[Pqc] Re: [saag] Re: Re: [SAAG] A New Theory on Post-quantum Migration
Deirdre Connolly <[email protected]> Tue, 4 Nov 2025 12:15:53 -0500
| Newsgroups | gmane.ietf.pqc,gmane.ietf.saag |
|---|---|
| Message-ID | <CAFR824zKEP9HdSHGxmjTUtsAOfBJ5=oicD_ndd7t=uzaY=cMcg@mail.gmail.com> |
++ Sophie and John On Tue, Nov 4, 2025, 11:00 AM John Mattsson <[email protected]> wrote: > Fully agree that we should should have high theoretical confidence in > lattice-based cryptography. When discussing “breaking” a cryptographic > algorithm, it is important to clarify what we mean. > > - Often, theoretical attacks do not break an entire field of cryptography; > often they affect specific algorithms using particular optimizations. For > example, the attack on SIKE relied on auxiliary torsion point information > and affects SIKE specifically, it has no impact on other isogeny-based > schemes such as CSIDH or SQISign. > > - Theoretical attacks often do not result in practical breaks. Often, they > merely reduce the effective security by a certain number of bits, without > making the system immediately exploitable, giving users time to migrate. > > - In practice, attacks on implementations are far more common than purely > theoretical attacks. These include bugs in the algorithm’s implementation, > side-channel vulnerabilities, or misuse of the algorithm in a protocol > context. > > Cheers, > John > > *From: *Sophie Schmieg <[email protected]> > *Date: *Tuesday, 4 November 2025 at 15:52 > *To: *Wang Guilin <[email protected]> > *Cc: *Deirdre Connolly <[email protected]>, IETF SAAG < > [email protected]>, pqc <[email protected]> > *Subject: *[saag] Re: [Pqc] Re: [SAAG] A New Theory on Post-quantum > Migration > > On Mon, Nov 3, 2025 at 2:09 PM Wang Guilin <Wang.Guilin= > [email protected]> wrote: > > > No solid source for this. This is also the reason why these assumptions > are called arguable in my slides. > > My intuitive idea is: Given that SIKE is not secure later but it was one > out of 15 PQ algorithms (Finalists+Alternate Candidates) in the 3rd round > of NIST competition, we may assume that a PQ algorithm could be at risk of > 1%. > > > https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization/round-3-submissions > > It will be great if anyone knows how to do such risk analysis much more > rigorously, and what more reasonable numbers could be assigned for such > initial assumptions. > > Guilin > > > I have a blog post in the making for exactly this topic. As a sneak peak, > a few words in advance: The gulf between lattice cryptography and isogeny > based cryptography is so vast, it is an ocean. Lattice cryptography is old, > almost as old as RSA and elliptic curves in its earliest forms. Lattices > themselves are central to various fields of mathematics, not just > cryptography, making lattices very well understood topics. Heck, elliptic > curves, originally arose as a lattice (the inverse function of the arc > length of an ellipsis has, when extended to the complex plane, two periods, > aka the periods form a lattice (the period lattice), this invited the study > of the complex plane modulo a lattice, an object which was then named an > elliptic curve. Moving from the complex numbers to finite fields gives us > the elliptic curves used in cryptography, still related to lattices via > their endomorphism ring). Compared to that, isogeny crypto is relatively > novel, and while isogenies are central to algebraic geometry, they are a > lot less well understood compared to lattices. My Bayesian prior for the > chances of ML-KEM/ML-DSA breaking is well below 1%, probably somewhere > between 1 in thousand to 1 in 100k. > > > *发件人:*Deirdre Connolly <[email protected]> > *收件人:*Wang Guilin <[email protected]> > *抄 送:*IETF SAAG <[email protected]>;pqc <[email protected]>;Wang Guilin < > [email protected]> > *时 间:*2025-11-03 12:26:07 > *主 题:*Re: [saag] [SAAG] A New Theory on Post-quantum Migration > > > A PQ signature has risk of 1/100, not as mature as > T… before 2035, against classic and CRQC attacks. > > Where is this number coming from? > > 3 noy 2025, B.e., 11:42 AM tarixində Wang Guilin <Wang.Guilin= > [email protected]> yazdı: > > Dear all, > > Last night, I gave a talk with title of A New Theory on Post-quantum > Migration at HotRFC lightning talk session. > > In case you are interested in it, welcome to discuss! (Personaly, I like > it) > > The sildes availvale here: > > https://datatracker.ietf.org/meeting/124/materials/slides-124-hotrfc-sessa-11-pq-migration-00 > > This talk offers a new viewpoint for the value of hybrid post-quantum (PQ) > migration. It is a quantitative analysis on different migration policies, > with simple probability reasoning. Not complex, understandable to everyone. > The context is based on recent discussions in Pquip, Jose/Cose, and Lamps > WGs. The purpose is to invoke further thoughts on PQ migration policies. > Under the assumptions given, hybrid signatures can reduce the migration > risk 5 times lower than pure PQ migration. > > Cheers, > > Guilin > > _______________________________________________ > saag mailing list -- [email protected] > To unsubscribe send an email to [email protected] > > -- > Pqc mailing list -- [email protected] > To unsubscribe send an email to [email protected] > > > > -- > > Sophie Schmieg | Information Security Engineer | ISE Crypto | > [email protected] > > -- Pqc mailing list -- [email protected] To unsubscribe send an email to [email protected]