{"id":638,"date":"2018-03-18T20:54:09","date_gmt":"2018-03-18T20:54:09","guid":{"rendered":"http:\/\/wordpress.rose-hulman.edu\/holden\/?page_id=638"},"modified":"2024-07-05T21:12:53","modified_gmt":"2024-07-05T21:12:53","slug":"cryptography-by-the-numbers","status":"publish","type":"page","link":"https:\/\/wordpress.rose-hulman.edu\/holden\/the-mathematics-of-secrets\/cryptography-by-the-numbers\/","title":{"rendered":"Cryptography by the Numbers"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-740 size-large\" src=\"http:\/\/wordpress.rose-hulman.edu\/holden\/wp-content\/uploads\/sites\/63\/2018\/03\/08-10_holden_fig-600-700x531.png\" alt=\"\" width=\"604\" height=\"458\" srcset=\"https:\/\/wordpress.rose-hulman.edu\/holden\/wp-content\/uploads\/sites\/63\/2018\/03\/08-10_holden_fig-600-700x531.png 700w, https:\/\/wordpress.rose-hulman.edu\/holden\/wp-content\/uploads\/sites\/63\/2018\/03\/08-10_holden_fig-600-300x228.png 300w, https:\/\/wordpress.rose-hulman.edu\/holden\/wp-content\/uploads\/sites\/63\/2018\/03\/08-10_holden_fig-600-768x583.png 768w, https:\/\/wordpress.rose-hulman.edu\/holden\/wp-content\/uploads\/sites\/63\/2018\/03\/08-10_holden_fig-600.png 1480w\" sizes=\"auto, (max-width: 604px) 100vw, 604px\" \/><\/p>\n<h6>NIST Recommendations<\/h6>\n<ul>\n<li>Modes of operation for block ciphers approved by NIST (<a href=\"https:\/\/csrc.nist.gov\/projects\/block-cipher-techniques\/bcm\/current-modes\">source<\/a>, updated February 12, 2018)\n<ul>\n<li>Encryption:\u00a0 6<\/li>\n<li>Authentication:\u00a0 1<\/li>\n<li>Encryption with Authentication:\u00a0 5<\/li>\n<li>Format-Preserving Encryption:\u00a0 2<\/li>\n<\/ul>\n<\/li>\n<li>Minimum key sizes approved by NIST (<a href=\"http:\/\/dx.doi.org\/10.6028\/NIST.SP.800-57pt1r4\">source<\/a>, published January 2016)\n<ul>\n<li>AES:\u00a0 128 bits<\/li>\n<li>Diffie-Hellman:\u00a0 2048 bits (617 digits)<\/li>\n<li>RSA:\u00a0 2048 bits (617 digits)<\/li>\n<li>Digital Signature Algorithm:\u00a0 2048 bits (617 digits) for public key, 224 bits (68 digits) for private key<\/li>\n<li>Elliptic Curve Cryptography:\u00a0 224 bits (68 digits)<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h6>Record-Breaking Computations<\/h6>\n<ul>\n<li>Record for factoring a product of two large primes of general form (<a href=\"https:\/\/listserv.nodak.edu\/cgi-bin\/wa.exe?A2=NMBRTHRY;dc42ccd1.2002\">source<\/a>, announced February 28, 2020):<\/li>\n<\/ul>\n<p style=\"padding-left: 60px\"><em>n\u00a0 <\/em>= 2140324650240744961264423072839333563008614715144755017797754920881418023447140136643345519095804679610992851872470914587687396261921557363047454770520805119056493106687691590019759405693457452230589325976697471681738069364894699871578494975937497937<br \/>\n= 64135289477071580278790190170577389084825014742943447208116859632024532344630238623598752668347708737661925585694639798853367<br \/>\n\u00d7<br \/>\n33372027594978156556226010605355114227940760344767554666784520987023841729210037080257448673296881877565718986258036932062711<br \/>\n(&#8220;<a href=\"https:\/\/en.wikipedia.org\/wiki\/RSA_numbers#RSA-250\">RSA-250<\/a>&#8220;, 829 bits, 250 digits)<\/p>\n<ul>\n<li>Record for finding a discrete logarithm modulo a prime (<a href=\"https:\/\/listserv.nodak.edu\/cgi-bin\/wa.exe?A2=NMBRTHRY;fd743373.1912\">source<\/a>, announced December 2, 2019):<\/li>\n<\/ul>\n<p style=\"padding-left: 60px\"><em>p <\/em>= RSA-240 + 49204 (the first <a href=\"https:\/\/en.wikipedia.org\/wiki\/Safe_prime\">safe prime<\/a> above &#8220;<a href=\"https:\/\/en.wikipedia.org\/wiki\/RSA_numbers#RSA-240\">RSA-240<\/a>&#8220;, 795 