Live data from Hacker News

An efficient key recovery attack on SIDH

eprint.iacr.org

11–15 of 15 posts

Re: An efficient key recovery attack on SIDH

#11
post #10
post #8

From the paper: "on a single core, the appended Magma code breaks the Microsoft SIKE challenges $IKEp182 and $IKEp217 in about 4 minutes and 6 minutes, respectively. A run on the SIKEp434 parameters, previously believed to meet NIST’s quantum security level 1, took about 62 minutes, again on a single core. We also ran the code on random instances of SIKEp503 (level 2), SIKEp610 (level 3) and SIKEp751 (level 5), which…

It's over AFAIK, announcement here https://www.nist.gov/news-events/news/2022/07/nist-announces... and CloudFlare blog here https://blog.cloudflare.com/nist-post-quantum-surprise/ . I wonder if NIST got advance notice or if SIKE was excluded on other ground, but in any case it wasn't standardized. The fact SIKE went to round 4 means that NIST likely ignored the attack...

There's another phase of the NIST event.

Re: An efficient key recovery attack on SIDH

#12
This is an epic result. One of the authors, Ward Beullens, also recently broke the Rainbow signature scheme: “Breaking Rainbow Takes a Weekend on a Laptop” - https://eprint.iacr.org/2022/214

He is on a roll at breaking post-quantum candidates and he and his coauthors will hopefully keep going. That this guy is able to do this kind of work in the open is a public good. Note that he has broken schemes after NIST has declared the systems safe enough to advance to the next round. This is really embarrassing for NIST. Do they really not have the capacity for doing this kind of research? One or two people can only do so much, no? One can only imagine what is being done in private.

Thanks for working in public Ward! You’re doing a better job at cryptanalysis than NIST can do with a team of people who do this as a full time job! You deserve a medal, along with other cryptanalysts who work in public and release results in public.

It’s a little sad that he uses Magma for his attacks since it isn’t Free Software but it’s not so important. The result is what is important.

Already as of today one group using SIKE is now considering switching to CSIDH: https://forum.xx.network/t/paper-an-efficient-key-recovery-a...

This underscores a recently reiterated point from djb on the NIST post-quantum mailing list: we should not have confidence in the security of these post-quantum schemes.

These kinds of breaks are a strong argument for the use of hybrid constructions such as ECC or even more conservative systems. Note that NSA opposes hybrid constructions and is pushing for post-quantum schemes to be deployed without hybrid protections.

SIKE, like Rainbow, both supposedly post-quantum have turned out to be less secure than currently deployed contemporary systems. They are neither post-quantum nor currently secure. Very impressive results!

Re: An efficient key recovery attack on SIDH

#13

This is an epic result. One of the authors, Ward Beullens, also recently broke the Rainbow signature scheme: “Breaking Rainbow Takes a Weekend on a Laptop” - https://eprint.iacr.org/2022/214 He is on a roll at breaking post-quantum candidates and he and his coauthors will hopefully keep going. That this guy is able to do this kind of work in the open is a public good. Note that he has broken schemes after NIST has de…

Ward Beullens is not an author of this paper.

Re: An efficient key recovery attack on SIDH

#14

This is an epic result. One of the authors, Ward Beullens, also recently broke the Rainbow signature scheme: “Breaking Rainbow Takes a Weekend on a Laptop” - https://eprint.iacr.org/2022/214 He is on a roll at breaking post-quantum candidates and he and his coauthors will hopefully keep going. That this guy is able to do this kind of work in the open is a public good. Note that he has broken schemes after NIST has de…

Ward Beullens is not an author of this paper.

Oh wow, I completely made a mistake here. Ward is amazing, but I should have properly credited Wouter Castryck and Thomas Decru for this paper. Embarrassing. I wish I could edit my comment now, the shame will last forever.

Re: An efficient key recovery attack on SIDH

#15
post #10
post #8

From the paper: "on a single core, the appended Magma code breaks the Microsoft SIKE challenges $IKEp182 and $IKEp217 in about 4 minutes and 6 minutes, respectively. A run on the SIKEp434 parameters, previously believed to meet NIST’s quantum security level 1, took about 62 minutes, again on a single core. We also ran the code on random instances of SIKEp503 (level 2), SIKEp610 (level 3) and SIKEp751 (level 5), which…

It's over AFAIK, announcement here https://www.nist.gov/news-events/news/2022/07/nist-announces... and CloudFlare blog here https://blog.cloudflare.com/nist-post-quantum-surprise/ . I wonder if NIST got advance notice or if SIKE was excluded on other ground, but in any case it wasn't standardized. The fact SIKE went to round 4 means that NIST likely ignored the attack...

This paper was posted only yesterday, 3 weeks after NIST announcement.
Post reply on HN