[Pqc] Re: [saag] [SAAG] A New Theory on Post-quantum Migration
"D. J. Bernstein" <[email protected]> 4 Nov 2025 12:03:47 -0000
| Newsgroups | gmane.ietf.pqc,gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
Wang Guilin writes:
> Given that SIKE is not secure later but it was one out of 15 PQ
> algorithms (Finalists+Alternate Candidates) in the 3rd round of NIST
> competition, we may assume that a PQ algorithm could be at risk of 1%.
https://cr.yp.to/papers/qrcsp-20231202.pdf#not-34 points out two reasons
to consider an older, wider selection than the 3rd-round or 4th-round
candidates in the NIST competition. The conclusions of that study were
that
* 48% of the round-1 post-quantum submissions in 2017,
* 25% of the round-1 submissions that survived round 1, and
* 36% of the round-1 submissions selected by NIST for round 2
were publicly broken by the end of 2023.
One can _hope_ that subsequent focus on a narrower pool of cryptosystems
will find all of the security problems in those, but it's not as if the
costs of basic lattice attacks have stabilized (see, e.g., last month's
https://eprint.iacr.org/2025/1910), not to mention that cryptanalysts
continue to be flooded with other targets.
I would love to see a study of cryptographic failure rates that's broad
enough to include not just KEM failures and signature failures but also,
e.g., OCB2 (refereed "security proof" in 2004, standardized in 2009,
smashed in 2019) and XCBv2 (refereed "security proof" in 2007,
standardized in 2010, broken for unusual block lengths in 2015, refereed
"security proof" for common block lengths in 2015, smashed in 2024).
https://eprint.iacr.org/2019/1336 has a remarkable collection of proof
failures, but doesn't start with a predefined pool, so drawing any
statistical conclusions is difficult.
Outside cryptography, it's normal for people to collect quantitative
data regarding failures, so as to predict future risks and guide
improvements. See, e.g.,
https://injuryfacts.nsc.org/motor-vehicle/occupant-protection/seat-belts/
regarding seat belts. It's surprising that such basic statistical data
collection isn't normal practice in cryptography.
---D. J. Bernstein
===== NOTICES =====
This document may not be modified, and derivative works of it may not be
created, and it may not be published except as an Internet-Draft. (That
sentence is the official language from IETF's "Legend Instructions" for
the situation that "the Contributor does not wish to allow modifications
nor to allow publication as an RFC". I'm fine with redistribution of
copies of this document; the issue is with modification.)
--
Pqc mailing list -- [email protected]
To unsubscribe send an email to [email protected]