Special Issue on Post-Quantum Cryptography for Embedded Systems
Shivam Bhasin, Fabrizio De Santis, Francesco Regazzoni · ACM Transactions on Embedded Computing Systems · 2024
In 2014, the National Institute of Standards and Technology (NIST) suggested that a quantum computer capable of breaking RSA could be built by 2030.The National Security Agency (NSA) warned in 2015 that progress in quantum computing had reached a point at which organizations should start deploying encryption algorithms designed to withstand attacks performed on quantum computers.Post-quantum cryptography refers to cryptographic algorithms that are resistant to attacks by quantum computers.To ensure a smooth transition from current cryptographic asymmetric algorithms to post-quantum algorithms, two key aspects shall be considered: implementation security and performance.This is particularly important for constrained devices, such as embedded and IoT devices, in various application domains, including industrial networks, critical infrastructures, banking, health, transportation, and many others.This motivates an urgent need for evaluating post-quantum cryptographic implementations on embedded systems for physical security and performance, including the integration of such implementations in current protocols and systems.This special issue brings together original manuscripts that explore the latest developments in implementing secure and efficient post-quantum cryptographic algorithms for embedded and IoT applications.After undergoing a comprehensive and rigorous review, nine papers have been selected to be featured in this special issue.The following is a brief summary of the papers included in this issue.The article titled "Side-Channel Analysis of Lattice-Based Post-Quantum Cryptography: Exploiting Polynomial Multiplication " [ 1 ] presents side-channel analysis methodologies targeting all polynomial multiplications of all lattice-based post-quantum key encapsulation mechanisms in the final round of the NIST post-quantum standardization procedure.The article presents practical experiments on real side-channel measurements demonstrating that the proposed methods allow one to extract the secret key from all lattice-based post-quantum key encapsulation mechanisms.Furthermore, the analysis shows that the used polynomial multiplication strategy can significantly impact the time complexity of the attack.The article titled "MemFHE: End-to-End Computing with Fully Homomorphic Encryption in Memory " [ 2 ] presents MemFHE, a first HW accelerator that supports both client and server functionalities for the latest homomorphic encryption schemes based on Ring-GSW.This accelerator utilizes Processing In Memory (PIM) technology.The authors thoroughly evaluate MemFHE across different security levels and compare its performance against state-of-the-art CPU implementations for Ring-GSW-based Fully Homomorphic Encryption (FHE) .MemFHE achieves