[Pqc] Re: [saag] Re: Re: [SAAG] A New Theory on Post-quantum Migration

Wang Guilin <[email protected]> Tue, 4 Nov 2025 19:46:11 +0000
Newsgroups gmane.ietf.pqc,gmane.ietf.saag
Message-ID <[email protected]>
For the definition of secure or well-constructed hybrid, our definitions seem the same.

About the initial risk provablities assigned, yes, it is just for starting calculation. It will be great if some new numbers could be given with solid sources or rationale.

See more comments inline.

Guilin

发件人:John Mattsson <[email protected]<mailto:[email protected]>>
收件人:Wang Guilin <[email protected]<mailto:[email protected]>>;Hale, Britta (CIV) <[email protected]<mailto:[email protected]>>;Deirdre Connolly <[email protected]<mailto:[email protected]>>
抄 送:IETF SAAG <[email protected]<mailto:[email protected]>>;pqc <[email protected]<mailto:[email protected]>>
时 间:2025-11-04 09:56:33
主 题:Re: [saag] Re: [Pqc] Re: [SAAG] A New Theory on Post-quantum Migration

Wang Guilin wrote:
>Hydrid is secure (in sense of one particular security property) if either of the component algorithm does.

I disagree with this definition. In line with NIST SP 800-227, I believe that a well-constructed composite should preserve the security properties of its components. Composites that degrade the security properties should not be regarded as secure.

---------
Guilin' comments: I mean, a well-constructed or decure hydrid is: it will be secure (in sense of one particular security property) if either of the component algorithm is.

So, our defintions look the same. My previous description may be a little confusing.
---------

Wang Guilin wrote:
>My intuitive idea is: Given that SIKE is not secure later but it was one out of 15 PQ algorithms (Finalists+Alternate Candidates) in the 3rd round of NIST competition, we may assume that a PQ algorithm could be at risk of 1%.

It seems very strange to draw general conclusions from this single event. Why should it apply to PQC as a whole, or to standardized algorithms? Empirically, adopting algorithms standardized by NIST has proven to be a very sound choice.

---------
Guilin' comments: Yes, your points valid. As I mentioned the above and in a previous reply, 1% is my personal estimation, no solid source.

It will be great to see if anyone has such probabilities or know how to derive those with solid approaches.
---------

More generally, using algorithms recommended by a government for its industry, and even more so those a government uses in its own national security systems, tends to provide robust security. In doing so, one benefits not only from the open body of public cryptanalytic research but also from insights derived from non-public analysis. In addition to the well-known fixes to DES and SHA, the B-curves designed by NSA and SAKKE designed by GCHQ turned out to be much better than many non-standardized alternatives. Their designs suggest either advance knowledge or caution in parameter selection. Later attacks (e.g., Weil descent, FFDLP in binary fields, SexTNFS) that devastated many academic curves had no impact on these government standards.

Cheers,
John

From: Wang Guilin <[email protected]<mailto:[email protected]>>
Date: Monday, 3 November 2025 at 21:12
To: Hale, Britta (CIV) <[email protected]<mailto:[email protected]>>, Deirdre Connolly <[email protected]<mailto:[email protected]>>, Wang Guilin <[email protected]<mailto:[email protected]>>
Cc: IETF SAAG <[email protected]<mailto:[email protected]>>, pqc <[email protected]<mailto:[email protected]>>
Subject: [saag] Re: [Pqc] Re: [SAAG] A New Theory on Post-quantum Migration

Not going into concrete ways of constructing hybrids. But I assume that hybrid means that it satisfies the basic motivation: Hydrid is secure (in sense of one particular security property) if either of the component algorithm does. In this sense, stripping attacks cannot be covered, as there are no stripping attacks at all for component algorithms.

For risks or bugs, I mean a signature algorithm may be totally broken (like signing key recovery or universary forgeable), existing forgeable for some messages, or simliar issues due to implemetation. But not bugs for interoperability or misuse, like taking H(m||s) as a unique index for a message m with a valid signature s wrt a given public key if the signature scheme is just EUF-CMA secure or non-deterministic.

Not necessarily more bugs for hybrid, I mean similar as the risk analysis shows. Namely, hydrid implementation code size is bigger, so it likely has more bugs. But from the viewpoint of reliability or risk, hybrid implemebtation may be more reliable or have lower risk. In this sense, hybrid may have lower effective bugs or lower bug ratio.

Guilin


发件人:Hale, Britta (CIV) <[email protected]<mailto:[email protected]>>
收件人:Deirdre Connolly <[email protected]<mailto:[email protected]>>;Wang Guilin <[email protected]<mailto:[email protected]>>
抄 送:IETF SAAG <[email protected]<mailto:[email protected]>>;pqc <[email protected]<mailto:[email protected]>>;Wang Guilin <[email protected]<mailto:[email protected]>>
时 间:2025-11-03 12:43:30
主 题:Re: [Pqc] Re: [saag] [SAAG] A New Theory on Post-quantum Migration

I would likewise be interested to know what version of “hybrid” was used as a basis for these calculations and what form of attack. Some variants of hybrids have known stripping attacks or are not SUF-CMA, etc. It is not clear how the claimed basis of probabilities were combined with known vulnerabilities for certain types of hybrid/composites to get resulting probabilities.

It is stated that there are “not necessarily” more bugs – which can be true – but the “not necessarily” argument also applies improved security for hybrids, so I would like to understand if that quantitative impact is consistently applied.



From:Deirdre Connolly <[email protected]<mailto:[email protected]>>
Date: Monday, November 3, 2025 at 9:26 AM
To: Wang Guilin <[email protected]<mailto:[email protected]>>
Cc: IETF SAAG <[email protected]<mailto:[email protected]>>, pqc <[email protected]<mailto:[email protected]>>, Wang Guilin <[email protected]<mailto:[email protected]>>
Subject: [Pqc] Re: [saag] [SAAG] A New Theory on Post-quantum Migration
NPS WARNING: *external sender* verify before acting.
> A PQ signature has risk of 1/100, not as mature as
T… before 2035, against classic and CRQC attacks.
Where is this number coming from?
3 noy 2025, B.e., 11:42 AM tarixində Wang Guilin <[email protected]<mailto:[email protected]>> yazdı:
Dear all,
Last night, I gave a talk with title of A New Theory on Post-quantum Migration at HotRFC lightning talk session.
In case you are interested in it, welcome to discuss! (Personaly, I like it)
The sildes availvale here:
https://datatracker.ietf.org/meeting/124/materials/slides-124-hotrfc-sessa-11-pq-migration-00

This talk offers a new viewpoint for the value of hybrid post-quantum (PQ) migration. It is a quantitative analysis on different migration policies, with simple probability reasoning. Not complex, understandable to everyone. The context is based on recent discussions in Pquip, Jose/Cose, and Lamps WGs. The purpose is to invoke further thoughts on PQ migration policies. Under the assumptions given, hybrid signatures can reduce the migration risk 5 times lower than pure PQ migration.
Cheers,
Guilin
_______________________________________________
saag mailing list -- [email protected]<mailto:[email protected]>
To unsubscribe send an email to [email protected]<mailto:[email protected]>

-- 
Pqc mailing list -- [email protected]
To unsubscribe send an email to [email protected]