![Damien Robert Profile](https://pbs.twimg.com/profile_images/1285297886230728712/bH5MiYQ8_x96.jpg)
Damien Robert
@GondoPloum
Followers
297
Following
1K
Statuses
646
Topics of interest: math, crypto, climate change... @[email protected]
Joined November 2014
@JDHamkins @gro_tsen Thanks for keeping us informed! Interesting because 2007 is also the date of Boban's exam I picked it up from.
0
0
1
RT @BenjWeso: Random walks in number-theoretic cryptology: on Thursday (Aug. 29, 2pm CEST) I'll be defending my "habilitation". I'll presen…
0
10
0
@gro_tsen @JDHamkins Thanks @gro_tsen for recovering the discussion! The link is no longer available, but I actually had saved the pdf. Here it is (in French): This is Exercice 4.
1
0
1
@JDHamkins @gro_tsen of the professor either. I was looking at it for the same reason as you: I was seeing this problem popping up in different places (@gro_tsen mentioned his blog, I also saw it in this blog post: , and I was trying to recover the logic exam I saw it first.
0
0
1
@asanso And invited talks by Wouter Castryck, Céline Maistret, Claus Fieker, Jordan Ellenberg and Katherine Stange. An awesome list of speakers!
0
0
3
RT @isogenies: New work on improving SQIsign using two dimensional isogenies. A post-quantum signature scheme with compact public keys, sig…
0
16
0
@kutasp @durumcrustulum @isogenies @bwesterb Not quite because we currently use the smallest response possible, of degree ≈ \sqrt{p}, for the verification. To have a hope to compute the response in dim 1, we would need to find a 2^n-isogeny, and we can only find one of degree ≈ p, so twice as big. So we could hope for x2.
1
0
3
@isogenies @durumcrustulum @bwesterb Yes, we definitively don't claim our current implementation is optimal. There are a lot of different trade offs / potential improvements we did not have time to explore. Still quite proud of the current version :)
0
0
3
@bwesterb @isogenies In the other direction, we could replace a matrix by explicit Kummer points, this would save the scalar multiplications (around 25% of our verification time), but add 64B to the signature size.
0
0
1
@isogenies @durumcrustulum @bwesterb But I don't see a way for dim 2 to reach better than x4 dim 1 unless we find completely new ideas, and even x4 will be difficult. So at best we could hope for a 25% speed up on this part, which takes 50% of the verification time...
1
0
1