| 研究生: |
王彥珽 Wang, Yan-Ting |
|---|---|
| 論文名稱: |
高擴充性Hybrid PQC系統電路設計 Hardware Implementation of a Highly Scalable Hybrid PQC Protocol System |
| 指導教授: |
陳培殷
Chen, Pei-Yin |
| 學位類別: |
碩士 Master |
| 系所名稱: |
電機資訊學院 - 資訊工程學系 Department of Computer Science and Information Engineering |
| 論文出版年: | 2026 |
| 畢業學年度: | 114 |
| 語文別: | 中文 |
| 論文頁數: | 35 |
| 中文關鍵詞: | 橢圓曲線密碼學 、後量子密碼學 、混合式密碼協定 、模組化硬體架構 、可擴充硬體系統 |
| 外文關鍵詞: | Elliptic Curve Cryptography, Post-Quantum Cryptography, Hybrid Cryptographic Protocol, Modular Hardware Architecture, Scalable Hardware System |
| 相關次數: | 點閱:109 下載:5 |
| 分享至: |
| 查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報 |
隨著量子計算技術的快速發展,使得目前被廣泛使用的傳統公鑰密碼演算法面臨全面破解的威脅。為了應對此威脅,美國國家標準與技術學院(NIST)制定能夠抵抗量子攻擊的後量子演算法。然而,不同於傳統演算法已經經歷數十年的實戰驗證,後量子演算法的安全性仍需持續接受檢驗。因此,從傳統密碼學過渡至後量子密碼學的重要時期,混合傳統與量子演算法的混合協定(Hybrid Protocol)成為兼顧安全性與抗量子能力的過渡解方。
過去的相關研究多著重於各自演算法的效能優化與硬體加速,而混合式協定則主要以軟體實現。較少討論硬體整合。因此本研究提出高擴充性的Hybrid PQC硬體系統,於硬體中整合傳統與後量子演算法,並完成雙重身分驗證、雙重金鑰交換與會話金鑰產生等協定流程。此外,演算法核心採用模組化設計,使用仲裁器(Arbiter)進行資料調度,透過統一的通訊介面整合各個演算法核心。未來若是特定演算法出現安全性問題或是需要更新時,只需要修改對應核心與介面,可降低整體系統重新設計與整合的成本。
本研究於TSMC 40nm製程下完成電路合成與功能驗證。目前整合各密碼學核心使用單一頻率,整體系統運作頻率為50MHz。實驗結果顯示,嵌入式軟體實作完成一次混合協定約需73.08ms,而本研究硬體系統僅需49.18ms,硬體所需執行時間約為軟體的0.67倍。本研究成功於單一硬體平台上整合傳統與後量子演算法,為密碼學過渡時期提供具備實用性與擴充性的硬體安全架構。
To address the security and architectural challenges associated with the transition from classical cryptography to Post-Quantum Cryptography (PQC), this study proposes a highly scalable and modular Hybrid PQC hardware system that integrates classical cryptographic algorithms, including EdDSA, ECDH, AES-GCM, and HKDF, with the post-quantum algorithms ML-KEM and ML-DSA. A central Arbiter performs address decoding, data routing, and interface coordination among the cryptographic modules, while standardized Wrapper interfaces allow individual cryptographic cores to be replaced or updated with limited modification to the top-level control architecture. The proposed system was implemented in Verilog HDL and synthesized using a TSMC 40 nm standard-cell library, resulting in a synthesized area of approximately 3.41 mm². Experimental results show that the hardware implementation completes the full protocol flow, including dual authentication, hybrid key establishment, key derivation, and authenticated symmetric encryption, in approximately 49.18 ms at a system frequency of 50 MHz. Compared with the equivalent software implementation on a PYNQ-Z2 platform, which requires 73.08 ms, the proposed hardware system reduces the execution time by approximately 32.70% and achieves a speed improvement of approximately 1.49 times. Overall, this study demonstrates the feasibility of integrating classical and post-quantum cryptographic algorithms within a modular and extensible hardware architecture for the transition toward post-quantum cryptography.
