发表机构
Lucid Motors; EYL Inc.(Lucid Motors; EYL公司)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究采用AI辅助设计后量子密码加速器,通过字节级黄金参考预言机与随机对抗性浸泡测试填补标准检测的漏洞,在Kintex-7芯片上实现高占用率部署,验证了AI生成后量子密码硬件的可靠性。
AI 中文摘要
后量子迁移需按既定时间表推进,而已流片的芯片若存在缺陷则无法远程修补。标准验收检测无法检测出整个类别的ML-DSA缺陷。签名过程会持续重采样直至候选值满足其范数边界,因此执行路径会随消息变化,而已知答案测试(KAT)仅采样固定值,仅能达到其种子触发的深度。我们的加速器通过了完整的KAT回归测试,但所采用的范数检查速度快于块RAM延迟,导致每个候选值的最终系数未经验证;该缺陷在拒绝循环第5次迭代时显现。盲点在于检测工具而非工程师,无法通过消除人为因素解决。我们替换了该检测工具:采用字节级精确的黄金参考预言机结合随机对抗性浸泡测试,驱动拒绝循环覆盖所有固定向量,从而填补了漏洞:完成301343次依赖数据的签名,零缺陷逃逸。由于该检测工具仅评判结果而非生成结果,信任与作者身份可分离,使AI作者身份成为可回答的问题。我们报告了232次记录的实验,其中一个具能动性的大语言模型在Kintex-7 XC7K160T芯片上,从RTL到PCIe启动阶段,驱动了统一的ML-KEM-768与ML-DSA-65加速器,且具备片上密钥保管功能,最终流片时的切片占用率达98.5%。实验成功率为71.6%,其中与硬件耦合相关的成功率为71.6%,文档与研究相关的成功率为77-85%,综合与启动阶段的成功率为50-53%,可通过可观测性解释:故障集中在仅存在物理侧校正信号的区域。如此不可靠的“作者”生成的产物在全部6种FIPS操作中均实现字节级精确——其部署基线在相同的779945次检查的零缺陷浸泡测试中存活——这就是我们的核心主张。
英文摘要
Post-quantum migration is mandated on published timelines, and silicon that ships with a defect cannot be patched remotely. The standard acceptance gate cannot detect an entire class of ML-DSA defects. Signing resamples until a candidate meets its norm bounds, so the executed path varies with the message, whereas known-answer tests (KATs) sample fixed values and reach only the depths their seeds trigger. Our accelerator passed its full KAT regression while carrying a norm check that outran block-RAM latency, leaving each candidate's final coefficients unverified; the escape surfaced at reject-loop iteration 5. The blind spot lies in the instrument, not the engineer; care cannot remove it. We replace that gate. A byte-exact golden-reference oracle paired with randomized adversarial soak drives the rejection loop past any fixed vector, closing the gap: 301,343 data-dependent signings, zero escapes. Because the gate judges artifacts and never authors, trust becomes separable from authorship, making AI authorship an answerable question. We report 232 logged experiments in which an agentic large language model drove a unified ML-KEM-768 and ML-DSA-65 accelerator with on-chip key custody from RTL to PCIe bring-up on one Kintex-7 XC7K160T, shipped at 98.5% slice occupancy. Success was 71.6%, following a hardware-coupling gradient, 77-85% for documentation and research against 50-53% for synthesis and bring-up, which observability can explain: failure concentrates where corrective signals are physical-side only. That so unreliable an author produced an artifact byte-exact across all six FIPS operations -- its deployed baseline surviving the same 779,945-check zero-failure soak -- is the claim.