bits, 240 digits)<\/p>\n<p style=\"padding-left: 60px\">774356626343973985966622216006087686926705588649958206166317147722421706101723470351970238538755049093424997<br \/>\n\u2261 5<sup>92603135928144195363094955331732855502961099191437611616729420475898744562365366788100548099072093487548258752802923326447367244150096121629264809207598195062213366889859186681126928982506005127728321426751244111412371767375547225045851716<\/sup><br \/>\n(mod <em>p<\/em>)<\/p>\n<ul>\n<li>Record for finding a discrete logarithm in a finite field (<a href=\"https:\/\/listserv.nodak.edu\/cgi-bin\/wa.exe?A2=NMBRTHRY;62ab27f0.1907\">source<\/a>, announced July 10, 2019):\u00a0 Finite field has 2<sup>30750<\/sup> elements; size of the field is 30750 bits (14672 digits).<br \/>\nThe finite field was obtained by taking polynomials in two variables, <em>x <\/em>and <em>t<\/em>, and reducing them modulo <em>t<\/em><sup>30 <\/sup>+\u00a0<em>t<\/em> + 1, modulo <em>x<\/em><sup>1025 <\/sup>+\u00a0<em>x<\/em> + <em>t<\/em><sup>3<\/sup>, and modulo 2.The challenge was to take the logarithm of<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/wordpress.rose-hulman.edu\/holden\/wp-content\/ql-cache\/quicklatex.com-6d850a8f9c43699df5664cc9f7627b0c_l3.png\" class=\"ql-img-inline-formula quicklatex-auto-format\" alt=\"&#92;&#100;&#105;&#115;&#112;&#108;&#97;&#121;&#115;&#116;&#121;&#108;&#101;&#32;&#92;&#115;&#117;&#109;&#95;&#123;&#105;&#61;&#48;&#125;&#94;&#123;&#51;&#48;&#55;&#52;&#57;&#125;&#32;&#92;&#108;&#101;&#102;&#116;&#40;&#32;&#92;&#108;&#102;&#108;&#111;&#111;&#114;&#32;&#92;&#112;&#105;&#32;&#92;&#99;&#100;&#111;&#116;&#32;&#50;&#94;&#123;&#105;&#43;&#49;&#125;&#32;&#92;&#114;&#102;&#108;&#111;&#111;&#114;&#32;&#92;&#98;&#109;&#111;&#100;&#123;&#50;&#125;&#32;&#92;&#114;&#105;&#103;&#104;&#116;&#41;&#32;&#92;&#99;&#100;&#111;&#116;&#32;&#116;&#94;&#123;&#50;&#57;&#32;&#45;&#32;&#40;&#105;&#32;&#92;&#98;&#109;&#111;&#100;&#123;&#51;&#48;&#125;&#41;&#125;&#32;&#92;&#99;&#100;&#111;&#116;&#32;&#120;&#94;&#123;&#92;&#108;&#102;&#108;&#111;&#111;&#114;&#32;&#105;&#32;&#47;&#32;&#51;&#48;&#32;&#92;&#114;&#102;&#108;&#111;&#111;&#114;&#125;\" title=\"Rendered by QuickLaTeX.com\" height=\"52\" width=\"344\" style=\"vertical-align: -21px;\"\/>with respect to the generator<em> g<\/em>\u00a0 =\u00a0 <em>x<\/em> + <em>t<\/em><sup>9 <\/sup>.<\/li>\n<\/ul>\n<ul>\n<li>Record for finding a discrete logarithm on an elliptic curve of general form modulo <em>p<\/em> (<a href=\"https:\/\/bitcointalk.org\/index.php?topic=5244940.msg54630922#msg54630922\">source<\/a>, announced June 16, 2020):<\/li>\n<\/ul>\n<p style=\"padding-left: 60px\"><em>p <\/em>= 2<sup>256<\/sup> &#8211; 2<sup>32<\/sup> &#8211; 2<sup>9<\/sup> &#8211; 2<sup>8<\/sup> &#8211; 2<sup>7<\/sup> &#8211; 2<sup>6<\/sup> &#8211; 2<sup>4<\/sup> &#8211; 1 = 115792089237316195423570985008687907853269984665640564039457584007908834671663<\/p>\n<p style=\"padding-left: 60px\"><em>A<\/em> \u2261 31464123230573852164273674364426950 <em>G\u00a0 <\/em>(mod <em>p<\/em>)<\/p>\n<p style=\"padding-left: 60px\">The logarithm was from the <a href=\"https:\/\/bitcointalk.org\/index.php?topic=5218972\">100 BTC Bitcoin Challenge<\/a> and was specified to have at most 115 bits (35 digits).<\/p>\n<ul>\n<li>Record for finding the shortest vector in a randomly generated lattice (<a href=\"https:\/\/www.latticechallenge.org\/svp-challenge\/halloffame.php\">source<\/a>, announced February 8, 2021):\u00a0 A point in a lattice in 180 dimensions which is distance 3509 from the origin.