Implementation and Benchmarking of Round 2 Candidates in the NIST Post-Quantum Cryptography Standardization Process Using Hardware and Software/Hardware Co-design Approaches

Implementation and Benchmarking of Round 2 Candidates in the NIST Post-Quantum Cryptography Standardization Process Using Hardware and Software/Hardware Co-design Approaches
复制标题

DOI:
--
复制
发表时间:
2020
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
V. Dang;Farnoud Farahmand;Michal Andrzejczak;Kamyar Mohajerani;D. Nguyen;K. Gaj
V. Dang;Farnoud Farahmand;Michal Andrzejczak;Kamyar Mohajerani;D. Nguyen;K. Gaj
中科院分区:
其他
文献类型:
--
作者:
V. Dang;Farnoud Farahmand;Michal Andrzejczak;Kamyar Mohajerani;D. Nguyen;K. Gaj

文献摘要

被引文献

相似文献

硬件中的性能通常在分化加密标准化工作中的领先候选人方面发挥了重要作用。在使用FPGA和ASICS实施时,两次过去的NIST密码竞赛的获胜者(在AES和Keccak的情况下,Rijndael在AES和Keccak的情况下)一直在两个快速的候选人中排名。加密操作的硬件实现可能很容易超过至少一部分主要性能指标的软件实现,例如速度,功耗和能源使用情况,以及针对物理攻击的安全性,包括侧通道分析。使用硬件还允许更高的灵活性将这些属性的一个子集交换为另一种属性。在标准化过程的早期阶段,大量候选人使准确且公平的比较非常具有挑战性。然而,在过去的所有主要密码标准化工作中,在评估过程的早期就确定了未来的获胜者,并保持领先优势,直到选择标准为止。此外,将一些候选人确定为固有的缓慢或昂贵的硬件有助于消除一部分候选人,从而节省了无数小时的密码分析。最后,早期实施为未来的设计空间探索提供了基准,为在给定的加密竞争的后期阶段铺平了一种方法,以更全面,更公平的基准测试。在本文中,我们首先总结,比较和分析其他小组报告的结果,直到2020年3月中旬,即直到NIST PQC过程的第2轮结束。然后,我们概述了使用硬件和软件/硬件共同设计方法实现和基准对PQC候选者实施和基准测试的方法。我们将硬件方法应用于6个基于晶格的CCA-Sec-Sec-Secure键封装机制(KEMS),代表4个NIST PQC提交。然后,我们将软件硬件共同设计方法应用于12个基于晶格的CCA-Secure KEMS,代表了第2轮第2轮提交。我们希望,与其他小组报告的结果相结合,我们的研究将为NIST提供有关第2轮PQC候选人的相对性能的有用信息,假设至少他们的主要操作以及整个算法, - 加载到硬件。
Performance in hardware has typically played a major role in differentiating among leading candidates in cryptographic standardization efforts. Winners of two past NIST cryptographic contests (Rijndael in case of AES and Keccak in case of SHA-3) were ranked consistently among the two fastest candidates when implemented using FPGAs and ASICs. Hardware implementations of cryptographic operations may quite easily outperform software implementations for at least a subset of major performance metrics, such as speed, power consumption, and energy usage, as well as in terms of security against physical attacks, including side-channel analysis. Using hardware also permits much higher flexibility in trading one subset of these properties for another. A large number of candidates at the early stages of the standardization process makes the accurate and fair comparison very challenging. Nevertheless, in all major past cryptographic standardization efforts, future winners were identified quite early in the evaluation process and held their lead until the standard was selected. Additionally, identifying some candidates as either inherently slow or costly in hardware helped to eliminate a subset of candidates, saving countless hours of cryptanalysis. Finally, early implementations provided a baseline for future design space explorations, paving a way to more comprehensive and fairer benchmarking at the later stages of a given cryptographic competition. In this paper, we first summarize, compare, and analyze results reported by other groups until mid-May 2020, i.e., until the end of Round 2 of the NIST PQC process. We then outline our own methodology for implementing and benchmarking PQC candidates using both hardware and software/hardware co-design approaches. We apply our hardware approach to 6 lattice-based CCA-secure Key Encapsulation Mechanisms (KEMs), representing 4 NIST PQC submissions. We then apply a software-hardware co-design approach to 12 lattice-based CCA-secure KEMs, representing 8 Round 2 submissions. We hope that, combined with results reported by other groups, our study will provide NIST with helpful information regarding the relative performance of a significant subset of Round 2 PQC candidates, assuming that at least their major operations, and possibly the entire algorithms, are off-loaded to hardware.