High Performance Cryptographic Engine PANAMA: Hardware Implementation G
Total Page:16
File Type:pdf, Size:1020Kb
High Performance Cryptographic Engine PANAMA: Hardware Implementation G. Selimis, P. Kitsos, and O. Koufopavlou VLSI Design Labotaroty Electrical & Computer Engineering Department, University of Patras Patras, Greece Email: [email protected] hardware implementations are more efficiency in FPGAs ABSTRACT than general purpose CPUs due to the fact that the algorithm specifications suits much better in FPGA structure. In this paper a hardware implementation of a dual operation cryptographic engine PANAMA is presented. The Typical application with high speed requirements is implementation of PANAMA algorithm can be used both as encryption or decryption of video-rate in conditional access a hash function and a stream cipher. A basic characteristic applications (e-g pay TV). The modern networks have been of PANAMA is a high degree of parallelism which has as implemented to satisfy the demand for high bandwidth result high rates for the overall system throughput. An other multimedia services. Then the switches which they are profit of the PANAMA is that one only architecture placed at the nodes of the network must provide high throughput. So if there is a need for secure networks, the supports two cryptographic operations – encryption/ systems in the network switches should not introduce delays. decryption and data hashing. The proposed system operates PANAMA [3] is a cryptographic module that can be used in 96.5 MHz frequency with maximum data rate 24.7 Gbps. both as a cryptographic hash function and as stream cipher in The proposed system outperforms previous any hash applications with ultra high speed requirements functions and stream ciphers implementations in terms of In this paper an efficient implementation of the PANAMA is performance. Additional techniques can increase the presented. The introduced system works either as a hash achieved throughput about 90%. function or stream cipher. The proposed implementation is suitable for application with ultra high speed data rates. Comparisons with other previous published hash functions 1. INTRODUCTION and stream ciphers implementations prove that the proposed Today more and more sensitive data is stored digitally. Bank one performs better in terms of overall system throughput. accounts, medical records and personal emails are some This paper is organized as follows: In section 2 the main categories that data must keep secure. The science of features of Hash Functions and Stream Ciphers are cryptography tries to encounter the lack of security. Data presented. In section 3 the PANAMA specifications are confidentiality, authentication, non-reputation and data given. The proposed Dual Operation Cryptographic Engine integrity are some of the main parts of cryptography. The PANAMA is presented in detail in section 4. The FPGA evolution of cryptography drove in very complex synthesis results are given in section 5, and finally section 6 cryptographic models which they could not be implemented concludes the paper. before some years. The revolution of computers and especially CMOS technology permit the design and the 2. DEFINITIONS implementation of systems with characteristics as limited area resources, low power consumption and high speed. Then due the CMOS technology known cryptographic 2.1 Hash Functions standards were implemented and today they provide secure The operation of a Hash function H is to map an input of transactions. arbitrary length into a fixed number of output bits, the hash The use of systems with increasing complexity, which value. Hash functions are used in cryptography mainly for usually are more secure, has as result low rate of throughput. authentication and digital signature schemes. The Last years the authors of new cryptographic algorithms try to requirements for a hash function are as follows: suit high complexity transformations in systems with the • The input can be of any length. view of high throughput rates. The assistance of FPGA and • Fixed - length output. ASIC technologies in this road is substantial. FPGAs • H(x) is relatively easy to compute for any given x. especially, are used for efficient and flexible implementations. When a current algorithm is broken and a • H(x) is one-way function which means that given a hash new standard is created (e.g. Advanced Encryption Standard- value h, it is computationally infeasible to find some AES [1]), it is perceivable that field devices are upgraded input x such that H(x) = h. with a new encryption algorithm [2]. In addition the • H(x) is collision-free which means it is computationally input bits (gamma stage- γ ). The stage updating infeasible to find any two messages x and y such that transformation