Andrea Basso

@andreavbasso.bsky.social

Postdoc researcher on isogeny-based and post-quantum cryptography at IBM Research🇨🇭

New paper out 🎉 We introduce a new UPKE based on FESTA that supports unbounded updates and whose security is equivalent to FESTA! Our main result: a (four-dimensional) variant of FESTA has uniformly random public keys, which means that any random walk is a valid pk update.

ePrint Updates@eprint.ing.bot · 3mo ago

Updatable Public-Key Encryption from FESTA (Andrea Basso, Tako Boris Fouotsa, Fatna Kouider, Péter Kutas, Luciano Maino, Laurane Marco) ia.cr/2026/1014

Abstract. Updatable public-key encryption (UPKE) is a cryptographic primitive that was proposed for secure messaging to provide forward secrecy in public-key settings. It extends standard public-key encryption with a key-update mechanism that lets anyone update a receiver’s public key and issue a corresponding token for updating the secret key. Unlike traditional forward secrecy where all past messages should remain secure after a key leakage, UPKEs guarantee security only as long as at least one honest update has occurred.
While classically-secure efficient instantiations of UPKE are known from Diffie-Hellman assumptions, constructing an UPKE scheme with updates remains an open problem. In this work, we propose an isogeny-based UPKE that relies on a dimension-four version of the FESTA public-key encryption scheme. It is practically efficient and supports an unbounded amount of updates. Moreover, we provide a formal security proof based on a problem in isogeny-based cryptography that has received considerable scrutiny.

We're organizing a workshop on cryptographic group actions bringing together the isogeny and code communities. The workshop is just before Eurocrypt, a quick train away from Rome in the beautiful Marche. Early registration ends this week, so grab your spot soon! magic-workshop.github.io

MaGIC 2026 - Marche Workshop on Group Actions in Cryptography

A workshop dedicated to the study of cryptographic group actions, a rapidly evolving area at the intersection of algebraic geometry, number theory, and post-quantum cryptography. The workshop will bri...

magic-workshop.github.io

New paper out! 🎉 We translate the algebraic group model to the (generic) isogeny setting, generalising previous results that were limited to oriented isogenies (we show that any result that holds in the AGAM also holds in the AIM). Using this model, we obtain two important results:

ePrint Updates@eprint.ing.bot · 7mo ago

The Algebraic Isogeny Model: A General Model with Applications to SQIsign and Key Exchanges (Marius A. Aardal, Andrea Basso, Doreen Riepel) ia.cr/2026/032

Abstract. We introduce the Algebraic Isogeny Model (AIM): an algebraic model, akin to the Algebraic Group Model in the group setting, for isogenies and supersingular elliptic curves. This model is significantly more general than previous ones, such as the Algebraic Group Action Model: the AIM works with arbitrary isogenies over 𝔽_(p²), rather than being limited to oriented ones, which gives considerably more power to the adversary.

Within this model, we obtain three results. First, we show that any result in the AGAM can be lifted to the AIM, strengthening previous results against more powerful adversaries. Then, we prove that the SQIsign identification protocol is ID-sound: in turn, this implies that SQIsign is EUF-CMA secure in the Quantum Random Oracle Model, resolving (in the AIM) a long-standing open problem. Lastly, we establish the equivalence of the DLOG and CDH problems for all SIDH-derived key exchanges, such as M-SIDH, binSIDH, and terSIDH.

Using Learning with Rounding to Instantiate Post-Quantum Cryptographic Algorithms (Andrea Basso, Joppe W. Bos, Jan-Pieter D'Anvers, Angshuman Karmakar, Jose Maria Bermudo Mera, Joost Renes, Sujoy Sinha Roy, Frederik Vercauteren, Peng Wang, Yuewu Wang, Shicong Zhang, Chenxin Zhong) ia.cr/2025/1382

