Implementing RLWE-based Schemes Using an RSA Co-Processor

Implementing RLWE-based Schemes Using an RSA Co-Processor
复制标题

DOI:
10.13154/tches.v2019.i1.169-208
复制
发表时间:
2018-11
期刊:
IACR Trans. Cryptogr. Hardw. Embed. Syst.
影响因子:
--
通讯作者:
Martin R. Albrecht;Christian H. Hanser;Andrea Höller;T. Pöppelmann;Fernando Virdia;Andreas Wallner
Martin R. Albrecht;Christian H. Hanser;Andrea Höller;T. Pöppelmann;Fernando Virdia;Andreas Wallner
中科院分区:
其他
文献类型:
--
作者:
Martin R. Albrecht;Christian H. Hanser;Andrea Höller;T. Pöppelmann;Fernando Virdia;Andreas Wallner

文献摘要

被引文献

相似文献

我们通过利用快速长整数乘法的可用性,将现有的RSA/ECC协处理器重新用于(理想的)基于格的加密。这种协处理器部署在护照和身份证中的智能卡、安全微控制器和硬件安全模块(HSM)中。特别地,我们展示了基于模块lwe的Kyber密钥封装机制(KEM)的一种变体的实现,该机制是为商用智能卡芯片(SLE 78)的高性能而量身定制的。为了从RSA/ECC协处理器中获益,我们将Kronecker替换与教科书和Karatsuba多项式乘法相结合。此外,我们使用AES协处理器来实现PRNG和SHA-256协处理器来实现哈希函数,从而加速Kyber变体中的对称操作。这允许我们在79.6 ms内执行cca安全的Kyber768密钥生成,在102.4 ms内封装,在132.7 ms内解封装。
We repurpose existing RSA/ECC co-processors for (ideal) lattice-based cryptography by exploiting the availability of fast long integer multiplication. Such co-processors are deployed in smart cards in passports and identity cards, secured microcontrollers and hardware security modules (HSM). In particular, we demonstrate an implementation of a variant of the Module-LWE-based Kyber Key Encapsulation Mechanism (KEM) that is tailored for high performance on a commercially available smart card chip (SLE 78). To benefit from the RSA/ECC co-processor we use Kronecker substitution in combination with schoolbook and Karatsuba polynomial multiplication. Moreover, we speed-up symmetric operations in our Kyber variant using the AES co-processor to implement a PRNG and a SHA-256 co-processor to realise hash functions. This allows us to execute CCA-secure Kyber768 key generation in 79.6 ms, encapsulation in 102.4 ms and decapsulation in 132.7 ms.