AI 中文总结
研究提出用于后量子密码学的紧凑RISC-V扩展HORCRUX,通过针对多种算法共享内核引入新指令,优化用于嵌入式系统。实验表明其在FPGA上有显著加速,增加资源少,还给出ASIC结果,模块化结构保持向后兼容性,为受限嵌入式系统部署PQC提供方案。
AI 中文摘要
本文提出了一种用于后量子密码学(PQC)的紧凑RISC-V扩展HORCRUX,它提供了支持所有NIST批准的PQC算法的统一指令集扩展(ISE)。HORCRUX解决了受限环境中密码敏捷性、高性能和低资源消耗之间的艰难权衡,这在专注于有限PQC子集的硬件扩展中通常缺失。通过针对ML-KEM、MLDSA、SLH-DSA、HQC和Falcon中的共享内核,该扩展引入了由资源高效、紧密耦合的协处理器执行的新RISC-V指令。该架构针对具有严格能量预算和有限面积的嵌入式系统进行了优化。在Zynq UltraScale+ FPGA上的实验评估表明,基于哈希的方案加速高达129倍,基于格的方案加速9倍,基于代码的方案加速27倍,同时增加的查找表(LUT)少于21k,触发器(FF)少于4.4k。还报告了65纳米CMOS中综合后表征的ASIC结果以及严格的功耗表征,以验证该架构的能源效率。该扩展的模块化结构保持了与标准RISC-V内核的向后兼容性,为在受限嵌入式系统上部署PQC提供了可扩展的解决方案。
英文摘要
This work presents a compact RISC-V extension for Post-Quantum Cryptography (PQC) called HORCRUX, which provides a unified Instruction-Set Extension (ISE) supporting all NIST-approved PQC algorithms. HORCRUX addresses the difficult trade-off between crypto-agility, high performance, and low resource consumption in constrained environments, a balance typically missing in hardware extensions that focus on limited PQC subsets. By targeting shared kernels across ML-KEM, MLDSA, SLH-DSA, HQC, and Falcon, the extension introduces new RISC-V instructions executed by a resource-efficient, tightly coupled coprocessor. This architecture is specifically optimized for embedded systems with strict energy budgets and limited area. Experimental evaluation on a Zynq UltraScale+ FPGA demonstrates speedups of up to 129x for hash-based, 9x for lattice-based, and 27x for code-based schemes, while adding fewer than 21k LUTs and 4.4k FFs. ASIC results from postsynthesis characterization in 65 nm CMOS are also reported, alongside a rigorous power characterization to validate the architecture's energy efficiency. The extension's modular structure maintains backward compatibility with standard RISC-V cores, offering a scalable solution for deploying PQC on constrained embedded systems.
Comments15 pages, 8 tables, 3 figures