Experimenting with Post-Quantum Cryptography
security.googleblog.com
security.googleblog.com
This article is about the implementation of an asymmetric protocol based on the RLWE (https://en.wikipedia.org/wiki/Ring_Learning_with_Errors) problem.
Size of hash, or number of iterations? Or either? And will it still be "convenient security" available for those that "only" have classical computers? (ie: is will be get away with "small" increases in size, and get to keep (some of) our current speed)?
> Biological computing is (AFAIK) irrelevant to the speedups provided by quantum mechanics.
I didn't think otherwise. But they might be relevant to combinatorial problems, and so relevant to security?
Bernstein also recently released a paper on NTRU Prime which I just became aware of, although it makes no mention of the patent issue. https://ntruprime.cr.yp.to/ntruprime-20160511.pdf
In any case, it'd be interesting to get an answer on this, since NTRU has looked interesting for a long time, but the patents were pretty unfortunate.
It is indeed a combination of R-LWE and ECC because it doesn't yet seem reasonable to depend on R-LWE alone. Not only because of the possibility of implementation faults in NewHope, but also because of the possibility of significant crypto-analytic advances against R-LWE, even with classical computers.
Uh-oh.
Apparently not even Perfect Forward Secrecy can protect against this: https://en.wikipedia.org/wiki/Forward_secrecy#Attacks
I'm interested in being able to make long term claims based on web-of-trust models, and I've been nervous about basing it around RSA/DSA key pairs.
In that sort of world, what do the keys actually look like? Is it comparable to being able to distribute a single public root key?
Hash Based signatures in a web of trust would result in enormous amounts of signature data for each public key.
A stateful hash based signing protocol like XMSS might be more suitable.
Hopefully a Post Quantum small signature alternative appears.
um... when actual information must be _matched_
via "0" and "1" harrumph's principles... eerie ahem...
and the lever is relativeness... zzz... eh... using
stochastical methods to...zzzz ...strategy... zzz
[slept away]
Like so many other things in computer science history, that seems like a great way to make it the de-facto standard.
However, the second condition seems to not be met if Google is right, because they mention there are promising papers published.
>Since we selected New Hope, we've noted two promising papers in this space, which are welcome.
https://security.googleblog.com/2016/07/experimenting-with-p...
It would be much easier if the original link was changed.
I suspect Deepak Chopra is going to appropriate it soon enough.
[0] http://www.hyperelliptic.org/tanja/ [1] https://pqcrypto.eu.org/mini.html