简介: |
ABSTRACT Post-Quantum Cryptography (PQC) refers to a new class of cryptographic algorithms that are resistant against all known attacks using quantum computers, but at the same time can be implemented by themselves using traditional computing platforms, such as smartphones, tablets, laptops, and hardware accelerators based on integrated circuits. PQC is a cryptographic community's response to the emerging threat of full-scale quantum computers, expected to be developed within the next decade or two. The main goal of PQC is to replace the existing public-key cryptography standards, protecting the majority of the Internet traffic, such as RSA and Elliptic Curve Cryptography (ECC). The PQC standardization process, launched by the American National Institute of Standards and Technology in 2016, has recently reached Round 2, with 26 candidates remaining. These candidates represent five major PQC families: code-based, isogeny-based, lattice-based, multivariate, and symmetric-based, and can be used to implement encryption, digital signature, and key exchange schemes of the future. To date, the assessment of candidates has focused primarily on their security and general-purpose microprocessor efficiency. The goal of this talk is to set the foundation for the early, systematic, and comprehensive study of the hardware and embedded system efficiency of the most promising PQC candidates, through the employment of novel methodologies, such as Software/Hardware Codesign and High-Level Synthesis. With this groundwork, we believe that the development time for full hardware and software/hardware implementations can be significantly reduced, allowing fair and comprehensive benchmarking of the most promising candidates, and a fair choice of the most efficient and flexible algorithms as the future American and de facto worldwide PQC cryptographic standards. The next 5–10 years are very likely to bring the biggest revolution in cryptography since the invention of public-key cryptography in the mid-1970s. The proposed comprehensive benchmarking effort will give all involved researchers a unique opportunity to influence the choice of future cryptographic standards, which are likely to be developed and deployed within the next decade and remain in use for the significant portion (if not the rest) of the 21st century. BIO Kris Gaj is a professor in the ECE Department at George Mason University, U.S.A., located near Washington D.C. He is a co-director of the Cryptographic Engineering Research Group (CERG), involved in the majority of previous and current cryptographic competitions, from AES to PQC. In particular, his team has led hardware evaluation of candidates for the new hash function standard, SHA-3 in 2010-2012, and for the new authenticated cipher portfolio, CAESAR, in 2016-2019. His current research and teaching interests include cryptographic engineering and hardware security, with the special focus on the development of new hardware architectures and embedded system implementations for post-quantum public-key cryptosystems, lightweight cryptography, and codebreaking, as well as benchmarking of cryptographic hardware and embedded systems, high-level synthesis, software/hardware codesign, and side-channel analysis.
|