[4115] in cryptography@c2.net mail archive
Re: quantum cryptanalysis
daemon@ATHENA.MIT.EDU (Ulrich Kuehn)
Tue Feb 2 10:41:20 1999
Date: Tue, 2 Feb 1999 13:10:40 +0100 (MET)
From: Ulrich Kuehn <kuehn@ESCHER.UNI-MUENSTER.DE>
To: coderpunks@toad.com, cryptography@c2.net
In-Reply-To: <19990201204002.27972.qmail@nym.alias.net>
lcs Mixmaster Remailer writes:
> Second, quantum computers will already threaten much cryptography in
> use today. They would be able to factor numbers and find discrete logs,
> breaking the public key systems. For symmetric ciphers, they effectivelly
> halve the key length, which might even allow breaking 128 bit ciphers.
> (Which is why the new AES will support keys up to 256 bits.)
>
Can you explain the halfing effect on the key length? Or may be you
have some pointers to the literature on that?
Ciao,
Ulrich
--
Ulrich Kuehn ------------------ ukuehn@acm.org
kuehn@math.uni-muenster.de
http://wwwmath.uni-muenster.de/~kuehn/