Quantcast
Channel: If we don't trust current PQ algorithms enough to use them on their own why should we trust them for a hybrid? - Cryptography Stack Exchange
Viewing all articles
Browse latest Browse all 3

Answer by cypherfox for If we don't trust current PQ algorithms enough to use them on their own why should we trust them for a hybrid?

$
0
0

Actually, we do trust many (but obviously not all) post-quantum cryptosystems more than traditional schemes. We haven't been using them because they fail to meet practical space and time trade-offs.

We start pessimistic with high parameters, then gradually cut down the space by filtering out bad or slow parameter classes until we have reasonable space and time trade-offs for various security levels.

However, if we are wrong and some assumption is proven incorrect, we want to be sure our protocols are no less secure than the traditional systems we know better. The hybrid solutions are no weaker than their strongest component.

What is the rationale for choosing some PQ algorithm today and believing it will protect data in the future?

Exactly the same rationale for choosing any algorithm today and believing it will do its task despite future developments. Alternatively, don't choose. Use them all ! .. and then really hope at least one is actually good. Or ignore PQ schemes and use preshared keys. We should be using preshared keys more often. If I have established secure channels with my peers and wish to introduce them, I can give them preshared keys in addition to public keys.


Viewing all articles
Browse latest Browse all 3

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>