3 ms·
No. I think that is the exact point he was making that quantum key distribution is orthogonal to post-quantum cryptography and that the consensus is that poat-q
by bloomer 8y ago
No. I think that is the exact point he was making that quantum key distribution is orthogonal to post-quantum cryptography and that the consensus is that poat-quantum cryptography will actually be used while quantum key distribution is basically an academic exercise because it doesn't have practical utility for the problem it is attempting to solve.
- krastanov 8y agoI am confused. How is "security that does not depend on any 'difficulty' conjectures / information theoretically perfect" not of practical utility?
- NoKnowledge 8y agoThe so called quantum key-exchange requires a shared secret, so it is actually doing key-expansion. Besides that it has practical problems in side-channel protection and cannot achieve a high enough bandwidth to be of interest in most practical settings.
- roywiggins 8y agoIf you wanted to toss out public key cryptography as insecure, I guess you could use QKE to make symmetric key cryptography more practical. You would have a secure method of communicating your keys, and wouldn't have to worry that your new post-quantum public key cryptography was broken- since symmetric cryptography just isn't vulnerable in the same way.
- krastanov 8y agoEdit: Deleted an incorrect comment. This is a good description of what I am missing: https://crypto.stackexchange.com/questions/2719/is-quantum-key-distribution-safe-against-mitm-attacks-too https://crypto.stackexchange.com/questions/2719/is-quantum-k... (man in the middle attacks)