Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-0 vector-toc-not-available vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-0 skin-theme-clientpref-day vector-sticky-header-enabled" lang="de" dir="ltr"><head>
<meta charset="UTF-8">
<title>Post-Quanten-Kryptographie</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="icon" type="image/png" href="./_res_/favicon.png">
<link rel="canonical" href="https://de.wikipedia.org/wiki/Post-Quanten-Kryptographie"> <link href="./_mw_/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.wikimediamessages.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link href="./_mw_/ext.gadget.citeRef.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.defaultPlainlinks.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiCommonHide.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiCommonLayout.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiCommonStyle.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiDarkmode.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiResponsive.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.specialSearch.css" rel="stylesheet" type="text/css">
<link rel="stylesheet" type="text/css" href="./_mw_/site.styles.css">
<link rel="stylesheet" type="text/css" href="./_mw_/noscript.css">
<link rel="stylesheet" type="text/css" href="./_res_/footer.css">
<link rel="stylesheet" type="text/css" href="./_res_/vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Post-Quanten-Kryptographie rootpage-Post-Quanten-Kryptographie skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading"><span class="mw-page-title-main">Post-Quanten-Kryptographie</span></h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="contentSub">
<div id="mw-content-subtitle"></div>
</div>
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="de" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="de" dir="ltr"><p><b>Post-Quanten-Kryptographie</b> (<span style="font-style:normal;font-weight:normal"><a href="Englische_Sprache" title="Englische Sprache">englisch</a></span> <span lang="en-Latn" style="font-style:italic">post-quantum cryptography</span>, <b>PQC</b>) bezeichnet ein Teilgebiet der <a href="Kryptographie" title="Kryptographie">Kryptographie</a>, das sich mit <a href="Kryptographisches_Primitiv" title="Kryptographisches Primitiv">kryptographischen Primitiven</a> befasst, die im Gegensatz zu den meisten aktuell verwendeten <a href="Asymmetrisches_Kryptosystem" title="Asymmetrisches Kryptosystem">asymmetrischen Kryptosystemen</a> selbst unter Verwendung von <a href="Quantencomputer" title="Quantencomputer">Quantencomputern</a> praktisch nicht zu <a href="Entzifferung#Entzifferung_in_der_Kryptologie" title="Entzifferung">entziffern</a> sind.
Der Begriff <i>post-quantum cryptography</i> wurde von <a href="Daniel_J._Bernstein" title="Daniel J. Bernstein">Daniel J. Bernstein</a> eingeführt,<sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> der auch 2006 an der Organisation der ersten Fachkonferenz PQCrypto zu diesem Thema beteiligt war.<sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p>

<div class="mw-heading mw-heading2"><h2 id="Asymmetrische_Verfahren">Asymmetrische Verfahren</h2></div>
<p>Der Begriff wurde geprägt, da die ersten asymmetrischen Kryptosysteme auf der Schwierigkeit der <a href="Primfaktorzerlegung" title="Primfaktorzerlegung">Primfaktorzerlegung</a> und der Berechnung <a href="Diskreter_Logarithmus" title="Diskreter Logarithmus">diskreter Logarithmen</a> beruhten, zwei Probleme, die theoretisch –&nbsp;bei ausreichend leistungsstarken Quantencomputern&nbsp;– durch den <a href="Shor-Algorithmus" title="Shor-Algorithmus">Shor-Algorithmus</a> zu lösen sind.<sup id="cite_ref-djb-intro_3-0" class="reference"><a href="#cite_note-djb-intro-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
</p><p>Die Leistungsfähigkeit bisheriger Quantencomputer ist für derartige Berechnungen bei weitem nicht ausreichend und ein wissenschaftlicher Durchbruch oder Meilenstein kaum vorhersagbar; 2001 war <a href="IBM" title="IBM">IBM</a> lediglich in der Lage, die Zahl 15 zu <a href="Faktorisierung" title="Faktorisierung">faktorisieren</a>,<sup id="cite_ref-tp_4-0" class="reference"><a href="#cite_note-tp-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> 2012 gelang die Faktorisierung der Zahl 21.<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Symmetrische_Verfahren">Symmetrische Verfahren</h2></div>
