[Pqc] Re: [saag] Re: Re: [SAAG] A New Theory on Post-quantum Migration

John Mattsson <[email protected]> Tue, 4 Nov 2025 16:00:17 +0000
Newsgroups gmane.ietf.pqc,gmane.ietf.saag
Message-ID <GVXPR07MB9678AEC3DCA1F2D8DD25C1DA89C4A@GVXPR07MB9678.eurprd07.prod.outlook.com>
Fully agree that we should should have high theoretical confidence in lattice-based cryptography. When discussing “breaking” a cryptographic algorithm, it is important to clarify what we mean.

- Often, theoretical attacks do not break an entire field of cryptography; often they affect specific algorithms using particular optimizations. For example, the attack on SIKE relied on auxiliary torsion point information and affects SIKE specifically, it has no impact on other isogeny-based schemes such as CSIDH or SQISign.

- Theoretical attacks often do not result in practical breaks. Often, they merely reduce the effective security by a certain number of bits, without making the system immediately exploitable, giving users time to migrate.

- In practice, attacks on implementations are far more common than purely theoretical attacks. These include bugs in the algorithm’s implementation, side-channel vulnerabilities, or misuse of the algorithm in a protocol context.

Cheers,
John

From: Sophie Schmieg <[email protected]>
Date: Tuesday, 4 November 2025 at 15:52
To: Wang Guilin <[email protected]>
Cc: Deirdre Connolly <[email protected]>, IETF SAAG <[email protected]>, pqc <[email protected]>
Subject: [saag] Re: [Pqc] Re: [SAAG] A New Theory on Post-quantum Migration

On Mon, Nov 3, 2025 at 2:09 PM Wang Guilin <[email protected]<mailto:[email protected]>> wrote:

No solid source for this. This is also the reason why these assumptions are called arguable in my slides.

My intuitive idea is: Given that SIKE is not secure later but it was one out of 15 PQ algorithms (Finalists+Alternate Candidates) in the 3rd round of NIST competition, we may assume that a PQ algorithm could be at risk of 1%.

https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization/round-3-submissions

It will be great if anyone knows how to do such risk analysis much more rigorously, and what more reasonable numbers could be assigned for such initial assumptions.

Guilin


I have a blog post in the making for exactly this topic. As a sneak peak, a few words in advance: The gulf between lattice cryptography and isogeny based cryptography is so vast, it is an ocean. Lattice cryptography is old, almost as old as RSA and elliptic curves in its earliest forms. Lattices themselves are central to various fields of mathematics, not just cryptography, making lattices very well understood topics. Heck, elliptic curves, originally arose as a lattice (the inverse function of the arc length of an ellipsis has, when extended to the complex plane, two periods, aka the periods form a lattice (the period lattice), this invited the study of the complex plane modulo a lattice, an object which was then named an elliptic curve. Moving from the complex numbers to finite fields gives us the elliptic curves used in cryptography, still related to lattices via their endomorphism ring). Compared to that, isogeny crypto is relatively novel, and while isogenies are central to algebraic geometry, they are a lot less well understood compared to lattices. My Bayesian prior  for the chances of ML-KEM/ML-DSA breaking is well below 1%, probably somewhere between 1 in thousand to 1 in 100k.

发件人:Deirdre Connolly <[email protected]<mailto:[email protected]>>
收件人:Wang Guilin <[email protected]<mailto:[email protected]>>
抄 送:IETF SAAG <[email protected]<mailto:[email protected]>>;pqc <[email protected]<mailto:[email protected]>>;Wang Guilin <[email protected]<mailto:[email protected]>>
时 间:2025-11-03 12:26:07
主 题:Re: [saag] [SAAG] A New Theory on Post-quantum Migration

> A PQ signature has risk of 1/100, not as mature as
T… before 2035, against classic and CRQC attacks.

Where is this number coming from?

3 noy 2025, B.e., 11:42 AM tarixində Wang Guilin <[email protected]<mailto:[email protected]>> yazdı:
Dear all,

Last night, I gave a talk with title of A New Theory on Post-quantum Migration at HotRFC lightning talk session.

In case you are interested in it, welcome to discuss! (Personaly, I like it)

The sildes availvale here:
https://datatracker.ietf.org/meeting/124/materials/slides-124-hotrfc-sessa-11-pq-migration-00

This talk offers a new viewpoint for the value of hybrid post-quantum (PQ) migration. It is a quantitative analysis on different migration policies, with simple probability reasoning. Not complex, understandable to everyone. The context is based on recent discussions in Pquip, Jose/Cose, and Lamps WGs. The purpose is to invoke further thoughts on PQ migration policies. Under the assumptions given, hybrid signatures can reduce the migration risk 5 times lower than pure PQ migration.

Cheers,

Guilin

_______________________________________________
saag mailing list -- [email protected]<mailto:[email protected]>
To unsubscribe send an email to [email protected]<mailto:[email protected]>
--
Pqc mailing list -- [email protected]<mailto:[email protected]>
To unsubscribe send an email to [email protected]<mailto:[email protected]>


--

Sophie Schmieg | Information Security Engineer | ISE Crypto | [email protected]<mailto:[email protected]>

-- 
Pqc mailing list -- [email protected]
To unsubscribe send an email to [email protected]