Skip to main content
QUICK REVIEW

[论文解读] Envisioning the Future of Cyber Security in Post-Quantum Era: A Survey on PQ Standardization, Applications, Challenges and Opportunities

Saleh Darzi, Kasra Ahmadi|arXiv (Cornell University)|Oct 18, 2023
Cryptographic Implementations and Security被引用 7
一句话总结

本文对后量子密码学(PQC)进行了全面综述,分析了NIST标准化及入围的PQC方案,涵盖基于格、基于哈希、基于编码、基于同源性以及多变量密码学等类别。评估了安全性、性能、侧信道抗性及标准化指标,结论指出由于物联网、区块链和机器学习等不同领域间需求相互冲突,应用特定的PQC设计至关重要。

ABSTRACT

The rise of quantum computers exposes vulnerabilities in current public key cryptographic protocols, necessitating the development of secure post-quantum (PQ) schemes. Hence, we conduct a comprehensive study on various PQ approaches, covering the constructional design, structural vulnerabilities, and offer security assessments, implementation evaluations, and a particular focus on side-channel attacks. We analyze global standardization processes, evaluate their metrics in relation to real-world applications, and primarily focus on standardized PQ schemes, selected additional signature competition candidates, and PQ-secure cutting-edge schemes beyond standardization. Finally, we present visions and potential future directions for a seamless transition to the PQ era.

研究动机与目标

  • 分析后量子密码学(PQC)标准化的现状,重点关注NIST的选择流程与评估指标。
  • 评估标准化及入围PQC方案的安全性、性能及侧信道脆弱性。
  • 识别将遗留系统(如智能电网、物联网、区块链)迁移到PQC所面临的挑战与需求。
  • 探索在机器学习、区块链及嵌入式系统等领域的应用特定PQC需求。
  • 预测面向密码敏捷性与向后量子时代安全迁移的未来研究方向。

提出的方法

  • 对NIST PQC入围方案及选定的替代方案进行了系统性分析,评估其数学基础与构造设计。
  • 通过硬问题的正式分析(如学习误差问题、基于编码的问题、SIKE)评估安全性,包括对量子攻击的抵抗能力。
  • 通过性能基准测试与侧信道防护措施的集成,评估实现效率与侧信道漏洞。
  • 将评估指标(如密钥大小、签名大小、运行时间)映射到物联网、区块链及机器学习等实际应用场景的约束条件。
  • 提出一种面向应用特定PQC采纳的框架,强调密码敏捷性与早期迁移,以减轻SNDL威胁。
  • 探索非传统PQC方法,如Raccoon——一种受Dilithium启发、具备侧信道抗性的基于格的签名方案。
Figure 1. The time required for encapsulation, decapsulation, and key generation for Lattice based schemes on NIST’s $4^{th}$ round KEMs. The figure on the left corresponds to ARM platforms, while the figure on the right pertains to Intel platforms.
Figure 1. The time required for encapsulation, decapsulation, and key generation for Lattice based schemes on NIST’s $4^{th}$ round KEMs. The figure on the left corresponds to ARM platforms, while the figure on the right pertains to Intel platforms.

实验结果

研究问题

  • RQ1NIST标准化的PQC方案在安全性、性能及侧信道抗性方面存在哪些关键差异?
  • RQ2物联网、区块链及机器学习系统中的应用特定需求(如尺寸、速度、隐私)如何与通用PQC标准产生冲突?
  • RQ3在设计阶段而非实现后补丁的方式中,侧信道抗性能在多大程度上被集成到PQC方案中?
  • RQ4存储现在、稍后解密(SNDL)攻击对长期数据机密性有何影响,以及向PQC迁移的紧迫性如何?
  • RQ5是否存在一种单一标准化的PQC方案可满足所有实际应用场景,还是应用特定PQC开发不可避免?

主要发现

  • NIST的标准化流程已选定基于格的方案(如Kyber,密钥封装机制)和Dilithium(签名)作为主要候选方案,因其在安全性和效率之间实现了良好平衡。
  • 侧信道攻击仍是PQC实现中的关键威胁,从设计之初就具备侧信道抗性的方案(如Raccoon)相比后期加固的现有方案展现出更高的效率。
  • 存储现在、稍后解密(SNDL)攻击对长期数据机密性构成严重风险,即使在大规模量子计算机出现之前,也亟需向PQC迁移。
  • 没有单一PQC方案能满足所有应用需求:物联网侧重低成本与低功耗,区块链要求紧凑签名,而机器学习则需要强隐私保护原 primitive。
  • 通用PQC的标准化是必要但不充分的;标准化之后,专门的PQC竞赛与应用特定方案很可能会陆续出现。
  • 密码敏捷性——即快速迁移到新密码系统的能力——至关重要,应优先考虑,以确保后量子时代系统的长期韧性。
Figure 2. The time required for signing, verifying, and key generation for Lattice based schemes on NIST’s $4^{th}$ round signatures. The figure on the left corresponds to ARM platforms, while the figure on the right pertains to Intel platforms.
Figure 2. The time required for signing, verifying, and key generation for Lattice based schemes on NIST’s $4^{th}$ round signatures. The figure on the left corresponds to ARM platforms, while the figure on the right pertains to Intel platforms.

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。