What Is Post-Quantum Cryptography? – NIST
nist.gov
nist.gov
The developers of OpenSSH agree enough to use this scheme in OpenSSH.
DJB is high profile enough that all of his stuff gets a lot of cryptanalysis from experts. This isn't a rando proposing a scheme that no one can follow, and no one can be bothered to review. He consistently designs cryptographic systems which perform better and are less error prone to implement than systems designed by committees of people.
I promise you, CRYSTALS-Kyber does not lack for expert analysis.
I ask all this because there's a pretty big "Schneier Facts" vibe to anything that involves Bernstein, and because I don't think you'll find many cryptographers --- probably even including on the NTRU Prime team --- that would sign off on his critique of Kyber and the NIST process. I could be wrong, but if I am, could you tell me how?
https://csrc.nist.gov/Projects/post-quantum-cryptography/sel...
Some previous discussion on this from 2022 and 2023:
Or simply because it was the most convenient algorithm at the time (2022).
There may also be regulated industries where Officially Approved™ algorithms need to be used, and if you're not on the list you're not going to be enabled, so if the developers of OpenSSH want to protect their users in those situations, then they're going to have to offer something on the list (even if it's not enable by default, or further down the preference ranking in the default settings).
* https://ubuntu.com/blog/ubuntu-22-04-fips-140-3-modules-avai...
* https://www.stigviewer.com/stig/canonical_ubuntu_22.04_lts/2...
* https://www.stigviewer.com/stig/red_hat_enterprise_linux_9/2...
* https://support.apple.com/en-ca/guide/certifications/apc35eb...
So in my opinion, NTRU Prime is a good cryptosystem. But it's not particularly better than Kyber: each has small advantages and disadvantages, and both got a ton of expert review (Kyber even more than NTRU Prime), and they will probably stand or fall together depending on improvements in lattice cryptanalysis.
I also don't think Kyber suffers from design-by-committee. There are a zillion small choices to make in these lattice schemes, and while some choices are definitely wrong, both the NTRU Prime and Kyber teams made reasonable ones. The same goes for SABER and regular NTRU.
But really, there are very few "trustworthy" PQCrypto algorithms/implementations and he is the author of more than one of those.
Personally I think that FALCON is brilliant, but it is very difficult to securely implement or even precisely define, due to heavy use of floating-point arithmetic in the signing routine. I don't want to put words in DJB's mouth, but if you share his concern for ease of secure implementation, ease of auditing and side-channel protection, then you may prefer SPHINCS+ or, if the performance of SPHINCS+ is not acceptable in your workload, possibly Dilithium.
Of course, if signature size is make-or-break, then of the choices currently slated for standardization, FALCON has the smallest signatures. But it is possible that the new signature onramp will change that in a few years -- if you can be confident in the security of whatever is chosen within so short a time.
Has NIST stopped to recommend one winner and opted for several. Or, do these have different purposes?
Dilithium is faster but less conservative, harder to implement securely, and produces medium sigs.
FALCON is even harder to implement securely, faster to verify and produces smaller sigs, though still much larger than classical systems. IMHO this choice was questionable, in that its advantages overlap too heavily with Dilithium to be worth another standard, but NIST apparently felt otherwise.
"NTRU encryption algorithm, is an NTRU lattice-based alternative to RSA and elliptic curve cryptography (ECC) and is based on the shortest vector problem in a lattice (which is not known to be breakable using quantum computers)."[0]
Do you have a project webpage?
It got me thinking. Once someone truly does break current gen encryption via quantum or otherwise, how much time would go by before it is made known to the public that the encryption is broken?
It seems the safest path forward is to assume encryption is broken and move to post-quantum crypto before we “need” to.
It's actually "so much value" that it's not possible to take much of it if you reveal that you did. People can "fork (parts of) the financial system" even more easily (per actor) than what happens with cryptocurrencies.
Sure, it's a huge hassle with huge overhead but you cannot reveal the capability and also take more than that hassle is worth. I think this means that anyone capable of doing it would not reveal the ability as as a first priority, as others here have also suggested. Especially for a state actor, the trade-off is very clear.
At that point though, why would anyone be on the buy side of the sell to USD?
