-
br-m<jpk68:matrix.org> It looks like some of OpenAI's recent math research has resulted in more ideal scaling assumptions for PQC
-
br-m<jpk68:matrix.org> I'm not too sure how accurate this is, but apparently due to tighter Cohn-Elkies and sphere-packing bounds, you can calculate machine-verified boundaries on high-dimensional lattices. This is in contrast to existing lattice-based NIKE schemes such as SWOOSH, which had to be over-padded to compensate for the possibility of worst-case reduction attacks
-
br-m<jpk68:matrix.org> Like, basically, it seems you can more tightly bound the LWE error stuff without being super conservative with padding and such
-
br-m<jpk68:matrix.org> I think this sort of shrinking could also be done with codes used in things like McEliece. It seems there's also a preprint with elliptic curve-related research, which may be able to speed up key exchange
-
br-m<jpk68:matrix.org> github.com/openai/math/blob/main/pr…026/exact-bsd-low-selmer-corank.pdf
-
br-m<jpk68:matrix.org> My bad for overusing words like "seems", "looks like", etc., but I'm not too confident I understand half of this stuff correctly
3 minutes ago