Extended version-to be, or not to be stateful: post-quantum secure boot using hash-based signatures

被引:0
|
作者
Wagner, Alexander [1 ,2 ]
Oberhansl, Felix [1 ]
Schink, Marc [1 ,2 ]
机构
[1] Garching near Munich, Fraunhofer AISEC, Munich, Germany
[2] Tech Univ Munich, Munich, Germany
关键词
Post-quantum cryptography; Hash-based signatures; LMS; XMSS; SPHINCS+; Secure boot; Hardware/software co-design;
D O I
10.1007/s13389-024-00362-4
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
While research in PQC has gained significant momentum, its adoption in real-world products is slow. This is largely due to concerns about practicability and maturity. The secure boot process of embedded devices is one scenario where such restraints can result in fundamental security problems. In this work, we present a flexible hardware/software co-design for HBS schemes which enables the transition to a post-quantum secure boot today. These signature schemes stand out due to their straightforward security proofs and are on the fast track to standardisation. Unlike previous work, we exploit the performance intensive similarities of the stateful LMS and XMSS schemes as well as the stateless SPHINCS+ scheme. Thus, we enable designers to use a stateful or stateless scheme depending on the constraints of each individual application. To demonstrate the feasibility of our approach, we compare our results with hardware accelerated implementations of classical asymmetric algorithms. Further, we outline the use of different HBS schemes during the boot process. We compare different schemes, show the importance of parameter choices, and demonstrate the performance gain with different levels of hardware acceleration.
引用
收藏
页码:631 / 648
页数:18
相关论文
共 50 条
  • [1] To Be, or Not to Be Stateful: Post-Quantum Secure Boot using Hash-Based Signatures
    Wagner, Alexander
    Oberhansl, Felix
    Schink, Marc
    PROCEEDINGS OF THE 2022 WORKSHOP ON ATTACKS AND SOLUTIONS IN HARDWARE SECURITY, ASHES 2022, 2022, : 85 - 94
  • [2] Post-Quantum Authentication in OpenSSL with Hash-Based Signatures
    Butin, Denis
    Waelde, Julian
    Buchmann, Johannes
    2017 TENTH INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND UBIQUITOUS NETWORK (ICMU), 2017, : 81 - 86
  • [3] Reliable Hash Trees for Post-quantum Stateless Cryptographic Hash-based Signatures
    Mozaffari-Kermani, Mehran
    Azarderakhsh, Reza
    PROCEEDINGS OF THE 2015 IEEE INTERNATIONAL SYMPOSIUM ON DEFECT AND FAULT TOLERANCE IN VLSI AND NANOTECHNOLOGY SYSTEMS (DFTS), 2015, : 103 - 108
  • [4] Fault Detection Architectures for Post-Quantum Cryptographic Stateless Hash-Based Secure Signatures Benchmarked on ASIC
    Mozaffari-Kermani, Mehran
    Azarderakhsh, Reza
    Aghaie, Anita
    ACM TRANSACTIONS ON EMBEDDED COMPUTING SYSTEMS, 2017, 16 (02)
  • [5] Patent Landscape in the field of Hash-Based Post-Quantum Signatures (Invited Paper)
    Agrawal, Megha
    Duraisamy, Kumar
    Ganesan, Karthikeyan Sabari
    Gupta, Shivam
    Kandele, Suyash
    Konduru, Sai Sandilya
    Maddipati, Harika Chowdary
    Raghavendra, K.
    Sahu, Rajeev Anand
    Saraswat, Vishal
    PROGRESS IN CRYPTOLOGY - INDOCRYPT 2023, PT II, 2024, 14460 : 240 - 261
  • [6] Secure authentication framework for IoT applications using a hash-based post-quantum signature scheme
    Tandel, Purvi
    Nasriwala, Jitendra
    SERVICE ORIENTED COMPUTING AND APPLICATIONS, 2024,
  • [7] Post-Quantum Secure Boot
    Kumar, Vinay B. Y.
    Gupta, Naina
    Chattopadhyay, Anupam
    Kasper, Michael
    Krauss, Christoph
    Niederhagen, Ruben
    PROCEEDINGS OF THE 2020 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION (DATE 2020), 2020, : 1582 - 1585
  • [8] A scalable post-quantum hash-based group signature
    Shafieinejad, Masoumeh
    Esfahani, Navid Nasr
    DESIGNS CODES AND CRYPTOGRAPHY, 2021, 89 (05) : 1061 - 1090
  • [9] A scalable post-quantum hash-based group signature
    Masoumeh Shafieinejad
    Navid Nasr Esfahani
    Designs, Codes and Cryptography, 2021, 89 : 1061 - 1090
  • [10] Agile Acceleration of Stateful Hash-based Signatures in Hardware
    Thoma, Jan Philipp
    Hartlief, Darius
    Gueneysu, Tim
    ACM TRANSACTIONS ON EMBEDDED COMPUTING SYSTEMS, 2024, 23 (02)