The Cost to Break SIKE: A Comparative Hardware-Based Analysis with AES and SHA-3

被引:6
作者
Longa, Patrick [1 ]
Wang, Wen [2 ]
Szefer, Jakub [2 ]
机构
[1] Microsoft Res, Redmond, WA 98052 USA
[2] Yale Univ, New Haven, CT USA
来源
ADVANCES IN CRYPTOLOGY - CRYPTO 2021, PT III | 2021年 / 12827卷
关键词
Cost model; Cryptanalysis; SIKE; Efficient hardware and software implementations;
D O I
10.1007/978-3-030-84252-9_14
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This work presents a detailed study of the classical security of the post-quantum supersingular isogeny key encapsulation (SIKE) protocol using a realistic budget-based cost model that considers the actual computing and memory costs that are needed for cryptanalysis. In this effort, we design especially-tailored hardware accelerators for the time-critical multiplication and isogeny computations that we use to model an ASIC-powered instance of the van Oorschot-Wiener (vOW) parallel collision search algorithm. We then extend the analysis to AES and SHA-3 in the context of the NIST post-quantum cryptography standardization process to carry out a parameter analysis based on our cost model. This analysis, together with the state-of-the-art quantum security analysis of SIKE, indicates that the current SIKE parameters offer higher practical security than currently believed, closing an open issue on the suitability of the parameters to match NIST's security levels. In addition, we explore the possibility of using significantly smaller primes to enable more efficient and compact implementations with reduced bandwidth. Our improved cost model and analysis can be applied to other cryptographic settings and primitives, and can have implications for other post-quantum candidates in the NIST process.
引用
收藏
页码:402 / 431
页数:30
相关论文
empty
未找到相关数据