KORD:通过协议-硬件协同设计突破无经销商FSS的密钥生成瓶颈
KORD: Breaking the Key-Generation Bottleneck in Dealerless FSS via Protocol--Hardware Co-Design
浏览论文内容
中文总结 AI 辅助
KORD是协议-硬件协同设计方案,通过专用芯片的信任根将无经销商FSS的密钥生成交互压缩为单轮,大幅降低通信开销,提升吞吐量,在ResNet-18推理中显著减少密钥生成耗时占比。
中文摘要 AI 辅助
函数秘密共享(Function Secret Sharing, FSS)已成为隐私保护计算的核心原语。然而,每次FSS调用都需要由可信经销商生成一对新鲜的函数密钥,这扩大了系统的信任边界并阻碍了实际部署。现有的无经销商协议消除了对经销商的依赖,但会产生大量通信开销,且交互轮次随输入位宽线性增长,使得密钥生成成为主要瓶颈。本文提出KORD,一种协议-硬件协同设计方案,可大幅降低无经销商FSS密钥生成的成本。其核心是一对专用芯片,通过双向认证建立共同的信任根,并在该信任根内重构FSS密钥,从而无需经销商。该信任根进一步形成一个安全边界,KORD在该边界内重构生成协议,将现有无经销商协议的多轮交互压缩为单轮,且与GGM深度无关。交叉密钥调度方案随后交错执行独立的GGM树遍历,以维持高计算吞吐量。在涵盖多种FSS基础构件的综合测试中,KORD的单密钥生成通信开销较最先进的分布式FSS协议降低了7633至70274倍。布线后分析显示,采用21.5K LUT的情况下,在204 MHz频率下可实现每秒1275万个32位DPF密钥的生成,AES通道利用率达99.8%。在私有ResNet-18推理任务中,KORD将密钥生成在端到端时间中的占比从超过96%降至11.9%。
英文摘要
Function secret sharing (FSS) has become a core primitive in privacy-preserving computation. However, each FSS invocation requires a fresh pair of function keys generated by a trusted dealer , expands the system's trust boundary and hinders practical deployment. Existing dealerless protocols eliminate this dependency, but incur substantial communication and a number of interaction rounds that grows linearly with the input bit-width, making key generation a major bottleneck. This paper present KORD, a protocol--hardware co-design that dramatically reduces the cost of dealerless FSS key generation. At its core is a pair of special-purpose chips that establish a common root of trust through mutual attestation and, within it, reconstruct FSS keys---eliminating the need for a dealer. This root of trust further forms a security boundary within which KORD restructures the generation protocol, collapsing the interaction of prior dealerless protocols into a single round, independent of GGM depth. A cross-key scheduling scheme then interleaves independent GGM-tree traversals, sustaining high computational throughput. KORD reduces per-key-generation communication by 7,633--70,274$\times$ over the state-of-the-art distributed FSS protocol across a comprehensive suite of FSS building blocks. Post-route analysis projects 12.75 million 32-bit DPF keys per second at 204 MHz using 21.5K LUTs, with 99.8% AES lane utilization. On private ResNet-18 inference, KORD cuts the share of end-to-end time spent on key generation from over 96% to 11.9%.
发表机构
- College of Computer Science and Technology, National University of Defense Technology(国防科技大学计算机学院)
- Key Laboratory of Advanced Microprocessor Chips and Systems, National University of Defense Technology(国防科技大学先进微处理器芯片与系统重点实验室)
机构由 AI 辅助整理,请以论文原文为准。