[Pqc] Re: [saag] Re: Re: [SAAG] A New Theory on Post-quantum Migration

Deirdre Connolly <[email protected]> Tue, 4 Nov 2025 12:15:53 -0500
Newsgroups gmane.ietf.pqc,gmane.ietf.saag
Message-ID <CAFR824zKEP9HdSHGxmjTUtsAOfBJ5=oicD_ndd7t=uzaY=cMcg@mail.gmail.com>
++ Sophie and John

On Tue, Nov 4, 2025, 11:00 AM John Mattsson <[email protected]>
wrote:

> Fully agree that we should should have high theoretical confidence in
> lattice-based cryptography. When discussing “breaking” a cryptographic
> algorithm, it is important to clarify what we mean.
>
> - Often, theoretical attacks do not break an entire field of cryptography;
> often they affect specific algorithms using particular optimizations. For
> example, the attack on SIKE relied on auxiliary torsion point information
> and affects SIKE specifically, it has no impact on other isogeny-based
> schemes such as CSIDH or SQISign.
>
> - Theoretical attacks often do not result in practical breaks. Often, they
> merely reduce the effective security by a certain number of bits, without
> making the system immediately exploitable, giving users time to migrate.
>
> - In practice, attacks on implementations are far more common than purely
> theoretical attacks. These include bugs in the algorithm’s implementation,
> side-channel vulnerabilities, or misuse of the algorithm in a protocol
> context.
>
> Cheers,
> John
>
> *From: *Sophie Schmieg <[email protected]>
> *Date: *Tuesday, 4 November 2025 at 15:52
> *To: *Wang Guilin <[email protected]>
> *Cc: *Deirdre Connolly <[email protected]>, IETF SAAG <
> [email protected]>, pqc <[email protected]>
> *Subject: *[saag] Re: [Pqc] Re: [SAAG] A New Theory on Post-quantum
> Migration
>
> On Mon, Nov 3, 2025 at 2:09 PM Wang Guilin <Wang.Guilin=
> [email protected]> wrote:
>
>
> No solid source for this. This is also the reason why these assumptions
> are called arguable in my slides.
>
> My intuitive idea is: Given that SIKE is not secure later but it was one
> out of 15 PQ algorithms (Finalists+Alternate Candidates) in the 3rd round
> of NIST competition, we may assume that a PQ algorithm could be at risk of
> 1%.
>
>
> https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization/round-3-submissions
>
> It will be great if anyone knows how to do such risk analysis much more
> rigorously, and what more reasonable numbers could be assigned for such
> initial assumptions.
>
> Guilin
>
>
> I have a blog post in the making for exactly this topic. As a sneak peak,
> a few words in advance: The gulf between lattice cryptography and isogeny
> based cryptography is so vast, it is an ocean. Lattice cryptography is old,
> almost as old as RSA and elliptic curves in its earliest forms. Lattices
> themselves are central to various fields of mathematics, not just
> cryptography, making lattices very well understood topics. Heck, elliptic
> curves, originally arose as a lattice (the inverse function of the arc
> length of an ellipsis has, when extended to the complex plane, two periods,
> aka the periods form a lattice (the period lattice), this invited the study
> of the complex plane modulo a lattice, an object which was then named an
> elliptic curve. Moving from the complex numbers to finite fields gives us
> the elliptic curves used in cryptography, still related to lattices via
> their endomorphism ring). Compared to that, isogeny crypto is relatively
> novel, and while isogenies are central to algebraic geometry, they are a
> lot less well understood compared to lattices. My Bayesian prior  for the
> chances of ML-KEM/ML-DSA breaking is well below 1%, probably somewhere
> between 1 in thousand to 1 in 100k.
>
>
> *发件人:*Deirdre Connolly <[email protected]>
> *收件人:*Wang Guilin <[email protected]>
> *抄 送:*IETF SAAG <[email protected]>;pqc <[email protected]>;Wang Guilin <
> [email protected]>
> *时 间:*2025-11-03 12:26:07
> *主 题:*Re: [saag] [SAAG] A New Theory on Post-quantum Migration
>
> > A PQ signature has risk of 1/100, not as mature as
> T… before 2035, against classic and CRQC attacks.
>
> Where is this number coming from?
>
> 3 noy 2025, B.e., 11:42 AM tarixində Wang Guilin <Wang.Guilin=
> [email protected]> yazdı:
>
> Dear all,
>
> Last night, I gave a talk with title of A New Theory on Post-quantum
> Migration at HotRFC lightning talk session.
>
> In case you are interested in it, welcome to discuss! (Personaly, I like
> it)
>
> The sildes availvale here:
>
> https://datatracker.ietf.org/meeting/124/materials/slides-124-hotrfc-sessa-11-pq-migration-00
>
> This talk offers a new viewpoint for the value of hybrid post-quantum (PQ)
> migration. It is a quantitative analysis on different migration policies,
> with simple probability reasoning. Not complex, understandable to everyone.
> The context is based on recent discussions in Pquip, Jose/Cose, and Lamps
> WGs. The purpose is to invoke further thoughts on PQ migration policies.
> Under the assumptions given, hybrid signatures can reduce the migration
> risk 5 times lower than pure PQ migration.
>
> Cheers,
>
> Guilin
>
> _______________________________________________
> saag mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>
> --
> Pqc mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>
>
>
> --
>
> Sophie Schmieg | Information Security Engineer | ISE Crypto |
> [email protected]
>
>

-- 
Pqc mailing list -- [email protected]
To unsubscribe send an email to [email protected]