Luca De Feo

@bsky.defeo.lu

Researcher in cryptography @ IBM Research, chief isogenista, SageMath developer, DevOps in my spare time. Opinions my own. On Mastodon: @luca_defeo@ioc.exchange

I'm looking for a job! I'm an experienced researcher in cryptography. My focus is on the transition to post-quantum cryptographic protocols and protocols related to blockains. If that sounds like someone you might want to hire or you know someone who might, let's talk!

I'm looking for a PhD student to work with me on formal verification for cryptographic protocols. This is a 4-year position at VU Amsterdam, co-supervised with Kristina Sojakova. Send me an email if you want to know more!

Major announcement: My highly successful Applied Cryptography course taught last year at the American University of Beirut is returning as an online course, available for FREE for any qualifying student from any Lebanese university! Read more + apply today — and please spread the word!

Applied Cryptography: Free Online Course for 50 Lebanese University Students This Summer

We're opening 50 spots for students at Lebanese universities to take the Applied Cryptography course online, completely free of charge, starting June 2026. Applications are open now.

symbolic.software

Cedarcrypt CFP deadline: April 10! We're still seeking talks, workshops & research presentations on applied crypto, post-quantum, ZK, secure implementation & more. Also looking for sponsors to fund student stipends. July 13–16, Paphos, Cyprus. Help shape crypto education in the Levant!

Cedarcrypt 2026 - Applied Cryptography Summer School & Conference

Join us for four days of applied cryptography in the Mediterranean. July 13-16, 2026 at AUB Mediterraneo Campus, Paphos, Cyprus.

cedarcrypt.org

Thomas and I looked at directed isogeny graphs! In dim 1, we often ignore directedness, as there are only 2 "problematic" curves. Not so in dim 2: we analyze the action of automorphisms on level structures and the resulting directed graphs. Crucial: Directed (2,2)-graphs looks Ramanujan after all!

ePrint Updates@eprint.ing.bot · 5mo ago

Expander properties of superspecial isogeny digraphs with level structure (Thomas Decru, Krijn Reijnders) ia.cr/2026/500

Abstract. Charles, Goren and Lauter proved that the supersingular ℓ-isogeny graph is a Ramanujan graph, which is an optimal expander. Jordan and Zaytman argued that this is no longer true in dimension two, but Florit and Smith showed that those graphs exhibit good expansion properties nonetheless. Castryck, Decru and Smith however have pointed out that the higher-dimensional analogue setting should only consider a subset of all edges, namely the paths corresponding to (ℓ^(k), ℓ^(k))-isogenies, so-called good extensions, instead of all (ℓ^(a), ℓ^(b), ℓ^(c), ℓ^(d))-isogenies in general, which contain bad extensions too. Such bad extensions lead to many small cycles in the graph, which are a cryptographic problem due to collisions and a graph-theoretic nuisance as these superfluous edges counteract part of the expansion properties. Restricting to good extensions makes the resulting graph directed, as outgoing edges now depend on the incoming edge. We study (ℓ, ℓ)-level surfaces and (ℓ)^(g)-isogeny digraphs restricted to good extensions for concrete small dimensions and degrees ℓ. These graphs exhibit excellent expander properties: by our heuristic evidence, they are Ramanujan graphs for all primes ℓ in dimension 1, and for ℓ = 2 in dimension 2. Our main conjecture implies that this would still be the case for ℓ = 3 in dimension 2, but not for any larger ℓ in dimension 2, or any ℓ in dimension 3 and up. Furthermore, we generalize the work of Florit and Smith from ℓ = 2 to general primes ℓ, by classifying all abelian surfaces with nontrivial automorphism groups and their actions on their maximal isotropic (ℓ, ℓ)−subgroups.

UPDATE: The European Parliament voted today to *end* untargeted mass scanning of private communications, firmly rejecting the error-prone and unconstitutional surveillance practices of recent years! Next: trilogue negotiations w/ Commission and Council.

TL;DR: - SQIsign more general than initially thought. - More space for protocol design! - SQIsign NIST v2 still the best signature, by a small margin. Ilinca already foreshadowed some of this in www.youtube.com/watch?v=5tGb..., though that's a different POV we're still writing up.

ePrint Updates@eprint.ing.bot · 5mo ago

The SQInstructor: a guide to SQIsign and the Deuring Correspondence with level structures (Giacomo Borin, Luca De Feo, Guido Maria Lido, Sina Schaeffler) ia.cr/2026/493

Abstract. We explore the use of level structures to generalize the SQIsign signature scheme. We give a general framework where, given the public key and the commitment, the challenge is to exhibit an isogeny between them with an additional requirement, namely to map a chosen level structure to nother. We then instantiate the framework using 1-dimensional and 2-dimensional isogenies.
In doing that we provide a new explicit Deuring correspondence for supersingular elliptic curves with level structures and solve new constrained norm equations.

Come be part of Cedarcrypt, our historic new initiative to grow cryptography research, development and representation in the Levant region! We're seeking speakers and workshop leaders: our call for submissions is open! Learn more: cedarcrypt.org Please spread the word!

Cedarcrypt 2026 - Applied Cryptography Summer School & Conference

Join us for four days of applied cryptography in the Mediterranean. July 13-16, 2026 at AUB Mediterraneo Campus, Paphos, Cyprus.

cedarcrypt.org

I just donated to help equip Lebanon's first responders and firefighters with essential life-saving supplies to help them deal with the massive crises unfolding due to Israeli attacks on civilian areas. Please consider donating: fundahope.com/en/campaigns...

Equipping Lebanon's First Responders 2026

March 2026: We are fundraising to equip Lebanon’s national first responders - The Civil Defense (الدفاع المدني) with essential and life-saving supp

fundahope.com