Fast Hardware Architectures for Supersingular Isogeny Diffie-Hellman Key Exchange on FPGA

Fast Hardware Architectures for Supersingular Isogeny Diffie-Hellman Key Exchange on FPGA
复制标题

FPGA 上超奇异同源 Diffie-Hellman 密钥交换的快速硬件架构

DOI:
10.1007/978-3-319-49890-4_11
复制
发表时间:
2016
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Mehran Mozaffari Kermani
Mehran Mozaffari Kermani
中科院分区:
--
文献类型:
--
作者:
Brian Koziel;R. Azarderakhsh;Mehran Mozaffari Kermani

文献摘要

被引文献

相似文献

在本文中,我们提出了一种恒定时间的硬件实现,即使与高度优化的Haswell计算机架构相比,也能实现超奇异等源Diffie-Hellman (SIDH)的新速度记录。我们在FPGA上采用了Costello等人在CRYPTO 2016上提出的无反转投影等同源公式。现代FPGA可以利用\(\mathbb {F}_{p^{2}}\)中高度并行化的算法,这是超奇异等构算法的基础。此外,通过使用许多算术单元,我们并行化同质性评估,将大程度同质性的计算速度提高了约57%. On a constant-time implementation of 124-bit quantum security SIDH on a Virtex-7, we generate ephemeral public keys in 10.6 and 11.6 ms and generate the shared secret key in 9.5 and 10.8 ms for Alice and Bob, respectively. This improves upon the previous best time in the literature for 768-bit implementations by a factor of 1.48. Our 83-bit quantum security implementation improves upon the only other implementation in the literature by a speedup of 1.74 featuring fewer resources and constant-time.
In this paper, we present a constant-time hardware implementation that achieves new speed records for the supersingular isogeny Diffie-Hellman (SIDH), even when compared to highly optimized Haswell computer architectures. We employ inversion-free projective isogeny formulas presented by Costello et al. at CRYPTO 2016 on an FPGA. Modern FPGA’s can take advantage of heavily parallelized arithmetic in \(\mathbb {F}_{p^{2}}\), which lies at the foundation of supersingular isogeny arithmetic. Further, by utilizing many arithmetic units, we parallelize isogeny evaluations to accelerate the computations of large-degree isogenies by approximately 57%. On a constant-time implementation of 124-bit quantum security SIDH on a Virtex-7, we generate ephemeral public keys in 10.6 and 11.6 ms and generate the shared secret key in 9.5 and 10.8 ms for Alice and Bob, respectively. This improves upon the previous best time in the literature for 768-bit implementations by a factor of 1.48. Our 83-bit quantum security implementation improves upon the only other implementation in the literature by a speedup of 1.74 featuring fewer resources and constant-time.