[CFRG] Re: [pqc-forum] PQ KEM comparison tool
Demi Marie Obenour <demiobenour@gmail.com> Fri, 03 July 2026 17:55 UTC
Return-Path: <demiobenour@gmail.com>
X-Original-To: cfrg@mail2.ietf.org
Delivered-To: cfrg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 48EA510DE8CCC for <cfrg@mail2.ietf.org>; Fri, 3 Jul 2026 10:55:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1783101313; bh=GiK2pdCyC0OFMIys7Z+O1WUw2DnmMYGDt4vUi8MdP84=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=YKamJX6Z8EstBbipwDk412AmrZZ3o6/FaUJMIB/AWwrYUWA+BwCpvS6gEQnmGDpTr Hc4/uyd8WP/au/7PqAtNiwNWm4CkfZk2QQqBbp5oXW5wP4P3E7Q8e9aHBFOW2iYAyu 5C9rMP36oNk2kxZ9SXkCY3tA/MO4hqT7hRs2Vb+4=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4y3z3uCCQUhL for <cfrg@mail2.ietf.org>; Fri, 3 Jul 2026 10:55:12 -0700 (PDT)
Received: from mail-yw1-x1135.google.com (mail-yw1-x1135.google.com [IPv6:2607:f8b0:4864:20::1135]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 7B65310DE8A01 for <cfrg@irtf.org>; Fri, 3 Jul 2026 10:52:14 -0700 (PDT)
Received: by mail-yw1-x1135.google.com with SMTP id 00721157ae682-7fe36f1be74so10333477b3.2 for <cfrg@irtf.org>; Fri, 03 Jul 2026 10:52:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783101128; x=1783705928; darn=irtf.org; h=in-reply-to:autocrypt:from:content-language:references:cc:to :subject:user-agent:mime-version:date:message-id:from:to:cc:subject :date:message-id:reply-to; bh=9ovOu1S/nhWNZQ/Y9MDptVoLDcfA6Iro7BueLqRHnD8=; b=R40cy2vmPTG522TcIKc+W8Ow0nH0uvX9KUTKNrnarZTnyy5eouRvzA+mKShha2vxaL +a8x0jj1/Hdq7njlCUt7LiaMaVoUA4epJDexU2ZlXk94QVxxrJhTSLKL7PjegN/WBWuM m1wSd/US/G/vJM/obmKnOAe1cyEMcV09qSTp+v/k2NwkjNhJB8Z2YsAkZiC5RpwC1kN7 LVlE1JVRMRNr9k9jYvJhMVkaSm4h9fk3UQplaYq/VXWskbfA6FCg+M/7rCgR9wpFhvhY /Eb+OIqXDFcmBj5ZzqvhNhlraBTxzbd/hX/JEpRXF1dXotDfT0A3XCoNJ6kUZCxO9Nsn /FeA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783101128; x=1783705928; h=in-reply-to:autocrypt:from:content-language:references:cc:to :subject:user-agent:mime-version:date:message-id:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=9ovOu1S/nhWNZQ/Y9MDptVoLDcfA6Iro7BueLqRHnD8=; b=Brfpi+sk3hSNrHNk3x1uGGjAKW/zfMMTUBxAupW+4FvnXA/VwzcZbnwgGFxHmxckgg wV/Yv7UJoF1pjFL1nblI4xBJ3AN1UnQpXZELxZovSVHG2/XCg/c0XeCUn0jEF25R11IG FSkRa8hiBuRg+MpQV9NbxD0Z3VvGKApiypQlvIWHXinL6Gu+VDX2iz13IG35sd79K9WR q0HZnPQOe9/eOaHe/r5IwrvlhVPXu2pxv36Z0vqOspYZ64s1avI/0Fq5bcBtkTnnA9Nk qWi1XWOm99UMtjZhBc8OZVIfGXKPouC+653zjGhi7wkd/2lbhzQYX1X3iZ5I4Mko0SgD Qhlw==
