Abstract
The powerful computing capabilities of quantum computers and certain quantum computing-based algorithms pose significant threats to current cryptographic algorithms. Public key algorithms, such as RSA and ECC, will no longer be secure in the era of quantum computers. PQC and quantum encryption are two encryption technologies that have been developed to address the challenges posed by quantum computing. Compared to quantum encryption, PQC. still employs traditional encryption based on mathematical problems, making it more portable and cost-effective. In 2016, the NIST initiated the PQC standardization process. Following three rounds of competition, CRYSTALS-Kyber (Kyber), a lattice based cryptography scheme, became the only PKE/ KEM scheme selected for standardisation. The first PQC KEM scheme published by NIST in February 2024, the ML-KEM, is derived from Kyber with minor modifications.In evaluating the new PQC cryptographic candidate, NIST prioritised algorithmic security and performance over the three rounds of the process. As new algorithms are selected for standardisation, their performance will become more crucial, impacting their potential use in the future. Hardware design offers higher parallelism compared to software design, thereby offering higher speeds. In hardware design, improving algorithm execution speed, and hardware efficiency, and protecting implementations from physical attacks are key challenges.To address the hardware design challenges in implementating the complete Kyber or ML-KEM scheme, the goal of this thesis is to design high-speed and highly efficient Kyber hardware accelerators, in addition to evaluating potential bitstream attacks on the actual Kyber hardware design.Firstly, a fully pipelined high-speed Kyber accelerator is proposed. This accelerator utilizes a MDC-NTT module, with a compact NTT/ INTT design, and takes advantage of FIFOs to connect individual modules, to help match the throughput rates between different modules. The input-Keccak-output pipeline of the SHA3 module is explored. The pipeline between and within modules is explored to improve overall execution speed. The pipelined accelerator reduces reliance on data storage. The results show that the proposed architecture improves speed by 25-44% and hardware efficiency by 19-33% under three different security levels. Secondly, a NTT architecture employing a FIFO interleaved memory scheme is proposed. This architecture utilizes more customisable FIFO units instead of BRAM modules, greatly reducing hardware area while maintaining competitive speeds. Finally, bitstream fault injection attacks against FPGA implementations of ML-KEM are evaluated. Four initial attacks are proposed which include: disabling DSP, disabling BRAM, setting the ROM in the NTT to zero, and an attack against the CBD2 sampling. All four attacks can be applied in both the key generation and key encapsulation phases, with the CBD2 attack requiring the least number of manipulated bitstream bits. Additionally, a scheme for attacking the $Nonce$ counter is proposed, which requires only 32 bits of the bitstream to be modified, and additional DSP disabling to filter redundant LUT units. All attacks can be performed in the key generation and key encapsulation phase of a Kyber/ML-KEM architecture. Countermeasures to protect both the hard IP cores and LUT-based modules are presented, which include testing for zero values and splitting LUTs.
| Date of Award | Dec 2024 |
|---|---|
| Original language | English |
| Awarding Institution |
|
| Sponsors | Engineering and Physical Sciences Research Council |
| Supervisor | Maire O'Neill (Supervisor) & Ayesha Khalid (Supervisor) |
Keywords
- Post-quantum cryptography
- CRYSTALS- Kyber
- FPGA
- hardware security
- bitstream fault attack
- hardware architecture
Cite this
- Standard