MIKE debuts as compact isogeny-based post-quantum NIKE
The scheme offers 80-byte level-I public keys and millisecond-scale operations, with constant-time C and Rust code.
Researchers have released MIKE (Module Isogeny Key Exchange), an isogeny-based non-interactive key exchange aimed at post-quantum cryptography, with constant-time C and Rust implementations plus a higher-level SageMath version.
Announcing the first public release on the NIST PQC forum, Damien Robert described MIKE as the smallest PQC NIKE the team is aware of. At NIST level I, public keys are 80 bytes, smaller than CSIDH-family variants. On an AMD Ryzen 7 PRO 7840U at 3.3 GHz with turbo and multithreading off, key generation takes about 0.65 ms and shared-secret derivation about 4.9 ms for the faster parameter set. That is more than two orders of magnitude quicker than earlier isogeny NIKEs and within roughly a factor of two of SWOOSH’s passively secure variant.
Structurally MIKE resembles SIKE: both key generation and secret derivation compute a single isogeny. It uses smaller parameters and discloses far less about secret keys, which the authors say blocks the class of attacks that broke SIKE. Passive security reduces to the supersingular isogeny problem in the Algebraic Isogeny Model. A recent advance against that problem (Wesolowski, 2026) forced larger parameters than an earlier sketch; because the attack’s concrete cost is still unsettled, the release ships both conservative and more aggressive parameter sets.
Despite heavy underlying math, the reference SageMath code is about 1,000 lines. John Preuß Mattsson called the work still research but among the more promising PQC developments in years, arguing schemes such as MIKE and SQIsign could enable lightweight post-quantum primitives an order of magnitude smaller than ML-KEM and ML-DSA, and that the SIKE break advanced understanding rather than ending isogeny cryptography.