Plagiarism as a patent amplifier: Understanding the delayed rollout of PQC
blog.cr.yp.to
blog.cr.yp.to
[0] https://mailarchive.ietf.org/arch/msg/cfrg/qLTveWOdTJcLn4HP3...
I haven't finished reading this post yet, and I don't know much about cryptography, so it is somewhat risky for me to be summarizing it; but my summary is that Google's planned rollout of post-quantum-resistant TLS was aborted in November 02016 without explanation after only a few months rather than being continued for a few years as planned, apparently because it infringed a patent by Ding, even though it was based on a paper by Peikert that didn't credit Ding and thus didn't give any warning that a patent might be lying in wait. The plagiarism mentioned in the title is summarized just before the section "The concept of plagiarism":
> But 2012 Ding did reduce the LPR ciphertext size "nearly twofold", specifically replacing "one of the two ring elements" with "a binary string of the same dimension n", in the words of 2014 Peikert. The problem is that this isn't how 2014 Peikert was describing 2012 Ding; this was 2014 Peikert claiming this space reduction as something new, the result of an "innovation" in 2014 Peikert.
Though the post doesn't say this, the patent in question (https://patents.google.com/patent/US9246675B2) was filed in 02013 and issued in January 02016.
Bernstein explains that one result of this delay in deployment is that a great deal of TLS traffic that has already been captured and archived will probably be decrypted when quantum computers become available. He doesn't mention this, but I think this includes ciphersuites that claim "perfect forward secrecy".
Very much so, yes.
At the same time, I wonder how much he asked for from Google and how open the algorithm would have been (/ if it could have been "bought out").
I'm not a big fan of the patent system and maybe we'd all be better off with something else, or with nothing at all, but given that the system's there it's not unreasonable for people who think up valuable things to use it. (Within reason! If Ding says "everyone who uses this has to give me ten billion dollars" then obviously what happens is that Ding gets no money and no one else gets to use Ding's idea, and that's plainly the worst of all worlds. But presumably Ding isn't stupid and that sort of outcome is unlikely.)
Obviously it's a different matter if e.g. there are other equally good ways to do Ding's thing and Ding tried to conceal his patent in the hope that others would pick his way of doing it and make expensive-to-change decisions from which he could then profit.
(I'm not sure whether "the alleged plagiarism of Peikert" means "Ding's alleged plagiarism of Peikert" or "the alleged plagiarism committed by Peikert"; what Bernstein is alleging is definitely the latter.)
The Forbes reference actually says that an oversight body allows the NSA to keep encrypted data forever, not that they actually do. There is so much encrypted data on the internet now that the NSA would have to use a significant amount of all the storage produced each year to keep a running archive of everything. A victory of sorts...
[1] https://www.forbes.com/sites/andygreenberg/2013/06/20/leaked...
Back in 2016, Google began an experiment with "post-quantum cryptography", deploying some cryptographic algorithms in Chrome and in Google's servers that should be resistant to attack by quantum computers. (Most present-day crypto would be very badly broken if non-toy quantum computing becomes practical.)
But they shut it down after a few months, even though it seemed to be working well. They'd originally said that if it went well they'd find a better algorithm and switch to it in a couple of years. So what happened?
Plausible answer: shortly after beginning this experiment they were contacted by a cryptography researcher (Jintai Ding) who holds a patent that allegedly covers the algorithm they were using. The easiest course of action when this happens is just to shut the thing down.
So how come they didn't know about this patent?
Plausible answer: because another cryptography researcher (Chris Peikert) deliberately and systematically misled the academic community in order to avoid them noticing Ding's work -- because Ding did an important thing in 2012, and Peikert did essentially the same thing in 2014, and Peikert wanted to take credit for inventing it. Peikert succeeded, everyone thinks he invented the relevant things first, and no one thought to check whether Ding might have patents on it.
(I reiterate that I am summarizing Bernstein's claims, and I do not know whether they are right or not.)
TLDR of the TLDR: according to Bernstein, a dishonest academic cryptographer went out of his way to deceive his colleagues into ignoring earlier work by another cryptographer, so as to get the credit for it himself, this led to an important patent being overlooked by Google, and this has been a completely unnecessary stumbling block in the way of getting post-quantum cryptography deployed, so that Peikert's (alleged) selfishness and dishonesty have made everyone's data much less safe against future quantum-computer-based attacks.
E.g., I think the following scenario is consistent with all DJB's straightforwardly checkable claims: Peikert did see Ding's 2012 paper, or at least its 2014 revision, but didn't read it carefully and didn't appreciate that it meant Ding had anticipated Peikert's innovations by 2 years; Peikert's subsequent writing on the subject is misleading but not intended to deceive.
And, of course, if DJB is wrong on some of the straightforwardly checkable claims, all bets are off.
DJB is opinionated and iconoclastic, for sure, but I wouldn't generally expect him to make claims that are flatly false. E.g., if he says that Ding (2012) does basically all the important things that Peikert (2014) does then I would expect that to be correct. But I don't know the Bernstein/Peikert history, and even generally reliable people can go badly wrong when it comes to people they really hate...
Presumably Peikert will see this post and will either not respond publicly, or respond. If he responds publicly he will either deny or affirm Bernstein's claims. If he does not respond, he is being consciously and deliberately deceptive. If he affirms Bernstein's claims, he was being consciously and deliberately deceptive in the past. If he denies Bernstein's claims, then either they are correct or not. If they are correct, then his denial is just more of the kind of deception Bernstein caught him at. If they are incorrect, then Bernstein is the one at fault.
But of course the general public doesn't read the PQC mailing list: where the actual experts in this area communicate. And Dan knows this. That's why he posted this set of accusations on a blog that has a general audience, knowing full well that Peikert won't be able to defend himself to the same people.
When you say "If [Peikert] does not respond, he is being consciously and deliberately deceptive" you captured precisely the problem with writing this post: it makes a bunch of weak, unsupported allegations against Peikert in a forum where most readers can't judge the evidence and Peikert can't respond. It's incredibly dishonest -- and its a matter of public concern, since I believe Dan's post is consistent with a pattern of bullying and intimidation of researchers who criticize his NIST proposals on scientific grounds.
I think there is a legitimate public interest in understanding why PQC hasn't been widely adopted.
TL;DR: people frequently miss works that are published only on ePrint servers. It appears that Peikert cited the work in a later draft and Dan disagrees with the citation. I can’t tell you whether the techniques are different: this isn’t my research area. However Dan even acknowledges that the distributions of the shared secret are different (as Peikert acknowledges in his work), but then claims this doesn’t matter in common applications. I’m not here to adjudicate what seems to be a minor question of presentation, but I would like to see much more care around something as serious as a plagiarism accusation, particularly given the personal rancor between these two.