Verified NTT Multiplications for NISTPQC KEM Lattice Finalists: Kyber, SABER, and NTRU

Verified NTT Multiplications for NISTPQC KEM Lattice Finalists: Kyber, SABER, and NTRU
复制标题

NISTPQC KEM Lattice 决赛入围者的 NTT 乘法验证:Kyber、SABRE 和 NTRU

DOI:
10.46586/tches.v2022.i4.718-750
复制
发表时间:
2022
期刊:
IACR Trans. Cryptogr. Hardw. Embed. Syst.
影响因子:
--
通讯作者:
Bo
Bo
中科院分区:
--
文献类型:
--
作者:
Vincent Hwang;Jiaxiang Liu;Gregor Seiler;Xiaomu Shi;M. Tsai;Bow;Bo

文献摘要

相似文献

后量子密码学需要一组不同于传统公钥密码学(如椭圆曲线)的算术例程。特别是,在每一个基于网格的NISTPQC密钥建立决赛中,仍然在NISTPQC第3轮中的基于网格的方案的每一个最先进的优化实现目前都使用基于数论变换的不同复数乘法。我们使用CryptoLine工具验证了NTRU、Kyber和SABER中使用的基于NTT的乘法,用于英特尔CPU的AVX2实现和ARM Cortex M4的pqm4实现。e扩展的CryptoLine,并因此能够验证,在六个实例乘法是正确的,包括范围properties.We证明了可行性的程序员验证他或她的高速汇编代码的PQC,以及验证别人的高速PQC软件的汇编代码,与程序员的一些合作。
Postquantum cryptography requires a different set of arithmetic routines from traditional public-key cryptography such as elliptic curves. In particular, in each of the lattice-based NISTPQC Key Establishment finalists, every state-ofthe-art optimized implementation for lattice-based schemes still in the NISTPQC round 3 currently uses a different complex multiplication based on the Number Theoretic Transform. We verify the NTT-based multiplications used in NTRU, Kyber, and SABER for both the AVX2 implementation for Intel CPUs and for the pqm4 implementation for the ARM Cortex M4 using the tool CryptoLine. e extended CryptoLine and as a result are able to verify that in six instances multiplications are correct including range properties.We demonstrate the feasibility for a programmer to verify his or her high-speed assembly code for PQC, as well as to verify someone else’s high-speed PQC software in assembly code, with some cooperation from the programmer.