On Mon, Jan 06, 2025 at 05:18:35PM +1100, Viktor Dukhovni wrote:

> On Mon, Jan 06, 2025 at 09:57:42AM +0400, Loganaden Velvindron wrote:
> 
> > I went through v3 of the draft and I was wondering why we couldn't
> > have x448 as a "backup" choice in hybrid mode ?
> 
> FWIW, I have an implementation of X448MLKEM1024, just no code point,
> to associate it with.  Relative performance is not great, and (doing
> my best impersonation of David Benjamin) until there's a workable
> keyshare prediction specification, it would be very unlikey to get
> used.
> 
>                        keygen    encaps    decaps keygens/s  encaps/s  
> decaps/s
>      X25519MLKEM768 0.000053s 0.000070s 0.000056s   18821.2   14208.0   
> 17876.4
>      X448MLKEM1024  0.000221s 0.000334s 0.000171s    4534.7    2995.0    
> 5831.5

Sorry, the original cut/paste failed to fold the lines properly, the
above should be more readable.

-- 
    Viktor.

_______________________________________________
TLS mailing list -- tls@ietf.org
To unsubscribe send an email to tls-le...@ietf.org

Reply via email to