[Pqc] Re: [EXT] Re: [saag] Re: Re: [SAAG] A New Theory on Post-quantum Migration
Wang Guilin <[email protected]> Thu, 6 Nov 2025 00:41:35 +0000
| Newsgroups | gmane.ietf.pqc,gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
> In my understanding, that planning is a mistake – a combination of overestimating the risk of Lattice-based crypto failure (has been studied for about 30 years, compared to about 50 years of ECC crypto studies), and underestimating the likelihood/speed of CRQC arrival. 30 years of studying Lattice-based crypto failure? Not sure which the first literature is in this area, in your viewpoint. As I know, the concept of LWE is proposed in [1], in 2005. Up to now, 20 years. Also, in this thread, it seems more relevant to just discuss specific algorithms, rather than the history of an area or a sub-area. In this case, please note that both Dilithium and Kyber were published in 2017 [2, 3]. PS, as a bonus, notice that the design team of Dilithium give the following message on the home page of Dilithium at https://pq-crystals.org/dilithium/: " For users who are interested in using Dilithium, we recommend the following: * Use Dilithium in a so-called hybrid mode in combination with an established "pre-quantum" signature scheme. " [1] Oded Regev. On lattices, learning with errors, random linear codes, and cryptography. In Harold N. Gabow and Ronald Fagin, editors, 37th ACM STOC, pages 84–93. ACM Press, May 2005 [2] CRYSTALS -- Dilithium: Digital Signatures from Module Lattices. https://eprint.iacr.org/2017/633; IACR TCHES, 2018(1):238–268 [3] CRYSTALS -- Kyber: a CCA-secure module-lattice-based KEM. https://eprint.iacr.org/2017/634; EuroS&P 2018: 353-367 Guilin ________________________________ From: Blumenthal, Uri - 0553 - MITLL <[email protected]> Sent: Wednesday, November 5, 2025 11:52 PM To: SIDDESH PAWAR; [email protected]; [email protected] Subject: [Pqc] Re: [EXT] Re: [saag] Re: Re: [SAAG] A New Theory on Post-quantum Migration ZjQcmQRYFpfptBannerEnd My take, If ECC is anyhow prone to Quantum attack and also the part of implementation is old and received by the attackers, then why are we planning traditional crypt+ pqc (NIST approved). In my understanding, that planning is a mistake – a combination of overestimating the risk of Lattice-based crypto failure (has been studied for about 30 years, compared to about 50 years of ECC crypto studies), and underestimating the likelihood/speed of CRQC arrival. Their hope basically is that the protected data will lose all value before CRQC arrives, and maybe the QC part will hold. Instead we should focus on rapid migration techniques for the infra collaborating with big players like DigiCert, checkpoint, hp, for the pure pqc migration. Design and Evaluation of StrongVPN, a Pure Post-Quantum VPN Architecture<https://www.techrxiv.org/users/978467/articles/1345362-design-and-evaluation-of-strongvpn-a-pure-post-quantum-vpn-architecture> IMHO, that is correct. https://www.techrxiv.org/users/978467/articles/1345362-design-and-evaluation-of-strongvpn-a-pure-post-quantum-vpn-architecture I totally understand that the proven technology is more convincing to the industry then the future evolution. Even if we are considering the migration techniques, do we have any plan under discussion so far. I’ll also add that Lattice-based crypto (Kyber, NTRU) has formal proofs, while ECC crypto does not. 😉 ________________________________ From: Blumenthal, Uri - 0553 - MITLL <[email protected]> Sent: 04 November 2025 19:54 To: [email protected] <[email protected]>; [email protected] <[email protected]> Subject: [Pqc] Re: [EXT] Re: [saag] Re: Re: [SAAG] A New Theory on Post-quantum Migration My take. Does this mean ECC+PQ can be declared insecure on the basis of, e.g., declaring that small code size is a "security property" and that ECC+PQ is more code than just PQ? The only good cipher is the null cipher? Yes, it can. An extra attack surface is an extra attack surface. Here's an example. There's a problem right now of attackers recording data to decrypt with future quantum computers. In that case, ECC part is irrelevant – helping at best only until CRQC. There are protocols such as TLS responding to this by rolling out ECC+PQ concatenation: * Maybe the PQ part holds up. If so, big step forward! * Maybe the PQ part ends up as another disaster. If so, at least ECC+PQ isn't worse than current normal usage of ECC. If the data sensitivity persists through the appearance of CRQC – which is the main purpose of the governments driving PQC rollout – then ECC+PQ is exactly as secure as PQ alone, not counting for implementation bugs that could make it worse. Skipping the ECC part would fail horribly on the second point. Not at all. It might only help for “short-lived” data. If that’s all you care for – then ECC+PQ (or ECC alone) would work fine for you. Otherwise – it’s a waste of time and resources to even argue about it. -- Pqc mailing list -- [email protected] To unsubscribe send an email to [email protected]