NIST finalizes 3 algorithms for post-quantum cryptography
After selecting four cryptographic algorithms designed to withstand attack by quantum computers, the National Institute of Standards and Technology (NIST) has started the process of standardizing these algorithms. NIST has released draft standards for three of the four algorithms it selected in 2022, while the draft standard for FALCON, the fourth algorithm, will be released in about a year.
In other words, NIST is calling on the cryptographic community to provide feedback on the draft standards. It will accept feedback on its post-quantum cryptography standardization project until 22 November 2023.
Figure 1 NIST has been working with government, academia, and industry from around the world to develop a new set of encryption standards that will work with our current computers while being resistant to the quantum machines of the future.
Currently, sensitive electronic information—like email and wire transfer data—is protected using public-key encryption techniques based on mathematical models and cannot be broken down by a conventional computer. However, quantum computers, though still in their infancy, are sufficiently powerful to break these encryption mechanisms.
But while quantum computers are powerful enough to break current encryption algorithms, they don’t exist yet. So, security experts emphasize the need to plan ahead, partly because it takes years to integrate new algorithms across all computer systems.
Post-quantum cryptography
In 2016, when the idea of quantum computers started making waves, NIST began its efforts to develop quantum-resistant algorithms by calling cryptographic experts to submit candidate algorithms as part of its post-quantum cryptography standardization project. Cryptographic experts from dozens of countries submitted 69 eligible algorithms by the November 2017 deadline set by NIST.
Next, NIST released these 69 candidate algorithms for cryptographers to analyze and invited them to crack if possible. In an open and transparent process, NIST organized multiple rounds of evaluation to reduce the number of candidate algorithms.
In July 2022, NIST selected four algorithms for its Federal Information Processing Standard (FIPS) initiative. First, CRYSTALS-Kyber, covered in FIPS 203, is designed for general encryption purposes such as creating secure websites.
Second, CRYSTALS-Dilithium, covered in FIPS 204, is designed to protect the digital signatures we use when signing documents remotely. Third, SPHINCS+, covered in FIPS 205, is also designed for digital signatures. Fourth, FALCON, also designed for digital signatures, is slated to receive its own draft FIPS in 2024.
Figure 2 NIST announced the first four post-quantum cryptography algorithms based on structured lattices and hash functions, two families of math problems that could resist a quantum computer’s assault.
Multiple rounds of evaluation
According to Dustin Moody, a NIST mathematician and leader of the project, while these three algorithms will constitute the first group of post-quantum encryption standards NIST creates, they will not be the last. In fact, besides the four algorithms NIST selected in 2022, the project team has also selected a second set of algorithms for ongoing evaluation.
These algorithms are intended to augment the first set announced in 2022. NIST plans to publish draft standards in 2024 for any of these algorithms selected for standardization. “These additional algorithms are designed for general encryption, but they are based on different math problems than CRYSTALS-Kyber,” Moody said. “They will offer alternative defense methods should one of the selected algorithms show a weakness in the future.”
Moody said that it’s likely that there will be one or two additional algorithms. “For the moment, we are requesting feedback on the drafts,” he added. “Just in case we need to change anything or missed anything.”
Related Content
Post-Quantum Cryptography: Are You Ready?
NIST Hits Quantum Teleport Key Out of the Park
The Future of Cryptography in Hardware Processors
Hardware security entering quantum computing era
Why cryptographers are worried about a post-quantum world
googletag.cmd.push(function() { googletag.display(‘div-gpt-ad-native’); });
–>
The post NIST finalizes 3 algorithms for post-quantum cryptography appeared first on EDN.


