Spent a couple of weekends optimizing hash-only key exchange, mostly inspired by the recurring, and fortunately so far unsuccessful, theories that lattice cryptography may be broken sooner than expected.
The result is a small but meaningful optimization over Merkle puzzles: exchanging a cryptographic key using ONLY hashes, with a better computation/bandwidth tradeoff than the classical construction.
It’s still not practical for real world key exchange, but it appears to push the state of the art a little further.
I’ll soon share a working implementation targeting parameter sets where an attacker would need roughly $100K–$1M of scalable compute, while the honest parties can still run the exchange on a regular laptop.
Thanks to
@SuiNetwork,
@WalrusProtocol,
@Mysten_Labs, community members, my wife and the external reviewers who helped challenge the idea.