Advanced Lattice Sieving on GPUs, with Tensor Cores
Advanced Lattice Sieving on GPUs, with Tensor Cores
复制标题
GPU 上的高级晶格筛选,具有张量核心
DOI:
--
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
W. V. Woerden
中科院分区:
文献类型:
--
作者:
L. Ducas;M.M.J. Stevens;W. V. Woerden
. In this work, we study GPU implementations of various state-of-the-art sieving algorithms for lattices (Becker-Gama-Joux 2015, Becker-Ducas-Gama-Laarhoven 2016, Herold-Kirshanova 2017) inside the General Sieve Kernel (G6K, Albrecht et al. 2019). In particular, we extensively exploit the recently introduced Tensor Cores – originally designed for raytracing and machine learning – and demonstrate their fit-ness for the cryptanalytic task at hand. We also propose a new dual-hash technique for efficient detection of ‘lift-worthy’ pairs to accelerate a key ingredient of G6K: finding short lifted vectors. We obtain new computational records, reaching dimension 180 for the SVP Darmstadt Challenge improving upon the previous record for di-mension 155. This computation ran for 51 . 6 days on a server with 4 NVIDIA Turing GPUs and 1 . 5TB of RAM. This corresponds to a gain of about two orders of magnitude over previous records both in terms of wall-clock time and of energy efficiency.