[saag] Re: [Ext] Re: draft-paulwh-crypto-components-02

Wang Guilin <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
>It could be that there are no secure quantum-safe algorithms.
>That all the candidates will fail.

Up to now, can not say that this will no happen absolutely. But very likely, this will not happen. On one hand, now, crypto community has at least 6 different approaches to design PQ algorithms. On the other hand, crypto algorithm designers are learning and making good progress as the development of quantum computers are making progress.

In my understanding, security guys (including IETF) are trying to do theur best, though they are aware that some risks are still possible, even they are doing their best.

On Feb. 19, 3 days ago, Microsoft introduced Majorana 1, "the world’s first quantum chip powered by a new Topological Core architecture."

https://news.microsoft.com/source/features/innovation/microsofts-majorana-1-chip-carves-new-path-for-quantum-computing/

The Majorana 1 chip seems only having 8 qubits, but "it can scale to a million qubits"
and "will realize quantum computers capable of solving meaningful, industrial-scale problems in years, not decades."

It does sound a big breakthrough, though not sure how the new architecture has been verified that "it can scale to a million qubits".

Not mentioned anything about breaking RSA 2048 or cryptoanalysis, but it may signal that the developing QC is accelerateling.

>So, I'm saying, if you are paranoid enough to think we need 2 quantum-safe
>(PQ) algorithms, then let me suggest maybe we actually need some other backup.

I am also interested in the work of SKEX. Nice to know that there will be a side meeting about it at IETF 122. Thanks, Paul.

Guilin

From:Michael Richardson <[email protected]<mailto:[email protected]>>
To:Wang Guilin <[email protected]<mailto:[email protected]>>;saag <[email protected]<mailto:[email protected]>>
Date:2025-02-22 03:32:49
Subject:Re: [saag] Re: [Ext] Re: draft-paulwh-crypto-components-02


Wang Guilin <[email protected]<mailto:[email protected]>> wrote:
    > However, such a quick switching actually does not give good protection
    > for the data exchanged before the flaw in the PQ algorithm is
    > found. So, an even more conservative hybrid solution is to have 1
    > traditional algorithm combined with 2 PQ algorithms, with a few more PQ
    > algorithms in store as back up. So, in the case either of the 2 PQ
    > algorithms is found insecure, a new back up PQ algorithm can come to
    > replace. Theregore, the data exchanged before flaw is found could be
    > protected well.

It could be that there are no secure quantum-safe algorithms.
That all the candidates will fail.   Maybe someone will get a Fields Medal
for proving this... Perphaps it will fall out of someone prooving the
Reinmann Hypothesis. I dunno.

Maybe the surviving algorithms will be too big to run more than once daily
between "enterprises, and we'll need to use it to bootstrap/maintain Kerberos
KDC<->KDC communications only.

We had a side meeting in Bribane on "SKEX", which was a way to distribute
symmetric keys from multiple providers. I'm unclear why it didn't get more
feet. It was very similiar to Kerberos, but outward facing rather than
enterprise internal.

So, I'm saying, if you are paranoid enough to think we need 2 quantum-safe
(PQ) algorithms, then let me suggest maybe we actually need some other backup.

--
Michael Richardson <[email protected]<mailto:[email protected]>>   . o O ( IPv6 IøT consulting )
           Sandelman Software Works Inc, Ottawa and Worldwide

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.