High-Speed Hardware Architectures and FPGA Benchmarking of CRYSTALS-Kyber, NTRU, and Saber

High-Speed Hardware Architectures and FPGA Benchmarking of CRYSTALS-Kyber, NTRU, and Saber
复制标题

DOI:
10.1109/tc.2022.3222954
复制
发表时间:
2023-02-01
影响因子:
3.7
通讯作者:
Gaj, Kris
Gaj, Kris
中科院分区:
计算机科学2区
文献类型:
--
作者:
Dang, Viet Ba;Mohajerani, Kamyar;Gaj, Kris

文献摘要

被引文献

相似文献

后量子密码术(PQC)是密码界对使用量子计算机执行攻击的危险的一种反应。所有的PQC方案都可以使用传统的(非量子)计算系统在软件和硬件中实现。自1970年中期S发明公钥方案以来,PQC是密码学中最大的革命。基于格的密钥交换方案因其相对较短的公钥和密文而成为NIST PQC标准化进程中的主要候选方案。本文提出了四种基于格的密钥封装机制(KEM)的新型高速硬件结构,它们代表了三个NIST PQC入围方案:NTRU(具有两个不同的变体,NTRU-HPS和NTRU-HRSS)、Crystal-Kyber和Saber。在当今的现场可编程门阵列中,我们根据这些候选者的性能和资源利用情况对其进行基准测试。根据算法和安全级别的不同,我们最好的架构在区域-时间乘积方面的表现优于迄今报道的其他组的最佳设计,其系数从1.01到2.88不等。此外,我们的研究表明,Crystal-Kyber和Saber的硬件性能非常相似。假设安全级别相同,两者在执行时间方面都比NTRU快36-62倍(密钥生成)和3-7倍(解封)。
Post-Quantum Cryptography (PQC) has emerged as a response of the cryptographic community to the danger of attacks performed using quantum computers. All PQC schemes can be implemented in software and hardware using conventional (non-quantum) computing systems. PQC is the biggest revolution in cryptography since the invention of public-key schemes in the mid-1970 s. Lattice-based key exchange schemes have emerged as leading candidates in the NIST PQC standardization process due to their relatively short public keys and ciphertexts. This paper presents novel high-speed hardware architectures for four lattice-based Key Encapsulation Mechanisms (KEMs) representing three NIST PQC finalists: NTRU (with two distinct variants, NTRU-HPS and NTRU-HRSS), CRYSTALS-Kyber, and Saber. We benchmark these candidates in terms of their performance and resource utilization in today's FPGAs. Our best architectures outperform the best designs from other groups reported to date in terms of the area-time product by factors ranging from 1.01 to 2.88, depending on the algorithm and security level. Additionally, our study demonstrates that CRYSTALS-Kyber and Saber have very similar hardware performance. Both outperform NTRU in terms of execution time by a factor 36-62 for key generation and 3-7 for decapsulation, assuming the same security level.