Elliptic Curve Cryptography: A Basic Introduction
blog.boot.dev
blog.boot.dev
Indeed, OpenSSH recently enabled PQC by default (NTRU Prime over X25519) [1]. ECC has, at best, a short-to-medium term lifespan right now.
1. https://www.zdnet.com/article/openssh-now-defaults-to-protec...
Ring-LWE is faster than ECC, but has keys and ciphertexts of 600+B instead of as few as 32 B (for eg curve/ed25519). NTRU is pretty similar, with slower key generation and slightly smaller ciphertexts. If you go to the bleeding edge, you might be able to cut these to 300-400 bytes with severe compromises in eg error rate and security margin. There are also structured code-based systems with fairly similar sizes to the Ring-LWE ones, but they aren't finalists.
McEliece is fast to encrypt and decrypt and has small ciphertexts (as few as 128 bytes), but has enormous public keys (multi-hundred KB) that are also slow to generate. The biggest benefit of McEliece is that we're pretty confident it will hold up to analysis.
SIKE (an alternate) has reasonable keys and ciphertexts (200-250 B) but is pretty slow, on the order of 5ms on a laptop for the smallest parameters. The bleeding-edge CSIDH is much slower, but has even smaller keys, but we can't be at all confident that CSIDH is secure.
On the sig side, Falcon is fast but extremely complicated, and has as low as ~660B sigs. Its main competitor, Dilithium, is modestly slower and larger, and also significantly simpler. The much more conservative SPHINCS+ is very slow and produces ~8kB sigs.
That way, you keep the post-quantum crypto out of the kernel, and if done carefully by hashing together PQC, ECDH, and a pre-shared-pre-key to generate the pre-shared key, it would be easier to demonstrate that it's no weaker than WireGuard. If the daemon removes and forgets the negotiated pre-shared-keys after 24 hours, then against classic attackers you'd still have perfect forward secrecy, and against quantum attackers you'd have 24-hour forward secrecy (assuming no statistical flaws in ChaCha20).
I'd say by far the most important thing will stay resistance to unknown classical algorithms, at least until trends change.
https://cloudsecurityalliance.org/press-releases/2022/03/09/...
[0] https://andrea.corbellini.name/2015/05/17/elliptic-curve-cry...
He was so deeply into math theory that he hadn't even looked at or cared about the practical applications of his work.
I was taking a chemistry class where we were learning by rote how to apply the Grand Orthogonality Theorem. We were clearly computing inner products, but I couldn't suss out the big picture and the chem professor didn't know either, so I went to the math department and joined a seminar, which happened to be almost nextdoor to the chemistry class. The professor teaching it had never heard of the applications to chemistry/spectroscopy, though he was delighted to find out.
Not 30 yards apart, two groups of people were approaching the same subject from opposite angles with zero awareness of each other.
Silos are amazing.
You "wrap around" because you're using a finite field. As far as I understand, the finite field of the scalars allows you to have an inverse for the multiplication, and the finite field of the points is there to make the calculation easier.
Not quite as bad but, I didn't really get any good insight in how ECC works.
P.S. I'm just making this comment so I can keep a track of this.
Now you give me A and E, why can't I just compute the path from A until I hit E? That looks like the same effort, so what did I miss?
Got it, sorry xD
(Okay, I have only a tenuous understanding of this myself. I’m a physicist, not a mathematician! Mathematicians are intimidating.)