SMAUG-T update v4.0

154 views
Skip to first unread message

Hyoeun Seong

unread,
Oct 4, 2024, 7:39:13 AM10/4/24
to KpqC-bulletin

Dear all,
SMAUG-T version 4.0 is now available on GitHub.
Thanks to several analysis reports(vulnerabilities found from TIMECOP integrationimproved Meet-LWE, and reports on code errors), we have made improvements to the design and parameters.

The key updates are as follows:
  • Parameter updates: The parameter has been updated to increase the Hamming weight for the secret key. This update enhances secret randomness and reduces DFP while still meeting the targeted security.
  • New sparse CBD sampler: A newly designed secure and efficient sparse CBD is now used for ephemeral randomness generation in encap/decap. To improve side-channel resistance and efficiency, the fixed-weight sampler has been avoided in encap/decap.
  • HWT sampler: The fixed-weight sampler in key generation has been updated with a ternary version of the secure HWT sampler (2024/548) based on shuffling. Considering the reports on HWT sampling, the coefficient representation has been applied.
  • Multiplication: Polynomial multiplication has also been updated to use coefficient representation instead of its indices, utilizing NTT/Toom-Cook.

For the TiMER parameter, reference implementation has also been updated and the AVX2 implementation of it will be released shortly.

Best regards,
Team SMAUG-T

Hyoeun Seong

unread,
Oct 13, 2024, 9:12:45 PM10/13/24
to KpqC-bulletin
Dear all,
We have updated the AVX2 implementation of the TiMER parameter.

It's available in the additional_implemenation/TiMER_optimized_implemenation

Regards and thanks,
Team SMAUG-T

2024년 10월 4일 금요일 오후 8시 39분 13초 UTC+9에 Hyoeun Seong님이 작성:
Reply all
Reply to author
Forward
0 new messages