Benchmarking Post-quantum Cryptography in TLS

被引:40
|
作者
Paquin, Christian [1 ]
Stebila, Douglas [2 ]
Tamvada, Goutam [2 ]
机构
[1] Microsoft Res, Redmond, WA USA
[2] Univ Waterloo, Waterloo, ON, Canada
来源
基金
加拿大自然科学与工程研究理事会;
关键词
Post-quantum key exchange; Post-quantum authentication; Transport Layer Security (TLS); Network performance; Emulation; SECURITY;
D O I
10.1007/978-3-030-44223-1_5
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Post-quantum cryptographic primitives have a range of tradeoffs compared to traditional public key algorithms, either having slower computation or larger public keys and ciphertexts/signatures, or both. While the performance of these algorithms in isolation is easy to measure and has been a focus of optimization techniques, performance in realistic network conditions has been less studied. Google and Cloudflare have reported results from running experiments with post-quantum key exchange algorithms in the Transport Layer Security (TLS) protocol with real users' network traffic. Such experiments are highly realistic, but cannot be replicated without access to Internet-scale infrastructure, and do not allow for isolating the effect of individual network characteristics. In this work, we develop and make use of a framework for running such experiments in TLS cheaply by emulating network conditions using the networking features of the Linux kernel. Our testbed allows us to independently control variables such as link latency and packet loss rate, and then examine the performance impact of various post-quantum-primitives on TLS connection establishment, specifically hybrid elliptic curve/post-quantum key exchange and post-quantum digital signatures, based on implementations from the Open Quantum Safe project. Among our key results, we observe that packet loss rates above 3-5% start to have a significant impact on post-quantum algorithms that fragment across many packets, such as those based on unstructured lattices. The results from this emulation framework are also complemented by results on the latency of loading entire web pages over TLS in real network conditions, which show that network latency hides most of the impact from algorithms with slower computations (such as supersingular isogenies).
引用
收藏
页码:72 / 91
页数:20
相关论文
共 50 条
  • [1] Challenges and Rewards of Implementing and Benchmarking Post-Quantum Cryptography in Hardware
    Gaj, Kris
    [J]. PROCEEDINGS OF THE 2018 GREAT LAKES SYMPOSIUM ON VLSI (GLSVLSI'18), 2018, : 359 - 364
  • [2] Feasibility and Benchmarking of Post-Quantum Cryptography in the Cooperative ITS Ecosystem
    Lonc, Brigitte
    Aubry, Alexandre
    Bakhti, Hafeda
    Christofi, Maria
    Mehrez, Hassane Aissaoui
    [J]. 2023 IEEE VEHICULAR NETWORKING CONFERENCE, VNC, 2023, : 215 - 222
  • [3] Constrained Device Performance Benchmarking with the Implementation of Post-Quantum Cryptography
    Fitzgibbon, Gregory
    Ottaviani, Carlo
    [J]. CRYPTOGRAPHY, 2024, 8 (02)
  • [4] Post-Quantum Cryptography in Use: Empirical Analysis of the TLS Handshake Performance
    Doering, Ronny
    Geitz, Marc
    [J]. PROCEEDINGS OF THE IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2022, 2022,
  • [5] Post-Quantum Cryptography
    Monroe, Don
    [J]. COMMUNICATIONS OF THE ACM, 2023, 66 (02) : 15 - 17
  • [6] Post-quantum cryptography
    Bernstein, Daniel J.
    Lange, Tanja
    [J]. NATURE, 2017, 549 (7671) : 188 - 194
  • [7] Post-quantum cryptography
    Daniel J. Bernstein
    Tanja Lange
    [J]. Nature, 2017, 549 : 188 - 194
  • [8] Authentication Protocol for Secure Automotive Systems: Benchmarking Post-Quantum Cryptography
    Ravi, Prasanna
    Sundar, Vijaya Kumar
    Chattopadhyay, Anupam
    Bhasin, Shivam
    Easwaran, Arvind
    [J]. 2020 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS (ISCAS), 2020,
  • [9] Post-Quantum Crystography: A Combination of Post-Quantum Cryptography and Steganography
    Gabriel, A. J.
    Alese, B. K.
    Adetunmbi, A. O.
    Adewale, O. S.
    [J]. 2013 8TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2013, : 449 - +
  • [10] Quantum-Resistant TLS 1.3: A Hybrid Solution Combining Classical, Quantum and Post-Quantum Cryptography
    Garcia, Carlos Rubio
    Aguilera, Abraham Cano
    Olmos, Juan Jose Vegas
    Monroy, Idelfonso Tafur
    Rommel, Simon
    [J]. 2023 IEEE 28TH INTERNATIONAL WORKSHOP ON COMPUTER AIDED MODELING AND DESIGN OF COMMUNICATION LINKS AND NETWORKS, CAMAD 2023, 2023, : 246 - 251