{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,28]],"date-time":"2026-02-28T16:11:37Z","timestamp":1772295097209,"version":"3.50.1"},"publisher-location":"Cham","reference-count":83,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783031070815","type":"print"},{"value":"9783031070822","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-07082-2_21","type":"book-chapter","created":{"date-parts":[[2022,5,28]],"date-time":"2022-05-28T00:09:51Z","timestamp":1653696591000},"page":"582-612","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":31,"title":["Practical Post-Quantum Signature Schemes from\u00a0Isomorphism Problems of\u00a0Trilinear Forms"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1135-466X","authenticated-orcid":false,"given":"Gang","family":"Tang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8057-4060","authenticated-orcid":false,"given":"Dung Hoang","family":"Duong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2682-6508","authenticated-orcid":false,"given":"Antoine","family":"Joux","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2521-2520","authenticated-orcid":false,"given":"Thomas","family":"Plantard","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4334-1449","authenticated-orcid":false,"given":"Youming","family":"Qiao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1562-5105","authenticated-orcid":false,"given":"Willy","family":"Susilo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,5,25]]},"reference":[{"key":"21_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-31856-9_1","volume-title":"STACS 2005","author":"M Agrawal","year":"2005","unstructured":"Agrawal, M., Saxena, N.: Automorphisms of finite rings and applications to complexity of problems. In: Diekert, V., Durand, B. (eds.) STACS 2005. LNCS, vol. 3404, pp. 1\u201317. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/978-3-540-31856-9_1"},{"key":"21_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1007\/11672142_8","volume-title":"STACS 2006","author":"M Agrawal","year":"2006","unstructured":"Agrawal, M., Saxena, N.: Equivalence of f-algebras and cubic forms. In: Durand, B., Thomas, W. (eds.) STACS 2006. LNCS, vol. 3884, pp. 115\u2013126. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11672142_8"},{"key":"21_CR3","doi-asserted-by":"crossref","unstructured":"Alagic, G., et al.: Status report on the second round of the NIST post-quantum cryptography standardization process. Technical report, National Institute of Standards and Technology (2020)","DOI":"10.6028\/NIST.IR.8240"},{"key":"21_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"411","DOI":"10.1007\/978-3-030-64834-3_14","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"N Alamati","year":"2020","unstructured":"Alamati, N., De Feo, L., Montgomery, H., Patranabis, S.: Cryptographic group actions and applications. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020. LNCS, vol. 12492, pp. 411\u2013439. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_14"},{"issue":"1","key":"21_CR5","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1017\/S1446788700013999","volume":"16","author":"MD Atkinson","year":"1973","unstructured":"Atkinson, M.D.: Alternating trilinear forms and groups of exponent 6. J. Aust. Math. Soc. 16(1), 111\u2013128 (1973)","journal-title":"J. Aust. Math. Soc."