Post‐Quantum Implementations
Matthias J. Kannwischer, Ruben Niederhagen, Francisco Rodríguez‐Henríquez, Peter Schwabe · 2025
This chapter gives an overview of techniques for secure and efficient implementation of so-called post-quantum cryptography, the anticipated next generation of asymmetric cryptography. It focuses on the essentials of the construction and aspects that are particularly relevant for efficient and secure implementation of post-quantum cryptography. The chapter discusses constant-time implementations of the respective primitive that systematically avoid data flow from secret inputs into branch conditions, memory addresses, and variable-time arithmetic instructions. Most post-quantum key-encapsulation mechanisms have in common that the core constructions only achieve chosen-plaintext attack (CPA) security, that is, they are only secure in the presence of a passive adversary that cannot perform chosen-ciphertext attacks (CCA). While in some cases, CPA security may be sufficient, many protocols do require CCA security.