MIKE

a fast and compact post-quantum NIKE


MIKE (Module Isogeny Key-Exchange) is a fast and compact post-quantum non-interactive key exchange, based on isogeny assumptions (like the SQIsign signature). MIKE boasts the smallest public (and secret) keys amongst a large range of post-quantum KEMs.

Performance

We provide two conservative parameter sets: rigorous and fast.[1]

Pure C implementation using assembly-optimised finite-field arithmetic; includes no AVX. Implementation is constant time and includes supersingularity verification of public keys. Benchmarked on AMD Ryzen 7 PRO 7840U @ 3.3GHz with turboboost and multithreading disabled. Results rounded to three figures of precision.
NIST
Level
Public Key
(B)
Secret Key
(B)
Key Gen
(ms)
Shared Key
(ms)
Fast I 80 29 0.651 4.86
III 122 43 2.11 15.0
V 160 57 4.16 28.6
Rigorous I 96 47 1.49 10.5
III 144 71 4.55 31.3
V 192 95 11.2 69.9

Resources

Implementations

Team

Listed alphabetically.

Funding

Contact

mike@inria.fr

Notes

  1. The fast variant makes more aggressive (but still ultimately conservative) parameter choices for both the underlying field characteristic and secret key length. However, picking shorter secret keys results in a distribution of public keys that is far from uniform: to make the proof work, we make the fairly mild assumption that the "fast" public keys are indistinguishable from random. We emphasise that breaking this assumption does not give a (direct) attack on MIKE.