[saag] Re: [Ext] Re: draft-paulwh-crypto-components-02
Wang Guilin <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
>It could be that there are no secure quantum-safe algorithms. >That all the candidates will fail. Up to now, can not say that this will no happen absolutely. But very likely, this will not happen. On one hand, now, crypto community has at least 6 different approaches to design PQ algorithms. On the other hand, crypto algorithm designers are learning and making good progress as the development of quantum computers are making progress. In my understanding, security guys (including IETF) are trying to do theur best, though they are aware that some risks are still possible, even they are doing their best. On Feb. 19, 3 days ago, Microsoft introduced Majorana 1, "the world’s first quantum chip powered by a new Topological Core architecture." https://news.microsoft.com/source/features/innovation/microsofts-majorana-1-chip-carves-new-path-for-quantum-computing/ The Majorana 1 chip seems only having 8 qubits, but "it can scale to a million qubits" and "will realize quantum computers capable of solving meaningful, industrial-scale problems in years, not decades." It does sound a big breakthrough, though not sure how the new architecture has been verified that "it can scale to a million qubits". Not mentioned anything about breaking RSA 2048 or cryptoanalysis, but it may signal that the developing QC is accelerateling. >So, I'm saying, if you are paranoid enough to think we need 2 quantum-safe >(PQ) algorithms, then let me suggest maybe we actually need some other backup. I am also interested in the work of SKEX. Nice to know that there will be a side meeting about it at IETF 122. Thanks, Paul. Guilin From:Michael Richardson <[email protected]<mailto:[email protected]>> To:Wang Guilin <[email protected]<mailto:[email protected]>>;saag <[email protected]<mailto:[email protected]>> Date:2025-02-22 03:32:49 Subject:Re: [saag] Re: [Ext] Re: draft-paulwh-crypto-components-02 Wang Guilin <[email protected]<mailto:[email protected]>> wrote: > However, such a quick switching actually does not give good protection > for the data exchanged before the flaw in the PQ algorithm is > found. So, an even more conservative hybrid solution is to have 1 > traditional algorithm combined with 2 PQ algorithms, with a few more PQ > algorithms in store as back up. So, in the case either of the 2 PQ > algorithms is found insecure, a new back up PQ algorithm can come to > replace. Theregore, the data exchanged before flaw is found could be > protected well. It could be that there are no secure quantum-safe algorithms. That all the candidates will fail. Maybe someone will get a Fields Medal for proving this... Perphaps it will fall out of someone prooving the Reinmann Hypothesis. I dunno. Maybe the surviving algorithms will be too big to run more than once daily between "enterprises, and we'll need to use it to bootstrap/maintain Kerberos KDC<->KDC communications only. We had a side meeting in Bribane on "SKEX", which was a way to distribute symmetric keys from multiple providers. I'm unclear why it didn't get more feet. It was very similiar to Kerberos, but outward facing rather than enterprise internal. So, I'm saying, if you are paranoid enough to think we need 2 quantum-safe (PQ) algorithms, then let me suggest maybe we actually need some other backup. -- Michael Richardson <[email protected]<mailto:[email protected]>> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]