},{"key":"21_CR6","doi-asserted-by":"crossref","unstructured":"Babai, L.: Graph isomorphism in quasipolynomial time [extended abstract]. In: STOC 2016, pp. 684\u2013697 (2016)","DOI":"10.1145\/2897518.2897542"},{"key":"21_CR7","unstructured":"Bai, S., et al.: Crystals-dilithium: algorithm specifications and supporting documentation (version 3.1) (2021). https:\/\/pq-crystals.org\/dilithium\/data\/dilithium-specification-round3-20210208.pdf"},{"key":"21_CR8","unstructured":"Bardet, M.: \u00c9tude des syst\u00e8mes alg\u00e9briques surd\u00e9termin\u00e9s. Applications aux codes correcteurs et \u00e0 la cryptographie. PhD thesis, Universit\u00e9 Pierre et Marie Curie-Paris VI (2004)"},{"key":"21_CR9","unstructured":"Bardet, M., Faug\u00e8re, J.C., Salvy, B., Yang, B.Y.: Asymptotic behaviour of the degree of regularity of semi-regular polynomial systems. In: Proceedings of the MEGA, vol. 5 (2005)"},{"issue":"4","key":"21_CR10","doi-asserted-by":"publisher","first-page":"590","DOI":"10.1016\/j.jco.2015.04.001","volume":"31","author":"J Berthomieu","year":"2015","unstructured":"Berthomieu, J., Faug\u00e8re, J.-C., Perret, L.: Polynomial-time algorithms for quadratic isomorphism of polynomials: the regular case. J. Complex. 31(4), 590\u2013616 (2015)","journal-title":"J. Complex."},{"key":"21_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1007\/978-3-030-34578-5_9","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2019","author":"W Beullens","year":"2019","unstructured":"Beullens, W., Kleinjung, T., Vercauteren, F.: CSI-FiSh: efficient isogeny based signatures through class group computations. In: Galbraith, S.D., Moriai, S. (eds.) ASIACRYPT 2019. LNCS, vol. 11921, pp. 227\u2013247. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-34578-5_9"},{"key":"21_CR12","doi-asserted-by":"crossref","unstructured":"Bellare, M., Neven, G.: Multi-signatures in the plain public-Key model and a general forking lemma. In: CCS 2006, pp. 390\u2013399 (2016)","DOI":"10.1145\/1180405.1180453"},{"key":"21_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"493","DOI":"10.1007\/978-3-030-45724-2_17","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2020","author":"X Bonnetain","year":"2020","unstructured":"Bonnetain, X., Schrottenloher, A.: Quantum security analysis of CSIDH. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT 2020. LNCS, vol. 12106, pp. 493\u2013522. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45724-2_17"},{"key":"21_CR14","unstructured":"Bouillaguet, C.: Etudes d\u2019hypotheses algorithmiques et attaques de primitives cryptographiques. PhD thesis, PhD thesis, Universit\u00e9 Paris-Diderot-\u00c9cole Normale Sup\u00e9rieure (2011)"},{"key":"21_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"473","DOI":"10.1007\/978-3-642-19379-8_29","volume-title":"Public Key Cryptography \u2013 PKC 2011","author":"C Bouillaguet","year":"2011","unstructured":"Bouillaguet, C., Faug\u00e8re, J.-C., Fouque, P.-A., Perret, L.: Practical cryptanalysis of the identification scheme based on the isomorphism of polynomial with one secret problem. In: Catalano, D., Fazio, N., Gennaro, R., Nicolosi, A. (eds.) PKC 2011. LNCS, vol. 6571, pp. 473\u2013493. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-19379-8_29"},{"key":"21_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/978-3-642-38348-9_13","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2013","author":"C Bouillaguet","year":"2013","unstructured":"Bouillaguet, C., Fouque, P.-A., V\u00e9ber, A.: Graph-theoretic algorithms for the \u201cisomorphism of polynomials\u2019\u2019 problem. In: Johansson, T., Nguyen, P.Q. (eds.) EUROCRYPT 2013. LNCS, vol. 7881, pp. 211\u2013227. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-38348-9_13"},{"key":"21_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"94","DOI":"10.1007\/3-540-38424-3_7","volume-title":"Advances in Cryptology-CRYPT0\u2019 90","author":"G Brassard","year":"1991","unstructured":"Brassard, G., Yung, M.: One-way group actions. In: Menezes, A.J., Vanstone, S.A. (eds.) CRYPTO 1990. LNCS, vol. 537, pp. 94\u2013107. Springer, Heidelberg (1991). https:\/\/doi.org\/10.1007\/3-540-38424-3_7"},{"key":"21_CR18","unstructured":"Brooksbank, P.A., Li, Y., Qiao, Y., Wilson, J.B.: Improved algorithms for alternating matrix space isometry: from theory to practice. In: 28th ESA 2020, pp. 26:1\u201326:15 (2020)"},{"key":"21_CR19","doi-asserted-by":"publisher","first-page":"545","DOI":"10.1016\/j.jalgebra.2016.12.007","volume":"473","author":"PA Brooksbank","year":"2017","unstructured":"Brooksbank, P.A., Maglione, J., Wilson, J.B.: A fast isomorphism test for groups whose Lie algebra has genus 2. J. Algebra 473, 545\u2013590 (2017)","journal-title":"J. Algebra"},{"issue":"3","key":"21_CR20","doi-asserted-by":"publisher","first-page":"572","DOI":"10.1006\/jcss.1998.1608","volume":"58","author":"JF Buss","year":"1999","unstructured":"Buss, J.F., Frandsen, G.S., Shallit, J.O.: The computational complexity of some problems of linear algebra. J. Comput. Syst. Sci. 58(3), 572\u2013596 (1999)","journal-title":"J. Comput. Syst. Sci."},{"key":"21_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"392","DOI":"10.1007\/3-540-45539-6_27","volume-title":"Advances in Cryptology \u2014 EUROCRYPT 2000","author":"N Courtois","year":"2000","unstructured":"Courtois, N., Klimov, A., Patarin, J., Shamir, A.: Efficient algorithms for solving overdefined systems of multivariate polynomial equations. In: Preneel, B. (ed.) EUROCRYPT 2000. LNCS, vol. 1807, pp. 392\u2013407. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/3-540-45539-6_27"},{"key":"21_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"395","DOI":"10.1007\/978-3-030-03332-3_15","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2018","author":"W Castryck","year":"2018","unstructured":"Castryck, W., Lange, T., Martindale, C., Panny, L., Renes, J.: CSIDH: an efficient post-quantum commutative group action. In: Peyrin, T., Galbraith, S. (eds.) ASIACRYPT 2018. LNCS, vol. 11274, pp. 395\u2013427. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03332-3_15"},{"issue":"1","key":"21_CR23","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1515\/jmc-2012-0016","volume":"8","author":"A Childs","year":"2014","unstructured":"Childs, A., Jao, D., Soukharev, V.: Constructing elliptic curve isogenies in quantum subexponential time. J. Math. Cryptol. 8(1), 1\u201329 (2014)","journal-title":"J. Math. Cryptol."},{"issue":"1","key":"21_CR24","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1080\/00927878808823558","volume":"16","author":"AM Cohen","year":"1988","unstructured":"Cohen, A.M., Helminck, A.G.: Trilinear alternating forms on a vector space of dimension 7. Commun. Algebra 16(1), 1\u201325 (1988)","journal-title":"Commun. Algebra"},{"key":"21_CR25","unstructured":"Couveignes, J.M.: Hard homogeneous spaces. IACR Cryptology ePrint Archive (2006)"},{"key":"21_CR26","unstructured":"Crandall, R.E.: Method and apparatus for public key exchange in a cryptographic system. U.S. Patent number 5159632 (1992)"},{"key":"21_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-3-030-64837-4_3","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"L De Feo","year":"2020","unstructured":"De Feo, L., Kohel, D., Leroux, A., Petit, C., Wesolowski, B.: SQISign: compact post-quantum signatures from quaternions and isogenies. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020. LNCS, vol. 12491, pp. 64\u201393. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64837-4_3"},{"key":"21_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"164","DOI":"10.1007\/11496137_12","volume-title":"Applied Cryptography and Network Security","author":"J Ding","year":"2005","unstructured":"Ding, J., Schmidt, D.: Rainbow, a new multivariable polynomial signature scheme. In: Ioannidis, J., Keromytis, A., Yung, M. (eds.) ACNS 2005. LNCS, vol. 3531, pp. 164\u2013175. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11496137_12"},{"key":"21_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"356","DOI":"10.1007\/978-3-030-26951-7_13","volume-title":"Advances in Cryptology \u2013 CRYPTO 2019","author":"J Don","year":"2019","unstructured":"Don, J., Fehr, S., Majenz, C., Schaffner, C.: Security of the fiat-shamir transformation in the quantum random-oracle model. In: Boldyreva, A., Micciancio, D. (eds.) CRYPTO 2019. LNCS, vol. 11693, pp. 356\u2013383. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-26951-7_13"},{"issue":"1","key":"21_CR30","doi-asserted-by":"publisher","first-page":"167","DOI":"10.1007\/s00022-013-0202-2","volume":"105","author":"J Draisma","year":"2013","unstructured":"Draisma, J., Shaw, R.: Some noteworthy alternating trilinear forms. J. Geom. 105(1), 167\u2013176 (2013). https:\/\/doi.org\/10.1007\/s00022-013-0202-2","journal-title":"J. Geom."},{"key":"21_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"157","DOI":"10.1007\/978-3-030-45388-6_6","volume-title":"Public-Key Cryptography \u2013 PKC 2020","author":"A El Kaafarani","year":"2020","unstructured":"El Kaafarani, A., Katsumata, S., Pintore, F.: Lossy CSI-FiSh: efficient signature scheme with tight reduction to decisional CSIDH-512. In: Kiayias, A., Kohlweiss, M., Wallden, P., Zikas, V. (eds.) PKC 2020. LNCS, vol. 12111, pp. 157\u2013186. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45388-6_6"},{"issue":"3\u20134","key":"21_CR32","doi-asserted-by":"publisher","first-page":"295","DOI":"10.1007\/BF01895716","volume":"14","author":"P Erd\u0151s","year":"1963","unstructured":"Erd\u0151s, P., R\u00e9nyi, A.: Asymmetric graphs. Acta Math. Hung. 14(3\u20134), 295\u2013315 (1963)","journal-title":"Acta Math. Hung."},{"key":"21_CR33","unstructured":"Faug\u00e8re, J.-C.: A new efficient algorithm for computing gr\u00f6bner bases without reduction to zero (F5). In: Proceedings of the 2002 International Symposium on Symbolic and Algebraic Computation, pp. 75\u201383 (2002)"},{"key":"21_CR34","doi-asserted-by":"crossref","unstructured":"Faugere, J.-C., El Din, M.S., Spaenlehauer, P.-J.: Computing loci of rank defects of linear matrices using gr\u00f6bner bases and applications to cryptology. In: ISSAC 2010, pp. 257\u2013264 (2010)","DOI":"10.1145\/1837934.1837984"},{"key":"21_CR35","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1016\/j.jsc.2013.03.004","volume":"55","author":"J-C Faugere","year":"2013","unstructured":"Faugere, J.-C., El Din, M.S., Spaenlehauer, P.-J.: On the complexity of the generalized minrank problem. J. Symb. Comput. 55, 30\u201358 (2013)","journal-title":"J. Symb. Comput."},{"key":"21_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1007\/978-3-540-85174-5_16","volume-title":"Advances in Cryptology \u2013 CRYPTO 2008","author":"J-C Faug\u00e8re","year":"2008","unstructured":"Faug\u00e8re, J.-C., Levy-dit-Vehel, F., Perret, L.: Cryptanalysis of MinRank. In: Wagner, D. (ed.) CRYPTO 2008. LNCS, vol. 5157, pp. 280\u2013296. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-85174-5_16"},{"key":"21_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1007\/11761679_3","volume-title":"Advances in Cryptology - EUROCRYPT 2006","author":"J-C Faug\u00e8re","year":"2006","unstructured":"Faug\u00e8re, J.-C., Perret, L.: Polynomial equivalence problems: algorithmic and theoretical aspects. In: Vaudenay, S. (ed.) EUROCRYPT 2006. LNCS, vol. 4004, pp. 30\u201347. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11761679_3"},{"key":"21_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"759","DOI":"10.1007\/978-3-030-17659-4_26","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2019","author":"L De Feo","year":"2019","unstructured":"De Feo, L., Galbraith, S.D.: SeaSign: compact isogeny signatures from class group actions. In: Ishai, Y., Rijmen, V. (eds.) EUROCRYPT 2019. LNCS, vol. 11478, pp. 759\u2013789. