In 2023, NIST selected Falcon as one of the quantum–resistant digital signatures, which uses the hash-and-sign paradigm in the style of Gentry–Peikert–Vaikuntanathan framework and instantiated over NTRU lattices. SOLMAE, as a variant of Falcon, was submitted to KpqC competition by taking all the pros of Falcon and Mitaka and reducing their cons as much as possible. In this paper, we analyze the asymptotic computational complexity of Falcon and SOLMAE that take \(\varTheta (n \log n)\) in their KeyGen, Sign and Verif procedures simultaneously and verify their performance by ANSI C language implementation. Our experiment shows that SOLMAE achieves the same high security and short key and signature sizes as Falcon, but it has faster Sign procedure than Falcon, while taking a bit longer time in KeyGen procedure. However, the Sign and Verif procedures of SOLMAE-512 is about 10 times faster than those of ECDSA P256r1 currently used in TSL or SSL.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Asymptotic Complexity and Performance Comparison of Falcon and SOLMAE using their C Implementation

  • Kwangjo Kim,
  • YeonJun Kim

摘要

In 2023, NIST selected Falcon as one of the quantum–resistant digital signatures, which uses the hash-and-sign paradigm in the style of Gentry–Peikert–Vaikuntanathan framework and instantiated over NTRU lattices. SOLMAE, as a variant of Falcon, was submitted to KpqC competition by taking all the pros of Falcon and Mitaka and reducing their cons as much as possible. In this paper, we analyze the asymptotic computational complexity of Falcon and SOLMAE that take \(\varTheta (n \log n)\) in their KeyGen, Sign and Verif procedures simultaneously and verify their performance by ANSI C language implementation. Our experiment shows that SOLMAE achieves the same high security and short key and signature sizes as Falcon, but it has faster Sign procedure than Falcon, while taking a bit longer time in KeyGen procedure. However, the Sign and Verif procedures of SOLMAE-512 is about 10 times faster than those of ECDSA P256r1 currently used in TSL or SSL.