3 ms·
This is the first I've heard of NTRU. Has it been proven immune to quantum computational attacks, or has an efficient attack algorithm just not been found yet?
by fjorder 14y ago
This is the first I've heard of NTRU. Has it been proven immune to quantum computational attacks, or has an efficient attack algorithm just not been found yet?
The former would be world-shaking, so that's probably not the case unless I've been living under a rock. The latter just means that it might be safe, but it might be broken at any time if somebody comes up with the right algorithm. If you're making long-term information infrastructure plans that's something you have to account for.
- quonn 14y agoYes, but that problem also exists without quantum computers (qc). Advances may break existing crypto, even if proven secure under certain assumptions. This is because the advance may introduce a shortcut that proves the assumptions are unsufficient. NTRU has been proven safe from known quantum attacks and has been around for some time. There certainly were efforts to attack NTRU using qc. If it would be included in OpenSSL and NSS, it is likely those efforts would be intensified. I therefore suggest that getting it into those libraries may be the best we can do right now.
- quonn 14y agoSee http://www.pqcrypto.org/www.springer.com/cda/content/document/cda_downloaddocument/9783540887010-c1.pdf http://www.pqcrypto.org/www.springer.com/cda/content/documen... for more info.