TL;DR
Public keys and signatures on standard BLS12 curves are deterministically structured, making them vulnerable to Deep Packet Inspection (DPI) censorship at the networking layer. Point-to-Uniform obfuscation (like Elligator Squared) mitigates this, but applying it to BLS12-381 creates a massive computational bottleneck for receiving validators due to its heavy 11-isogeny bridge.
By utilizing an optimized BLS12-479+ curve with an even cofactor, we can implement an explicit inverse 2-isogeny bridge. This reduces the deobfuscation overhead on the receiver’s end to just ~73,000 CPU cycles (<30 µs) — a 19.7x speedup, ensuring near-zero latency during mass block broadcasting.
The Problem: EIP-2537 and the 11-Isogeny Bottleneck
Censorship resistance requires hiding cryptographic material within uniform random strings. In a One-to-Many gossip protocol, a validator (sender) obfuscates a signature once, but tens of thousands of nodes (receivers) must deobfuscate it to verify the packet.
As standardized in EIP-2537, the Fp-to-G1 mapping for BLS12-381 relies on an 11-isogeny, requiring the evaluation of 11th and 15th-degree polynomials. While suitable for basic hash_to_curve operations, using this monolithic bridge for Elligator Squared deobfuscation costs ~1,439,000 cycles. This is unacceptably heavy for high-throughput gossipsub propagation.
The Solution: Constructive 2-Isogeny Inversion
Instead of relying on monolithic polynomial root-finding, I have modeled a steganographically optimized curve (BLS12-479+). Its even cofactor natively supports a mathematically trivial 2-isogeny bridge.
Using explicit Vélus formulas, the inverse mapping is evaluated strictly as a sum of rational poles. The heavy lifting (solving quadratics for obfuscation) is strictly offloaded to the block proposer (sender). The network receivers only execute the lightweight forward isogeny.
Hardware Benchmarks (Magma Implementation)
| Metric | BLS12-381 (RFC 9381) | BLS12-479+ (Proposed) | Performance Gain |
|---|---|---|---|
| Isogeny Degree | 11-isogeny | 2-isogeny | - |
| Security Level | ~128-bit | ~160-bit | +32 bits |
| Obfuscation (Sender) | ~4,250,000 cycles | ~1,793,000 cycles | ~2.37x Speedup |
| Deobfuscation (Receiver) | ~1,439,000 cycles | ~73,000 cycles | ~19.7x Speedup |
Note: The local benchmarks track pure cryptographic clock cycles without P2P network noise.
Links & Proofs
I have published the full algebraic proofs, kernel extraction theorems, and Magma scripts for both G1​ and G2​ mappings:
I would highly appreciate feedback from the core cryptography community on the feasibility of transitioning to even-cofactor curves for censorship-resistant consensus layers. Are there any hidden EVM precompile edge cases I should consider with this curve topology?
As a theoretical follow-up to the EIP-2537 hash_to_curve baseline:
It is worth recalling the results of Koshelev et al. regarding optimized indifferentiable hashing to j=0 curves (like BLS12-381). While their work provides elegant mathematical optimizations for the forward Hash-to-Curve mapping (e.g., minimizing exponentiations compared to the standard Wahby-Boneh 11-isogeny approach), the inverse mapping (Point-to-Uniform via Elligator Squared) remains fundamentally constrained by the isogeny degree itself.
By transitioning to a curve like BLS12-479+ with a mathematically trivial 2-isogeny, we essentially complement those forward-mapping optimizations. It ensures that the Elligator Squared deobfuscation on the receiver’s end is just as hardware-efficient, completely bypassing the monolithic polynomial evaluations inherent to higher-degree isogenies.
It would also be interesting to explore if any of the recent batch-hashing techniques proposed by Koshelev could be adapted to further optimize the proposer-side (sender) obfuscation overhead on this new curve topology.
References / Theoretical Context:
-
D. Koshelev. “Indifferentiable hashing to ordinary elliptic Fq -curves of j=0 with the cost of one exponentiation in Fq .” Designs, Codes and Cryptography, 90(3):621–641, 2022. <https://doi.org/10.1007/s10623-022-01012-8>
-
D. Koshelev. “The most efficient indifferentiable hashing to elliptic curves of j-invariant 1728.” Journal of Mathematical Cryptology, 16(1):119–131, 2022. <https://doi.org/10.1515/jmc-2021-0051>
-
J. Chávez-Saab, F. RodrĂguez-HenrĂquez, and M. Tibouchi. “SwiftEC: Shallue–van de Woestijne indifferentiable function to elliptic curves.” Journal of Cryptology, 37(4):Article 34, 2024. <https://doi.org/10.1007/s00145-024-09529-y>
-
D. Koshelev. “Simultaneously simple universal and indifferentiable hashing to elliptic curves.” In Progress in Cryptology – AFRICACRYPT, Lecture Notes in Computer Science. Springer, 2025/2026. <https://doi.org/10.1007/978-3-031-97260-7_18>