课题基金 / 基金详情

Development of Tamper-resistant Post-Quantum Cryptographic Hardware

Development of Tamper-resistant Post-Quantum Cryptographic Hardware
防篡改后量子密码硬件的开发
批准号:
19K24336
负责人:
YLIMAEYRY VILLE
金额:
$1.83万
依托单位:
依托单位国家:
日本
项目类别:
Grant-in-Aid for Research Activity Start-up
财政年份:
2019
资助国家:
日本
项目状态:
已结题
起止时间:
2019-08-30 至 2021-03-31

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
在本财政年度,我们对Saber后量子密码(PQC)密钥交换算法进行了以下两个方面的研究。硬件实现我们在多个模型中实现了散列函数SHA-256和Shake-128,包括资源高效的完全流水线实现,以及部分展开的低延迟实现。设计了计算模块同时执行的调度机制,使得密钥交换的硬件实现能够实现算法的多步骤并行化。旁路安全评估我们考虑了(A)利用被攻击设备发出的电磁辐射对PQC算法的乘法模块进行传统的旁路攻击(B)提出了一种新的旁路攻击,该攻击可以利用展开的分组密码和散列函数中的路径激活偏差,例如用于SABER(C)对PQC的故障注入攻击的SHA-256,该攻击故意在被攻击的设备处理PQC密钥交换时导致错误计算。我们相信(A)的研究在其他著作中得到了广泛的考察,因此我们没有进行详细的探讨。然而,使用(B),我们演示了一种可能被利用来揭示散列算法的秘密输入的新型旁路泄漏。此外,使用(C),我们发现攻击者可以通过向设备中使用的时钟信号注入错误来跳过一些计算来泄露关于密钥交换的秘密信息。
英文摘要
During this fiscal year, we carried out research into the SABER post-quantum cryptographic (PQC) key exchange algorithm in the the following 2 areas.1. Hardware implementationWe implemented hashing functions SHA-256 and SHAKE-128 in multiple models, including the resource effective fully pipelined implementation, and the partially unrolled, low latency implementation. We designed the scheduling of simultaneous execution of computation modules which allows the hardware implementation of the key exchange to parallelize several steps of the algorithm.2. Side-channel security evaluationWe considered (A) traditional side-channel attacks on multiplication modules of PQC algorithms using electro-magnetic radiation emanating from the attacked device (B) a new side-channel attack we proposed which can exploit path activation biases in unrolled block ciphers and hashing functions, such as SHA-256 used in SABER (C) fault injection attacks on PQC, which intentionally produce erroneous computation in the attacked device processing the PQC key exchange. We believe the research of (A) is widely examined in other works, so we did not pursue it in detail. However, using (B), we demonstrated a new type of side-channel leakage that might be exploited to reveal secret inputs of the hashing algorithms. Further, using (C), we found that an attacker may reveal secret information about the key exchange by injecting faults into the clock signal used in the device to skip some computation.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1109/tifs.2020.3033441
发表时间: 2021-01-01
期刊: IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY
影响因子: 6.8
作者: [Yli-Mayry, Ville, Ueno, Rei, Homma, Naofumi]
通讯作者: Homma, Naofumi
海外基金