<p>Für <a href="Symmetrisches_Kryptosystem" title="Symmetrisches Kryptosystem">symmetrische Verschlüsselungsverfahren</a> wie beispielsweise <a href="Advanced_Encryption_Standard" title="Advanced Encryption Standard">AES</a> sind Quantencomputer eine relativ kleine Bedrohung, da hier mittels des <a href="Grover-Algorithmus" title="Grover-Algorithmus">Grover-Algorithmus</a> die in Bit gemessene Sicherheit eines Schlüssels um die Hälfte reduziert würde. Der gestiegenen Rechenleistung ließe sich mit entsprechend längeren Schlüsseln entgegenwirken.<sup id="cite_ref-tp_4-1" class="reference"><a href="#cite_note-tp-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Zukunft">Zukunft</h2></div>
<p>Aussichtsreich scheint die Entwicklung von PQ-sicheren Verschlüsselungsalgorithmen auf Basis mathematischer <a href="Gitter_(Mathematik)" title="Gitter (Mathematik)">Gitter</a>, die beispielsweise bei Ring-LWE oder beim bis 2021 patentierten <a href="NTRUEncrypt" title="NTRUEncrypt">NTRUEncrypt</a> als Grundlage verwendet werden.<sup id="cite_ref-tp_4-2" class="reference"><a href="#cite_note-tp-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup>
Darüber hinaus gibt es Forschung<sup id="cite_ref-ieee-jintai-ding_6-0" class="reference"><a href="#cite_note-ieee-jintai-ding-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> auf Basis von
</p>
<ul><li><a href="Multivariates_Polynom" class="mw-redirect" title="Multivariates Polynom">multivariaten Polynomen</a>, beispielsweise das Unbalanced-Oil-and-Vinegar-Verfahren</li>
<li><a href="Kryptologische_Hashfunktion" class="mw-redirect" title="Kryptologische Hashfunktion">kryptologischen Hashfunktionen</a>, beispielsweise das <a href="Merkle-Signatur" title="Merkle-Signatur">Merkle-Signaturverfahren</a> oder das <a href="Lamport-Einmal-Signaturverfahren" title="Lamport-Einmal-Signaturverfahren">Lamport-Einmal-Signaturverfahren</a></li>
<li><a href="Vorw%C3%A4rtsfehlerkorrektur" title="Vorwärtsfehlerkorrektur">fehlerkorrigierenden Codes</a>, beispielsweise das <a href="McEliece-Kryptosystem" title="McEliece-Kryptosystem">McEliece-Kryptosystem</a></li>
<li>supersingulären elliptischen Kurven, beispielsweise SIKE</li>
<li>gitterbasierter Kryptografie, beispielsweise CRYSTALS DILITHIUM</li></ul>
<p>Ein weiteres Forschungsgebiet ist die Anpassung kryptographischer Beweistechniken an Quantenangreifer. Beispielsweise benutzt der Sicherheitsbeweis eines klassischen <a href="Zero-Knowledge-Beweis" class="mw-redirect" title="Zero-Knowledge-Beweis">Zero-Knowledge-Beweisverfahrens</a> eine Technik namens <i>Rewinding</i>, bei der der interne Zustand des Angreifers kopiert wird. Der Zustand eines Quantenangreifers kann nach dem <a href="No-Cloning-Theorem" title="No-Cloning-Theorem">No-Cloning-Theorem</a> aber nicht immer kopiert werden, die Beweistechnik muss entsprechend angepasst werden.<sup id="cite_ref-watrous09qzk_7-0" class="reference"><a href="#cite_note-watrous09qzk-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p><p>Seit 2016 läuft beim US <a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">National Institute of Standards and Technology</a> (NIST) ein <a href="Post-Quanten-Kryptographie-Standardisierung_des_NIST" title="Post-Quanten-Kryptographie-Standardisierung des NIST">Standardisierungsprozess</a>, um jeweils einen Algorithmus für Schlüsselaustausch/Verschlüsselung und Digitale Signaturen zu testen und zu standardisieren. Im Juli 2022 entschied das NIST, dass für allgemeine Verschlüsselungen die gitterbasierte <a href="CRYSTALS-Kyber" class="mw-redirect" title="CRYSTALS-Kyber">CRYSTALS-Kyber</a> Technologie verwendet werden wird und für digitale Signaturen die Algorithmen CRYSTALS-Dilithium<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup>, FALCON<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> und <i>SPHINCS+</i><sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Weblinks">Weblinks</h2></div>
