{"id":"https://openalex.org/W2944971662","doi":"https://doi.org/10.1145/3316781.3317887","title":"Pushing the speed limit of constant-time discrete Gaussian sampling. A case study on the Falcon signature scheme","display_name":"Pushing the speed limit of constant-time discrete Gaussian sampling. A case study on the Falcon signature scheme","publication_year":2019,"publication_date":"2019-05-23","ids":{"openalex":"https://openalex.org/W2944971662","doi":"https://doi.org/10.1145/3316781.3317887","mag":"2944971662"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/3316781.3317887","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://birmingham.elsevierpure.com/files/67769723/Pushing_the_speed_limit.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5044163841","display_name":"Angshuman Karmakar","orcid":"https://orcid.org/0000-0003-2594-588X"},"institutions":[{"id":"https://openalex.org/I4210114974","display_name":"IMEC","ror":"https://ror.org/02kcbn207","country_code":"BE","type":"nonprofit","lineage":["https://openalex.org/I4210114974"]},{"id":"https://openalex.org/I99464096","display_name":"KU Leuven","ror":"https://ror.org/05f950310","country_code":"BE","type":"funder","lineage":["https://openalex.org/I99464096"]}],"countries":["BE"],"is_corresponding":false,"raw_author_name":"Angshuman Karmakar","raw_affiliation_strings":["imec-COSIC, KU Leuven, Leuven-Heverlee, Belgium"],"affiliations":[{"raw_affiliation_string":"imec-COSIC, KU Leuven, Leuven-Heverlee, Belgium","institution_ids":["https://openalex.org/I4210114974","https://openalex.org/I99464096"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5089396173","display_name":"Sujoy Sinha Roy","orcid":"https://orcid.org/0000-0002-9805-5389"},"institutions":[{"id":"https://openalex.org/I79619799","display_name":"University of Birmingham","ror":"https://ror.org/03angcq70","country_code":"GB","type":"funder","lineage":["https://openalex.org/I79619799"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Sujoy Sinha Roy","raw_affiliation_strings":["School of Computer Science, University of Birmingham, United Kingdom"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, University of Birmingham, United Kingdom","institution_ids":["https://openalex.org/I79619799"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5032574536","display_name":"Fr\u00e9derik Vercauteren","orcid":"https://orcid.org/0000-0002-7208-9599"},"institutions":[{"id":"https://openalex.org/I4210114974","display_name":"IMEC","ror":"https://ror.org/02kcbn207","country_code":"BE","type":"nonprofit","lineage":["https://openalex.org/I4210114974"]},{"id":"https://openalex.org/I99464096","display_name":"KU Leuven","ror":"https://ror.org/05f950310","country_code":"BE","type":"funder","lineage":["https://openalex.org/I99464096"]}],"countries":["BE"],"is_corresponding":false,"raw_author_name":"Frederik Vercauteren","raw_affiliation_strings":["imec-COSIC, KU Leuven, Leuven-Heverlee, Belgium"],"affiliations":[{"raw_affiliation_string":"imec-COSIC, KU Leuven, Leuven-Heverlee, Belgium","institution_ids":["https://openalex.org/I4210114974","https://openalex.org/I99464096"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5082347771","display_name":"Ingrid Verbauwhede","orcid":"https://orcid.org/0000-0002-0879-076X"},"institutions":[{"id":"https://openalex.org/I99464096","display_name":"KU Leuven","ror":"https://ror.org/05f950310","country_code":"BE","type":"funder","lineage":["https://openalex.org/I99464096"]},{"id":"https://openalex.org/I4210114974","display_name":"IMEC","ror":"https://ror.org/02kcbn207","country_code":"BE","type":"nonprofit","lineage":["https://openalex.org/I4210114974"]}],"countries":["BE"],"is_corresponding":false,"raw_author_name":"Ingrid Verbauwhede","raw_affiliation_strings":["imec-COSIC, KU Leuven, Leuven-Heverlee, Belgium"],"affiliations":[{"raw_affiliation_string":"imec-COSIC, KU Leuven, Leuven-Heverlee, Belgium","institution_ids":["https://openalex.org/I99464096","https://openalex.org/I4210114974"]}]}],"institution_assertions":[],"countries_distinct_count":2,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.058,"has_fulltext":true,"fulltext_origin":"pdf","cited_by_count":18,"citation_normalized_percentile":{"value":0.751346,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":91},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11017","display_name":"Chaos-based Image/Signal Encryption","score":0.9932,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10304","display_name":"Geometric