EDBT 2026 Demo / reviewers in the wild / expert
Rami El Khatib
dblp:244/8940 · also Rami Elkhatib
· DBLP profile ↗
9ranked-venue papers
7as first author
6since 2021 · last 2024
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 3 · 3 first-author · 3 since 2021Security and privacy · 3 · 2 first-author · 2 since 2021Theory of computation · 3 · 2 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Cryptographic Engineering a Fast and Efficient SIKE in FPGAabstractRecent attacks have shown that SIKE is not secure and should not be used in its current state. However, this work was completed before these attacks were discovered and might be beneficial to other cryptosystems such as SQISign. The primary downside of SIKE is its performance. However, this work achieves new SIKE speed records even using less resources than the state-of-the-art. Our approach entails designing and optimizing a new field multiplier, SIKE-optimized Keccak unit, and high-level controller. On a Xilinx Virtex-7 FPGA, this architecture performs the NIST Level 1 SIKE scheme key encapsulation and key decapsulation functions in 2.23 and 2.39 ms, respectively. The combined key encapsulation and decapsulation time is 4.62 ms, which outperforms the next best Virtex-7 implementation by nearly 2 ms. Our implementation achieves speed records for the NIST Level 1, 2, and 3 parameter sets. Only our NIST Level 5 parameter set was beat by an all-out performance implementation. Our implementations also efficiently utilize the FPGA resources, achieving new records in area-time product metrics for all parameter sets. Overall, this work continues to push the bar for accelerating SIKE computations to make a stronger case for SIKE standardization. Rami El Khatib, Brian Koziel, Reza Azarderakhsh, Mehran Mozaffari Kermani |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2022 | Faster Isogenies for Post-quantum Cryptography: SIKE
Rami El Khatib, Brian Koziel, Reza Azarderakhsh |
CT-RSA | 1 |
| 2022 | High-Performance FPGA Accelerator for SIKEabstractNew primes were proposed for Supersingular Isogeny Key Encapsulation (SIKE) in NIST standardization process of Round 2 after further cryptanalysis research showed that the security levels of the initial primes chosen were over-estimated [#AdjCCMR18, #SIKESubmission2]. In this paper, we develop a highly optimized \mathbb{F}_{p} Montgomery multiplication algorithm and architecture that further utilizes the special form of SIKE prime compared to previous implementations available in the literature. We furthermore improve the scheduling for our program Rom. As SIKE Stays as an alternate candidate in Round 3 of standardization it has high potential to be standardized in Round 4. Therefore, we implement SIKE for all Round 2 NIST security levels (SIKEp434 for NIST security level 1, SIKEp503 for NIST security level 2, SIKEp610 for NIST security level 3, and SIKEp751 for NIST security level 5) on Xilinx Artix 7 and Xilinx Virtex 7 using the proposed multiplier. Our best implementation (NIST security level 1) runs 38% faster and occupies 30% less hardware resources in comparison to the leading counterpart available in the literature [#brian-2019] and implementations for other security levels achieved similar improvement. Rami El Khatib, Reza Azarderakhsh, Mehran Mozaffari Kermani |
IEEE Trans. Computers | 1 |
| 2022 | Accelerated RISC-V for Post-Quantum SIKEabstractIn this work, we present a fast and area-efficient software-hardware implementation of the supersingular isogeny key encapsulation (SIKE) mechanism. Our software-hardware design achieves both the flexibility of software as well as the efficient performance of intense computations of hardware. In particular, our implementation takes advantage of new and highly optimized hardware modules for addition, multiplication, and hardware-software control, targeted at Xilinx FPGAs. In conjunction with a small RISC-V processor, we can support all four SIKE parameter sets. On a Virtex-7 FPGA, this implementation occupies 3,492 slices, 78 DSPs, and 29 BRAMs, to perform encapsulation and decapsulation over SIKEp434, SIKEp503, SIKEp610, and SIKEp751 in 14.5, 19.2, 29.8, and 42.7 ms, respectively. Despite supporting all four parameter sets, this design has the best area-time product of all isogeny accelerators in the literature. Rami El Khatib, Brian Koziel, Reza Azarderakhsh, Mehran Mozaffari Kermani |
IEEE Trans. Circuits Syst. I Regul. Pap. | 1 |