FWIW, secondary to that: 100%, industry and NIST are actively voicing this, there's an interesting Google blog somewhere about work on it in Chrome (tl;dr: behind flags in chrome, but you can try it today. I think this is what I'm thinking of: https://blog.chromium.org/2023/08/protecting-chrome-traffic-...)
Enigma was already broken. AIUI, Turing et al helped automate the deciphering messages, which was heavy going manually because of the volumes involved.
Bletchley Park did have to do cryptanalysis on Enigma when a new rotor was added though.
Completely 'original' breaking did occur at Bletchley Park with (e.g.) the Lorenz cipher; see William "Bill" Tutte.
The book is much better about both.
Enigma was originally broken by a team of Polish cryptanalysts, who invented both a paper method to break it (Zygalski sheets) and the machine shown in movie (Rejewski's bomba). Turing later worked on a team to improve the bomba, which was a significant achievement but he didn't invent or spearhead the whole thing.
All this "don't use a machine to do a man's job" was bullshit invented for the movie, as were like half the other conflicts. Everyone involved knew that breaking Enigma was important, and they were already using a machine to do it, but after the Nazis changed their use of Enigma, the Brits needed mathematical insights to improve the speed of their machine.
The main characters in the film did exist and had some of the personality traits shown, but mostly didn't interact they way that the film showed. Turing was openly gay. Cairncross (the spy) didn't work with Turing. The codebreakers didn't choose which intercepted information to use and how, etc.
Many of the bigger inventions in history were popularized by someone other than the original inventor, because everything is a remix: https://www.youtube.com/watch?v=nJPERZDfyWc
He's a movie trope instead of a character or a person.
The Poles had broken Enigma before the outbreak of war (1945-09-01) with the help of intelligence from France. Bletchley Park used computers to speed up the process of going through the messages.[0]
It has been remarked that 'cracking Enigma shortened the war by X years',[1] so for some people this could be considered "significantly influenced".
However, after reading Engineers of Victory by Paul Kennedy:
> Kennedy recounts the inside stories of the invention of the cavity magnetron, a miniature radar “as small as a soup plate,” and the Hedgehog, a multi-headed grenade launcher that allowed the Allies to overcome the threat to their convoys crossing the Atlantic; the critical decision by engineers to install a super-charged Rolls-Royce engine in the P-51 Mustang, creating a fighter plane more powerful than the Luftwaffe’s; and the innovative use of pontoon bridges (made from rafts strung together) to help Russian troops cross rivers and elude the Nazi blitzkrieg. He takes readers behind the scenes, unveiling exactly how thousands of individual Allied planes and fighting ships were choreographed to collectively pull off the invasion of Normandy, and illuminating how crew chiefs perfected the high-flying and inaccessible B-29 Superfortress that would drop the atomic bombs on Japan.
* https://www.penguinrandomhouse.com/books/91616/engineers-of-...
I think there were more important developments than cracking Enigma, as influential as that could have been.
If we're talking about codes, then I think the Americans breaking the Japanese ones was more important: the US would have won regardless just because of industrial output, but the intercepts allowed things like being able to predict Midway and being able to take out Yamamoto had more meaningful operational results than what was gained out of Ultra, IMHO.
In the European theatre, I think the Merlin engine was much more critical to the outcome of the war (especially in the Battle of Britain), and the cavity magnetron was more important in the Battle of the Atlantic (along with re-learning to use convoys, like was done in WW1).
[0] Bletchley Park broke other codes, like Lorenz; see William "Bill" Tutte.
An even safer path would be to use both "classical" and post-quantum methods in combination ("hybrid"). You're protected against someone building quantum computers (and inventing new math to break classical cryptography, which is less likely) and also against yet-undiscovered weaknesses of post-quantum primitives.
For confidential data, the only rational thing to do is assume asymmetric crypto is already broken, or will be broken soon. And for non-confidential data, well...come on, who wants to waste time combing through data and deciding if it's confidential or not?
AES-256 is a symmetric encryption method and PQC has nothing to do with it.
The article in question mentions one of the key risks of not introducing quantum-resistant methods: harvesting the encrypted data and waiting for a future date to decrypt it. This is a real risk, and breakthroughs in this field are difficult to predict. Considering the fact that NIST’s guidance applies to most of the federal government, it is prudent for their strictest forms of security standards to provide a high level of assurance against state-level threat actors.