Advanced Lattice Sieving on GPUs, with Tensor Cores

Advanced Lattice Sieving on GPUs, with Tensor Cores
复制标题

GPU 上的高级晶格筛选,具有张量核心

DOI:
--
复制
发表时间:
2021
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
W. V. Woerden
W. V. Woerden
中科院分区:
--
文献类型:
--
作者:
L. Ducas;M.M.J. Stevens;W. V. Woerden

文献摘要

被引文献

相似文献

. 在这项工作中,我们研究了通用筛核(G6K, Albrecht et al. 2019)内各种最先进的网格筛选算法的GPU实现(becker - gamma - joux 2015, becker - ducas - gamma - laarhoven 2016, Herold-Kirshanova 2017)。特别是,我们广泛利用最近推出的张量核心-最初是为光线追踪和机器学习设计的-并证明它们适合手头的密码分析任务。我们还提出了一种新的双哈希技术,用于有效检测“值得提升”的对,以加速G6K的一个关键要素:寻找短提升向量。我们获得了新的计算记录,在SVP达姆施塔特挑战中达到了180维,比之前155维的记录有所改善。这个计算运行了51。6天的服务器上有4个NVIDIA图灵gpu和1。5TB RAM。这相当于在时钟时间和能源效率方面比以前的记录增加了大约两个数量级。
. In this work, we study GPU implementations of various state-of-the-art sieving algorithms for lattices (Becker-Gama-Joux 2015, Becker-Ducas-Gama-Laarhoven 2016, Herold-Kirshanova 2017) inside the General Sieve Kernel (G6K, Albrecht et al. 2019). In particular, we extensively exploit the recently introduced Tensor Cores – originally designed for raytracing and machine learning – and demonstrate their fit-ness for the cryptanalytic task at hand. We also propose a new dual-hash technique for efficient detection of ‘lift-worthy’ pairs to accelerate a key ingredient of G6K: finding short lifted vectors. We obtain new computational records, reaching dimension 180 for the SVP Darmstadt Challenge improving upon the previous record for di-mension 155. This computation ran for 51 . 6 days on a server with 4 NVIDIA Turing GPUs and 1 . 5TB of RAM. This corresponds to a gain of about two orders of magnitude over previous records both in terms of wall-clock time and of energy efficiency.