X-Forwarded-Encrypted: i=1; AHgh+RrqpWYWjfYUxdxI8V58q4J7UWy+4aBtxL7UwsNhBBSb6EUwwmIMUrNMHKi2EXF39X1tjR/y@irtf.org
X-Gm-Message-State: AOJu0YyusNie9wAkRcWtWxHLHL1AwIXSP6guP8UvkLiJjH8t4xPR6zNa /4I+CndmWQO3lQiAjPwhtC9q5wyDmSqw7nK7DnOW0IB50jBo2BUZbrCH
X-Gm-Gg: AfdE7cnOQOCummw7F8ZKcOUSs9mTDat7g4QLBY6jRTt8l224G9VTSIM63Z+baK+S1Wy bgiqexMg7M7jPOZE0fWW/K9fRm1Awh6VKyrPA2opi4tQm3i+s3QSDcsi8glASEwG21u5wnSW1p/ UWI9GHKh7RdDJsW8MTudPa/GaU/ancHdMRHqLSmC4vczS2MaUlwRrCQyVL43TUvAGTsELT09X9z f9hBW8NUjhI18hDYLrKL9gRis11ijlLy5LkggaR2JA/y8iqZ/6Z0yA55IirgsOesrTn7+NqGszx cm4JIQtox8sYZZvBjFTQTw/4pJndTF958MFEjDnvGL7+Dkt0ZcGu72zbTyGIqWsK+J5DxToJXA+ IDlKdmYzvHzzFX67mZwK6dk9ZVcNqOV1A1b0hmuJMe1LVXzxMlYzzaEmKebHAlYnsUT3MyBIDHD niS3GLMMlSxZaq5u3k5bSovWPiZXPJ+XGXSu6sz2PCE2pzFsodQDA1nKX0XdvfQ+lcOPVJjzPvs PQ1tK+r57R1FDciS3GaEfCcQCQXwoPH3YQ4mek=
X-Received: by 2002:a05:690c:2604:b0:80c:85b6:75bb with SMTP id 00721157ae682-8173a4d6761mr3292477b3.68.1783101127824; Fri, 03 Jul 2026 10:52:07 -0700 (PDT)
Received: from [10.138.34.110] (h69-131-147-66.cncrtn.broadband.dynamic.tds.net. [69.131.147.66]) by smtp.gmail.com with ESMTPSA id 00721157ae682-8144af50fa5sm26633957b3.27.2026.07.03.10.52.05 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 03 Jul 2026 10:52:06 -0700 (PDT)
Message-ID: <62f7a7ff-b8dc-4369-b364-7aaa38daafc7@gmail.com>
Date: Fri, 03 Jul 2026 13:52:02 -0400
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: Damien Robert <damien.olivier.robert@gmail.com>, pqc-forum <pqc-forum@list.nist.gov>
References: <D527D3F9-A057-49DD-A256-9B4D6A8A2124@thomwiggers.nl> <AS4PR07MB882594EB25611E38AE668F0389F52@AS4PR07MB8825.eurprd07.prod.outlook.com> <d4f142a5-e354-4780-81d5-f67e8df3d019n@list.nist.gov>
Content-Language: en-US
From: Demi Marie Obenour <demiobenour@gmail.com>
Autocrypt: addr=demiobenour@gmail.com; keydata= xsFNBFp+A0oBEADffj6anl9/BHhUSxGTICeVl2tob7hPDdhHNgPR4C8xlYt5q49yB+l2nipd aq+4Gk6FZfqC825TKl7eRpUjMriwle4r3R0ydSIGcy4M6eb0IcxmuPYfbWpr/si88QKgyGSV Z7GeNW1UnzTdhYHuFlk8dBSmB1fzhEYEk0RcJqg4AKoq6/3/UorR+FaSuVwT7rqzGrTlscnT DlPWgRzrQ3jssesI7sZLm82E3pJSgaUoCdCOlL7MMPCJwI8JpPlBedRpe9tfVyfu3euTPLPx wcV3L/cfWPGSL4PofBtB8NUU6QwYiQ9Hzx4xOyn67zW73/G0Q2vPPRst8LBDqlxLjbtx/WLR 6h3nBc3eyuZ+q62HS1pJ5EvUT1vjyJ1ySrqtUXWQ4XlZyoEFUfpJxJoN0A9HCxmHGVckzTRl 5FMWo8TCniHynNXsBtDQbabt7aNEOaAJdE7to0AH3T/Bvwzcp0ZJtBk0EM6YeMLtotUut7h2 