<\/li>\n<li>Record for solving the Learning With Errors problem in the highest dimension (<a href=\"https:\/\/www.latticechallenge.org\/lwe_challenge\/halloffame.php\">source<\/a>, announced June 12, 2022):\u00a0 A point in a lattice in 90 dimensions with a relative error size of 0.005.<\/li>\n<li>Record for solving the Learning With Errors problem with the largest relative error (<a href=\"https:\/\/www.latticechallenge.org\/lwe_challenge\/halloffame.php\">source<\/a>, announced March 6, 2022):\u00a0 A point in a lattice in 40 dimensions with a relative error size of 0.035.<\/li>\n<li>Record for solving the syndrome decoding problem (as used in Classic McEliece) with the longest length solution (<a href=\"https:\/\/isd.mceliece.org\/1347.html\">source<\/a>, announced February 26, 2023):\u00a0 A string of 1347 bits, 25 of which had value 1.<\/li>\n<li>Record for recovering a McEliece (with Goppa code) secret key from a public key (<a href=\"https:\/\/www.tii.ae\/news\/tii-mceliece-encryption-challenges-winners-announced\">source<\/a>, announced May 30, 2024): \u00a0 Public key is a matrix with 40 rows and 253 columns.<\/li>\n<li>Record for recovering a McEliece (with Goppa code) plaintext from a public key and a ciphertext (<a href=\"https:\/\/www.tii.ae\/news\/tii-mceliece-encryption-challenges-winners-announced\">source<\/a>, announced May 30, 2024): \u00a0 Public key is a matrix with 230 rows and 988 columns.<\/li>\n<li>Record for solving the quasi-cyclic syndrome decoding problem (as used in BIKE) with the longest length solution (<a href=\"https:\/\/decodingchallenge.org\/q-c\/record\/23\">source<\/a>, announced April 18, 2022):\u00a0 A string of 3138 bits, 56 of which had value 1.<\/li>\n<li>Record for breaking reduced-size Kyber with the largest secret key size (<a href=\"https:\/\/twitter.com\/AlexanderMay10\/status\/1687112360266514432\">source<\/a>, announced August 3, 2023): A 1536-bit secret key.<\/li>\n<\/ul>\n<h6>Quantum Computing Records<\/h6>\n<ul>\n<li>Largest number reported factored using Shor&#8217;s Algorithm for fast quantum computing:\u00a0 21\u00a0 (<a href=\"https:\/\/doi.org\/10.1038\/nphoton.2012.259\">source<\/a>, published October 21, 2012)<\/li>\n<li>Largest number reported factored using quantum computation at any speed:\u00a0 249919 (<a href=\"http:\/\/www.nature.com\/articles\/s41598-018-36058-z\">source<\/a>, published December 5, 2018)<\/li>\n<\/ul>\n<h6>Quantum Cryptography Records<\/h6>\n<ul>\n<li>Fastest quantum key agreement systems:\n<ul>\n<li>Medium-distance:\u00a0 1.02 Mbit\/s over 20 km of optical fiber (<a href=\"https:\/\/www.osapublishing.org\/oe\/abstract.cfm?uri=oe-16-23-18790\">source<\/a>,\u00a0published October 30, 2008)<\/li>\n<li>Long-distance:\u00a0 12.7 kbit\/s over 307\u00a0km of optical fiber (<a href=\"http:\/\/www.nature.com\/nphoton\/journal\/v9\/n3\/full\/nphoton.2014.327.html\">source<\/a>, published February 9, 2015)<\/li>\n<\/ul>\n<\/li>\n<li>Longest quantum key agreement systems:\n<ul>\n<li>Fiber-optic:\u00a0 404 km (<a href=\"https:\/\/journals.aps.org\/prl\/abstract\/10.1103\/PhysRevLett.117.190501\">source<\/a>, published November 2, 2016)<\/li>\n<li>Ground-to-ground: 144 km (<a href=\"http:\/\/xqp.physik.lmu.de\/publications\/files\/articles_2007\/prl_98_010504.pdf\">source<\/a>, published January 5, 2007)<\/li>\n<li>Air-to-ground: 20 km (<a href=\"http:\/\/www.nature.com\/articles\/nphoton.2013.46\">source<\/a>, published March 31, 2013)<\/li>\n<li>Ground-to-air:\u00a0 10 km (<a href=\"http:\/\/iopscience.iop.org\/article\/10.1088\/2058-9565\/aa701f\/meta\">source<\/a>, published June 6, 2017)<\/li>\n<li>Satellite-to-ground:\u00a0 1200 km (<a