Sitemap
Press enter or click to view image in full size

Member-only story

Kyber Is Great. But We Need an Alternative: NIST Should Announce Soon

6 min readDec 7, 2024

--

In the 3rd round of the NIST PQC competition, Kyber was selected for standardization for a key encapsulation method and thus is looking to replace ECDH as a key exchange method. Overall, Kyber was by far the best method for the 3rd round candidates and was the fastest for key generation and for encapsulation and decapsulation [here]:

Press enter or click to view image in full size

NIST has since defined a 4th round and is now assessing BIKE, Classic McEliece, HQC and SIKE [here], and which should be announced in the next month or two:

Press enter or click to view image in full size

Overall, SIKE has already been withdrawn as it was cracked at the end of Round 3. As we see from the above assessment, HQC and BIKE have a similar performance level, and both are code-based. For this, NIST wants a key encapsulation method which is not lattice-based [1]:

Press enter or click to view image in full size

--

--

Prof Bill Buchanan OBE FRSE
Prof Bill Buchanan OBE FRSE

Written by Prof Bill Buchanan OBE FRSE

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.