CIRCL
hertzbleed
CIRCL | hertzbleed | |
---|---|---|
6 | 4 | |
1,182 | 430 | |
1.9% | 0.0% | |
8.0 | 0.0 | |
7 days ago | over 1 year ago | |
Go | Python | |
GNU General Public License v3.0 or later | University of Illinois/NCSA Open Source License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
CIRCL
-
Lattice Asymetric Encryption
- https://github.com/cloudflare/circl
- Circl: Cloudflare Interoperable Reusable Cryptographic Library
-
Is the reference implementation of Classic McEliece in the NIST submission the only good source available for developers out there? General post-quantum questions.
I'm not sure if portability, speed, or general security is on require level here, but Cloudflare's CIRCL library is working on adding support for McEliece, you can find the implementation PR at https://github.com/cloudflare/circl/pull/378
- NIST post-quantum picks Kyber and Dilithium in Go
- NIST announces PQC-algoritms to be standardized
-
Hertzbleed Attack
The attack in question was only tested on SIKE, so it seems logical to start targeted disclosure on the community using and developing it, while using the general disclosures to target the broader cryptographic community.
Both Cloudflare and Microsoft are one of the few companies that have put significant investments into developing SIKE for post-quantum cryptography. Microsoft has a SIKE research team, and Cloudflare has been exploring SIKE for post-quantum TLS for years.
Both companies also maintain the key open-source implementations of SIKE [1][2], and Microsoft is spearheading the effort to standardize SIKE through NIST. Most open source cryptographic libraries don't implement SIKE.
[1]: https://github.com/cloudflare/circl
hertzbleed
- GitHub - FPSG-UIUC/hertzbleed
-
Hertzbleed Attack
The scientific article URL is broken, see correct link:
https://github.com/FPSG-UIUC/hertzbleed/pull/4
19 pages of detail, "Hertzbleed: Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86 (USENIX 2022)"
-
Hertzbleed
Research - https://github.com/FPSG-UIUC/hertzbleed - https://www.hertzbleed.com/hertzbleed.pdf
Code: https://github.com/FPSG-UIUC/hertzbleed
What are some alternatives?
kyber
PQCrypto-SIKE - This software is part of "Supersingular Isogeny Key Encapsulation", a submission to the NIST Post-Quantum Standardization project.
liboqs-go - Go bindings for liboqs
yubisigner - YubiSigner provides a convenient way to sign and securely verify file signatures with Yubico YubiKey, utilizing an organization's PKI infrastructure.
falcon.py - A python implementation of the signature scheme Falcon
curve25519-voi - High-performance Curve25519/ristretto255 for Go.
secp256k1-voi - High assurance Go secp256k1 (Mirror)
falcon
pqcrypto.js
kyber-k2so - Go implementation of the Kyber (version 3) post-quantum IND-CCA2 KEM.
pqc.js - JS bindings and playground of post-quantum asymmetric ciphers