GENERATION OF GENERAL SYSTEM PARAMETERS FOR FALCON CRYPTOSYSTEM FOR 256, 384, AND 512 SECURITY BITS

І.Д. Горбенко, Serhii Kandii, Maryna V. Yesina, Yelyzaveta Ostrianska · Telecommunications and Radio Engineering · 2022

Globally, the efforts of a significant number of crypto-theorists, mathematicians and cryptologists-practitioners are focused on the NIST PQC open competition. One of the main tasks of the competition is the development and adoption of post-quantum ES standard or standards. The finalists of the second stage of the NIST competition were three ES mechanisms – CRYSTALS-DILITHIUM, Falcon and Rainbow. In addition, three alternative candidates have been identified who need more detailed research. In general, a comprehensive analysis of the finalists is an important task for cryptologists in the global cryptocommunity. Moreover, security, i.e. proving the cryptographic stability of two finalist candidates, to the ES standard – CRYSTALS-DILITHIUM and Falcon, is based on problems in the theory and practice of algebraic lattices. Studies show that among the ES schemes on lattices it differs slightly from other candidates and has prospects for the adoption as a standard the Falcon algorithm. The main and dominant approach to the design of the Falcon ES mechanism is the use of the Fiat-Shamir transformation with interruptions. For the safe use of the Falcon ES, the sets of system-wide parameters that ensure resistance to all known and potential attacks must be found. In the process of forming the requirements for ES NIST within the competition was interested only in sets of system-wide parameters up to 256 bits of classical security inclusive. However, according to the authors of this work, in the future it is advisable to provide at least 384 and 512 bits of security for classical cryptanalysis and at least 192 and 256 bits of security for quantum cryptanalysis. The article brie

Read the paper · More papers on PaperTik