href=\"http:\/\/www.nature.com\/doifinder\/10.1038\/nature23655\">source<\/a>, published September 7, 2017)<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h6>Post-Quantum Cryptography<\/h6>\n<ul>\n<li>Submissions to the NIST Post-Quantum Cryptography Standardization process (<a href=\"https:\/\/csrc.nist.gov\/CSRC\/media\/Presentations\/Let-s-Get-Ready-to-Rumble-The-NIST-PQC-Competiti\/images-media\/PQCrypto-April2018_Moody.pdf\">source<\/a>, presented April 11, 2018)\n<ul>\n<li>Submissions received by NIST:\u00a0 82<\/li>\n<li>Submissions meeting minimum specified requirements:\u00a0 69<\/li>\n<li>Submissions still in contention as of the First PQC Standardization Conference:\u00a0 64<\/li>\n<li>Submitters involved: 278, from &#8220;25 Countries, 16 States, 6 Continents&#8221;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none\"><\/li>\n<li>Submissions selected for standardization after Round 3 (<a href=\"https:\/\/csrc.nist.gov\/news\/2022\/pqc-candidates-to-be-standardized-and-round-4\">source<\/a>, announced July 5, 2022)\n<ul>\n<li>CRYSTALS-KYBER (key-establishment for most use cases)<\/li>\n<li>CRYSTALS-Dilithium (digital signatures for most use cases)<\/li>\n<li>FALCON (digital signatures for use cases requiring smaller signatures)<\/li>\n<li>SPHINCS+ (digital signatures not relying on the security of lattices)<\/li>\n<\/ul>\n<\/li>\n<li>Public-key encryption and key-establishment algorithms deferred to Round 4 of the NIST Post-Quantum Cryptography Standardization process:\u00a0 BIKE, Classic McEliece, HQC, SIKE<\/li>\n<li>4th NIST PQC Standardization Conference:\u00a0 November 29-December 1, 2022<\/li>\n<li>\n<div class=\"nist-block\">\n<div class=\"font-heading-md\">Draft standards for KYBER, Dilithium, and SPINCS+ available for public comment:\u00a0 August 24, 2023<\/div>\n<\/div>\n<\/li>\n<li>FALCON draft standard available for public comment:\u00a0 2024<\/li>\n<\/ul>\n<ul>\n<li>Submissions to the New Call for Proposals: Digital Signature Algorithms with Short Signatures and Fast Verification (<a href=\"https:\/\/csrc.nist.gov\/csrc\/media\/Projects\/post-quantum-cryptography\/documents\/pqc-seminars\/presentations\/5-onramp-submissions-moody-06092023.pdf\">source<\/a>, announced June 9, 2023)\n<ul>\n<li>Submissions received by NIST:\u00a0 50<\/li>\n<li>Submitters involved: 262, from &#8220;5 continents and 28 countries&#8221;<\/li>\n<li>Submissions meeting minimum specified requirements:\u00a0 40 (<a href=\"https:\/\/csrc.nist.gov\/news\/2023\/additional-pqc-digital-signature-candidates\">source<\/a>, announced July 17, 2023)<\/li>\n<li>Number of submissions reported insecure in the first 30 hours:\u00a0 7 (<a href=\"https:\/\/groups.google.com\/a\/list.nist.gov\/g\/pqc-forum\">sources<\/a>)<\/li>\n<\/ul>\n<\/li>\n<li>Fifth PQC standardization conference: April 10-12, 2024.<\/li>\n<\/ul>\n<h6>Lightweight Cryptography<\/h6>\n<ul>\n<li>Submissions to the NIST Lightweight Cryptography Standardization process (<a href=\"https:\/\/csrc.nist.gov\/Projects\/Lightweight-Cryptography\">source<\/a>, updated <span id=\"pageUpdated\">April 19, 2019<\/span>)\n<ul>\n<li>Submissions received by NIST:\u00a0 57<\/li>\n<li>Submissions meeting minimum specified requirements:\u00a0 56<\/li>\n<\/ul>\n<\/li>\n<li>Submissions surviving to Round 2 of the NIST Lightweight Cryptography Standardization process (<a href=\"https:\/\/groups.google.com\/a\/list.nist.gov\/d\/msg\/lwc-forum\/-G6VEqTN5fg\/STOgPIY5FAAJ\">source<\/a>, announced August 30, 2019)\n<ul>\n<li>Round 2 candidate submissions:\u00a0 32<\/li>\n<li>3rd NIST Lightweight Cryptography Workshop:\u00a0 November 4-6, 