Why we cannot wait for better post-quantum signature algorithms
As Eric Rescorla wrote 
in 2024 
 
 You go to war with the algorithms you have, not the ones you wish you had 

Recent content on dr. Bas Westerbaan
As Eric Rescorla wrote 
in 2024 
 
 You go to war with the algorithms you have, not the ones you wish you had 

It seems like a no-brainer to deploy PQ/T hybrid signatures instead
of post-quantum signatures on its own. However, on closer inspection,
hybrids come with a serious drawback: they increase the number of options
and tempt reuse of existing infrastructure. Because of this
they delay agreement on what to deploy.
Thus especially in more fragmented ecosystems,
supporting…
For a decade now I’ve worked on migrating to PQC.
All this time I thought we’d have at least until 2035.
Moving deadlines is rough, but that’s what you gotta do when
circumstances change.
If quantum computers were such an imminent threat, why haven’t they factored
any number larger than 15 yet?
PQC is a fast moving field. A lot has happened in the last 20 months.
High time for an update to the 2024 overview, to take another look
where we are with the migration and what to expect for the coming years.
Cloudflare is launching an experiment with Chrome to evaluate fast,
scalable, and quantum-ready Merkle Tree Certificates, all without
degrading performance or changing WebPKI trust relationships.
We revisit the problem of private SCT auditing given the recent
advances in PIR and changes to the certificate transparency ecosystem.
We take another look at the current landscape of
post-quantum signature schemes,
and share some relevant surprising statistics on the
median number of bytes transferred over a connection on the web.
We take measure of where we are in the migration,
and what to expect for the coming years.
We propose X-Wing, a concrete, simple and IND-CCA secure
PQ/T hybrid KEM based on X25519 and ML-KEM.
We show how to construct a practical post-quantum
anonymous credential scheme.
Large post-quantum signatures force us to rethink
the WebPKI. While we’re at it, we simplify transparency.
I discuss the impact on the Web of NIST’s choices for post-quantum algorithms.
How much room does TLS have for the big post-quantum signatures?
We had a look at Cloudflare: it’s tight.
We proposed chained CmPKE, a Continuous Group Key Agreement and
their underlying efficient Post-Quantum Multi-Recipient
KEMs based on Kyber, NTRU LPRime, Frodo and SIKE.
Are there nice assumptions on a category such that any such category
must be a category of quantum types with quantum programs between them?
We compare performance of PQ KEMTLS against other TLS variants
on the drand system.
We suggest a small change to the Dilithium signature scheme
that allows reusing computation between aborted attempts
for a speed-up in signing time.
We show that any normal SEA splits as the direct sum of
a complete Boolean algebra, a convex normal SEA
and a so-called almost-convex normal SEA.
We show that there is a consistent choice of
square root in a finite field \(\mathbb{F}_{p^k}\)
for odd prime \(p \neq 1\) and \(k\neq 0\) if and only if \(k\) is odd.
A non-trivial σ-effectus with normalization
has as scalars either {0,1} or [0,1].
When states and predicates are separating,
then it must embed into the category Boolean algebras (in the first case)
and into the category of Banach order-unit spaces in the second case.
It’s known that affine and relevant monads preserve respectively drop
and dup equations. We prove a converse.
We prove a Representation Theorem for \(\omega\)-complete effect monoids.
The title says it all.
We propose a definition of purity for positive linear maps between
Euclidean Jordan Algebras.
A mathematical study of quantum computing, concentrating on two
related, but independent topics.
We give a new way to bound the security of QKD using only
the diagrammatic behavior of complementary observables
and essential uniqueness of purification for quantum channels.
We explicitly construct oracles to solve binary MQ,
which is the underlying hard problem of many proposed post-quantum
cryptographic schemes.
We generalize Stinespring’s Dilation Theorem to
arbitrary completely positive normal
maps between von Neumann algebra’s.
We study the sequential product, the operation \(p * q = \sqrt{p}
q \sqrt{p}\) on the set of effects of a von Neumann algebra that
represents sequential measurement of first \(p\) and then \(q\).
We give four axioms which completely determine the sequential
product.
Effectus theory is a new branch of categorical logic that aims to
capture the essentials of quantum logic, with probabilistic and
Boolean logic as special cases.
A universal property for \( A \mapsto \sqrt{B} A \sqrt{B} \)
appears in a chain of adjunctions.
State spaces in probabilistic and quantum computation are convex
sets, that is, Eilenberg–Moore algebras of the distribution monad.
This article studies some computationally relevant properties of
convex sets.
The star-algebra \( M_2 \otimes M_2 \) models a pair of qubits. We show in detail
that \( M_3 \oplus \mathbb{C} \) models an unordered pair of qubits. Then we use the late
19th century Schur-Weyl duality, to characterize the star-algebra that
models an unordered n-tuple of d-level quantum systems.
A Kochen-Specker system has at least 22 vertices.
A simplification and slight extension of Statman’s Hierarchy
Theorem.
An investigation of the sequential product on predicates
in the framework of Jacobs.
We introduce several notions of effective undecidability and show they
are equivalent to previously investigated notions of completeness
and creativity.