Re: Quantum slip - Quantum conspiracy
From: William Whyte (wwhyte251_at_yahoo.com)
Date: 05/23/05
- Next message: William Whyte: "Re: DSA and KDSA"
- Previous message: Anonymous: "Re: The Truth: Everything Blows Your Privacy!"
- In reply to: Joseph Ashwood: "Re: Quantum slip - Quantum conspiracy"
- Next in thread: none: "Re: Quantum slip - Quantum conspiracy"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 23 May 2005 06:51:41 -0700
> RSA is toast, DH is toast, ECC I'm not sure of but without the
knowledge I'd still bet it's toast, Ntru almost certainly toast, in
short I can't think of a single PKI algorithm that I believe would be
safe. RSA and DH are done in by Shor's algorithm.
ECDL and standard DL are both broken by Shor in similar ways. The best
paper about this is "Shor's discrete logarithm quantum algorithm for
Elliptic Curves" by John Proos and Christof Zalka, available from
http://www.cacr.math.uwaterloo.ca/ techreports/2003/corr2003-06.ps. To
solve ECDL over 160-bit prime fields you need a 1000-qubit computer; to
solve RSA-1024 (and presumably DL over 1024-bit fields) you need a
2000-qubit computer. So you can look on ECC as slightly more vulnerable
than RSA or DH/DSA, or you can look on ECC, RSA and DH/DSA as being
essentially equally vulnerable.
As far as NTRU goes, Christoph Ludwig
(http://www.cdc.informatik.tu-darmstadt.de/mitarbeiter/cludwig.html)
has published a paper with a quantum algorithm that claims to
square-root the running times for lattice reduction relative to a
specific algorithm due to Claus Schnorr. We at NTRU don't dispute the
square-rooting part of his result (though we do dispute other aspects
of his paper, which we think is based on a misunderstanding of the
effectiveness of Schnorr's algorithm -- see
http://eprint.iacr.org/2005/104 for more details). Even with this
result, running times for NTRU lattice reduction remain fully
exponential.
To the best of my knowledge, there are no quantum algorithms that
significantly improve breaking times for HFE-based cryptosystems, such
as the QUARTZ and SFLASH signature schemes.
- Next message: William Whyte: "Re: DSA and KDSA"
- Previous message: Anonymous: "Re: The Truth: Everything Blows Your Privacy!"
- In reply to: Joseph Ashwood: "Re: Quantum slip - Quantum conspiracy"
- Next in thread: none: "Re: Quantum slip - Quantum conspiracy"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|