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-17659-4_26"},{"key":"21_CR39","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1007\/3-540-47721-7_12","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 86","author":"A Fiat","year":"1987","unstructured":"Fiat, A., Shamir, A.: How to prove yourself: practical solutions to identification and signature problems. In: Odlyzko, A.M. (ed.) CRYPTO 1986. LNCS, vol. 263, pp. 186\u2013194. Springer, Heidelberg (1987). https:\/\/doi.org\/10.1007\/3-540-47721-7_12"},{"key":"21_CR40","unstructured":"Fouque, P.-A., et al.: Falcon: fast-fourier lattice-based compact signatures over NTRU (specification v1.2) (2020). https:\/\/falcon-sign.info\/falcon.pdf"},{"issue":"3","key":"21_CR41","doi-asserted-by":"publisher","first-page":"691","DOI":"10.1145\/116825.116852","volume":"38","author":"O Goldreich","year":"1991","unstructured":"Goldreich, O., Micali, S., Wigderson, A.: Proofs that yield nothing but their validity for all languages in NP have zero-knowledge proof systems. J. ACM 38(3), 691\u2013729 (1991)","journal-title":"J. ACM"},{"key":"21_CR42","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1007\/3-540-44448-3_4","volume-title":"Advances in Cryptology \u2014 ASIACRYPT 2000","author":"L Goubin","year":"2000","unstructured":"Goubin, L., Courtois, N.T.: Cryptanalysis of the TTM cryptosystem. In: Okamoto, T. (ed.) ASIACRYPT 2000. LNCS, vol. 1976, pp. 44\u201357. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/3-540-44448-3_4"},{"issue":"1","key":"21_CR43","first-page":"137","volume":"24","author":"M Grigni","year":"2004","unstructured":"Grigni, M., Schulman, L.J., Vazirani, M., Vazirani, U.V.: Quantum mechanical algorithms for the nonabelian hidden subgroup problem. Comb. 24(1), 137\u2013154 (2004)","journal-title":"Comb."},{"key":"21_CR44","unstructured":"Grochow, J.A., Qiao, Y.: On the complexity of isomorphism problems for tensors, groups, and polynomials I: tensor isomorphism-completeness. In: ITCS 2021, pp. 31:1\u201331:19 (2021)"},{"key":"21_CR45","doi-asserted-by":"crossref","unstructured":"Grochow, J.A., Qiao, Y.: On p-group isomorphism: search-to-decision, counting-to-decision, and nilpotency class reductions via tensors. In: CCC 2021, pp. 16:1\u201316:38 (2021)","DOI":"10.1145\/3625308"},{"key":"21_CR46","doi-asserted-by":"crossref","unstructured":"Grochow, J.A., Qiao, Y., Tang, G.: Average-case algorithms for testing isomorphism of polynomials, algebras, and multilinear forms. In: STACS 2021, pp. 38:1\u201338:17 (2021)","DOI":"10.46298\/jgcc.2022.14.1.9431"},{"key":"21_CR47","doi-asserted-by":"crossref","unstructured":"Grover, L.K.: A fast quantum mechanical algorithm for database search. In Proceedings of the Twenty-eighth Annual ACM Symposium on Theory of Computing, pp. 212\u2013219 (1996)","DOI":"10.1145\/237814.237866"},{"key":"21_CR48","doi-asserted-by":"crossref","unstructured":"Hallgren, S., Moore, C., R\u00f6tteler, M., Russell, A., Sen, P.: Limitations of quantum coset states for graph isomorphism. J. ACM 57(6):34:1\u201334:33 (2010)","DOI":"10.1145\/1857914.1857918"},{"issue":"4","key":"21_CR49","doi-asserted-by":"publisher","first-page":"644","DOI":"10.1016\/0196-6774(90)90014-6","volume":"11","author":"J H\u00e5stad","year":"1990","unstructured":"H\u00e5stad, J.: Tensor rank is NP-complete. J. Algorithms 11(4), 644\u2013654 (1990)","journal-title":"J. Algorithms"},{"issue":"8","key":"21_CR50","doi-asserted-by":"publisher","first-page":"3459","DOI":"10.1080\/00927872.2014.927475","volume":"43","author":"J Hora","year":"2015","unstructured":"Hora, J., Pudl\u00e1k, P.: Classification of 8-dimensional trilinear alternating forms over gf (2). Commun. Algebra 43(8), 3459\u20133471 (2015)","journal-title":"Commun. Algebra"},{"issue":"3","key":"21_CR51","doi-asserted-by":"publisher","first-page":"926","DOI":"10.1137\/18M1165682","volume":"48","author":"G Ivanyos","year":"2019","unstructured":"Ivanyos, G., Qiao, Y.: Algorithms based on *-algebras, and their applications to isomorphism of polynomials with one secret, group isomorphism, and polynomial identity testing. SIAM J. Comput. 48(3), 926\u2013963 (2019)","journal-title":"SIAM J. Comput."},{"key":"21_CR52","unstructured":"Beullens, W., et al.: SPHINCS+: submission to the NIST post-quantum project, vol. 3 (2020). https:\/\/sphincs.org\/data\/sphincs+-round3-specification.pdf"},{"key":"21_CR53","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"251","DOI":"10.1007\/978-3-030-36030-6_11","volume-title":"Theory of Cryptography","author":"Z Ji","year":"2019","unstructured":"Ji, Z., Qiao, Y., Song, F., Yun, A.: General linear group action on tensors: a candidate for post-quantum cryptography. In: Hofheinz, D., Rosen, A. (eds.) TCC 2019. LNCS, vol. 11891, pp. 251\u2013281. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-36030-6_11"},{"key":"21_CR54","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-642-25405-5_2","volume-title":"Post-Quantum Cryptography","author":"D Jao","year":"2011","unstructured":"Jao, D., De Feo, L.: Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies. In: Yang, B.-Y. (ed.) PQCrypto 2011. LNCS, vol. 7071, pp. 19\u201334. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25405-5_2"},{"key":"21_CR55","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/3-540-48405-1_2","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 99","author":"A Kipnis","year":"1999","unstructured":"Kipnis, A., Shamir, A.: Cryptanalysis of the HFE public key cryptosystem by relinearization. In: Wiener, M. (ed.) CRYPTO 1999. LNCS, vol. 1666, pp. 19\u201330. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-48405-1_2"},{"key":"21_CR56","doi-asserted-by":"crossref","unstructured":"K\u00f6bler, J., Sch\u00f6ning, U., Tor\u00e1n, J.: The graph isomorphism problem. Basel Birkh\u00fcser (1993)","DOI":"10.1007\/978-1-4612-0333-9"},{"issue":"1","key":"21_CR57","doi-asserted-by":"publisher","first-page":"170","DOI":"10.1137\/S0097539703436345","volume":"35","author":"G Kuperberg","year":"2005","unstructured":"Kuperberg, G.: A subexponential-time quantum algorithm for the dihedral hidden subgroup problem. SIAM J. Comput. 35(1), 170\u2013188 (2005)","journal-title":"SIAM J. Comput."},{"key":"21_CR58","unstructured":"Kuperberg, G.: Another subexponential-time quantum algorithm for the dihedral hidden subgroup problem. In: TQC 2013, pp. 20\u201334 (2013)"},{"key":"21_CR59","doi-asserted-by":"crossref","unstructured":"Li, Y., Qiao, Y.: Linear algebraic analogues of the graph isomorphism problem and the Erd\u0151s-R\u00e9nyi model. In: FOCS 2017, pp. 463\u2013474. IEEE Computer Society (2017)","DOI":"10.1109\/FOCS.2017.49"},{"key":"21_CR60","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"326","DOI":"10.1007\/978-3-030-26951-7_12","volume-title":"Advances in Cryptology \u2013 CRYPTO 2019","author":"Q Liu","year":"2019","unstructured":"Liu, Q., Zhandry, M.: Revisiting post-quantum Fiat-Shamir. In: Boldyreva, A., Micciancio, D. (eds.) CRYPTO 2019. LNCS, vol. 11693, pp. 326\u2013355. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-26951-7_12"},{"key":"21_CR61","unstructured":"Waterloo, Ontario: Maplesoft, a division of Waterloo Maple Inc., Maple (2020.2) (2020)"},{"key":"21_CR62","unstructured":"McKay, B.D.: Practical graph isomorphism. Congr. Numer. 30, 45\u201387 (1980)"},{"key":"21_CR63","doi-asserted-by":"publisher","first-page":"94","DOI":"10.1016\/j.jsc.2013.09.003","volume":"60","author":"BD McKay","year":"2014","unstructured":"McKay, B.D., Piperno, A.: Practical graph isomorphism II. J. Symb. Comput. 