Post-Quantum Forward-Secure Signatures with Hardware-Support for Internet of Things

Post-Quantum Forward-Secure Signatures with Hardware-Support for Internet of Things
复制标题

DOI:
10.1109/icc45041.2023.10279236
复制
发表时间:
2023-05
期刊:
ICC 2023 - IEEE International Conference on Communications
影响因子:
--
通讯作者:
Saif E. Nouma;Attila A. Yavuz
Saif E. Nouma;Attila A. Yavuz
中科院分区:
其他
文献类型:
--
作者:
Saif E. Nouma;Attila A. Yavuz

文献摘要

被引文献

相似文献

数字签名提供具有不可否认性的可扩展身份验证,因此是物联网(IoT)的重要工具。物联网应用包含大量低端设备,预计这些设备将长期运行,存在受损风险。因此,物联网需要后量子加密(PQC),它尊重低端设备的资源限制,同时提供折衷的弹性(例如前向安全)。然而,正如NIST PQC努力所见,量子安全签名对于低端物联网来说极其昂贵。当考虑到前向安全时,这些成本变得令人望而却步。我们提出了一种高度轻量级的后量子数字签名,称为硬件支持的高效签名(HASES),它满足资源有限的签名者(处理器、内存、带宽)的严格要求,并具有前向安全性。HASES通过安全包围域引入公钥预言,将密钥演化的一次性散列签名转化为多项式无界签名。签名者是非交互的,每个签名只生成几个哈希。与现有的硬件支持的替代方案不同,HASES不需要在签名者上安装安全硬件,这对于低端物联网是不可行的。HASES也不假定允许可扩展验证的非合谋服务器。我们证明了HASES是安全的,并在商用硬件和8位AVR ATmega2560微控制器上实现了它。我们的实验证实,HASES比(前向安全的)XMSS和(普通)Dilithium快271倍和34倍。在8位设备上,HASES的能效分别比(前向安全的)ANT和(普通的)BLISS高两倍多。我们开源HASES用于公开测试和适配。
Digital signatures provide scalable authentication with non-repudiation and therefore are vital tools for the Internet of Things (IoT). IoT applications harbor vast quantities of low-end devices that are expected to operate for long periods with a risk of compromise. Hence, IoT needs post-quantum cryptography (PQC) that respects the resource limitations of low-end devices while offering compromise resiliency (e.g., forward-security). However, as seen in NIST PQC efforts, quantum-safe signatures are extremely costly for low-end IoT. These costs become prohibitive when forward security is considered. We propose a highly lightweight post-quantum digital signature called HArdware-Supported Efficient Signature (HASES) that meets the stringent requirements of resource-limited signers (processor, memory, bandwidth) with forward security. HASES transforms a key-evolving one-time hash-based signature into a polynomially unbounded one by introducing a public key oracle via secure enclaves. The signer is non-interactive and only generates a few hashes per signature. Unlike existing hardware-supported alternatives, HASES does not require a secure-hardware on the signer, which is infeasible for low-end IoT. HASES also does not assume non-colluding servers that permit scalable verification. We proved that HASES is secure and implemented it on the commodity hardware and the 8-bit AVR ATmega2560 microcontroller. Our experiments confirm that HASES is $271\times\ \mathbf{and}\ 34\times$ faster than (forward-secure) XMSS and (plain) Dilithium. HASES is more than twice and magnitude more energy-efficient than (forward-secure) ANT and (plain) BLISS, respectively, on an 8-bit device. We open-source HASES for public testing and adaptation.