<ul><li><a rel="nofollow" class="external text" href="https://www.pqcrypto.org/">PQCrypto</a> – Post-Quantum-Kryptographie Konferenz</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Einzelnachweise">Einzelnachweise</h2></div>
<ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><a href="#cite_ref-1">↑</a></span> <span class="reference-text">Johannes Buchmann, Carlos Coronado, Martin Döring, Daniela Engelbert, Christoph Ludwig, Raphael Overbeck, Arthur Schmidt, Ulrich Vollmer, Ralf-Philipp Weinmann: <cite style="font-style:italic">Post-Quantum Signatures</cite>. 2004, Abschnitt 1 Introduction, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em">&nbsp;</span>1</span> (<a rel="nofollow" class="external text" href="http://eprint.iacr.org/2004/297.pdf">iacr.org</a> [PDF]).<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abookitem&amp;rfr_id=info:sid/de.wikipedia.org:Post-Quanten-Kryptographie&amp;rft.atitle=Abschnitt+1+Introduction&amp;rft.au=Johannes+Buchmann%2C+Carlos+Coronado%2C+Martin+D%C3%B6ring%2C+...&amp;rft.btitle=Post-Quantum+Signatures&amp;rft.date=2004&amp;rft.genre=bookitem&amp;rft.pages=1" style="display:none">&nbsp;</span></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><a href="#cite_ref-2">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="http://postquantum.cr.yp.to/">Homepage der PQCrypto 2006</a></span>
</li>
<li id="cite_note-djb-intro-3"><span class="mw-cite-backlink"><a href="#cite_ref-djb-intro_3-0">↑</a></span> <span class="reference-text"><a href="Daniel_J._Bernstein" title="Daniel J. Bernstein">Daniel J. Bernstein</a>: <cite class="lang" lang="en" dir="auto" style="font-style:italic">Introduction to post-quantum cryptography</cite>. 2009 (englisch, <a rel="nofollow" class="external text" href="http://www.pqcrypto.org/www.springer.com/cda/content/document/cda_downloaddocument/9783540887010-c1.pdf">springer.com/cda</a> [PDF] Einführungskapitel des Buchs <i>Post-quantum cryptography</i>).<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&amp;rfr_id=info:sid/de.wikipedia.org:Post-Quanten-Kryptographie&amp;rft.au=Daniel+J.+Bernstein&amp;rft.btitle=Introduction+to+post-quantum+cryptography&amp;rft.date=2009&amp;rft.genre=book" style="display:none">&nbsp;</span></span>
</li>
<li id="cite_note-tp-4"><span class="mw-cite-backlink">↑ <sup><a href="#cite_ref-tp_4-0">a</a></sup> <sup><a href="#cite_ref-tp_4-1">b</a></sup> <sup><a href="#cite_ref-tp_4-2">c</a></sup></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://www.heise.de/tp/features/Kryptographie-nach-dem-Quantencomputer-3396243.html"><i>Kryptographie nach dem Quantencomputer.</i></a> In: <i><a href="Telepolis" title="Telepolis">Telepolis</a>.</i> Abgerufen am 18. September 2013.</span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><a href="#cite_ref-5">↑</a></span> <span class="reference-text">Enrique Martín-López, Anthony Laing, Thomas Lawson, Roberto Alvarez, Xiao-Qi Zhou, Jeremy L. O’Brien: <cite style="font-style:italic">Experimental realization of Shor’s quantum factoring algorithm using qubit recycling</cite> (=&nbsp;<cite style="font-style:italic">Nature Photonics</cite>. <span style="white-space:nowrap">Band<span style="display:inline-block;width:.2em">&nbsp;</span>6</span>). 2012, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em">&nbsp;</span>773–776</span> (<a rel="nofollow" class="external text" href="http://www.nature.com/nphoton/journal/v6/n11/full/nphoton.2012.259.html">nature.com</a>).<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&amp;rfr_id=info:sid/de.wikipedia.org:Post-Quanten-Kryptographie&amp;rft.au=Enrique+Mart%C3%ADn-L%C3%B3pez%2C+Anthony+Laing%2C+Thomas+Lawson%2C+...&amp;rft.btitle=Experimental+realization+of+Shor%E2%80%99s+quantum+factoring+algorithm+using+qubit+recycling&amp;rft.date=2012&amp;rft.genre=book&amp;rft.pages=773-776&amp;rft.series=Nature+Photonics" style="display:none">&nbsp;</span></span>
</li>
