Hydra: An energy-efficient programmable cryptographic coprocessor supporting elliptic-curve pairing over fields of large characteristics

Hydra: An energy-efficient programmable cryptographic coprocessor supporting elliptic-curve pairing over fields of large characteristics
复制标题

Hydra:一种节能可编程加密协处理器,支持大特征字段上的椭圆曲线配对

DOI:
10.1007/978-3-319-09843-2_14
复制
发表时间:
2014
期刊:
Advances in Information and Computer Security --- 9th International Workshop on Security, IWSEC 2014
影响因子:
--
通讯作者:
and C.-M. Cheng
and C.-M. Cheng
中科院分区:
--
文献类型:
--
作者:
Y.-A. Chang;W.-C. Hong;M.-C. Hsiao;B.-Y. Yang;A.-Y. Wu;and C.-M. Cheng

文献摘要

相似文献

椭圆曲线上的双线性对在密码学和密码分析中有着广泛的应用。与其他流行的公钥密码系统相比,配对计算更为复杂。因此,基于软件和硬件的加密配对方法的有效实现受到了越来越多的关注。在本文中,我们着重于硬件实现,并介绍了Hydra的设计,Hydra是一种节能的可编程密码协处理器,支持大特征字段上的各种配对。我们还提出了几种Hydra的实现,其中最小的Hydra在TSMC 90 nm标准胞库中合成时仅使用116个K门。尽管具有额外的可编程性,但我们的设计甚至与专门的实现相比,在时间-面积周期产品方面具有竞争力,时间-面积周期产品是一种常见的优点,可以很好地衡量能源效率。例如,当芯片工作在200 MHz时,仅需要3.04 ms来计算Barreto-Naehrig曲线上的最佳ate配对。在当前文献中所有加密配对的硬件实现中,这当然是一个非常小的时间-面积周期产品。
Bilinear pairings on elliptic curves have many applications in cryptography and cryptanalysis. Pairing computation is more complicated compared to that of other popular public-key cryptosystems. Efficient implementation of cryptographic pairing, both software- and hardware-based approaches, has thus received increasing interest. In this paper, we focus on hardware implementation and present the design of Hydra, an energy-efficient programmable cryptographic coprocessor that supports various pairings over fields of large characteristics. We also present several implementations of Hydra, among which the smallest only uses 116 K gates when synthesized in TSMC 90 nm standard cell library. Despite the extra programmability, our design is competitive compared even with specialized implementations in terms of time-area-cycle product, a common figure of merit that provides a good measure of energy efficiency. For example, it only takes 3.04 ms to compute an optimal ate pairing over Barreto-Naehrig curves when the chip operates at 200 MHz. This is certainly a very small time-area-cycle product among all hardware implementations of cryptographic pairing in the current literature.