Where Star Wars Meets Star Trek: SABER and Dilithium on the Same Polynomial Multiplier

Where Star Wars Meets Star Trek: SABER and Dilithium on the Same Polynomial Multiplier
复制标题

《星球大战》与《星际迷航》的相遇:SABRE 和 Dilithium 具有相同的多项式乘数

DOI:
--
复制
发表时间:
2021
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
Santosh K. Ghosh
Santosh K. Ghosh
中科院分区:
--
文献类型:
--
作者:
Andrea Basso;Furkan Aydin;Daniel Dinu;Joseph Friel;Avinash L. Varna;Manoj R. Sastry;Santosh K. Ghosh

文献摘要

被引文献

相似文献

.安全通信通常需要加密和数字签名来保证消息的机密性和各方的真实性。然而,后量子密码协议通常是独立研究的。在这项工作中,我们确定了NIST标准化过程中两个finalist协议之间的强大协同作用。特别是,我们提出了一种技术,使SABER和Dilithium共享完全相同的多项式乘法器。由于多项式乘法在每个协议中起着关键作用,这对支持SABER和Dilithium的硬件实现有着重大影响。我们估计,现有的Dilithium实现可以增加对SABER的支持,而LUT计数仅增加4%。所提出的乘数的一个小的交易o缺点是,它可以产生不精确的结果与一些有限的输入。因此,我们对这种情况进行了彻底的分析,我们证明了这些事件发生的概率接近于零,并且我们表明这种特性不会影响实现的安全性。然后,我们在硬件中实现所提出的乘法器,以获得一个设计,具有竞争力的性能/面积权衡。在阿蒂克斯-7 FPGA上实现时,我们的NTT实现了519个周期的延迟,同时消耗了2012个LUT,并且仅消耗了331个IP-吞吐量。我们还提出了一种基于shu加密的方法,在多项式乘法期间以低开销提供侧信道保护。最后,我们评估的侧信道安全的Sakura-X FPGA板上提出的设计。
. Secure communication often require both encryption and digital signatures to guarantee the confidentiality of the message and the authenticity of the parties. However, post-quantum cryptographic protocols are often studied independently. In this work, we identify a powerful synergy between two finalist protocols in the NIST standardization process. In particular, we propose a technique that enables SABER and Dilithium to share the exact same polynomial multiplier. Since polynomial multiplication plays a key role in each protocol, this has a significant impact on hardware implementations that support both SABER and Dilithium. We estimate that existing Dilithium implementations can add support for SABER with only a 4% increase in LUT count. A minor trade-off of the proposed multiplier is that it can produce inexact results with some limited inputs. We thus carry out a thorough analysis of such cases, where we prove that the probability of these events occurring is near zero, and we show that this characteristic does not affect the security of the implementation. We then implement the proposed multiplier in hardware to obtain a design that offers competitive performance/area trade-offs. Our NTT implementation achieves a latency of 519 cycles while consuming 2 , 012 LUTs and only 331 flip-flops when implemented on an Artix-7 FPGA. We also propose a shuffling-based method to provide side-channel protection with low overhead during polynomial multiplication. Finally, we evaluate the side-channel security of the proposed design on a Sakura-X FPGA board.