3 ms·
You'll note they don't actually specify any asymmetric quantum-resistant algorithms. I'd guess if they did, NTRU or a derivative would be one they'd consider fi
by AlyssaRowan 11y ago
You'll note they don't actually specify any asymmetric quantum-resistant algorithms. I'd guess if they did, NTRU or a derivative would be one they'd consider first: Security Innovation were trying to sell them that at about the same time Certicom were pushing elliptic curves. (I'm not as convinced about ideal lattices, but that's an artifact of my not being as familiar with the field.)
Pre-shared keys, as they suggest there, have no forward secrecy - which makes them great for those who really like stealing, say, IPsec keys… like the NSA. It may work with the kind of old military key infrastructure they and GCHQ have, that regularly distributes random keys from centralised, organisationally-trusted sources on specialised hardware; it is a terrible recommendation for civilians.
Interesting that they're still married to P-384 (probably the most annoying curve to implement correctly). Properly-implemented Ed448-Goldilocks is safer, and that's what CFRG are going with for the "paranoid" level.
- eeZi 11y agoIPSec still has forward secrecy even with pre-shared keys.
- AnthonyMouse 11y agoThe way it does that is by using Diffie-Hellman or ECDH, which both rely on the hardness of the discrete logarithm problem that quantum computers would break.
- wolf550e 11y agoopenssl 1.0.2a on an old Conroe Core2 gets this: sign verify sign/s verify/s 256 bit ecdsa (nistp256) 0.0001s 0.0003s 8727.8 3493.3 384 bit ecdsa (nistp384) 0.0005s 0.0020s 2001.4 493.0 521 bit ecdsa (nistp521) 0.0010s 0.0017s 1021.3 603.0 Can P-384 (or Ed448-Goldilocks) be close to P-256 in speed?
- tveita 11y agoHere are some median times from the eBATS benchmark page for a 2013 Intel Xeon E3-1275 V3 3500MHz (http://bench.cr.yp.to/web-impl/amd64-titan0-crypto_sign.html http://bench.cr.yp.to/web-impl/amd64-titan0-crypto_sign.html) Cycles to generate a key pair: ed448goldilocks: 176924 ecdonaldp256: 290628 ecdonaldp384: 2202380 Cycles to sign 59 bytes: ed448goldilocks: 185056 ecdonaldp256: 381696 ecdonaldp384: 2367856 Cycles to verify 59 bytes: ed448goldilocks: 583900 ecdonaldp256: 913848 ecdonaldp384: 2741028 (ecdonaldp is ECDSA signatures with NIST P-256/384. The implementation used is OpenSSL, though I don't know which version) AFAIK no elliptic curve size is quantum secure, so I guess the goal is just to require slightly more qubits for an attack.
- jackgavigan 11y ago> You'll note they don't actually specify any asymmetric quantum-resistant algorithms. I'd guess if they did, NTRU or a derivative would be one they'd consider first... My bet would be on McEliece. It's been around longer, so has been subjected to more rigorous cryptanalysis than NTRU, and is not patented.