First-Order Masked Kyber on ARM Cortex-M4

First-Order Masked Kyber on ARM Cortex-M4
复制标题

ARM Cortex-M4 上的一阶 Masked Kyber

DOI:
--
复制
发表时间:
2022
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
Amber Sprenkels
Amber Sprenkels
中科院分区:
--
文献类型:
--
作者:
Daniel Heinz;Matthias J. Kannwischer;G. Land;P. Schwabe;Amber Sprenkels

文献摘要

参考文献

被引文献

相似文献

。在这项工作中,我们提出了一种针对ARM Cortex-M4进行优化的快速一阶安全Kyber实现。最值得注意的是,据我们所知,这是第一个获得自由许可的开源Cortex-M4屏蔽Kyber实现。NIST正在进行的后量子密码学标准化进程和新提出的旁路攻击增加了对入围者的旁路分析和对策的需求。在常用的PQM4方案的基础上,我们利用已有的对Cortex-M4上Kyber的优化,并进一步结合了各种新近工作的不同思想,取得了比原实现更好的性能和更高的安全性。我们展示了一阶安全实施的性能结果。我们在ARM Cortex-M4上的屏蔽Kyber768解封只需要2 978 441个周期,包括从内部RNG生成随机性。然后,我们使用具有100,000个跟踪的t检验方法来实际验证我们的实现。
. In this work, we present a fast and first-order secure Kyber implementation optimized for ARM Cortex-M4. Most notably, to our knowledge this is the first liberally-licensed open-source Cortex-M4 implementation of masked Kyber. The ongoing NIST standardization process for post-quantum cryptography and newly proposed side-channel attacks have increased the demand for side-channel analysis and countermeasures for the finalists. On the foundation of the commonly used PQM4 project, we make use of the previously presented optimizations for Kyber on a Cortex-M4 and further combine different ideas from various recent works to achieve a better performance and improve the security in comparison to the original implementations. Weshowourperformance results for first-order secure implementations. Our masked Kyber768 decapsulation on the ARM Cortex-M4 requires only 2 978 441 cycles, including randomness generation from the internal RNG. We then practically verify our implementation by using the t-test methodology with 100 000 traces.
DOI: 10.13154/tches.v2018.i1.142-174
发表时间: 2018-02
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
Tobias Oder;Tobias Schneider;T. Pöppelmann;Tim Güneysu
通讯作者: Tobias Oder;Tobias Schneider;T. Pöppelmann;Tim Güneysu