| 2021 | Accelerated RISC-V for SIKEabstractSoftware implementations of cryptographic algorithms are slow but highly flexible and relatively easy to implement. On the other hand, hardware implementations are usually faster but provide little flexibility and require a lot of time to implement efficiently. In this paper, we develop a hybrid software-hardware implementation of the third round of Supersingular Isogeny Key Encapsulation (SIKE), a post-quantum cryptography algorithm candidate for NIST. We implement an isogeny field accelerator for the hardware and integrate it with a RISC-V processor which also acts as the main control unit for the field accelerator. The main advantage of this design is the high performance gain from the hardware implementation and the flexibility and fast development the software implementation provides. This is the first hybrid RISC-V and accelerator of SIKE. Furthermore, we provide one implementation for all NIST security levels of SIKE. Our design has the best area-time at NIST security levels 3 and 5 out of all hardware and hybrid designs provided in the literature. Rami El Khatib, Reza Azarderakhsh, Mehran Mozaffari Kermani |
ARITH | 1 |
| 2021 | Hardware Deployment of Hybrid PQC: SIKE+ECDH
Reza Azarderakhsh, Rami El Khatib, Brian Koziel, Brandon Langenberg |
SecureComm (2) | 2 |
| 2020 | Highly Optimized Montgomery Multiplier for SIKE Primes on FPGAabstractNew primes were proposed for Supersingular Isogeny Key Encapsulation (SIKE) in NIST standardization process of Round 2 after further cryptanalysis research showed that the security levels of the initial primes chosen were overestimated [1], [2]. In this paper, we develop a highly optimized EpMontgomery multiplication algorithm and architecture that further utilizes the special form of SIKE prime compared to previous implementations available in the literature. We then implement SIKE for all Round 2 NIST security levels (SIKEp434 for NIST security level 1, SIKEp503 for NIST security level 2, SIKEp610 for NIST security level 3, and SIKEp751 for NIST security level 5) on Xilinx Virtex 7 using the proposed multiplier. Our best implementation (NIST security level 1) runs 29% faster and occupies 30% less hardware resources in comparison to the leading counterpart available in the literature [3] and implementations for other security levels achieved similar improvement. Rami El Khatib, Reza Azarderakhsh, Mehran Mozaffari Kermani |
ARITH | 1 |
| 2020 | Fast, Small, and Area-Time Efficient Architectures for Key-Exchange on Curve25519abstractThis paper demonstrates fast and compact implementations of Elliptic Curve Cryptography (ECC) for efficient key agreement over Curve25519. Curve25519 has been recently adopted as a key exchange method for several applications and included in the National Institute of Standards and Technology (NIST) recommendations for public key cryptography. This paper presents three different performance level designs including lightweight, area-time efficient, and high-performance architectures. Lightweight hardware implementations are used for several Internet of Things (IoT) applications due to their resources being at premium. Our lightweight architecture utilizes 90% less resources compared to the best previous work while it is still more optimized in term of A middot; T (area×time). For efficient implementation from either time or utilized resources, our area-time efficient architecture can establish almost 7,000 key sessions per second which is 64% faster than the previous works. The area-time efficient architecture uses well scheduled interleaved multiplication combined with a reduction algorithm. Additionally, we offer a fast architecture for high performance applications based on the 4-level Karatsuba method and Carry-Compact Addition (CCA). Our high-performance architecture also outperforms previous work in terms of A middot; T. The results show 9% and 29% improvement in A middot; T and Admiddot;T (DSP_count×time), respectively. All architectures are variable-base-point implemented on the Xilinx Zynq-7020 FPGA family where performance and implementation metrics are reported and compared. Finally, various side-channel attack countermeasures are embedded in the proposed architectures. Mojtaba Bisheh-Niasar, Rami El Khatib, Reza Azarderakhsh, Mehran Mozaffari Kermani |
ARITH | 2 |
| 2019 | Optimized Algorithms and Architectures for Montgomery Multiplication for Post-quantum Cryptography
Rami El Khatib, Reza Azarderakhsh, Mehran Mozaffari Kermani |
CANS | 1 |