[tor-dev] Post-quantum proposals #269 and #270

Jeff Burdges burdges at gnunet.org
Fri Aug 5 09:07:34 UTC 2016


I suspect the two known families you "do not want to rule out" are SIDH
schemes and LWE schemes with no ring structure, like Frodo.  At present
SIDH is too slow and LWE keys are too big, but both could improve
dramatically over the next several years. 

Jeff



-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: This is a digitally signed message part
URL: <http://lists.torproject.org/pipermail/tor-dev/attachments/20160805/3915ef94/attachment-0001.sig>


More information about the tor-dev mailing list