Faster elliptic-curve discrete logarithms on FPGAs
Faster elliptic-curve discrete logarithms on FPGAs
复制标题
FPGA 上更快的椭圆曲线离散对数
DOI:
--
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
Ralf Zimmermann
中科院分区:
文献类型:
--
作者:
D. Bernstein;Susanne Engels;T. Lange;R. Niederhagen;C. Paar;P. Schwabe;Ralf Zimmermann
This paper accelerates computations of discrete logarithms on elliptic curves over binary fields on FPGAs. As toy example, this paper successfully attacks the SECG standard curve sect113r2, a binary elliptic curve that was not removed from the SECG standard until 2010 and was not disabled in OpenSSL until June 2015. Furthermore, this paper successfully attacks a 117.35-bit ECDL on an elliptic curve over F2127 . This is a new size record for completed ECDL computations, using a prime order that is more than 40 times larger than the previous record holder. More importantly, this paper uses FPGAs much more efficiently, saving a factor close to 3/2 in the size of each high-speed ECDL core. This paper squeezes 3 cores into a low-cost Spartan-6 FPGA and many more cores into larger FPGAs. The paper Public domain. This work was supported by NSF (U.S.) under grant 1018836; by NWO (Netherlands) under grants 639.073.005, 613.001.011, and Veni 2013 project 13114; and by the European Commission through the ICT program under contracts INFSO-ICT-284833 (PUFFIN) and ICT-645421 ECRYPT-CSA. Permanent ID of this document: 01ac92080664fb3a778a430e028e55c8. Daniel J. Bernstein University of Illinois at Chicago, USA E-mail: djb@cr.yp.to Daniel J. Bernstein · Tanja Lange Eindhoven University of Technology, The Netherlands E-mail: tanja@hyperelliptic.org Ruben Niederhagen Fraunhofer Institute for Secure Information Technology, Germany? E-mail: ruben@polycephaly.org ?The work was done while the author was with Eindhoven University of Technology. Susanne Engels · Christof Paar · Ralf Zimmermann Ruhr-University Bochum, Germany E-mail: susanne.engels@rub.de E-mail: christof.paar@rub.de E-mail: ralf.zimmermann@rub.de Peter Schwabe Radboud University, The Netherlands E-mail: peter@cryptojedi.org also benchmarks many smaller-size attacks to demonstrate reliability of the estimates.