Countering quantum FUD Daniel J. Bernstein Joint work with: Nadia - - PowerPoint PPT Presentation

countering quantum fud
SMART_READER_LITE
LIVE PREVIEW

Countering quantum FUD Daniel J. Bernstein Joint work with: Nadia - - PowerPoint PPT Presentation

Countering quantum FUD Daniel J. Bernstein Joint work with: Nadia Heninger Paul Lou Luke Valenta Countering quantum FUD Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta All crypto is broken? FUD : Nobody knows exactly when


slide-1
SLIDE 1

Countering quantum FUD

Daniel J. Bernstein Joint work with: Nadia Heninger Paul Lou Luke Valenta

Countering quantum FUD Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta

slide-2
SLIDE 2

All crypto is broken?

FUD: “Nobody knows exactly when quantum computing will become a reality, but when and if it does, it will signal the end of traditional cryptography.”

Countering quantum FUD Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta

slide-3
SLIDE 3

All crypto is broken?

FUD: “Nobody knows exactly when quantum computing will become a reality, but when and if it does, it will signal the end of traditional cryptography.” Sales pitch: Buy QKD! (Never mind QKD security disasters.)

Countering quantum FUD Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta

slide-4
SLIDE 4

All crypto is broken?

FUD: “Nobody knows exactly when quantum computing will become a reality, but when and if it does, it will signal the end of traditional cryptography.” Sales pitch: Buy QKD! (Never mind QKD security disasters.) Fact check: Actually, many cryptosystems are unbroken.

Countering quantum FUD Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta

slide-5
SLIDE 5

Public-key crypto is broken?

FUD: “When the first quantum factoring devices are built the security of public-key cryptosystems will vanish.”

Countering quantum FUD Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta

slide-6
SLIDE 6

Public-key crypto is broken?

FUD: “When the first quantum factoring devices are built the security of public-key cryptosystems will vanish.” Sales pitch: Buy QKD! (Never mind lack of functionality.)

Countering quantum FUD Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta

slide-7
SLIDE 7

Public-key crypto is broken?

FUD: “When the first quantum factoring devices are built the security of public-key cryptosystems will vanish.” Sales pitch: Buy QKD! (Never mind lack of functionality.) Fact check: Actually, many public-key cryptosystems are unbroken.

Countering quantum FUD Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta

slide-8
SLIDE 8

RSA and ECC are broken?

FUD: RSA is dead. “There’s not going to be a larger key-size where a classical user

  • f RSA gains a significant advantage
  • ver a quantum computing attacker.”

Countering quantum FUD Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta

slide-9
SLIDE 9

RSA and ECC are broken?

FUD: RSA is dead. “There’s not going to be a larger key-size where a classical user

  • f RSA gains a significant advantage
  • ver a quantum computing attacker.”

Sales pitch: Buy codes! Lattices! Multivariates! Hash signatures!

Countering quantum FUD Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta

slide-10
SLIDE 10

RSA and ECC are broken?

FUD: RSA is dead. “There’s not going to be a larger key-size where a classical user

  • f RSA gains a significant advantage
  • ver a quantum computing attacker.”

Sales pitch: Buy codes! Lattices! Multivariates! Hash signatures! Fact check (new): Actually, RSA survives with big keys.

Countering quantum FUD Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta

slide-11
SLIDE 11

RSA: Back from the dead

Picture credit: http://fpswin.com/wp-content/uploads/2011/12/cfMOq.jpg Countering quantum FUD Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta

slide-12
SLIDE 12

Post-quantum RSA

https://eprint.iacr.org/2017/351 We generated a 1TB RSA key. Preliminary security analysis: >2100 security against all known attacks.

Countering quantum FUD Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta

slide-13
SLIDE 13

Post-quantum RSA

https://eprint.iacr.org/2017/351 We generated a 1TB RSA key. Preliminary security analysis: >2100 security against all known attacks. Used only about 2 million core-hours. Also have preliminary implementation

  • f RSA-KEM encryption and decryption.

Countering quantum FUD Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta