Sökning: WFRF:(Li Sirui)
> (2022) >
A Hierarchical Para...
A Hierarchical Parallel Discrete Gaussian Sampler for Lattice-Based Cryptography
-
- Shen, Sirui (författare)
- Nanjing Univ, Sch Elect Sci & Engn, Nanjing, Peoples R China.
-
- Song, Wenqing (författare)
- Nanjing Univ, Sch Elect Sci & Engn, Nanjing, Peoples R China.
-
- Wang, Xinyu (författare)
- Nanjing Univ, Sch Elect Sci & Engn, Nanjing, Peoples R China.
-
visa fler...
-
- Shao, Xinyu (författare)
- Nanjing Univ, Dept Math, Nanjing, Peoples R China.
-
- Fu, Yuxiang (författare)
- Nanjing Univ, Sch Elect Sci & Engn, Nanjing, Peoples R China.
-
- Lu, Zhonghai (författare)
- KTH,Elektronik och inbyggda system
-
- Li, Li (författare)
- Nanjing Univ, Sch Elect Sci & Engn, Nanjing, Peoples R China.
-
visa färre...
-
Nanjing Univ, Sch Elect Sci & Engn, Nanjing, Peoples R China Nanjing Univ, Dept Math, Nanjing, Peoples R China. (creator_code:org_t)
- Institute of Electrical and Electronics Engineers (IEEE), 2022
- 2022
- Engelska.
-
Ingår i: 2022 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS (ISCAS 22). - : Institute of Electrical and Electronics Engineers (IEEE). ; , s. 1729-1733
- Relaterad länk:
-
https://urn.kb.se/re...
-
visa fler...
-
https://doi.org/10.1...
-
visa färre...
Abstract
Ämnesord
Stäng
- Discrete Gaussian sampling is one of the important components in lattice-based cryptosystems which are promising candidates for post-quantum cryptographic algorithms. For sufficient security and satisfactory performance, the Knuth-Yao algorithm is an efficient way to implement discrete Gaussian samplers. Nevertheless, most polynomials in lattice-based cryptography have 256 coefficients or more, which suffers from long latency to complete the sample generation. In this paper, the first parallel discrete Gaussian sampler with hierarchical structure is proposed, while keeping statistical distance to the actual distribution. Based on the imbalanced visiting frequency of the probability matrix, a three-stage generation strategy is adopted with hierarchical bit search units (BSUs) that can greatly reduce area consumption of the repeated costly lookup tables. Besides the architecture improvement, a lowest-set-bit scanning scheme is introduced to BSUs. Moreover, the parallelism of our design provides obfuscation ability against side-channel attacks (SCAs). A practical hardware implementation of discrete Gaussian distributions with sigma = 3.33 on the Xilinx Virtex-5 XC5VLX30 FPGA device spends 26.12 ns on average to generate 256 samples, consuming 994 slices. Results have verified its advantages of area efficiency over the state-of-the-arts (SOAs).
Ämnesord
- NATURVETENSKAP -- Matematik -- Sannolikhetsteori och statistik (hsv//swe)
- NATURAL SCIENCES -- Mathematics -- Probability Theory and Statistics (hsv//eng)
Nyckelord
- Lattice-based cryptography
- discrete Gaussian sampler
- Knuth-Yao algorithm
- FPGA implementation
Publikations- och innehållstyp
- ref (ämneskategori)
- kon (ämneskategori)