side-channel attack strategies, increasing the security parameter (typically the block cipher key size) by a polynomial factor involves an increase of a side-channel attack complexity by an exponential factor, making the probability of a successful attack negligible. We believe this work provides a first interesting example of the way the algorithmic design of a cryptographic scheme influences its side-channel resistance.
Christophe Petit 0001, François-Xavier Standaert, Olivier Pereira, Tal Malkin, Moti Yung
AsiaCCS1