4 ms·
That pqRSA paper by DJB is a joke, but it's mathematically correct and an interesting thought experiment - RSA really becomes post-quantum when you use a 1 TB k
by bcaa7f3a8bbc 6y ago
That pqRSA paper by DJB is a joke, but it's mathematically correct and an interesting thought experiment - RSA really becomes post-quantum when you use a 1 TB key because it outgrows what Shor's algorithm can scale at that point. The paper is actually better, it proposed an original algorithm, GEECM, that's faster than Shor's algorithm for numbers with many small factors, then also showed pqRSA is safe from GEECM. He even submitted the algorithm to the NIST Post-Quantum Competition for review (among his more practical algorithms like Classic McEliece), it's just hilarious.
> DJB yelling from the back of the room "How much RAM does the NIST benchmarking machine have??" Dustin Moody replying "Dan, we're not benchmarking pqRSA!"
https://crypto.stackexchange.com/questions/59591/why-is-pqrsa-in-the-nist-pqc-submissions https://crypto.stackexchange.com/questions/59591/why-is-pqrs...
Here's his explanation of the idea:
https://cr.yp.to/talks/2017.06.27/slides-djb-20170627-pqrsa-16x9.pdf https://cr.yp.to/talks/2017.06.27/slides-djb-20170627-pqrsa-...
- SAI_Peregrinus 6y agoGiven the number of Star Wars references in the various NIST Post-Quantum Competition scheme names (CRYSTALS-KYBER, SABER, NewHope) I'm rather sad he didn't call it "Post Quantum RSA - The Phantom Menace".