From the paper: "on a single core, the appended Magma code breaks the Microsoft SIKE challenges $IKEp182 and $IKEp217 in about 4 minutes and 6 minutes, respectively. A run on the SIKEp434 parameters, previously believed to meet NIST’s quantum security level 1, took about 62 minutes, again on a single core. We also ran the code on random instances of SIKEp503 (level 2), SIKEp610 (level 3) and SIKEp751 (level 5), which…
It's over AFAIK, announcement here https://www.nist.gov/news-events/news/2022/07/nist-announces... and CloudFlare blog here https://blog.cloudflare.com/nist-post-quantum-surprise/ . I wonder if NIST got advance notice or if SIKE was excluded on other ground, but in any case it wasn't standardized. The fact SIKE went to round 4 means that NIST likely ignored the attack...
An efficient key recovery attack on SIDH
11–15 of 15 posts
Re: An efficient key recovery attack on SIDH
#12He is on a roll at breaking post-quantum candidates and he and his coauthors will hopefully keep going. That this guy is able to do this kind of work in the open is a public good. Note that he has broken schemes after NIST has declared the systems safe enough to advance to the next round. This is really embarrassing for NIST. Do they really not have the capacity for doing this kind of research? One or two people can only do so much, no? One can only imagine what is being done in private.
Thanks for working in public Ward! You’re doing a better job at cryptanalysis than NIST can do with a team of people who do this as a full time job! You deserve a medal, along with other cryptanalysts who work in public and release results in public.
It’s a little sad that he uses Magma for his attacks since it isn’t Free Software but it’s not so important. The result is what is important.
Already as of today one group using SIKE is now considering switching to CSIDH: https://forum.xx.network/t/paper-an-efficient-key-recovery-a...
This underscores a recently reiterated point from djb on the NIST post-quantum mailing list: we should not have confidence in the security of these post-quantum schemes.
These kinds of breaks are a strong argument for the use of hybrid constructions such as ECC or even more conservative systems. Note that NSA opposes hybrid constructions and is pushing for post-quantum schemes to be deployed without hybrid protections.
SIKE, like Rainbow, both supposedly post-quantum have turned out to be less secure than currently deployed contemporary systems. They are neither post-quantum nor currently secure. Very impressive results!
Re: An efficient key recovery attack on SIDH
#13This is an epic result. One of the authors, Ward Beullens, also recently broke the Rainbow signature scheme: “Breaking Rainbow Takes a Weekend on a Laptop” - https://eprint.iacr.org/2022/214 He is on a roll at breaking post-quantum candidates and he and his coauthors will hopefully keep going. That this guy is able to do this kind of work in the open is a public good. Note that he has broken schemes after NIST has de…
Re: An efficient key recovery attack on SIDH
#14This is an epic result. One of the authors, Ward Beullens, also recently broke the Rainbow signature scheme: “Breaking Rainbow Takes a Weekend on a Laptop” - https://eprint.iacr.org/2022/214 He is on a roll at breaking post-quantum candidates and he and his coauthors will hopefully keep going. That this guy is able to do this kind of work in the open is a public good. Note that he has broken schemes after NIST has de…
Ward Beullens is not an author of this paper.
Re: An efficient key recovery attack on SIDH
#15From the paper: "on a single core, the appended Magma code breaks the Microsoft SIKE challenges $IKEp182 and $IKEp217 in about 4 minutes and 6 minutes, respectively. A run on the SIKEp434 parameters, previously believed to meet NIST’s quantum security level 1, took about 62 minutes, again on a single core. We also ran the code on random instances of SIKEp503 (level 2), SIKEp610 (level 3) and SIKEp751 (level 5), which…
It's over AFAIK, announcement here https://www.nist.gov/news-events/news/2022/07/nist-announces... and CloudFlare blog here https://blog.cloudflare.com/nist-post-quantum-surprise/ . I wonder if NIST got advance notice or if SIKE was excluded on other ground, but in any case it wasn't standardized. The fact SIKE went to round 4 means that NIST likely ignored the attack...