2019<\/li>\n<li>4th NIST Lightweight Cryptography Workshop (virtual):\u00a0 October 19-21, 2020<\/li>\n<\/ul>\n<\/li>\n<li>Submissions surviving to Round 3 of the NIST Lightweight Cryptography Standardization process (<a href=\"https:\/\/groups.google.com\/a\/list.nist.gov\/g\/lwc-forum\/c\/YWlcPTYNAbQ\">source<\/a>, announced March 29, 2021)\n<ul>\n<li>Round 3 candidate submissions:\u00a0 10\u00a0 (ASCON, Elephant, GIFT-COFB, Grain128-AEAD, ISAP, Photon-Beetle, Romulus, Sparkle, TinyJambu, and Xoodyak)<\/li>\n<li>5th NIST Lightweight Cryptography Workshop (virtual):\u00a0 May 9-11, 2022<\/li>\n<\/ul>\n<\/li>\n<li>NIST selects <strong>Ascon <\/strong>as the family of algorithms for the new Lightweight Cryptography Standard! (<a href=\"https:\/\/csrc.nist.gov\/News\/2023\/lightweight-cryptography-nist-selects-ascon\">source<\/a>, announced February 7, 2023)\n<ul>\n<li><a href=\"https:\/\/twitter.com\/mjos_crypto\/status\/1622973400481247233?cn=ZmxleGlibGVfcmVjcw%3D%3D&amp;refsrc=email\">Unofficial brief description<\/a> of Ascon<\/li>\n<li>6th NIST Lightweight Cryptography Workshop (virtual):\u00a0 June 21-22, 2023<\/li>\n<li>Draft standards available for public comment:\u00a0 2023<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<div class=\"SnapLinksContainer\" style=\"margin-left: 0px;margin-top: 0px\">\n<p><!-- Used for easily cloning the properly namespaced rect --><\/p>\n<\/div>\n<div class=\"SnapLinksContainer\" style=\"margin-left: 0px;margin-top: 0px\">\n<div class=\"SL_SelectionRect\">\n<div class=\"SL_SelectionLabel\"><\/div>\n<\/div>\n<p><!-- Used for easily cloning the properly namespaced rect --><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>NIST Recommendations Modes of operation for block ciphers approved by NIST (source, updated February 12, 2018) Encryption:\u00a0 6 Authentication:\u00a0 1 Encryption with Authentication:\u00a0 5 Format-Preserving Encryption:\u00a0 2 Minimum key sizes approved by NIST (source, published January 2016) AES:\u00a0 128 bits Diffie-Hellman:\u00a0 2048 bits (617 digits) RSA:\u00a0 2048 bits (617 digits) Digital Signature Algorithm:\u00a0 2048 bits &hellip; <a href=\"https:\/\/wordpress.rose-hulman.edu\/holden\/the-mathematics-of-secrets\/cryptography-by-the-numbers\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Cryptography by the Numbers<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":938,"featured_media":0,"parent":155,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-638","page","type-page","status-publish","hentry"],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/P8uE0W-ai","_links":{"self":[{"href":"https:\/\/wordpress.rose-hulman.edu\/holden\/wp-json\/wp\/v2\/pages\/638","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.rose-hulman.edu\/holden\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/wordpress.rose-hulman.edu\/holden\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.rose-hulman.edu\/holden\/wp-json\/wp\/v2\/users\/938"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.rose-hulman.edu\/holden\/wp-json\/wp\/v2\/comments?post=638"}],"version-history":[{"count":72,"href":"https:\/\/wordpress.rose-hulman.edu\/holden\/wp-json\/wp\/v2\/pages\/638\/revisions"}],"predecessor-version":[{"id":2202,"href":"https:\/\/wordpress.rose-hulman.edu\/holden\/wp-json\/wp\/v2\/pages\/638\/revisions\/2202"}],"up":[{"embeddable":true,"href":"https:\/\/wordpress.rose-hulman.edu\/holden\/wp-json\/wp\/v2\/pages\/155"}],"wp:attachment":[{"href":"https:\/\/wordpress.rose-hulman.edu\/holden\/wp-json\/wp\/v2\/media?parent=638"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}