Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="4EWKHNLdl3IfezDz" --4EWKHNLdl3IfezDz Content-Type: text/plain; charset="UTF-8" Content-Disposition: inline Mike Hamburg writes: > it is qualitatively an OW problem and not an IND problem. So at least > that part of the concern is mitigated somewhat. Can you please explain how it's mitigated? The stated reason for concern was that "IND-CPA is more complicated than OW-CPA". Obviously this "scChk" hypothesis is also more complicated than OW-CPA. I don't see how the switch of hypothesis addresses the concern. I agree that distinguishers are a complication avoided by the scChk definition, but the scChk definition has its own quantum complications, so it's not as if there's some clear attraction for cryptanalysts. Meanwhile the broader reason stated for "alarm bells" was the "mismatch between the assumptions made in a claim of provable security and the assumptions that cryptanalysts have been trying to break". Switching to scChk exacerbates this concern today, even if scChk turns out to attract cryptanalysis in the long term. ---D. J. Bernstein -- You received this message because you are subscribed to the Google Groups "pqc-forum" group. To unsubscribe from this group and stop receiving emails from it, send an email to pqc-forum+unsubscribe@list.nist.gov. To view this discussion on the web visit https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/20230124171112.627598.qmail%40cr.yp.to. --4EWKHNLdl3IfezDz Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEE3QolqQXydru4e4ITsMANTjsOVFkFAmPQETAACgkQsMANTjsO VFkaow/+M9mNvbhmXRTlMbq8tGPl4ezT7hmE4oJy9ouzVsROACr5aaUkigr5qjV/ 2HUhBx+sksIR1fB+tmEgjO9nBqRcfkpYhdY0ggIgxnm5Nwy+OlwSHqoPBrggVsRa rExKCpyAHilaG4Z+OFZUMW5ymlHFRM/hk7NvdMV2UfF0D6UdB4ENgnYHcw9q/rZr Yhhjxi5M60XWmIxFccg2hWtE8RDYYjh76v9Vy+KQU1+xhxtxpkaMWesXL7XW7QjR 6sWYAVMQLJYLKh9N/OXzYX1BdO2+8kVKKwYfgH6GHKWd6u9i/28wB9wJccrQ0obu zNCzXAhazEYLPC8S42jzESRwxy5uH0lL+uaLacvRsd7gamkNfe2JDIOi5dagY/s+ sGGUN1aQ5MfpVKQYCE0CQwHsKzFazJiHxbjBmrZAH95DaTr+zmoYqDUtHj9NHYHV J+P+NTRZrj/ydIet9SgV9KhNVy/5yIiZjGyT/SUY9Pb74dlS+Jt8tyFNnvOM01/q zksDPLuWJTZ2X8H9ACRdxK8qyspb9e82rKQWZgSiKrAOE7L63XV/as2Ybf3k3Tk7 yK8KjsfoOfDzR/bvpBhqYsKEKuy31aWlldrzxXgr/56eo5eIHM4Rj0Z/oUFj2+Sm eeFYLdAn/Y9e2pa89P7HnUeke0CTuOeiV9miqsSmYNgozduSzx0= =bxZO -----END PGP SIGNATURE----- --4EWKHNLdl3IfezDz--