60, 94\u2013112 (2014)","journal-title":"J. Symb. Comput."},{"key":"21_CR64","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"218","DOI":"10.1007\/0-387-34805-0_21","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 89 Proceedings","author":"RC Merkle","year":"1990","unstructured":"Merkle, R.C.: A certified digital signature. In: Brassard, G. (ed.) CRYPTO 1989. LNCS, vol. 435, pp. 218\u2013238. Springer, New York (1990). https:\/\/doi.org\/10.1007\/0-387-34805-0_21"},{"issue":"1","key":"21_CR65","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1080\/03081087.2012.661424","volume":"61","author":"N Midoune","year":"2013","unstructured":"Midoune, N., Noui, L.: Trilinear alternating forms on a vector space of dimension 8 over a finite field. Linear Multilinear Algebra 61(1), 15\u201321 (2013)","journal-title":"Linear Multilinear Algebra"},{"key":"21_CR66","doi-asserted-by":"publisher","first-page":"519","DOI":"10.1090\/S0025-5718-1985-0777282-X","volume":"44","author":"PL Montgomery","year":"1985","unstructured":"Montgomery, P.L.: Modular multiplication without trial division. Math. Comput. 44, 519\u2013521 (1985)","journal-title":"Math. Comput."},{"issue":"6","key":"21_CR67","doi-asserted-by":"publisher","first-page":"1842","DOI":"10.1137\/050644896","volume":"37","author":"C Moore","year":"2008","unstructured":"Moore, C., Russell, A., Schulman, L.J.: The symmetric group defies strong fourier sampling. SIAM J. Comput. 37(6), 1842\u20131864 (2008)","journal-title":"SIAM J. Comput."},{"key":"21_CR68","unstructured":"Moore, C., Russell, A., Vazirani, U.: A classical one-way function to confound quantum adversaries. arXiv preprint quant-ph\/0701115 (2007)"},{"key":"21_CR69","unstructured":"Moody, D.: The Homestretch: the beginning of the end of the NIST PQC 3rd Round, PQCrypto (2021). https:\/\/pqcrypto2021.kr\/download\/program\/2.2_PQCrypto2021.pdf"},{"issue":"2","key":"21_CR70","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1006\/jsco.1994.1007","volume":"17","author":"EA O\u2019Brien","year":"1994","unstructured":"O\u2019Brien, E.A.: Isomorphism testing for $$p$$-groups. J. Symb. Comput. 17(2), 133\u2013147 (1994)","journal-title":"J. Symb. Comput."},{"key":"21_CR71","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/3-540-68339-9_4","volume-title":"Advances in Cryptology \u2014 EUROCRYPT \u201996","author":"J Patarin","year":"1996","unstructured":"Patarin, J.: hidden fields equations (HFE) and isomorphisms of polynomials (IP): two new families of asymmetric algorithms. In: Maurer, U. (ed.) EUROCRYPT 1996. LNCS, vol. 1070, pp. 33\u201348. Springer, Heidelberg (1996). https:\/\/doi.org\/10.1007\/3-540-68339-9_4"},{"key":"21_CR72","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"463","DOI":"10.1007\/978-3-030-45724-2_16","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2020","author":"C Peikert","year":"2020","unstructured":"Peikert, C.: He gives C-sieves on the CSIDH. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT 2020. LNCS, vol. 12106, pp. 463\u2013492. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45724-2_16"},{"issue":"3","key":"21_CR73","doi-asserted-by":"publisher","first-page":"1506","DOI":"10.1109\/TETC.2021.3073475","volume":"9","author":"T Plantard","year":"2021","unstructured":"Plantard, T.: Efficient word size modular arithmetic. IEEE Trans. Emerg. Top. Comput. 9(3), 1506\u20131518 (2021)","journal-title":"IEEE Trans. Emerg. Top. Comput."},{"issue":"3","key":"21_CR74","doi-asserted-by":"publisher","first-page":"738","DOI":"10.1137\/S0097539703440678","volume":"33","author":"O Regev","year":"2004","unstructured":"Regev, O.: Quantum computation and lattice problems. SIAM J. Comput. 