and Algebraic Topology","score":0.9901,"subfield":{"id":"https://openalex.org/subfields/2608","display_name":"Geometry and Topology"},"field":{"id":"https://openalex.org/fields/26","display_name":"Mathematics"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/lattice-based-cryptography","display_name":"Lattice-based Cryptography","score":0.50534016},{"id":"https://openalex.org/keywords/rejection-sampling","display_name":"Rejection sampling","score":0.42694843}],"concepts":[{"id":"https://openalex.org/C163716315","wikidata":"https://www.wikidata.org/wiki/Q901177","display_name":"Gaussian","level":2,"score":0.76312315},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5784631},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.5736464},{"id":"https://openalex.org/C137660015","wikidata":"https://www.wikidata.org/wiki/Q6497083","display_name":"Lattice-based cryptography","level":5,"score":0.50534016},{"id":"https://openalex.org/C118463975","wikidata":"https://www.wikidata.org/wiki/Q220849","display_name":"Digital signature","level":3,"score":0.4609348},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.44297582},{"id":"https://openalex.org/C140779682","wikidata":"https://www.wikidata.org/wiki/Q210868","display_name":"Sampling (signal processing)","level":3,"score":0.44132686},{"id":"https://openalex.org/C187192777","wikidata":"https://www.wikidata.org/wiki/Q381699","display_name":"Rejection sampling","level":5,"score":0.42694843},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.35722017},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.3494857},{"id":"https://openalex.org/C99138194","wikidata":"https://www.wikidata.org/wiki/Q183427","display_name":"Hash function","level":2,"score":0.22587886},{"id":"https://openalex.org/C144901912","wikidata":"https://www.wikidata.org/wiki/Q471906","display_name":"Quantum cryptography","level":4,"score":0.14909422},{"id":"https://openalex.org/C84114770","wikidata":"https://www.wikidata.org/wiki/Q46344","display_name":"Quantum","level":2,"score":0.12365031},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.11118868},{"id":"https://openalex.org/C107673813","wikidata":"https://www.wikidata.org/wiki/Q812534","display_name":"Bayesian probability","level":2,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.0},{"id":"https://openalex.org/C106131492","wikidata":"https://www.wikidata.org/wiki/Q3072260","display_name":"Filter (signal processing)","level":2,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C111350023","wikidata":"https://www.wikidata.org/wiki/Q1191869","display_name":"Markov chain Monte Carlo","level":3,"score":0.0},{"id":"https://openalex.org/C169699857","wikidata":"https://www.wikidata.org/wiki/Q2122243","display_name":"Quantum information","level":3,"score":0.0},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C37669827","wikidata":"https://www.wikidata.org/wiki/Q6904703","display_name":"Monte Carlo molecular modeling","level":4,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/3316781.3317887","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"https://research.birmingham.ac.uk/portal/en/publications/pushing-the-speed-limit-of-constanttime-discrete-gaussian-sampling-a-case-study-on-the-falcon-signature-scheme(43615c1c-7066-4313-8061-6c88973566f3).html","pdf_url":"https://birmingham.elsevierpure.com/files/67769723/Pushing_the_speed_limit.pdf","source":{"id":"https://openalex.org/S4306402634","display_name":"University of Birmingham Research Portal (University of Birmingham)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I79619799","host_organization_name":"University of Birmingham","host_organization_lineage":["https://openalex.org/I79619799"],"host_organization_lineage_names":["University of Birmingham"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"publishedVersion","is_accepted":true,"is_published":true},{"is_oa":true,"landing_page_url":"http://pure-oai.bham.ac.uk/ws/files/67769723/Pushing_the_speed_limit.pdf","pdf_url":"http://pure-oai.bham.ac.uk/ws/files/67769723/Pushing_the_speed_limit.pdf","source":{"id":"https://openalex.org/S4306402634","display_name":"University of Birmingham Research Portal (University of Birmingham)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I79619799","host_organization_name":"University of Birmingham","host_organization_lineage":["https://openalex.org/I79619799"],"host_organization_lineage_names":["University of