发表机构
XLIM, CNRS UMR 7252, Université de Limoges(利摩日大学 XLIM 实验室)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
研究加比杜林码及其推广的恒时解码,提出AG码恒时解码算法,证明其二次复杂度,给出\(q\)多项式左除恒时算法,集成算法到RQC - Block - MS - AG方案,性能虽比HQC慢但密文和密钥大小更小。
AI 中文摘要
加比杜林码是里德 - 所罗门码的秩度量类似物。尽管这些码用于不同的高效基于秩的密码系统,如实数二次型密码系统(RQC)或洛德罗密码系统,但对于密码系统的实际开发而言,恒时实现至关重要,而此前加比杜林码尚无恒时实现。本文提出了增强加比杜林(AG)码的首个恒时解码算法,AG码是加比杜林码的简单变体,通过添加零列得到,涵盖了加比杜林码的情况。AG码用于RQC密码系统的最高效变体。证明了AG码解码可实现二次复杂度。还给出了\(q\)多项式左除的恒时算法及AG码解码过程的完整描述。这些算法集成到RQC - Block - MS - AG方案中,并通过基准测试评估实现性能。结果表明,实现优于原始RQC,虽比HQC慢约四倍,但密文和密钥大小约小四倍,凸显了性能与紧凑性之间的诱人权衡。
英文摘要
Gabidulin codes are a rank metric analog of Reed-Solomon codes. They are of great importance in rank-metric cryptography, as they are employed in highly efficient rank-based schemes, such as RQC and the Loidreau cryptosystem. However, until now, there has been no constant-time implementation of these codes, even though such an implementation is crucial for real-life development of cryptosystems. In this paper, we propose the first constant-time decoding algorithm of augmented Gabidulin (AG) codes, a simple variation of Gabidulin codes, in which columns of zeros are added to the end of a Gabidulin code. AG codes are used in the most efficient variants of the RQC cryptosystem. We prove that AG codes decoding can be achieved with quadratic complexity by reducing the decoding of an AG code to the decoding of a shorter standard Gabidulin code. In addition to the description of the complete AG codes decoding procedure, we present a constant-time algorithm for the left division of $q$-polynomials that can be used in every constant-time implementation of Gabidulin code variants. These algorithms are integrated into the RQC-Block-MS-AG scheme, and we evaluate the performance of our implementation through benchmarks. Our results show that our constant-time implementation outperforms the original RQC, though it remains approximately four to five times slower than HQC. However, it achieves ciphertext and key sizes about four times smaller, highlighting an appealing trade-off between performance and compactness.