3 ms·
It seems like the post-quantum algorithm that Signal selected [0] involves lattices [1] somehow: > Kyber is an IND-CCA2-secure key encapsulation mechanism (KEM
by faitswulff 2y ago
It seems like the post-quantum algorithm that Signal selected [0] involves lattices [1] somehow:
> Kyber is an IND-CCA2-secure key encapsulation mechanism (KEM), whose security is based on the hardness of solving the learning-with-errors (LWE) problem over module lattices.
Curious to see if Chen's work will eventually lead to Signal selecting a different algorithm.
[0]: https://signal.org/blog/pqxdh/ https://signal.org/blog/pqxdh/
[1]: https://pq-crystals.org/kyber/ https://pq-crystals.org/kyber/
- contact9879 2y agoGreen explicitly mentions Kyber in his post. > NIST-approved schemes based on lattice problems include Kyber and Dilithium (which I wrote about recently.) > Chen’s algorithm does not immediately apply to the recently-standardized NIST algorithms such as Kyber or Dilithium. And it's not just Signal. Apple's new iMessage protocol, PQ3, uses Kyber, too. [1] Most deployments of PQ-crypto that I know of have used Kyber. [1] https://security.apple.com/blog/imessage-pq3/ https://security.apple.com/blog/imessage-pq3/
- glitchc 2y agodeleted
- jameswryan 2y agoRainbow is not a KEM, but a signature scheme.
- deleted 2y ago[deleted]
- tptacek 2y agoMore or less all of the "serious", actually deployed PQC schemes involve lattices, going back before the competition.
- contact9879 2y agoI've seen some Classic McEliece deployments, too. Well, I know of only one: Mullvad. https://github.com/mullvad/mullvadvpn-app/blob/main/talpid-tunnel-config-client/src/classic_mceliece.rs https://github.com/mullvad/mullvadvpn-app/blob/main/talpid-t...
- tptacek 2y agoSome helpful, perhaps valid context is that lattice-based cryptography was a contender even before PQC became a thing (NTRU being the obvious example). Really the only point I'm trying to make here is that there's nothing eyebrow-raising about systems using lattice crypto; after IFP/FFDLP stuff like RSA and ECDLP, lattices are maybe the next most mainstream approach to constructing asymmetric systems.
- pclmulqdq 2y agoI'm late to the party, but McEliece codes have also been around for a very long time, predating AES by a fair margin. The biggest problem with them is that the public keys are gigantic and the private keys are very large - even bigger than the keys used in lattice-based cryptosystems. This has caused them to always be a sort of fringe form of cryptography. The good part is that McEliece codes are based on a proven NP-hard algorithm, so cracking them in polynomial time needs P = NP.