Post-quantum RSA (pqRSA)
Daniel J. Bernstein Joint work with: Josh Fried Nadia Heninger Paul Lou Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA (pqRSA) Daniel J. Bernstein Joint work with: - - PowerPoint PPT Presentation
Post-quantum RSA (pqRSA) Daniel J. Bernstein Joint work with: Josh Fried Nadia Heninger Paul Lou Luke Valenta Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta Parameters Scaled-down targets for
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
◮ pqrsa15: 215-byte keys using 512-bit primes. ◮ pqrsa20: 220-byte keys using 512-bit primes. ◮ pqrsa25: 225-byte keys using 1024-bit primes.
◮ pqrsa30: 230-byte keys using 1024-bit primes.
◮ pqrsa40: 240-byte keys using 4096-bit primes.
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
◮ Key:
◮ Signature:
◮ Ciphertext for kem:
◮ Ciphertext for encrypt:
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
◮ 2017 H¨
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
◮ 2017 H¨
◮ Actually higher security: consider communication costs.
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
◮ 2017 H¨
◮ Actually higher security: consider communication costs. ◮ Actually higher security: consider latency limits.
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
◮ 2017 H¨
◮ Actually higher security: consider communication costs. ◮ Actually higher security: consider latency limits.
◮ Maybe lower security: e.g., lower-cost multiplications?
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
◮ 2017 H¨
◮ Actually higher security: consider communication costs. ◮ Actually higher security: consider latency limits.
◮ Maybe lower security: e.g., lower-cost multiplications? ◮ Prime size: 512 bits probably ok; 1024 ample.
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
◮ 2017 H¨
◮ Actually higher security: consider communication costs. ◮ Actually higher security: consider latency limits.
◮ Maybe lower security: e.g., lower-cost multiplications? ◮ Prime size: 512 bits probably ok; 1024 ample.
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
◮ Quantum computers are built. ◮ Many users continue using RSA.
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
◮ Quantum computers are built. ◮ Many users continue using RSA.
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
◮ Quantum computers are built. ◮ Many users continue using RSA.
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta
◮ Quantum computers are built. ◮ Many users continue using RSA.
Post-quantum RSA Daniel J. Bernstein, Josh Fried, Nadia Heninger, Paul Lou, Luke Valenta