Engineering Practical Rank-Code-Based Cryptographic Schemes on Embedded Hardware. A Case Study on ROLLO

Engineering Practical Rank-Code-Based Cryptographic Schemes on Embedded Hardware. A Case Study on ROLLO
复制标题

DOI:
10.1109/tc.2022.3225080
复制
发表时间:
2023-07
影响因子:
3.7
通讯作者:
Jingwei Hu;Wen Wang;K. Gaj;Liping Wang;Huaxiong Wang
Jingwei Hu;Wen Wang;K. Gaj;Liping Wang;Huaxiong Wang
中科院分区:
计算机科学2区
文献类型:
--
作者:
Jingwei Hu;Wen Wang;K. Gaj;Liping Wang;Huaxiong Wang

文献摘要

相似文献

在本文中,我们通过对基于LRPC代码的量子安全KEM方案(称为ROLLO)的案例研究,研究了FPGA平台上基于秩码的加密的实际性能,该方案是NIST后量子加密标准化第2轮候选方案之一。具体来说,我们提出了一个FPGA实现ROLLO KEM方案的封装和解封装操作,并对原始规范进行了一些修改。该设计是完全参数化的,使用代码生成脚本来支持ROLLO中指定的安全级别的广泛参数选择。在ROLLO硬件的核心,我们提出了一种通用的基于硬件的高斯消去方法,该方法可以处理非奇异和奇异矩阵。以往基于硬件的高斯消去算法只能处理非奇异高斯消去。然而,大量的密码系统,例如,基于秩-度量码的量子安全密钥封装机制,ROLLO和RQC,是NIST后量子密码标准化第2轮候选,需要对随机矩阵执行高斯消去,而不管奇点如何。据我们所知,这项工作是基于秩码的加密方案的第一个硬件实现。实验结果表明,基于秩码的方案是非常高效的。
In this paper, we investigate the practical performance of rank-code based cryptography on FPGA platforms by presenting a case study on the quantum-safe KEM scheme based on LRPC codes called ROLLO, which was among NIST post-quantum cryptography standardization round-2 candidates. Specifically, we present an FPGA implementation of the encapsulation and decapsulation operations of the ROLLO KEM scheme with some variations to the original specification. The design is fully parameterized, using code-generation scripts to support a wide range of parameter choices for security levels specified in ROLLO. At the core of the ROLLO hardware, we presented a generic approach for hardware-based Gaussian elimination, which can process both non-singular and singular matrices. Previous works on hardware-based Gaussian elimination can only process non-singular ones. However, a plethora of cryptosystems, for instance, quantum-safe key encapsulation mechanisms based on rank-metric codes, ROLLO and RQC, which are among NIST post-quantum cryptography standardization round-2 candidates, require performing Gaussian elimination for random matrices regardless of the singularity. To the best of our knowledge, this work is the first hardware implementation for rank-code-based cryptographic schemes. The experimental results suggest rank-code-based schemes can be highly efficient.