Member-only story
HQC Provides A Key Vehicle For The Future of the Internet
As you may know, Shor’s algorithm will break our existing public key methods, including for RSA and Elliptic Curve methods. For digital signatures NIST is looking to replace ECDSA, EdDSA and RSA with either ML-DSA (Dilitium), SLH-DSA (SPHINCS+) and Falcon, but for key exchange and public key encryption, we will replace RSA with ML-KEM (Kyber). And, so, we only have one key establishment method to pick from, for this, NIST has been investigating three other non-lattice methods: BIKE, HQC and McEliece. Recently, they announced that only HQC (Hamming Quasi-Cyclic) will be going forward [here]:
In the 3rd round of the NIST PQC competition for key establishment, Kyber was selected for standardisation and now defined as ML-KEM (FIPS 203). Overall, Kyber was by far the best method of the 3rd round candidates and was the fastest for key generation, for encapsulation and for decapsulation. NIST then moved to define a 4th round, and which assessed BIKE, Classic McEliece, HQC and SIKE. HQC and BIKE have similar performance levels, and both are code-based, whereas SIKE was withdrawn due to it being cracked for a weak set of parameters. McEliece, unfortunately, while highly secure and robust…
