Skip to main content

Featured Post

Kryptos - The Cipher (Part 4) - Correctly positioned decryption of the word BERLIN

EASTNORTHEAST - This is not exactly the hint Jim Sanborn (JS) gave for K4 on the 29th of January this year. He only gave NORTHEAST - which refers to the positions 26-34 of K4's plaintext.  Beside BERLIN and CLOCK it is the third revealed plaintext word of K4. However, also this hint does not seem to help much.  However, it just so happened, that a member in the yahoo kryptos group had a conversation with Jim Sanborn due to a submitted solution. Sandborn's answer to the question contained again the last clue which surprisingly was EASTNORTHEAST at position 22-34. Jim Sanborns compass rose at CIA There is disagreement if Jim revealed this on purpose or he did it accidentially, but the new extended clue seem to be serious and valid.Interestingly, EASTNORTHEAST is exactly the direction which is illustrated on the compass rose on one of the stones around kryptos, also created by Jim Sanborn. Actually, i dont really kn...

When the Finalists Fall: What Rainbow and SIKE Taught Us About Post-Quantum Standardisation

Cryptographic standardisation is usually presented as a process of selecting winners. Candidates are submitted, experts evaluate them, weaker designs are eliminated, and the strongest algorithms eventually become standards. The NIST Post-Quantum Cryptography standardisation process followed this general pattern, but with an unusual and important twist: two serious candidates survived almost until the end, only to suffer devastating cryptanalytic breaks. Rainbow was effectively eliminated late in the third round, while SIKE was broken shortly after advancing to the fourth round. And by this time already several years of research was done.

To me, these events are among the most remarkable aspects of the entire NIST process. They demonstrate both how difficult it is to evaluate new cryptographic assumptions and why public cryptanalysis must remain at the centre of cryptographic standardisation.

A global experiment in cryptanalysis

NIST began its post-quantum standardisation project because the public-key systems used today, particularly RSA and elliptic-curve cryptography, would be vulnerable to a sufficiently capable quantum computer. The objective was therefore to identify algorithms that could replace current public-key encryption, key-establishment and digital-signature mechanisms.

The formal call for proposals was published in December 2016. By the end of 2017, NIST had accepted 69 algorithms into the first round. The candidates represented several mathematical families, including lattices, error-correcting codes, multivariate polynomial systems, hash-based constructions and isogenies between elliptic curves. The field was reduced to 26 candidates in the second round and then to seven finalists and eight alternate candidates in the third round.

This was not a conventional competition in which an algorithm won by being faster than its rivals. Security was the primary requirement, and security could not be demonstrated by benchmarks alone. Each design had to withstand years of public attacks by cryptographers around the world.

That point is essential. A cryptographic scheme is not considered trustworthy because its designers cannot break it. It becomes trustworthy only after many other researchers have tried and failed.

Rainbow: broken during the final stretch

Rainbow was a multivariate digital-signature scheme. Its security was based on the difficulty of solving specially constructed systems of multivariate quadratic equations. Multivariate cryptography was attractive partly because it provided diversity: unlike several other leading candidates, Rainbow was not based on lattices.

Rainbow reached the third round as a signature finalist. By that stage, it had already survived years of analysis and had been treated as a plausible candidate for standardisation. Then, on 25 February 2022, Ward Beullens published Breaking Rainbow Takes a Weekend on a Laptop. The paper described new key-recovery attacks against the submitted Rainbow parameters. For the level-one parameter set, a private key could be recovered from the public key in an average of approximately 53 hours using an ordinary laptop. The attacks also outperformed the previously known attacks against the higher-security parameter sets.

The title captured the seriousness of the result. An algorithm intended to provide long-term protection against powerful future attackers could be compromised over a weekend using consumer hardware.

There is a technical nuance here. The paper did not show that every Rainbow parameter set could immediately be broken in a few hours. Larger parameters could potentially have been chosen. However, the submitted security claims had collapsed, the efficiency advantages would have been substantially reduced by increasing the parameters, and the attack suggested that the structure of Rainbow was less well understood than previously believed.

In practical standardisation terms, Rainbow was finished. What makes this episode striking is its timing. The attack appeared more than four years after the first-round candidates had been announced and only a few months before NIST completed the third round on 5 July 2022. Rainbow did not fail during an initial screening. It failed after years of research, optimisation and evaluation, while standing close to the finish line.

SIKE: from fourth-round candidate to broken in 25 days

The collapse of SIKE was even more dramatic. SIKE, the Supersingular Isogeny Key Encapsulation mechanism, was based on the SIDH key-exchange protocol. Its underlying mathematics involved isogenies—structure-preserving maps between elliptic curves. Compared with many lattice- and code-based candidates, SIKE offered extremely small public keys and ciphertexts. SIKE was not chosen as one of the first algorithms for standardisation at the end of the third round. Nevertheless, NIST considered its compact keys sufficiently attractive to justify further investigation. On 5 July 2022, NIST advanced SIKE, together with BIKE, Classic McEliece and HQC, into a fourth round of evaluation. NIST specifically identified SIKE’s small key and ciphertext sizes as an important advantage. Only 25 days later, on 30 July 2022, Wouter Castryck and Thomas Decru published an efficient key-recovery attack against SIDH. The attack used mathematical ideas that were very different from the generic attacks previously considered against the underlying isogeny problem. Instead of attacking the most obvious hard problem directly, it exploited additional information exchanged as part of the SIDH protocol.

