4 ms·
There is Post-Quantum Cryptography competition, with three e-signature algorithms selected for standardization: https://csrc.nist.gov/projects/post-quantum-cryp
by miga 4y ago
There is Post-Quantum Cryptography competition, with three e-signature algorithms selected for standardization: https://csrc.nist.gov/projects/post-quantum-cryptography https://csrc.nist.gov/projects/post-quantum-cryptography
Given that NIST itself warns PQC algorithm may be unsafe after 2035, this should be considered SHA-4.
- bawolff 4y agoSha-2 is already quantum safe. Sha is not a digital signature algorithm. That is a different type of crypto primitive.
- adastra22 4y agoHash functions aren’t significantly impacted by quantum computers. You may need to use a longer construction (eg. SHA512 instead of SHA256), but that’s it.
- bawolff 4y agoIm not a cryptographer, im kind of curious - is it possible to combine a birthday attack with grover's algorithm to attack sha256 in 2^64 time?
- adastra22 4y agoYou would get cube root speedup instead of sqrt for a collision (birthday attack), or sqrt instead of brute force for a preimage. So SHA256 is secure from preimage attacks even with a quantum computer, and gives 2^80 protection against collisions. SHA-2/384 would be sufficient for 128-bit security against collisions.
- ShredKazoo 4y ago>Given that NIST itself warns PQC algorithm may be unsafe after 2035 I thought post-quantum cryptography was supposed to be futureproof? Or am I misunderstanding