首页> 外文会议>2019 56th ACM/IEEE Design Automation Conference >Pushing the speed limit of constant-time discrete Gaussian sampling. A case study on the Falcon signature scheme.
【24h】

Pushing the speed limit of constant-time discrete Gaussian sampling. A case study on the Falcon signature scheme.

机译:推动恒定时间离散高斯采样的速度极限。猎鹰签名方案的案例研究。

获取原文
获取原文并翻译 | 示例

摘要

Sampling from a discrete Gaussian distribution has applications in lattice-based post-quantum cryptography. Several efficient solutions have been proposed in recent years. However, making a Gaussian sampler secure against timing attacks turned out to be a challenging research problem. In this work, we present a toolchain to instantiate an efficient constant-time discrete Gaussian sampler of arbitrary standard deviation and precision. We observe an interesting property of the mapping from input random bit strings to samples during a Knuth-Yao sampling algorithm and propose an efficient way of minimizing the Boolean expressions for the mapping. Our minimization approach results in up to 37% faster discrete Gaussian sampling compared to the previous work. Finally, we apply our optimized and secure Gaussian sampler in the lattice-based digital signature algorithm Falcon, which is a NIST submission, and provide experimental evidence that the overall performance of the signing algorithm degrades by at most 33% only due to the additional overhead of ‘constant-time’ sampling, including the 60% overhead of random number generation. Breaking a general belief, our results indirectly show that the use of discrete Gaussian samples in digital signature algorithms would be beneficial.CCS CONCEPTS• Security and privacy $ightarrow$ Side-channel analysis and counter-measures; Digital signatures; Hardware attacks and countermeasures; Cryptography.
机译:来自离散高斯分布的采样已在基于晶格的后量子密码学中得到了应用。近年来已经提出了几种有效的解决方案。然而,使高斯采样器免受定时攻击的影响被证明是一个具有挑战性的研究问题。在这项工作中,我们提出了一个工具链,用于实例化具有任意标准偏差和精度的高效恒定时间离散高斯采样器。我们在Knuth-Yao采样算法期间观察到了从输入随机位串到采样的映射的有趣特性,并提出了一种最小化映射布尔表达式的有效方法。与以前的工作相比,我们的最小化方法可使离散高斯采样速度提高多达37%。最后,我们将优化和安全的高斯采样器应用于基于NIST的基于格的数字签名算法Falcon中,并提供实验证据表明,仅由于额外的开销,签名算法的整体性能最多降低33% “恒定时间”采样,包括60%的随机数生成开销。打破普遍的信念,我们的结果间接表明,在数字签名算法中使用离散的高斯样本将是有益的。CCS概念•安全和隐私权\\ arrowarrow边信道分析和对策;数字签名;硬件攻击和对策;密码学。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号