AXI hardware accelerator for McEliece on FPGA embedded systems

This paper presents a McEliece hardware accelerator designed to be attached to an AXI infrastructure, addressing the efficient implementation of a flexible post-quantum cryptoprocessor on FPGA-based embedded systems. The complexity of the arithmetic circuits, combined with the adaptability to differ...

Descripción completa

Detalles Bibliográficos
Autores: Cantó Navarro, Enrique, López García, Mariano|||0000-0002-5556-233X
Tipo de recurso: artículo
Fecha de publicación:2024
País:España
Institución:Universitat Politècnica de Catalunya (UPC)
Repositorio:UPCommons. Portal del coneixement obert de la UPC
Idioma:inglés
OAI Identifier:oai:upcommons.upc.edu:2117/414465
Acceso en línea:https://hdl.handle.net/2117/414465
https://dx.doi.org/10.1109/TDSC.2024.3445181
Access Level:acceso abierto
Palabra clave:Quantum computers
Cryptography
Embedded computer systems
Field programmable gate arrays
Clocks
Codes
Microprocessors
Table lookup
Encryption
Public key cryptosystem
Real time and embedded systems
Reconfigurable hardware
Ordinadors quàntics
Criptografia
Sistemes incrustats (Informàtica)
Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica::Criptografia
Àrees temàtiques de la UPC::Informàtica::Arquitectura de computadors
Descripción
Sumario:This paper presents a McEliece hardware accelerator designed to be attached to an AXI infrastructure, addressing the efficient implementation of a flexible post-quantum cryptoprocessor on FPGA-based embedded systems. The complexity of the arithmetic circuits, combined with the adaptability to different applications by configurable parameters and run-time reprogramming, presents challenging issues for integrating the accelerator into these systems. The architecture of the accelerator is based on an application-specific instruction processor (ASIP), which executes a set of constant-time instructions from an internal register file and memories. The register file is used to perform instructions on Goppa codes over polynomials, whereas the vector memory is used when operations with binary matrices and vectors that are involved in the McEliece algorithm. The role of the embedded processor is reduced to the initial writing of the instruction memory of the accelerator, the launching of the required set of instructions to complete each stage of the algorithm and configuring the Direct Memory Access (DMA) controller to retrieve and store data from external memory. The run-time programming of the accelerator provides high flexibility in applications that requires post-quantum cryptography. A set of configurable parameters permits to adapt the security level of the McEliece encryption-decryption (n, m, t) and the area-performance tradeoff imposed by the target device. Thus, the accelerator can be implemented from low-cost to high-end FPGAs by configuring the data-width of DMA buses or the parallelism level of the Galois-Field adder-multiplier. Experimental results show the accelerator is suited for implementing efficiently the highest security parameters of the Classic McEliece, achieving a McEliece decryption speed-up from x370 to x556 and occupying a small number of resources on a low-cost FPGA. In high-end FPGAs, the accelerator can be configured using higher security parameters not achieved in previous related cryptoprocessors, providing even higher accelerations.