Based on the number of qubits necessary to break ECDLP, it looks like ~768 bit curves give equivalent security to RSA-3072. ECC gives a distorted perception of key and signature sizes. Post Quantum signature schemes have their key and signature sizes measured in KiB.
-
-
Prikaži ovu nit
-
This is old news it seems, but new to me. I am still curious why the classical cost of ECC is 3X the quantum cost relative to RSA. I think interest in Curve448 and Ed448 might increase given the recent fast progress of quantum computing at Google.https://crypto.stackexchange.com/questions/47760/is-there-a-good-reason-not-to-mention-that-ecc-is-weaker-than-rsa-on-a-quantum-c …
Prikaži ovu nit
Kraj razgovora
Novi razgovor -
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.