3 ms·
One of them has already fallen victim to a key recovery attack: https://twitter.com/yx7__/status/945283780851400704 https://twitter.com/yx7__/status/9452837808
by bascule 9y ago
One of them has already fallen victim to a key recovery attack:
https://twitter.com/yx7__/status/945283780851400704 https://twitter.com/yx7__/status/945283780851400704
Round2 (LWE-based) and SIKE (isogeny-based) are the particularly interesting ones to me. Both support comparatively small keys (~1kB), with Round2 seemingly winning on performance, but also patented.
- mort96 9y agoI never understood how or why patenting math is a thing.
- garmaine 9y agoIt is patenting the application of math.
- mort96 9y agoHow do you differentiate between math and the "application of math"?
- garmaine 9y agoYou can't patent an S-box transform. You can patent using a specific S-box transform to encrypt / decrypt data. That's the justification at least.
- betterunix2 9y agoMore like you can patent math when it is applied via a computer. So you would not be violating the patent by evaluating the S-box with pen and paper. It makes no particular sense, but the theory behind math patents being out of bounds is that math is a fact. Software patents, including crypto patents, do not "feel" like facts to most judges, even if they technically are (see: Curry-Howard Correspondence).
- deleted 9y ago[deleted]