[saag] Re: [Ext] Re: draft-paulwh-crypto-components-02
Michael Richardson <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
Wang Guilin <[email protected]> wrote: > However, such a quick switching actually does not give good protection > for the data exchanged before the flaw in the PQ algorithm is > found. So, an even more conservative hybrid solution is to have 1 > traditional algorithm combined with 2 PQ algorithms, with a few more PQ > algorithms in store as back up. So, in the case either of the 2 PQ > algorithms is found insecure, a new back up PQ algorithm can come to > replace. Theregore, the data exchanged before flaw is found could be > protected well. It could be that there are no secure quantum-safe algorithms. That all the candidates will fail. Maybe someone will get a Fields Medal for proving this... Perphaps it will fall out of someone prooving the Reinmann Hypothesis. I dunno. Maybe the surviving algorithms will be too big to run more than once daily between "enterprises, and we'll need to use it to bootstrap/maintain Kerberos KDC<->KDC communications only. We had a side meeting in Bribane on "SKEX", which was a way to distribute symmetric keys from multiple providers. I'm unclear why it didn't get more feet. It was very similiar to Kerberos, but outward facing rather than enterprise internal. So, I'm saying, if you are paranoid enough to think we need 2 quantum-safe (PQ) algorithms, then let me suggest maybe we actually need some other backup. -- Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 515 B)
-----BEGIN PGP SIGNATURE----- iQFKBAEBCgA0FiEEbsyLEzg/qUTA43uogItw+93Q3WUFAme41NIWHG1jcitpZXRm QHNhbmRlbG1hbi5jYQAKCRCAi3D73dDdZdmVB/9UNxNdJx9R9CnzZ0FsRqFcluqt NeGi6Ej+seoz2CXxdt6hv/pb388KoA6qa7u+Oqf2tojoVbVhamHH+1aoi8Vk/pgG qBW1uEQD7cClT0zzU/IR1hrYczC0mB1Q6mpqm2btvmhtbGvwJFKz/w6HbzQyE97B +KbLNFXPpOfJ4hiqGhUuxEztkA1FrmO6P4ntM/P9WuEmVOCaGyVTOyJXviGJop4v xi2OwAhXWL68mDlmSZu7AL2CKp2yS9Fw/+5gOE9TcPz0ThPs9jS18RJ1yBgvKWLa Ela2+o/fx7mefg+zy6iQnEQLMAM8naSBG7WZLSAlV2HBpHLc5AnhiuxqAQMV =1Wo3 -----END PGP SIGNATURE-----