Member-only story
Kyber Is Great. But We Need an Alternative: NIST Should Announce Soon
In the 3rd round of the NIST PQC competition, Kyber was selected for standardization for a key encapsulation method and thus is looking to replace ECDH as a key exchange method. Overall, Kyber was by far the best method for the 3rd round candidates and was the fastest for key generation and for encapsulation and decapsulation [here]:
NIST has since defined a 4th round and is now assessing BIKE, Classic McEliece, HQC and SIKE [here], and which should be announced in the next month or two:
Overall, SIKE has already been withdrawn as it was cracked at the end of Round 3. As we see from the above assessment, HQC and BIKE have a similar performance level, and both are code-based. For this, NIST wants a key encapsulation method which is not lattice-based [1]:
