Ergo and post-quantum crypto?

What are the barriers to implementing a Picnic scheme on Ergo?

Most important papers are here: https://microsoft.github.io/Picnic/

The primitives are simple and the hardness assumptions are more reasonable than many lattice-based imo.

Any thoughts, @kushti / @scalahub ?

5 Likes