IACR Transactions on Cryptographic Hardware and Embedded Systems · 2018 · 22 citations · 21 references
Cryptographic PrimitiveEngineeringInformation SecurityKyber VariantCryptographic TechnologyComputer ArchitectureCommunication ArchitectureHardware SecurityPublic Key AlgorithmParallel ComputingLong Integer MultiplicationComputer EngineeringLightweight CryptographyLattice-based CryptographyComputer ScienceCryptosystemData SecurityCryptographyCo-processorsDistributed ComputingParallel ProgrammingRsa Co-processor
We repurpose existing RSA/ECC co-processors for (ideal) lattice-based cryptography by exploiting the availability of fast long integer multiplication. Such co-processors are deployed in smart cards in passports and identity cards, secured microcontrollers and hardware security modules (HSM). In particular, we demonstrate an implementation of a variant of the Module-LWE-based Kyber Key Encapsulation Mechanism (KEM) that is tailored for high performance on a commercially available smart card chip (SLE 78). To benefit from the RSA/ECC co-processor we use Kronecker substitution in combination with schoolbook and Karatsuba polynomial multiplication. Moreover, we speed-up symmetric operations in our Kyber variant using the AES co-processor to implement a PRNG and a SHA-256 co-processor to realise hash functions. This allows us to execute CCA-secure Kyber768 key generation in 79.6 ms, encapsulation in 102.4 ms and decapsulation in 132.7 ms.
21
CRYSTALS - Kyber: A CCA-Secure Module-Lattice-Based KEM
Joppe W. Bos, Léo Ducas, Eike Kiltz et al. · 2018 · 920 citations · Full text
Hardware Security, Quantum Science, Quantum Cryptography +14
Classical hardness of learning with errors
Zvika Brakerski, Adeline Roux-Langlois, Chris Peikert et al. · 2013 · 584 citations