The results were devastating. The researchers reported that SIKEp434, which targeted NIST’s first security level, could be broken in approximately ten minutes on a single processor core. The attack was not a marginal reduction in security or a warning that parameters should be increased. It fundamentally destroyed the security of the submitted construction. NIST’s fourth-round page now states plainly that SIKE and SIDH are insecure and should not be used. This was an extraordinary reversal. In early July, SIKE was still regarded as sufficiently promising to deserve another round of analysis. Before the end of the same month, its central security mechanism had been broken.

Did the process fail?

It is tempting to interpret these events as evidence that the NIST process failed. How could algorithms survive for so many years and remain candidates so late in the process if they were vulnerable to such powerful attacks?

I think that interpretation is understandable but ultimately mistaken. The purpose of the evaluation process was not to ensure that every candidate entering the later rounds was secure. That would have required knowing the answer before conducting the evaluation. The purpose was to expose candidates to sustained public scrutiny and eliminate designs when serious weaknesses were discovered.

From that perspective, the process worked exactly when it mattered. Rainbow and SIKE were attacked before becoming standards and before they were deployed as the long-term foundations of critical infrastructure. A cryptographic competition in which no candidate is ever broken should not necessarily inspire confidence. It might instead indicate that the candidates did not receive enough attention. At the same time, the late timing should make us uncomfortable. Both cases show that several years without a catastrophic attack do not constitute proof of security. Cryptanalytic progress is not linear. A scheme can survive hundreds of incremental papers and then collapse because one researcher finds a new way of looking at its structure.

Survival is not proof

The Rainbow and SIKE stories illustrate a fundamental problem in cryptography: we generally cannot prove that practical public-key schemes are secure in an absolute sense. We can reduce their security to mathematical problems. We can estimate the complexity of known attacks. We can test implementations and examine side channels. We can compare parameters with the best available algorithms. But an unknown attack remains unknown until someone discovers it. This is particularly relevant for post-quantum cryptography. Some candidate families had decades of study behind them, while others depended on comparatively young assumptions or used old mathematics in new cryptographic ways. Attractive performance characteristics could therefore coexist with considerable uncertainty.

SIKE is perhaps the clearest example. Its tiny keys were valuable precisely because they resulted from a highly specialised construction. Yet that special structure also created an attack surface that was not fully understood. There is no simple formula for balancing innovation against conservatism. Selecting only the oldest constructions may exclude important improvements. Selecting aggressive new designs may expose users to assumptions that have not received enough scrutiny.

[1] Ward Beullens: Breaking Rainbow Takes a Weekend on a Laptop. CRYPTO (2) 2022: 464-479
[2] Wouter Castryck, Thomas Decru: An Efficient Key Recovery Attack on SIDH. EUROCRYPT (5) 2023: 423-447

Comments

Popular posts from this blog

Kryptos - The Cipher (Part 4) - Correctly positioned decryption of the word BERLIN

EASTNORTHEAST - This is not exactly the hint Jim Sanborn (JS) gave for K4 on the 29th of January this year. He only gave NORTHEAST - which refers to the positions 26-34 of K4's plaintext.  Beside BERLIN and CLOCK it is the third revealed plaintext word of K4. However, also this hint does not seem to help much.  However, it just so happened, that a member in the yahoo kryptos group had a conversation with Jim Sanborn due to a submitted solution. Sandborn's answer to the question contained again the last clue which surprisingly was EASTNORTHEAST at position 22-34. Jim Sanborns compass rose at CIA There is disagreement if Jim revealed this on purpose or he did it accidentially, but the new extended clue seem to be serious and valid.Interestingly, EASTNORTHEAST is exactly the direction which is illustrated on the compass rose on one of the stones around kryptos, also created by Jim Sanborn. Actually, i dont really kn...

Kryptos - The Cipher (Part 1) - Introduction

Introduction. Since I think that KRYPTOS does not need any introduction, I will only give you a brief description of one of the most famous and only partially solved ciphers known today: KRYPTOS - Von Jim Sanborn - Jim Sanborn, CC BY-SA 3.0, https://commons.wikimedia.org/w/index.php?curid=8253447 KRYPTOS was constructed in Nov. 1990 on the ground of the CIA Headquarter in Langley, Virginia by Jim Sanborn It contains 4 ciphers (K1,K2,K3,K4) on its left side and some kind of Vigenère-Table on its right side K1, K2 and K3 were solved by James Gillogly in 1999. Afterwards, the CIA and later the NSA claimed that they had a solution to the first three ciphers at an earlier point in time Ed Scheidt, a cryptoanalyst and former director of the CIA, gave Sanborn the input of possible cryptographic techniques to use K1 is a variant of the Vigenère-Cipher (Quagmire 3) with the codewords KRYPTOS and PALIMPSES...

Kryptos - The Cipher (Part 2) - K4 abnormalities and solution attempts

This is Part 2 about Kryptos and the first post can be found here . In this post i will focus more on abnormalities and solutions attempts. Kryptos' Abnormalities Drawn by author. One noticeable fact is, that the letters KRYPTOS somehow are involved in the decryption process of all previous ciphers. In K1 and K2 they were directly used as one of the keywords in the Vigenère-Variant Quagmire3. For K3 there are several ways to transpose the ciphertext in order to reveal the plaintext, but one of them has to do with ordering/reordering the letters of KRYPTOS alphabetically. So, it seems plausible, that also in K4 these letters play a role in one or the other way. A further hint towards this is, that the letters of KRYPTOS all appear on the right side or in direct neighborhood on the left side, as marked below: 25| OB KR 26| UOXOGHULBSOLIFBBWFLRVQQPRNGKS SO 27| T WTQSJQSSEKZZWATJKLUDIAWINFBN YP 28| VTTMZF...