@kutasp89.bsky.social

I'm looking for a job! I'm an experienced researcher in cryptography. My focus is on the transition to post-quantum cryptographic protocols and protocols related to blockains. If that sounds like someone you might want to hire or you know someone who might, let's talk!

New paper out 🎉 We introduce a new UPKE based on FESTA that supports unbounded updates and whose security is equivalent to FESTA! Our main result: a (four-dimensional) variant of FESTA has uniformly random public keys, which means that any random walk is a valid pk update.

ePrint Updates@eprint.ing.bot · 3mo ago

Updatable Public-Key Encryption from FESTA (Andrea Basso, Tako Boris Fouotsa, Fatna Kouider, Péter Kutas, Luciano Maino, Laurane Marco) ia.cr/2026/1014

Abstract. Updatable public-key encryption (UPKE) is a cryptographic primitive that was proposed for secure messaging to provide forward secrecy in public-key settings. It extends standard public-key encryption with a key-update mechanism that lets anyone update a receiver’s public key and issue a corresponding token for updating the secret key. Unlike traditional forward secrecy where all past messages should remain secure after a key leakage, UPKEs guarantee security only as long as at least one honest update has occurred.
While classically-secure efficient instantiations of UPKE are known from Diffie-Hellman assumptions, constructing an UPKE scheme with updates remains an open problem. In this work, we propose an isogeny-based UPKE that relies on a dimension-four version of the FESTA public-key encryption scheme. It is practically efficient and supports an unbounded amount of updates. Moreover, we provide a formal security proof based on a problem in isogeny-based cryptography that has received considerable scrutiny.

Thomas and I looked at directed isogeny graphs! In dim 1, we often ignore directedness, as there are only 2 "problematic" curves. Not so in dim 2: we analyze the action of automorphisms on level structures and the resulting directed graphs. Crucial: Directed (2,2)-graphs looks Ramanujan after all!

ePrint Updates@eprint.ing.bot · 5mo ago

Expander properties of superspecial isogeny digraphs with level structure (Thomas Decru, Krijn Reijnders) ia.cr/2026/500

Abstract. Charles, Goren and Lauter proved that the supersingular ℓ-isogeny graph is a Ramanujan graph, which is an optimal expander. Jordan and Zaytman argued that this is no longer true in dimension two, but Florit and Smith showed that those graphs exhibit good expansion properties nonetheless. Castryck, Decru and Smith however have pointed out that the higher-dimensional analogue setting should only consider a subset of all edges, namely the paths corresponding to (ℓ^(k), ℓ^(k))-isogenies, so-called good extensions, instead of all (ℓ^(a), ℓ^(b), ℓ^(c), ℓ^(d))-isogenies in general, which contain bad extensions too. Such bad extensions lead to many small cycles in the graph, which are a cryptographic problem due to collisions and a graph-theoretic nuisance as these superfluous edges counteract part of the expansion properties. Restricting to good extensions makes the resulting graph directed, as outgoing edges now depend on the incoming edge. We study (ℓ, ℓ)-level surfaces and (ℓ)^(g)-isogeny digraphs restricted to good extensions for concrete small dimensions and degrees ℓ. These graphs exhibit excellent expander properties: by our heuristic evidence, they are Ramanujan graphs for all primes ℓ in dimension 1, and for ℓ = 2 in dimension 2. Our main conjecture implies that this would still be the case for ℓ = 3 in dimension 2, but not for any larger ℓ in dimension 2, or any ℓ in dimension 3 and up. Furthermore, we generalize the work of Florit and Smith from ℓ = 2 to general primes ℓ, by classifying all abelian surfaces with nontrivial automorphism groups and their actions on their maximal isotropic (ℓ, ℓ)−subgroups.

This exactly. And it's not just theoretical, it can happen for real. "The Chinese state-sponsored cyberattack threat managed to infiltrate the "lawful intercept" network connections that police use in criminal investigations." www.darkreading.com/cyber-risk/s...

Sat Typhoon APT Subverts Law Enforcement Wiretapping

The Chinese state-sponsored cyberattack threat managed to infiltrate the "lawful intercept" network connections that police use in criminal investigations.

darkreading.com