[1] V. S. Miller, “Use of elliptic curves in cryptography,” in Advances in Cryptology—CRYPTO ’85, H. C. Williams, Ed., Lecture Notes in Computer Science, vol. 218. Berlin, Germany: Springer, 1986, pp. 417–426, doi: 10.1007/3-540-39799-X_31.
[2] R. L. Rivest, A. Shamir, and L. Adleman, “A method for obtaining digital signatures and public-key cryptosystems,” Communications of the ACM, vol. 21, no. 2, pp. 120–126, Feb. 1978, doi: 10.1145/359340.359342.
[3] P. W. Shor, “Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer,” SIAM Journal on Computing, vol. 26, no. 5, pp. 1484–1509, Oct. 1997, doi: 10.1137/S0097539795293172.
[4] National Institute of Standards and Technology, “Module-lattice-based key-encapsulation mechanism standard,” FIPS PUB 203, Aug. 2024, doi: 10.6028/NIST.FIPS.203.
[5] National Institute of Standards and Technology, “Module-lattice-based digital signature standard,” FIPS PUB 204, Aug. 2024, doi: 10.6028/NIST.FIPS.204.
[6] G. M. de Dormale, P. Bulens, and J.-J. Quisquater, “An improved Montgomery modular inversion targeted for efficient implementation on FPGA,” in Proc. 2004 IEEE Int. Conf. Field-Programmable Technology (FPT), Brisbane, QLD, Australia, 2004, pp. 441–444, doi: 10.1109/FPT.2004.1393320.
[7] M. A. Mehrabi and C. Doche, “Low-cost, low-power FPGA implementation of ED25519 and CURVE25519 point multiplication,” Information, vol. 10, no. 9, Art. no. 285, Sep. 2019, doi: 10.3390/info10090285.
[8] H. Hisil, K. K.-H. Wong, G. Carter, and E. Dawson, “Twisted Edwards curves revisited,” in Advances in Cryptology—ASIACRYPT 2008, Lecture Notes in Computer Science, vol. 5350. Berlin, Germany: Springer, 2008, pp. 326–343, doi: 10.1007/978-3-540-89255-7_20.
[9] D. E. S. Kundi, J. M. Bermudo Mera, P.-Y. Strub, and M. Hutter, “High-performance NTT hardware accelerator to support ML-KEM and ML-DSA,” in Proc. 2024 Workshop Attacks and Solutions in Hardware Security (ASHES ’24), 2024, pp. 100–105, doi: 10.1145/3689939.3695785.
[10] M. Li, J. Tian, X. Hu, Y. Cao, and Z. Wang, “High-speed and low-complexity modular reduction design for CRYSTALS-Kyber,” in Proc. 2022 IEEE Asia Pacific Conf. Circuits and Systems (APCCAS), Shenzhen, China, 2022, pp. 1–5, doi: 10.1109/APCCAS55924.2022.10090253.
[11] Y. Ko et al., “5G-AKA-HPQC: Hybrid postquantum cryptography protocol for quantum-resilient 5G primary authentication with forward secrecy,” IEEE Internet of Things Journal, vol. 13, no. 12, pp. 26977–27000, Jun. 2026, doi: 10.1109/JIOT.2026.3678536.
[12] K. Varner, W. Zaeske, S. Friedrich, A. Kaiser, and A. Bowman, “Agile, post-quantum secure cryptography in avionics,” CEAS Aeronautical Journal, vol. 17, no. 1, pp. 133–163, 2026, doi: 10.1007/s13272-025-00806-5.
[13] H. Krawczyk, M. Bellare, and R. Canetti, “HMAC: Keyed-hashing for message authentication,” RFC 2104, Feb. 1997, doi: 10.17487/RFC2104.
[14] H. Krawczyk and P. Eronen, “HMAC-based extract-and-expand key derivation function (HKDF),” RFC 5869, May 2010, doi: 10.17487/RFC5869.
[15] . Kojima, “x25519-fpga: An FPGA implementation of some X25519 operations,” GitHub. [Online]. Available: https://github.com/kazkojima/x25519-fpga
[16] M. Dworkin, “Recommendation for block cipher modes of operation: Galois/Counter Mode (GCM) and GMAC,” NIST Special Publication 800-38D, Nov. 2007, doi: 10.6028/NIST.SP.800-38D.