ρ is given by the formula: H(x) = H(y). ρ = σ oθ o π o γ 2.2 Stream Ciphers Symbol “o” denotes the associative comparison of transformations where the right-most transformation While block ciphers operate on large blocks of data, stream executed first. ciphers typically operate on smaller units of plaintext, The PANAMA hash function transforms the information of usually bits. With a stream cipher, the transformation of arbitrary length to a hash result of 256 bits. It consists of these smaller plaintext units will vary, depending on when two processes: message padding and iteration phase. During they are encountered during the encryption process. Stream message padding the information is converted to a stream of cipher generates what is called a keystream (a sequence of data which its length is multiple of 256 while during bits used as a key). Encryption is accomplished by iteration phase the cryptographic module follows the below combining the keystream with the plaintext, usually with sequence diagram (Table 1). the bitwise XOR operation. Table 1. The sequence diagram of the hash function Time step t Mode Input Output 3. PANAMA ALGORITHM 0 reset ------ ------ 1,…,V Push p t ------ The basic elements of PANAMA [3] algorithm are a finite V=1,…,V+32 Pull ------ ------ state machine with a 544-bit state which called stateα , an V+33 Pull ------ H 8192-bit buffer and the state update transformation which The PANAMA stream encryption scheme is initialized by denoted by ρ . When the data of buffer and state machine first loading the 256-bit key K, the 256-bit diversification are updated then an iteration happens, Push or Pull. The parameter Q and performing 32 additional blank pull three possible modes for the PANAMA module are Reset, operations. During keystream generation an 8-word block z Push and Pull. In Reset mode the state α and buffer are set is delivered at the output for every iteration. The full to 0. In Push mode an 8-word input is applied and there is scenario of encryption / decryption process is shown in no output. In Pull mode there is no input and an 8-word Table 2. output is delivered. The buffer behaves as a linear feedback Table 2. The sequence diagram of the stream encryption scheme shift register that ensures that input bits are injected into the Time step t Mode Input Output 0 reset ------ ------ state α over a wide interval of iterations. In the Push mode 1,…,V Push t ------ the input to the shift register is formed by the external input, p in the Pull mode, by part of stateα . Figure 1 shows the V=1,…,V+32 Pull ------ ------ Push and Pull modes of PANAMA. V+33 Pull ------ H In practice, the diversification parameter allows for frequent p resynchronization without the need to change the key. 0 31 buffer stage ρ 4. PROPOSED ARCHITECTURE The proposed architecture is presented in Figure 2. α encryption/ decryption KEY 256-bit 256-bit internal PARAMETER Q 0 31 memory 256-bit decryption/ encryption DATA ρ 256-bit PADDING UNIT 256-bit 256-bit hash value BIT NUMBER PANAMA α HASH CONTROL CRYPTO Figure 1. Push (above) and Pull (below) modes of PANAMA The updating transformation ρ of the state has high Figure 2. PANAMA - proposed architecture diffusion and distributed nonlinearity. It combines four The operation of PANAMA system has two options. It can different transformations: one for nonlinearity (sigma stage- operate as keystream generator for data encryption and also σ ), one for bit dispersion (theta stage-θ ), one for inter-bit as hash function. In the following Figure 3 the PANAMA proposed VLSI implementation is presented in detail. diffusion (pi stage-π ), and one of injection of buffer and XOR. Due the fact that one transformation is executed in a Key 256-bit array of registers 256-bit Q 256-bit M clock cycle the whole system has very high throughput rate. H 256-bit U register X 256-bit 32-bit 32-bit 32-bit 256-bit 256-bit αi αi+1 αi+2 M U 256-bit X transformation 544-bit OR-32 crypto C O γ 1 2 • • • 18 hash register XOR-32 N γ π θ σ T 544-bit 32-bit R O 1 218 L 544-bit • • • input Shifting : LSB to MSB 012 29 30 31 A π alpha state 256-bit N α D • • • 3 4 5 2 1 0 544-bit output 544-bit 256-bit 32-bit 32-bit 32-bit α α θ 1 2 • • • 18 αi i+1 i+4 Figure 3. The PANAMA proposed architecture in details 544-bit XOR-32 256-bit The main components of proposed PANAMA crypto engine σ 1 2 • • • 18 XOR-32 are: the alpha stateα , the buffer, the transformation round 32-bit ρ and the control unit. The alpha state has memory storage 544-bit of 544 bits and it is implemented by (17 *32-bit) registers. The same policy has been applied for the construction of XOR-32 buffer. The buffer is an array of registers. As the Figure 3 shows shown that the buffer consists of 32 cells. Every cell has 8 words or 8*32-bit registers.