Patrick Karl

dblp:258/9257 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
5since 2021 · last 2025
0000-0001-9476-9651ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 3 · 3 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2025 Performance and Communication Cost of Hardware Accelerators for Hashing in Post-Quantum Cryptography
abstract
SPHINCS+ is a signature scheme included in the first NIST post-quantum standard that bases its security on the underlying hash primitive. As most of the runtime of SPHINCS+ is caused by the evaluation of several hash- and pseudo-random functions, offloading this computation to dedicated hardware accelerators is a natural step. In this work, we evaluate different architectures for hardware acceleration of such a hash primitive with respect to its use-case and evaluate them in the context of SPHINCS+. We attach hardware accelerators for different hash primitives (SHAKE256 and Ascon-Xof for both full and round-reduced versions) to CPU interfaces having different transfer speeds. We show that for most use-cases, data transfer determines the overall performance if accelerators are equipped with FIFOs and that reducing the number of rounds in the permutation does not necessarily lead to significant performance improvements when using hardware acceleration. This work extends on a conference paper accepted at COSADE’24, first published in [ 19 ], and written by the same authors, where different architectures for hardware accelerators of hash functions are benchmarked and evaluated for SPHINCS+ as a case study. In this article, we provide results for additional parameter sets for SPHINCS+ and improve the performance of one of the accelerators by adding an additional RISC-V instruction for faster absorption. We then extend the performance benchmark by including the algorithms CRYSTALS-Kyber, CRYSTALS-Dilithium, and Falcon. Finally, we provide a power/energy comparison for the accelerators.
Patrick Karl, Jonas Schupp, Georg Sigl
ACM Trans. Embed. Comput. Syst.1
2024 Post-Quantum Signatures on RISC-V with Hardware Acceleration
abstract
CRYSTALS-Dilithium and Falcon are digital signature algorithms based on cryptographic lattices, which are considered secure even if large-scale quantum computers will be able to break conventional public-key cryptography. Both schemes have been selected for standardization in the NIST Post-Quantum competition. In this work, we present a RISC-V HW/SW codesign that aims to combine the advantages of software and hardware implementations, i.e., flexibility and performance. It shows the use of flexible hardware accelerators, which have been previously used for Public-Key Encryption (PKE) and Key-Encapsulation Mechanism (KEM), for Post-Quantum signatures. It is optimized for Dilithium as a generic signature scheme but also accelerates applications that require fast verification of Falcon’s compact signatures. We provide a comparison with previous works showing that for Dilithium and Falcon, cycle counts are significantly reduced, such that our design is faster than previous software implementations or other HW/SW codesigns. In addition to that, we present a compact Globalfoundries 22nm ASIC design that runs at 800 MHz. By using hardware acceleration, energy consumption for Dilithium is reduced by up to 92.2%, and up to 67.5% for Falcon’s signature verification.
Patrick Karl, Jonas Schupp, Tim Fritzmann, Georg Sigl
ACM Trans. Embed. Comput. Syst.1
2022 Hardware Accelerated FrodoKEM on RISC-V
abstract
FrodoKEM is an alternative finalist in the currently running standardization process for post-quantum secure cryptography, initiated by the National Institute of Standards and Technology (NIST). It is based on the well studied plain Learning With Errors (LWE) problem, leading to a high confidence in security. Its conservative design approach, however, makes it less performant when compared to other lattice-based candidates. In this work, we assemble a RISC-V based HW/SW codesign of FrodoKEM to speed up its computation. Our design supports all three parameter sets of the NIST submission. Compared to plain SW implementations on RISC-V, our accelerated design achieves speedup factors of up to 8.13.
Patrick Karl, Tim Fritzmann, Georg Sigl
DDECS1
2021 Algebraic Fault Analysis of Subterranean 2.0
abstract
Algebraic Fault Analysis (AFA) is based on the principles of algebraic cryptanalysis in conjunction with fault analysis. One of the main benefits of AFA is the ability to use off the shelf solving tools like SAT solvers to conduct fault analysis in an automated fashion. In this work we show how the principles of AFA can be applied to the authenticated encryption scheme Subterranean 2.0, a second round candidate of the ongoing NIST-LWC competition. In order to find the optimal parameters for a fault injection we investigated the fault model’s influence on the solving time. The optimal fault parameters turned out as a single bitflip fault in conjunction with a known but randomly chosen fault location, where the fault is applied just one cycle before the tag generation. We verify the efficiency of our attack by means of simulation. Conducting our proposed attack with optimal fault parameters requires only five fault injections to recover the secret key of Subterranean 2.0 in less than four seconds.
Michael Gruber, Patrick Karl, Georg Sigl
FDTC2
2021 DOMREP-An Orthogonal Countermeasure for Arbitrary Order Side-Channel and Fault Attack Protection
abstract
Protection against physical attacks is a major requirement for cryptographic implementations on devices which can be accessed by attackers. Side-channel and fault injection attacks are the most common types of physical attacks. In this work we present a novel generic solution for simultaneous protection against side-channel and fault attacks with arbitrary order. We combine domain oriented masking and repetition codes in an orthogonal way and call this approach DOMREP. The resistance against side-channel attacks and fault attacks can be scaled independently of each other, for the protection against higher-order side-channel analysis and the injection of multiple faults including SIFA. We develop the generic concept of orthogonal protection, and implement the DOMREP concept on GIMLI, a round two NIST LWC competition candidate, on a Xilinx Artix-7 FPGA. Our implementation of GIMLI is verified to be resistant against univariate first-order side-channel attacks by TVLA. The resistance against SIFA is verified by means of fault emulation of single as well as multiple bit faults. Our implementation of GIMLI achieves the expected security level according to these measurements. We also provide numbers for the area overhead for our protected implementation of GIMLI.
Michael Gruber, Matthias Probst, Patrick Karl, Thomas Schamberger, Lars Tebelmann, Michael Tempelmeier, Georg Sigl
IEEE Trans. Inf. Forensics Secur.3