[noise] Implementing HFS support for Noise
peter at cryptojedi.org
Wed Sep 25 07:12:29 PDT 2019
Trevor Perrin <trevp at trevp.net> wrote:
Dear Trevor, dear Daan, dear all,
> > For snow, I have used Kyber1024, by request of David, (and also because
> > of personal affiliation). However, to provide the users with some
> > choice, we should maybe also decide on a second one to "unofficially"
> > standardize. In any case, I agree to update to the winners from the NIST
> > competition once that's finished. Until then, should we implement a
> > second one (and which)?
> I don't know! What do you think are the other best options? We have
> an "Unofficial crypto algorithms list" where you can at least document
> any choices or options:
It might be most interesting to go for a KEM with a non-lattice
assumption and with substantially different performance characteristics
than Kyber or NewHope. I would suggest Classic McEliece or SIKE.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: not available
More information about the Noise