Post-Quantum and Lattice-Based Cryptography Questions

Cryptography designed to resist quantum attacks: lattice-based schemes, the underlying hard problems (LWE, SIS), and the mathematics of post-quantum standards. Covers why current public-key schemes are vulnerable to quantum algorithms and how migration candidates work. A specialized, forward-looking cryptography area.

HardTechnical
73 practiced

Given an NTRU parameter set: N = 701, q = 8192, and private polynomials with Hamming weight approximately d = 72, estimate the rough classical and quantum security level. Identify the attack vectors that are most relevant here, discuss any decryption failure concerns, and explain the trade-offs if q or d are changed.

EasyTechnical
72 practiced

Explain the McEliece code-based public-key encryption scheme at a high level. Describe the use of an error-correcting code (commonly binary Goppa codes), what constitutes the public and private keys, and how encryption and decryption operate via syndrome generation and decoding. Finally, list the main strengths and weaknesses of McEliece-style schemes.

HardSystem Design
56 practiced

Design an on-chain post-quantum signature scheme for a public blockchain where verification gas (computation) and signature size are constrained, every full node verifies transactions frequently, and signatures must be long-term secure. Choose a family (hash-based, lattice, multivariate, code-based) and justify your selection in terms of verification cost, signature size, propagation bandwidth, and upgradeability. Consider multisig and light client use-cases.

MediumTechnical
68 practiced

Explain what a security reduction is in cryptography and why reductions matter for post-quantum schemes. Distinguish between tight and non-tight reductions, and discuss practical implications for parameter selection, confidence in a scheme, and how reductions interact with random-oracle versus standard-model proofs.

MediumTechnical
73 practiced

Propose parameter choices for a McEliece-style code-based scheme aiming for approximately 128-bit classical security. Discuss choices for code length n, dimension k, error-correcting capability t, and code family (e.g., binary Goppa). Justify your choices against the complexity of ISD algorithms and discuss resulting public key sizes and performance trade-offs.

Unlock Full Question Bank

Get access to all 34 Post-Quantum and Lattice-Based Cryptography interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.