Extended version-to be, or not to be stateful: post-quantum secure boot using hash-based signatures

被引:0
|
作者
Wagner, Alexander [1 ,2 ]
Oberhansl, Felix [1 ]
Schink, Marc [1 ,2 ]
机构
[1] Garching near Munich, Fraunhofer AISEC, Munich, Germany
[2] Tech Univ Munich, Munich, Germany
关键词
Post-quantum cryptography; Hash-based signatures; LMS; XMSS; SPHINCS+; Secure boot; Hardware/software co-design;
D O I
10.1007/s13389-024-00362-4
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
While research in PQC has gained significant momentum, its adoption in real-world products is slow. This is largely due to concerns about practicability and maturity. The secure boot process of embedded devices is one scenario where such restraints can result in fundamental security problems. In this work, we present a flexible hardware/software co-design for HBS schemes which enables the transition to a post-quantum secure boot today. These signature schemes stand out due to their straightforward security proofs and are on the fast track to standardisation. Unlike previous work, we exploit the performance intensive similarities of the stateful LMS and XMSS schemes as well as the stateless SPHINCS+ scheme. Thus, we enable designers to use a stateful or stateless scheme depending on the constraints of each individual application. To demonstrate the feasibility of our approach, we compare our results with hardware accelerated implementations of classical asymmetric algorithms. Further, we outline the use of different HBS schemes during the boot process. We compare different schemes, show the importance of parameter choices, and demonstrate the performance gain with different levels of hardware acceleration.
引用
收藏
页码:631 / 648
页数:18
相关论文
共 50 条
  • [31] Developing Secure Messaging Software using Post-Quantum Cryptography
    Nguyen, Tat-Thang
    Luc, Nhu-Quynh
    Dao, Toan Thanh
    ENGINEERING TECHNOLOGY & APPLIED SCIENCE RESEARCH, 2023, 13 (06) : 12440 - 12445
  • [32] Post-Quantum Forward-Secure Signatures with Hardware-Support for Internet of Things
    Nouma, Saif E.
    Yavuz, Attila A.
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 4540 - 4545
  • [33] Cheap and secure metatransactions on the blockchain using hash-based authorisation and preferred batchers
    Hughes, William
    Magnusson, Tobias
    Russo, Alejandro
    Schneider, Gerardo
    BLOCKCHAIN-RESEARCH AND APPLICATIONS, 2023, 4 (02):
  • [34] Post-Quantum Secure Identity-Based Matchmaking Encryption
    Wang, Huige
    Chen, Kefei
    Xie, Qi
    Meng, Qian
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2025, 22 (01) : 833 - 844
  • [35] Secure Social Internet of Things Based on Post-Quantum Blockchain
    Yi, Haibo
    IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2022, 9 (03): : 950 - 957
  • [36] Quantum secure communication using hybrid post-quantum cryptography and quantum key distribution
    Aquina, Nick
    Rommel, Simon
    Monroy, Idelfonso Tafur
    2024 24TH INTERNATIONAL CONFERENCE ON TRANSPARENT OPTICAL NETWORKS, ICTON 2024, 2024,
  • [37] Post-Quantum Signatures in DNSSEC via Request-Based Fragmentation
    Goertzen, Jason
    Stebila, Douglas
    POST-QUANTUM CRYPTOGRAPHY, PQCRYPTO 2023, 2023, 14154 : 535 - 564
  • [38] Token Open Secure and Post-quantum Updatable Encryption Based on MLWE
    Song, Yang
    Gao, Haiying
    Sun, Keshuo
    Ma, Chao
    SECURITY, PRIVACY, AND APPLIED CRYPTOGRAPHY ENGINEERING, SPACE 2023, 2024, 14412 : 20 - 47
  • [39] Secure and Scalable Internet of Things Model Using Post-Quantum MACsec
    Choi, Juhee
    Lee, Junwon
    APPLIED SCIENCES-BASEL, 2024, 14 (10):
  • [40] A Lightweight Post-Quantum Lattice-Based RSA for Secure Communications
    Mustafa, Iqra
    Khan, Imran Ullah
    Aslam, Sheraz
    Sajid, Ahthasham
    Mohsin, Syed Muhammad
    Awais, Muhammad
    Qureshi, Muhammad Bilal
    IEEE ACCESS, 2020, 8 : 99273 - 99285