Saw that paper as well. Previously I would've said SIDH looks great (comparatively small key sizes, support for D-H-style key exchange as opposed to key transport) aside from its performance, so it's great to see progress on the performance front.
Some interesting performance comparisons of a Peikert KEX scheme (Ring-LWE key exchange scheme, a.k.a. "NewHope") vs the SIDH improvements: https://twitter.com/durumcrustulum/status/725805655408431104 -- Tony Arcieri
_______________________________________________ Curves mailing list Curves@moderncrypto.org https://moderncrypto.org/mailman/listinfo/curves