Hardware Noise Vectors for Post-Quantum Key Pair Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing lattice-based cryptographic methods face inefficiencies and vulnerabilities due to computationally expensive and susceptible noise vector generation processes, particularly in hardware and software platforms, which are prone to attacks and inefficient Gaussian sampling.
Innovation Solution
Directly obtain a noise vector from a hardware-implemented structure, such as a physical unclonable function (PUF), to generate a cryptographic key pair, ensuring a non-uniform distribution that enhances post-quantum security and resistance to attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Gaussian sampling is used to generate noise vectors for lattice-based cryptography, then the cryptographic security is maintained, but the computational cost increases and the system becomes susceptible to timing attacks
Solution Approach 1:
The patent extracts the noise vector generation process from traditional software-based Gaussian sampling and relocates it to a hardware-implemented structure. This hardware structure directly generates noise vectors with the required statistical properties, eliminating the need for computationally expensive Gaussian sampling algorithms while maintaining cryptographic security.
Solution Approach 2:
The patent replaces the software-based Gaussian sampling mechanism with a hardware-implemented structure. This substitution eliminates the computational overhead and timing attack vulnerabilities associated with software implementations, as hardware provides deterministic, constant-time operation with the required statistical properties.
2Adaptability or versatility
If software-based noise vector generation is used, then flexibility is maintained, but the system becomes prone to timing attacks and software vulnerabilities
Solution Approach 1:
The patent replaces software-based noise generation with a hardware-implemented structure. This substitution inherently protects against timing attacks because hardware operations execute in deterministic time, eliminating the timing variations that software-based approaches are susceptible to.
Solution Approach 2:
The patent introduces a hardware-implemented structure as an intermediary between the cryptographic algorithm and the noise vector generation process. This hardware intermediary provides a secure, attack-resistant interface that generates noise vectors with the required statistical properties without exposing the system to software-based vulnerabilities.
3Ease of manufacture
If uniform distribution is used for noise vectors, then implementation is simpler, but the cryptographic hardness of the LWE problem is reduced
Solution Approach 1:
The patent changes the distribution parameter of the noise vectors from uniform to a non-uniform distribution (such as discrete Gaussian or binomial distribution). This parameter change is achieved through the hardware-implemented structure, which directly generates samples from the required distribution without requiring complex software-based sampling algorithms, thus maintaining both cryptographic hardness and implementation simplicity.
Data Source
Figure 1~3
Figure 4~5
Figure 6
AI summary
The invention relates to a computer-implemented method for obtaining a cryptographic key pair (8,9) for use in a cryptographic method, the method comprising: randomly generating (S1) a private key (5, 8) of the cryptographic key pair (8,9); operating (S2) a hardware-implemented structure (4) using a randomly generated challenge (6) to obtain, in particular directly, a noise vector (7) from the hardware-implemented structure (4); and calculating (S3) a public key (9) of the cryptographic key pair (8,9) from the generated random private key (5, 8) using the noise vector (7) obtained from the hardware-implemented structure (4). The method advantageously offers a low-overhead, lightweight and hardened way of obtaining noise vectors 7 for use in calculating a public key of a PQ-secure cryptographic keypair. Also contemplated is a corresponding computing device and computer program product.