Abstract. The Learning with Rounding (LWR) problem, introduced as a deterministic variant of Learning with Errors (LWE), has become a promising foundation for post-quantum cryptography. This Systematization of Knowledge (SoK) paper presents a comprehensive survey of the theoretical foundations, algorithmic developments, and practical implementations of LWR-based cryptographic schemes. We introduce LWR within the broader landscape of lattice-based cryptography and post-quantum security, highlighting its advantages such as reduced randomness, improved efficiency, and enhanced side-channel resistance. We explore the evolution of security reductions from LWR to LWE, including recent advances that support practical parameter regimes and address challenges in both bounded and unbounded sample settings. This paper systematically reviews existing LWR-based schemes — including Saber, Lizard, Florete, Espada, Sable, and SMAUG — analyzing their design choices, parameter sets, and performance trade-offs. Furthermore, we examine the impact of LWR on side-channel resistance, failure probabilities, and masking efficiency, demonstrating its suitability for secure and efficient implementations. By consolidating the research spanning theory and practice, this SoK aims to guide future cryptographic design and standardization efforts leveraging LWR.
Image showing part 2 of abstract.

We (finally) published all the material from this course on SQIsign, including lecture slides and exercise sheets for the Sage laboratory. Available here: github.com/andreavico/S...

GitHub - andreavico/SQIsign_summer_school: Slides and worksheets for the introductory course on SQIsign held in Trento in May 2025

Slides and worksheets for the introductory course on SQIsign held in Trento in May 2025 - andreavico/SQIsign_summer_school

github.com

Andrea Basso@andreavbasso.bsky.social · last yr.

Next week @lucianomaino.bsky.social and I will teach a week-long course on SQIsign at the University of Trento. The course will be both in-person and online: if you're interested, you can tune in Monday morning at 10:30 at unitn.zoom.us/j/88902079708 (details and full schedule in the image below)

Title of the PhD course: Advances in Cryptography and Codes - Part 1: SQIsign

Lecturers: Andrea Basso (IBM Research Zurich, CH),
Luciano Maino (University of Bristol, UK)

The course in short: The course offers a comprehensive and rigorous introduction
to SQIsign, an advanced isogeny-based digital signature scheme designed to resist
attacks from quantum computers. The course will present the mathematical
foundations on which SQIsign is based and the algorithmic background necessary to
understand and evaluate the security of SQIsign and other isogeny-based protocols.
Complementing the theoretical material, the course also includes a practical
laboratory where students will use SageMath to study and implement various
aspects of SQIsign.

Where (in presence): Department of Mathematics, University of Trento (IT)
Via Sommarive, 5, 38123, Trento
(online): https://unitn.zoom.us/j/88902079708 (Passcode: 532383)
When: From May 19, 2025 to May 28, 2025

Detailed Program:
Monday 19/05 10:30 - 12:30 (Room A205) & 14:30 - 16:30 (Room A221)
Tuesday 20/05 10:30 - 12:30 (Room A215) & 14:30 - 16:30 (Room A213)
Wednesday 21/05 10:30 - 12:30 (Room A218) & 14:30 - 16:30 (Room A215)
Thursday 22/05 10:30 - 12:30 (Room A209) & 14:30 - 16:30 (Room A220)
Friday 23/05 10:30 - 12:30 (Room A215) & 14:30 - 16:30 (Room A215)
Tuesday 27/05 11:30 - 12:30 – Q&A, optional (Room A218)
Wednesday 28/05 11:30 - 12:30 – Q&A, optional (Room A218)

Isogeny-based signatures have consistently had a breakthrough every two years! Let's see what 2026 will bring... (Well, except for SQIsignHD that came a year too late, but that's probably because of Covid)

A timeline of isogeny-based signatures over the years:
2012 - A signature from group actions: First signature from
isogenies in the literature
2014 - SIDH: Also proposes an identification protocol
2016 - GPS: First signature from endomorphism ring knowledge 
2018 - SeaSign: First signature based on CSIDH
2020 - SQIsign: Compact and “practical" signature from endomorphism ring knowledge
2023 - SQIsignHD: HD representations make SQIsign signing much faster
2024 - SQIsign2D: Significantly improved SQIsign signing and verification