4 ms·
So the protocol seems to boil down to: 1) Already have a leader "Dealer" 2) The leader builds a K-of-N set of shared secret keys. 3) They publish a mapping o
by Rhapso 2y ago
So the protocol seems to boil down to:
1) Already have a leader "Dealer"
2) The leader builds a K-of-N set of shared secret keys.
3) They publish a mapping of each participant (participant_i->hash(secret_i))
4) The leader transmits each key to each participant
5) Participants exchange secrets pairwise, armed with the upfront mapping of participants->secrets
6) Select K and a k-of-N secret scheme such that a majority of participants now have a shared key
lots of the claims aren't meaningful:
- "post quantum" for example isn't a special value in this situation.
- "minimal use of cryptography" isn't relevant to practicality
- The "experimental" component doesn't meaningful contribute to the conclusion.
- No public-key-encryption really means "outsource sender identification to the network layer"
- They pretend using a system of equations to solve for a shared key isn't"cryptography".
In general the contribution of the paper reads as "offusicated". The lack of "public key cryptography" sets them up for a novel problem to solve, but it is an arbitrary handicap that doesn't provide utility.
This is academic "make up a novel and nontrivial problem and then solve it", its of utility to the process of producing grad students and publication count but not something we need to get excited about. Read it like a survey paper of the space, which it does well as.
- xhkkffbf 2y agoI'm not as cynical. I think quests like this are important to understanding what's important and not-so-important in protocols. Quests like post-quantum algorithms are important for me not because I believe in the chance of any quantum machine coming along. It's because we learn so much. The foundation of many public key systems is pretty sketchy. We trust them because no one has publicly described how to break them. But that doesn't mean that the truth isn't out there.
- Rhapso 2y agoRight but "Avoiding PKI" and "Secure Against Quantum Computers" barely even correlate. We have methods we consider post-quantum in heavy use. "PKI is generally sketchy and we would like to explore alternatives" is actually a much better rationalization than "post-quantum buzzword dropping"
- 3s 2y agoI disagree. Avoiding PKI and post-quantum security correlate very much. Even under plausibly post-quantum assumptions we only have a couple of assumptions from which we can build public key encryption. In contrast, here they avoid all use of public key cryptography which makes it provably post-quantum secure. It’s not using a buzzword for the sole sake of selling the paper. In general, using “minimal cryptography” (like random oracles / one-way functions) translates to real-world efficiency because you can instantiate these from a plethora of different concrete candidates.
- ilya_m 2y ago> Avoiding PKI and post-quantum security correlate very much. Even under plausibly post-quantum assumptions we only have a couple of assumptions from which we can build public key encryption. These statements presuppose an overly expansive definition of PKI, i.e., distribution of keys for public-key encryption. A more conservative definition is PKI = availability of trustworthy publicly verifiable signatures (i.e., public-key certificates). Post-quantum signatures can be based on target collision-resistant hash functions, like XMSS. The paper assumes pairwise private and authenticated channels. While in practice this is not necessarily a good substitute for PKI, in theory it is a strictly weaker setting.
- kreetx 2y agoI'm only somewhat into cryptography, but is PKI considered as sketchy in some way?
- Rhapso 2y agoNo. The proofs for the security security of most of the methods of public/private key systems are weaker than "you can't reverse this hash function". They are still robust in the face of computers that may physically exist in foreseeable futures. Elliptic Curve Encryption was adopted for being post-quantum twenty years ago and more work since then I haven't followed. The person I am arguing with is imagining a future pessimistic beyond what most would consider reasonable.
- treyd 2y ago> - No public-key-encryption really means "outsource sender identification to the network layer" Yeah I didn't read the full paper but from the abstract my intuition was telling me they just assumed away a bunch of things that are fairly necessary when actually implementing a BFT consensus as part of the environment.
- c0742e9366 2y agoI disagree with this uncharitable view of the paper. First, an important missing point is that the protocol does not require trusted setup. In contrast, most prior works require that parties hold threshold secret keys (necessitating a trusted third-party or expensive setup procedure). Second, a lot of effort is currently being poured into the transition to post-quantum. So having a post-quantum secure protocol is evidently valuable to a lot of people. Third, Byzantine agreement protocols usually always assume pairwise private and authenticated communication channels. It makes sense that protocols should not need to concern themselves with the communication layer and such channels can be realized from standard cryptographic building blocks anyways. Here the paper not using any PK-cryptography is especially nice because the protocol can be layered on top without a lot of fuss—no matter what the channels are based on. Last, this problem is far from "made up". It was an obvious (and also seemingly hard to solve) to people working in this area. Also, Byzantine agreement is a practically important problem and this is an elegant solution.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]