Bkg1b//r6bTBswMBXVJ5H44Qf0+eKeUg7whSC9qpYOzzrm7+0r9F5u3qF8ZTx55TJc2g656C 9a1P1MYVysLvkLvS4H+crmxA/i08Tc1h+x9RRvqba4lSzZ6/Tmt60DPM5Sc4R0nSm9BBff0N m0bSNRS8InXdO1Aq3362QKX2NOwcL5YaStwODNyZUqF7izjK4QARAQABzTxEZW1pIE1hcmll IE9iZW5vdXIgKGxvdmVyIG9mIGNvZGluZykgPGRlbWlvYmVub3VyQGdtYWlsLmNvbT7CwXgE EwECACIFAlp+A0oCGwMGCwkIBwMCBhUIAgkKCwQWAgMBAh4BAheAAAoJELKItV//nCLBhr8Q AK/xrb4wyi71xII2hkFBpT59ObLN+32FQT7R3lbZRjVFjc6yMUjOb1H/hJVxx+yo5gsSj5LS 9AwggioUSrcUKldfA/PKKai2mzTlUDxTcF3vKx6iMXKA6AqwAw4B57ZEJoMM6egm57TV19kz PMc879NV2nc6+elaKl+/kbVeD3qvBuEwsTe2Do3HAAdrfUG/j9erwIk6gha/Hp9yZlCnPTX+ VK+xifQqt8RtMqS5R/S8z0msJMI/ajNU03kFjOpqrYziv6OZLJ5cuKb3bZU5aoaRQRDzkFIR 6aqtFLTohTo20QywXwRa39uFaOT/0YMpNyel0kdOszFOykTEGI2u+kja35g9TkH90kkBTG+a EWttIht0Hy6YFmwjcAxisSakBuHnHuMSOiyRQLu43ej2+mDWgItLZ48Mu0C3IG1seeQDjEYP tqvyZ6bGkf2Vj+L6wLoLLIhRZxQOedqArIk/Sb2SzQYuxN44IDRt+3ZcDqsPppoKcxSyd1Ny 2tpvjYJXlfKmOYLhTWs8nwlAlSHX/c/jz/ywwf7eSvGknToo1Y0VpRtoxMaKW1nvH0OeCSVJ itfRP7YbiRVc2aNqWPCSgtqHAuVraBRbAFLKh9d2rKFB3BmynTUpc1BQLJP8+D5oNyb8Ts4x Xd3iV/uD8JLGJfYZIR7oGWFLP4uZ3tkneDfYzsFNBFp+A0oBEAC9ynZI9LU+uJkMeEJeJyQ/ 8VFkCJQPQZEsIGzOTlPnwvVna0AS86n2Z+rK7R/usYs5iJCZ55/JISWd8xD57ue0eB47bcJv VqGlObI2DEG8TwaW0O0duRhDgzMEL4t1KdRAepIESBEA/iPpI4gfUbVEIEQuqdqQyO4GAe+M kD0Hy5JH/0qgFmbaSegNTdQg5iqYjRZ3ttiswalql1/iSyv1WYeC1OAs+2BLOAT2NEggSiVO txEfgewsQtCWi8H1SoirakIfo45Hz0tk/Ad9ZWh2PvOGt97Ka85o4TLJxgJJqGEnqcFUZnJJ riwoaRIS8N2C8/nEM53jb1sH0gYddMU3QxY7dYNLIUrRKQeNkF30dK7V6JRH7pleRlf+wQcN fRAIUrNlatj9TxwivQrKnC9aIFFHEy/0mAgtrQShcMRmMgVlRoOA5B8RTulRLCmkafvwuhs6 dCxN0GNAORIVVFxjx9Vn7OqYPgwiofZ6SbEl0hgPyWBQvE85klFLZLoj7p+joDY1XNQztmfA rnJ9x+YV4igjWImINAZSlmEcYtd+xy3Li/8oeYDAqrsnrOjb+WvGhCykJk4urBog2LNtcyCj kTs7F+WeXGUo0NDhbd3Z6AyFfqeF7uJ3D5hlpX2nI9no/ugPrrTVoVZAgrrnNz0iZG2DVx46 x913pVKHl5mlYQARAQABwsFfBBgBAgAJBQJafgNKAhsMAAoJELKItV//nCLBwNIP/AiIHE8b oIqReFQyaMzxq6lE4YZCZNj65B/nkDOvodSiwfwjjVVE2V3iEzxMHbgyTCGA67+Bo/d5aQGj gn0TPtsGzelyQHipaUzEyrsceUGWYoKXYyVWKEfyh0cDfnd9diAm3VeNqchtcMpoehETH8fr RHnJdBcjf112PzQSdKC6kqU0Q196c4Vp5HDOQfNiDnTf7gZSj0BraHOByy9LEDCLhQiCmr+2 E0rW4tBtDAn2HkT9uf32ZGqJCn1O+2uVfFhGu6vPE5qkqrbSE8TG+03H8ecU2q50zgHWPdHM OBvy3EhzfAh2VmOSTcRK+tSUe/u3wdLRDPwv/DTzGI36Kgky9MsDC5gpIwNbOJP2G/q1wT1o Gkw4IXfWv2ufWiXqJ+k7HEi2N1sree7Dy9KBCqb+ca1vFhYPDJfhP75I/VnzHVssZ/rYZ9+5 1yDoUABoNdJNSGUYl+Yh9Pw9pE3Kt4EFzUlFZWbE4xKL/NPno+z4J9aWemLLszcYz/u3XnbO vUSQHSrmfOzX3cV4yfmjM5lewgSstoxGyTx2M8enslgdXhPthZlDnTnOT+C+OTsh8+m5tos8 HQjaPM01MKBiAqdPgksm1wu2DrrwUi6ChRVTUBcj6+/9IJ81H2P2gJk3Ls3AVIxIffLoY34E +MYSfkEjBz0E8CLOcAw7JIwAaeBT
