I understand why there is no HQC on the list at this point, but I wonder if it will be added to this recommendation at some point?
--
You received this message because you are subscribed to the Google Groups "pqc-forum" group.
To unsubscribe from this group and stop receiving emails from it, send an email to pqc-forum+...@list.nist.gov.
To view this discussion visit https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/4c934a50-e6e6-4a84-8cce-81bcd0400ffdn%40list.nist.gov.
To view this discussion visit https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/a40c6f57-440a-4482-b007-ea55e7f6feb9%40amongbytes.com.
Moving up to 256-bit cipher keys [...] isn't going to take noticeable time away from trying to
handle the other security problem.
Thanks for the pointer, Markku.I find it quite jarring that AES-128 and RSA / ECC are put at the same level "A". We wouldn't want organisations to spend time moving to AES-256 that could've been spent moving away from RSA. What options do you see to make that distinction clearer?
- If you read no further: do it everywhere it is easy, but prioritise
asymmetric/2k RSA if hard.
- Caveats: that Shor speedup is exponential but Grover is quadratic;
cost of Grover for AES-128 exceeds cost vs Shor with 4k RSA.
So the cost for
error correction is "orders of magnitude" even if the precise estimates
have shifted a bit, and indeed they're not at all equivalent.
-- Kind regards, Antony
--
You received this message because you are subscribed to the Google Groups "pqc-forum" group.
To unsubscribe from this group and stop receiving emails from it, send an email to pqc-forum+...@list.nist.gov.
To view this discussion visit https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/57addfe44ff905c0c476b752c5c913ad845066dd.camel%40vennard.ch.