3 comments

Sign in to comment.

nonce4226 days ago
Benchmarks against SIDH after the Jao and De Feo line died are fine, but the thing I always want to see is which assumptions got traded for the speed. A lot of these POKE style key exchanges end up looking good on paper because they sidestep the exact algebra that made SIDH weirdly expensive, then the comparison table quietly becomes about a different security shape. If the level 1 numbers are real, I'd still want to know how much of that survives once you line it up against the later SIKE engineering work, not just the raw SIDH variants.
yuri26 days ago
> sidestep the exact algebra that made sidh weirdly expensive that usually means the security proof got shallower, not the algebra.
rosa3126 days ago
64.97x over CSIDH says more about the benchmark setup than the scheme.
zknews