Compact, Scalable, and Efficient Discrete Gaussian Samplers for Lattice-Based Cryptography

Compact, Scalable, and Efficient Discrete Gaussian Samplers for Lattice-Based Cryptography
复制标题

DOI:
10.1109/iscas.2018.8351009
复制
发表时间:
2018-05
期刊:
2018 IEEE International Symposium on Circuits and Systems (ISCAS)
影响因子:
--
通讯作者:
A. Khalid;James Howe;C. Rafferty;F. Regazzoni;Máire O’Neill
A. Khalid;James Howe;C. Rafferty;F. Regazzoni;Máire O’Neill
中科院分区:
其他
文献类型:
--
作者:
A. Khalid;James Howe;C. Rafferty;F. Regazzoni;Máire O’Neill

文献摘要

被引文献

相似文献

基于格的密码学是后量子安全的主要候选者之一,它严重依赖离散高斯采样器来提供必要的不确定性,从而混淆秘密信息的计算。对于可重新配置的硬件,累积分布表(CDT)方案先前已被证明可以实现最高的吞吐量和最小的资源利用率,轻松超越其他现有采样器。然而,CDT 采样器的扩展性不佳。事实上,对于大参数,所需的查找表太大而无法实际实现。这项研究提出了多个较小采样器的层次结构,扩展了高斯卷积引理来计算最佳参数,其中各个采样器需要更小的查找表。评估大量参数集,包括加密、签名和密钥交换。制定了硬件优化参数并在 Xilinx Artix-7 FPGA 器件上实现了实际实现。所提出的采样设计在可重构硬件上展示了良好的性能,即使对于大参数也是如此,否则这被认为是不可行的。
Lattice-based cryptography, one of the leading candidates for post-quantum security, relies heavily on discrete Gaussian samplers to provide necessary uncertainty, obfuscating computations on secret information. For reconfigurable hardware, the cumulative distribution table (CDT) scheme has previously been shown to achieve the highest throughput and the smallest resource utilisation, easily outperforming other existing samplers. However, the CDT sampler does not scale well. In fact, for large parameters, the lookup tables required are far too large to be practically implemented. This research proposes a hierarchy of multiple smaller samplers, extending the Gaussian convolution lemma to compute optimal parameters, where the individual samplers require much smaller lookup tables. A large range of parameter sets, covering encryption, signatures, and key exchange are evaluated. Hardware-optimised parameters are formulated and a practical implementation on Xilinx Artix-7 FPGA device is realised. The proposed sampling designs demonstrate promising performance on reconfigurable hardware, even for large parameters, that were otherwise thought infeasible.