33(3), 738\u2013760 (2004)","journal-title":"SIAM J. Comput."},{"key":"21_CR75","unstructured":"Schulman, L.J.: Cryptography from tensor problems. IACR Cryptol. ePrint Arch. 2012, 244 (2012)"},{"key":"21_CR76","unstructured":"Seiler, G.: Faster AVX2 optimized NTT multiplication for Ring-LWE lattice cryptography. IACR Cryptol. ePrint Arch. 2018, 039 (2018)"},{"issue":"4","key":"21_CR77","doi-asserted-by":"publisher","first-page":"1193","DOI":"10.1109\/18.850662","volume":"46","author":"N Sendrier","year":"2000","unstructured":"Sendrier, N.: Finding the permutation between equivalent linear codes: the support splitting algorithm. IEEE Trans. Inf. Theory 46(4), 1193\u20131203 (2000)","journal-title":"IEEE Trans. Inf. Theory"},{"key":"21_CR78","unstructured":"Chen, M.S., et al.: Rainbow signature: one of the three nist post-quantum signature finalists (2021). https:\/\/www.pqcrainbow.org\/"},{"issue":"5","key":"21_CR79","doi-asserted-by":"publisher","first-page":"1484","DOI":"10.1137\/S0097539795293172","volume":"26","author":"PW Shor","year":"1997","unstructured":"Shor, P.W.: Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM J. Comput. 26(5), 1484\u20131509 (1997)","journal-title":"SIAM J. Comput."},{"key":"21_CR80","unstructured":"Stolbunov, A.: Cryptographic schemes based on isogenies. PhD thesis, Norwegian University of Science and Technology (2012)"},{"issue":"8","key":"21_CR81","doi-asserted-by":"publisher","first-page":"2642","DOI":"10.1016\/j.jalgebra.2009.07.029","volume":"322","author":"JB Wilson","year":"2009","unstructured":"Wilson, J.B.: Decomposing $$p$$-groups via Jordan algebras. J. Algebra 322(8), 2642\u20132679 (2009)","journal-title":"J. Algebra"},{"issue":"1","key":"21_CR82","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/BF02392023","volume":"126","author":"EM Wright","year":"1971","unstructured":"Wright, E.M.: Graphs on unlabelled nodes with a given number of edges. Acta Math. 126(1), 1\u20139 (1971)","journal-title":"Acta Math."},{"key":"21_CR83","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-642-42001-6_3","volume-title":"Number Theory and Cryptography","author":"JY-C Yeh","year":"2013","unstructured":"Yeh, J.Y.-C., Cheng, C.-M., Yang, B.-Y.: Operating degrees for XL vs. F4\/F5 for generic $$\\cal{M}Q$$ with number of equations linear in that of variables. In: Fischlin, M., Katzenbeisser, S. (eds.) Number Theory and Cryptography. LNCS, vol. 8260, pp. 19\u201333. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-42001-6_3"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2022"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-07082-2_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,27]],"date-time":"2025-05-27T22:02:51Z","timestamp":1748383371000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-07082-2_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031070815","9783031070822"],"references-count":83,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-07082-2_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"25 May 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Trondheim","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Norway","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 May 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3 June 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"41","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2022\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"372","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"85","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"23% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"18","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Peer review was double-blind with rebuttal.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}