George Mason University
Efficient and Secure Hardware Architectures and Software/Hardware Co-designs for Post-Quantum Cryptography
Abstract
Public-key cryptography has enabled the use of separate keys in encryption and decryption. Consequently, no initial, secure exchange of a secret key between two communicating parties is required. Classical public-key cryptosystems rely on the presumed hardness of two closely related mathematical problems: integer factorization and computing discretelogarithms. It is believed that those two problems are computationally infeasible when attempted to be solved using any classical computers. However, the potential breakthrough in quantum computing in the next decade can render many current public-key cryptosystems (RSA, ECC, DSA, and Diffie-Hellman) obsolete. In contrast, the current symmetric key standard, AES, can be used securely with feasible increases in key size. As a result, new public key algorithms resistant to quantum attacks have emerged and have been referred to as Post-Quantum Cryptography (PQC). Lattice-based schemes form one of the five most promising families of PQC and have been well-studied since the first construction was proposed in 1996. Regarding implementational aspects, all PQC schemes should be capable of: 1) Being implemented using any traditional methods, including software and hardware; 2) running efficiently on any modern computing platforms: PCs, tablets, smartphones, servers with FPGA accelerators, etc.; 3) Being resistant to side-channel attacks. Performance in hardware has typically played a significant role in differentiating among leading candidates in cryptographic standardization efforts. Winners of two past NIST cryptographic contests (Rijndael in the case of AES and Keccak in the case of SHA-3) were ranked consistently among the two fastest candidates when implemented using FPGAs and ASICs. Hardware implementations of cryptographic operations may quite easily outperform software implementations for at least a subset of significant performance metrics, such as latency, number of operations per second, power consumption, and energy usage, as well as in terms of security against physical attacks, including side-channel analysis. This study aims to advance hardware architectures, efficient and secure implementations, and benchmarking of lattice-based schemes. At the early stages of the PQC standardization process, we employ a software/hardware co-design approach to evaluate multiple candidates. This approach paves the way to our next target of designing more optimized, high-speed full hardware implementations of a smaller set of algorithms in Round 3 of the standardization process. Our goal is to conduct a comprehensive and fair benchmarking of PQC cryptosystems focusing on hardware efficiency. All high-speed implementations are designed to be resistant to timing attacks. We also analyze the power-based attack countermeasures, focusing on compact hardware implementations with the best Time-Area trade-off. We further identify the cost of protecting PQC hardware implementations against side-channel attacks.
Author and committee
dc:creator, dc:contributor.*- Author
-
- Dang, Viet B
Subjects
dc:subject × 5Identifiers
dc:identifier.*- Identifier
- hdl:1920/14526
- OAI identifier oai:identifier
- oai:MARS:1920/14526