2

We can't trust RSA to encrypt our Emails so what is best post-quantum cryptography system as alternative for RSA which provide good security and don't be breakable? because McEliece cryptosystem looks break with 2^60.55 bit operations..

Paŭlo Ebermann
  • 22,946
  • 7
  • 82
  • 119
john
  • 21
  • 2

1 Answers1

4

My impression is that there is no production ready post quantum scheme ATM.

NTRU seems to be decent (complete spec, reasonable parameter-sizes and performance), but I think it's patented. No idea about the licensing terms.

But whatever scheme you choose, don't use it instead of a conventional scheme(RSA, DH, ECDH) but in addition to a conventional scheme. If you use a good construction, your protocol will be as secure as the stronger of the schemes.

CodesInChaos
  • 25,121
  • 2
  • 90
  • 129