A lot of people say they want to learn about post-quantum cryptography. One day, your favourite regulation authority asks you to switch to post-quantum in the next five years. While a great motivator to finally learn about PQ, what does that actually mean for you and me, your company and your non-tech friends?
The talk will cover:
- why we need to switch to post-quantum
- are some cryptographic algorithms more vulnerable than others
- what you should change when.
More importantly, we'll talk about the algorithms under the schemes: Which one should you use for your server, and which one is maybe more suited as a conversation topic at dinner parties.
Finally, we'll look ahead: What are academics thinking about, and what is out there beyond key exchange and signatures?
The talk will be split into an introduction and four parts:
Intro:
PQ Mitigation timelines, Confidentiality is more vulnerable than Authenticity
(harvest-now-decrypt-later vs. just stopping to accept RSA signatures)
- The Novice. What does Shor tell us? What are periodic functions, and why are they vulnerable?
Conclusion: Factoring and Discrete logs are vulnerable because they are periodic. So what can we use instead? - The casual Enjoyer: A high level intro to
- random walks (isogenies)
- noisy equations (lattices)
- codes (noncommutative lattices)
- multivariate cryptography (noisy equations with more variables)
- symmetric MPC (just do the boring thing, obliviously and generically).
Conclusion: There's a lot of math, but at least you now know where to start and how to fake your way through the next 1:1 with your team lead.
- The deployer: what algorithms should you actually use? This is easy: NIST, ESI and other standards tell you what you are allowed to do in business applications- standards are usually not very flexible. Otherwise, the one you like best (maybe use a standard one, or one I invented (pls don't) ).
Optional: "But someone told me lattices are bad". Stop believing random people on the internet. Trust me instead, or actually, don't. Do your own research. In fact, do your own PhD in cryptography.
- The academic: What is an open question? Privacy tech is not being rolled out because there are no PQ-safe alternatives. Data-oblivious (Blind) evaluation is hard, short intution on why.