[Pqc] Re: [saag] [SAAG] A New Theory on Post-quantum Migration

Sophie Schmieg <[email protected]> Tue, 4 Nov 2025 09:51:25 -0500
Newsgroups gmane.ietf.pqc,gmane.ietf.saag
Message-ID <CAEEbLAYyCvL9CuvvoxYmByx7cT0z7B6W8DJ1G+mqAQAY=y1pqA@mail.gmail.com>
On Mon, Nov 3, 2025 at 2:09 PM Wang Guilin <Wang.Guilin=
[email protected]> wrote:

>
> No solid source for this. This is also the reason why these assumptions
> are called arguable in my slides.
>
> My intuitive idea is: Given that SIKE is not secure later but it was one
> out of 15 PQ algorithms (Finalists+Alternate Candidates) in the 3rd round
> of NIST competition, we may assume that a PQ algorithm could be at risk of
> 1%.
>
>
> https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization/round-3-submissions
>
> It will be great if anyone knows how to do such risk analysis much more
> rigorously, and what more reasonable numbers could be assigned for such
> initial assumptions.
>
> Guilin
>
>
I have a blog post in the making for exactly this topic. As a sneak peak, a
few words in advance: The gulf between lattice cryptography and isogeny
based cryptography is so vast, it is an ocean. Lattice cryptography is old,
almost as old as RSA and elliptic curves in its earliest forms. Lattices
themselves are central to various fields of mathematics, not just
cryptography, making lattices very well understood topics. Heck, elliptic
curves, originally arose as a lattice (the inverse function of the arc
length of an ellipsis has, when extended to the complex plane, two periods,
aka the periods form a lattice (the period lattice), this invited the study
of the complex plane modulo a lattice, an object which was then named an
elliptic curve. Moving from the complex numbers to finite fields gives us
the elliptic curves used in cryptography, still related to lattices via
their endomorphism ring). Compared to that, isogeny crypto is relatively
novel, and while isogenies are central to algebraic geometry, they are a
lot less well understood compared to lattices. My Bayesian prior  for the
chances of ML-KEM/ML-DSA breaking is well below 1%, probably somewhere
between 1 in thousand to 1 in 100k.


> *发件人:*Deirdre Connolly <[email protected]>
> *收件人:*Wang Guilin <[email protected]>
> *抄 送:*IETF SAAG <[email protected]>;pqc <[email protected]>;Wang Guilin <
> [email protected]>
> *时 间:*2025-11-03 12:26:07
> *主 题:*Re: [saag] [SAAG] A New Theory on Post-quantum Migration
>
> > A PQ signature has risk of 1/100, not as mature as
> T… before 2035, against classic and CRQC attacks.
>
> Where is this number coming from?
>
> 3 noy 2025, B.e., 11:42 AM tarixində Wang Guilin <Wang.Guilin=
> [email protected]> yazdı:
>
>> Dear all,
>>
>> Last night, I gave a talk with title of A New Theory on Post-quantum
>> Migration at HotRFC lightning talk session.
>>
>> In case you are interested in it, welcome to discuss! (Personaly, I like
>> it)
>>
>> The sildes availvale here:
>>
>> https://datatracker.ietf.org/meeting/124/materials/slides-124-hotrfc-sessa-11-pq-migration-00
>>
>> This talk offers a new viewpoint for the value of hybrid post-quantum
>> (PQ) migration. It is a quantitative analysis on different migration
>> policies, with simple probability reasoning. Not complex, understandable to
>> everyone. The context is based on recent discussions in Pquip, Jose/Cose,
>> and Lamps WGs. The purpose is to invoke further thoughts on PQ migration
>> policies. Under the assumptions given, hybrid signatures can reduce the
>> migration risk 5 times lower than pure PQ migration.
>>
>> Cheers,
>>
>> Guilin
>>
>> _______________________________________________
>> saag mailing list -- [email protected]
>> To unsubscribe send an email to [email protected]
>>
> --
> Pqc mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>


-- 

Sophie Schmieg | Information Security Engineer | ISE Crypto |
[email protected]

-- 
Pqc mailing list -- [email protected]
To unsubscribe send an email to [email protected]