In-Reply-To: <d4f142a5-e354-4780-81d5-f67e8df3d019n@list.nist.gov>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------aHnctqtRWHm1vf03Rez5zufV"
Message-ID-Hash: ZHWY3CWGV3Q5UGZ3IRMXHZLXEDTAXLPG
X-Message-ID-Hash: ZHWY3CWGV3Q5UGZ3IRMXHZLXEDTAXLPG
X-MailFrom: demiobenour@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; header-match-cfrg.irtf.org-1; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: IRTF CFRG <cfrg@irtf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Re: [pqc-forum] PQ KEM comparison tool
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/QM3t6di1bsgla6iIJ3gN6BbDoVk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>
On 7/3/26 13:37, Damien Robert wrote:
> Speaking of isogeny-based KEM, I would like to advertise our upcoming
> isogeny-based post-quantum Non-Interactive Key Exchange (NIKE), called
> **MIKE** (Module Isogeny Key Exchange), which we believe will be of great
> interest to this community.
>
> - **Compact keys:** 64B for NIST Level 1, and 128B for NIST Level 5.
>
> - **Fast key exchange:** For NIST Level 1, our Rust implementation requires
> <1 ms for key generation and <5 ms for the full key exchange (benchmarked
> on an AMD Ryzen 7 PRO 7840U @ 3.3GHz).
>
> - **Simple Implementation:** Our implementation is simple ($$\approx 4200$$
> LoC, excluding finite field arithmetic) and constant time
>
> - **Active security:** It is an actively-secure NIKE. The timings above
> include public key validation, which is a supersingularity test over
> $$\mathbb{F}_{p^2}$$.
>
> - **Provable security:** We prove MIKE's security (in the algebraic isogeny
> model) as a passively-secure NIKE or a KEM assuming only the supersingular
> endomorphism ring problem (the core assumption in isogeny-based
> cryptography).
>
>
> We aim to release the paper and code by the end of August.
This looks like a drop-in replacement for ECDH, except for the messages
being twice as large. I'm very much excited!
--
Sincerely,
Demi Marie Obenour (she/her/hers)
- [CFRG] PQ KEM comparison tool Thom Wiggers
- [CFRG] Re: [pqc-forum] PQ KEM comparison tool John Mattsson
- [CFRG] Re: [pqc-forum] PQ KEM comparison tool Aron
- [CFRG] Re: [pqc-forum] PQ KEM comparison tool Thom Wiggers
- [CFRG] Re: [pqc-forum] PQ KEM comparison tool Demi Marie Obenour