Implementing CRYSTALS Kyber and Dilithium in Intel SGX Secure Enclaves
Nabila Pratiwi, Muhammad Firmansyah, Martianus Frederic Ezerman · 2023
Intel SGX is an extra set of Intel processor instructions to create hardware-protected secure enclaves in a running program to ensure confidentiality and integrity. It is an example of a trusted execution environment (TEE) in commodity servers. One can utilize such an environment to perform cryptographic services with high security assurance.Quantum attack algorithms have spurred the community to devise quantum-secure asymmetric cryptographic primitives. We report an integration of interim CRYSTALS modules from NIST Post-Quantum Cryptography (PQC) Standard, namely Kyber for key encapsulation method (KEM) and Dilithium for signature scheme, in Intel SGX secure enclaves. They perform very competitively in both running time and memory resource requirements.