RISC-V-Assisted Hardware Software Co-Design of Novel, Efficient and Power/Electro-Magnetic Side Channel Attack-Secure Post-Quantum Cryptographic CRYSTALS Kyber and Dilithium
Implementing Organization
Indian Institute of Science
Principal Investigator
Dr. Thockchom Birjit Singha
Indian Institute Of Science
birjits@iisc.ac.in
Project Overview
With the reality of quantum computers not far from sight, NIST had called for quantum-safe crypto protocols which finalized Kyber as the Key Encapsulation Mechanism (KEM), and Dilithium as the Digital Signature Algorithm (DSA). In addition to the threat from quantum computers being readily able to break the existing crypto protocols like RSA, ECC, etc., they also face the jeopardy of Side Channel Attacks (SCAs) which recover the secret key involved in the cryptographic operations. Keeping in view the aforementioned threats, the proposed work undertakes an efficient design of the Post-Quantum Cryptography (PQC) Cryptographic Suite for Algebraic Lattices (CRYSTALS), Kyber and Dilithium assisted with RISC-V, also ensuring their immunity towards EM and power SCAs. With the secret key shared and signature verified between the sending and receiving parties by virtue of the CRYSTALS, an AES accelerator is expected to emulate a real-life communication of information across the parties which is side-channel secure.
With Number Theoretic Transform (NTT), Inverse Number Theoretic Transform (INTT) and Keccak common between the two algorithms, also occupying ~65–70 % of area and power w.r.t. the total implementation of the respective algorithm, a novel unified architecture for NTT/INTT accelerator is to be designed which works for either Kyber or Dilithium depending upon choice. Similarly, a novel unified Keccak accelerator is targeted which invokes different Secure Hash Algorithm (SHA) and Secure Hash Algorithm Keccak (SHAKE) variants upon requirement. Apart from the accelerators, the rest of the Kyber and Dilithium operations are performed in RISC-V, thereby making it a hardware software co-design.
With regard to SCA prevention, a Ring Oscillator (RO)-based sensor system is to be fitted with each sensor module comprising of a detector RO and a noise RO. The former, running at a fixed design frequency, is expected to detect an incoming probe for malicious EM SCA due to the interference in the field lines of the RO. Upon detection, the noise RO is to be triggered to generate a high-frequency noise which will interfere with the field lines of the probe, eventually rendering it dysfunctional. Also, a countermeasure called TYLOR is utilized to resist power SCA, which uses a Time-to-Digital Converter (TDC) to sense voltage fluctuations from crypto operations and feeds this data to a Finite State Machine (FSM), which adjusts the number of active bleed elements to keep the overall current constant. Thus, the attacker sees a constant power profile of the crypto-core owing to which no critical information can be deduced about the secret key involved in the cryptographic operations. The aforementioned design descriptions are to be included in a single chip which is to be tested using Keysight's EM/Power SCA setup for the accurate functioning of the PQC protocols, and its resilience towards SCAs after developing a Correlational Power Analysis (CPA) attack model.
Disclaimer:
Information available on this portal is sourced from various organizations and is provided for informational purposes only. Users are advised to verify details from the respective official sources.
Please enter your details
Please provide your name and email to continue. Your details are saved in this browser for future use.
Latest Updates
Loading…
⚠️
You are leaving this website
You are about to be redirected to an external website that is not operated by
India Science, Technology & Innovation (ISTI) Portal.