<li id="cite_note-ieee-jintai-ding-6"><span class="mw-cite-backlink"><a href="#cite_ref-ieee-jintai-ding_6-0">↑</a></span> <span class="reference-text"> <a rel="nofollow" class="external text" href="http://spectrum.ieee.org/computing/networks/qa-with-postquantum-computing-cryptography-researcher-jintai-ding"><cite>Q&amp;A With Post-Quantum Computing Cryptography Researcher Jintai Ding</cite></a>, <a href="Institute_of_Electrical_and_Electronics_Engineers" title="Institute of Electrical and Electronics Engineers">IEEE Spectrum</a>, 1.&nbsp;November 2008 (englisch).<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rft.type=newspaperArticle&amp;rft.subject=News&amp;rft.title=Q%26A+With+Post-Quantum+Computing+Cryptography+Researcher+Jintai+Ding&amp;rft.identifier=http%3A%2F%2Fspectrum.ieee.org%2Fcomputing%2Fnetworks%2Fqa-with-postquantum-computing-cryptography-researcher-jintai-ding&amp;rft.publisher=%5B%5BInstitute+of+Electrical+and+Electronics+Engineers%7CIEEE+Spectrum%5D%5D&amp;rft.date=2008-11-01&amp;rft.language=en">&nbsp;</span></span>
</li>
<li id="cite_note-watrous09qzk-7"><span class="mw-cite-backlink"><a href="#cite_ref-watrous09qzk_7-0">↑</a></span> <span class="reference-text">John Watrous: <cite style="font-style:italic">Zero-Knowledge against Quantum Attacks</cite>. In: <cite style="font-style:italic">SIAM J. Comput.</cite> 39. Jahrgang, <span style="white-space:nowrap">Nr.<span style="display:inline-block;width:.2em">&nbsp;</span>1</span>, 2009, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em">&nbsp;</span>25–58</span>, <a href="Digital_Object_Identifier" title="Digital Object Identifier">doi</a>:<span class="uri-handle" style="white-space:nowrap"><a rel="nofollow" class="external text" href="https://doi.org/10.1137/060670997">10.1137/060670997</a></span>.<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&amp;rfr_id=info:sid/de.wikipedia.org:Post-Quanten-Kryptographie&amp;rft.atitle=Zero-Knowledge+against+Quantum+Attacks&amp;rft.au=John+Watrous&amp;rft.date=2009&amp;rft.doi=10.1137%2F060670997&amp;rft.genre=journal&amp;rft.issue=1&amp;rft.jtitle=SIAM+J.+Comput.&amp;rft.pages=25-58&amp;rft.volume=39.+Jahrgang" style="display:none">&nbsp;</span></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><a href="#cite_ref-8">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://pq-crystals.org/dilithium/index.shtml">CRYSTALS-Dilithium</a></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><a href="#cite_ref-9">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://falcon-sign.info/">FALCON</a></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><a href="#cite_ref-10">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://sphincs.org/">SPHINCS+</a>.</span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><a href="#cite_ref-11">↑</a></span> <span class="reference-text"><cite style="font-style:italic">NIST Announces First Four Quantum-Resistant Cryptographic Algorithms</cite>. In: <cite style="font-style:italic">NIST</cite>. 5.&nbsp;Juli 2022 (<a rel="nofollow" class="external text" href="https://www.nist.gov/news-events/news/2022/07/nist-announces-first-four-quantum-resistant-cryptographic-algorithms">nist.gov</a> [abgerufen am 25.&nbsp;Juli 2022]).<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&amp;rfr_id=info:sid/de.wikipedia.org:Post-Quanten-Kryptographie&amp;rft.atitle=NIST+Announces+First+Four+Quantum-Resistant+Cryptographic+Algorithms&amp;rft.btitle=NIST&amp;rft.date=2022-07-05&amp;rft.genre=book" style="display:none">&nbsp;</span></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><a href="#cite_ref-12">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://hgi.rub.de/news/newsarchiv/hgi/zukunftssichere-datenverschluesselung">Zukunftssichere Datenverschlüsselung</a>, Horst Görtz Institut, Ruhr-Universität Bochum, 5. Juli 2022</span>
</li>
</ol></div><!--htdig_noindex--><div><div class="zim-footer">
Dieser Artikel wurde von <a class="external text" title="Zuletzt bearbeitet am 2024-06-07" href="https://de.wikipedia.org/wiki/?title=Post-Quanten-Kryptographie&amp;oldid=245706089">Wikipedia</a> herausgegeben. Der Text ist unter <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.de">Creative Commons Attribution-Share Alike 4.0</a> verfügbar, sofern nicht anders angegeben. Für die Mediendateien können zusätzliche Bedingungen gelten.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
<script src="./_webp_/webpHandler.js"></script>

</body></html>