Gaussian Sampling over the Integers: Efficient, Generic, Constant-Time

1 602
26.7
Опубликовано 27 июля 2017, 22:32
Sampling integers with Gaussian distribution is a fundamental problem that arises in almost every application of lattice cryptography, and it can be both time consuming and challenging to implement. Most previous work has focused on the optimization and implementation of integer Gaussian sampling in the context of specific applications, with fixed sets of parameters. We present new algorithms for discrete Gaussian sampling that are both generic (application independent), efficient, and more easily implemented in constant time without incurring a substantial slow-down, making them more resilient to side-channel (e.g., timing) attacks. In the process, we also present new analytical techniques that can be used to simplify the precision/security evaluation of floating point cryptographic algorithms, and showing that standard double precision (53-bit) floating numbers are typically enough to achieve high (>100-bit) level of security. 

See more on this video at microsoft.com/en-us/research/v...
Случайные видео
110 дней – 506 4808:00
Tips and Must-Have Tools for Small Shops
327 дней – 125 81721:53
Adam Savage Fixes His New Belt Sander!
11.07.21 – 14 4030:17
5000mAh(typ) + #RedmiNote10 5G = ?
автотехномузыкадетское