[noise] Implementing HFS support for Noise

Peter Schwabe peter at cryptojedi.org
Wed Sep 25 07:12:29 PDT 2019


Trevor Perrin <trevp at trevp.net> wrote:

Dear Trevor, dear Daan, dear all,

> > For snow, I have used Kyber1024, by request of David, (and also because
> > of personal affiliation). However, to provide the users with some
> > choice, we should maybe also decide on a second one to "unofficially"
> > standardize. In any case, I agree to update to the winners from the NIST
> > competition once that's finished. Until then, should we implement a
> > second one (and which)?
> 
> I don't know!  What do you think are the other best options?  We have
> an "Unofficial crypto algorithms list" where you can at least document
> any choices or options:
> 
> https://github.com/noiseprotocol/noise_wiki/wiki/Unofficial-crypto-algorithms-list

It might be most interesting to go for a KEM with a non-lattice
assumption and with substantially different performance characteristics
than Kyber or NewHope. I would suggest Classic McEliece or SIKE. 

Cheers,

Peter
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://moderncrypto.org/mail-archive/noise/attachments/20190925/1f79a118/attachment.sig>


More information about the Noise mailing list