Birmingham"],"type":"repository"},"license":"public-domain","license_id":"https://openalex.org/licenses/public-domain","version":"publishedVersion","is_accepted":true,"is_published":true},{"is_oa":true,"landing_page_url":"https://lirias.kuleuven.be/handle/123456789/641875","pdf_url":"https://lirias.kuleuven.be/bitstream/123456789/641875/2/article-3007.pdf","source":{"id":"https://openalex.org/S4306401954","display_name":"Lirias (KU Leuven)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I99464096","host_organization_name":"KU Leuven","host_organization_lineage":["https://openalex.org/I99464096"],"host_organization_lineage_names":["KU Leuven"],"type":"repository"},"license":"public-domain","license_id":"https://openalex.org/licenses/public-domain","version":"acceptedVersion","is_accepted":true,"is_published":false}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://research.birmingham.ac.uk/portal/en/publications/pushing-the-speed-limit-of-constanttime-discrete-gaussian-sampling-a-case-study-on-the-falcon-signature-scheme(43615c1c-7066-4313-8061-6c88973566f3).html","pdf_url":"https://birmingham.elsevierpure.com/files/67769723/Pushing_the_speed_limit.pdf","source":{"id":"https://openalex.org/S4306402634","display_name":"University of Birmingham Research Portal (University of Birmingham)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I79619799","host_organization_name":"University of Birmingham","host_organization_lineage":["https://openalex.org/I79619799"],"host_organization_lineage_names":["University of Birmingham"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"publishedVersion","is_accepted":true,"is_published":true},"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":24,"referenced_works":["https://openalex.org/W1014461153","https://openalex.org/W1511255594","https://openalex.org/W1548516269","https://openalex.org/W1595771334","https://openalex.org/W1614548964","https://openalex.org/W1972050218","https://openalex.org/W2038619601","https://openalex.org/W2140256428","https://openalex.org/W2404668229","https://openalex.org/W2412886904","https://openalex.org/W2494078997","https://openalex.org/W2613335035","https://openalex.org/W2741654699","https://openalex.org/W2792220042","https://openalex.org/W2796314191","https://openalex.org/W2888804078","https://openalex.org/W2900370870","https://openalex.org/W2949834252","https://openalex.org/W2950169363","https://openalex.org/W2951956639","https://openalex.org/W2953028926","https://openalex.org/W3028781487","https://openalex.org/W4248003330","https://openalex.org/W72736654"],"related_works":["https://openalex.org/W4225280523","https://openalex.org/W4200520489","https://openalex.org/W3194820855","https://openalex.org/W2989065323","https://openalex.org/W2900370870","https://openalex.org/W2375742443","https://openalex.org/W2149381099","https://openalex.org/W2083767537","https://openalex.org/W2038619601","https://openalex.org/W1598269861"],"abstract_inverted_index":{"Sampling":[0],"from":[1,67],"a":[2,23,34,43,75,127,165],"discrete":[3,50,101,176],"Gaussian":[4,24,51,102,116,177],"distribution":[5],"has":[6],"applications":[7],"in":[8,18,96,118,179],"lattice-based":[9,120],"post-quantum":[10],"cryptography.":[11],"Several":[12],"efficient":[13,48,82],"solutions":[14],"have":[15],"been":[16],"proposed":[17],"recent":[19],"years.":[20],"However,":[21],"making":[22],"sampler":[25,52,117],"secure":[26,115],"against":[27],"timing":[28],"attacks":[29],"turned":[30],"out":[31],"to":[32,45,72,98,105,149],"be":[33,184],"challenging":[35],"research":[36],"problem.":[37],"In":[38],"this":[39],"work,":[40],"we":[41,110],"present":[42],"toolchain":[44],"instantiate":[46],"an":[47,61,81],"constant-time":[49],"of":[53,64,84,138,153,160,175],"arbitrary":[54],"standard":[55],"deviation":[56],"and":[57,79,114,130],"precision.":[58],"We":[59],"observe":[60],"interesting":[62],"property":[63],"the":[65,86,90,106,119,135,139,150,157,173],"mapping":[66],"input":[68],"random":[69,161],"bit":[70],"strings":[71],"samples":[73,178],"during":[74],"Knuth-Yao":[76],"sampling":[77,103],"algorithm":[78,123,141],"propose":[80],"way":[83],"minimizing":[85],"Boolean":[87],"expressions":[88],"for":[89],"mapping.":[91],"Our":[92],"minimization":[93],"approach":[94],"results":[95,169],"up":[97],"37%":[99],"faster":[100],"compared":[104],"previous":[107],"work.":[108],"Finally,":[109],"apply":[111],"our":[112,168],"optimized":[113],"digital":[121,180],"signature":[122,181],"Falcon,":[124],"which":[125],"is":[126],"NIST":[128],"submission,":[129],"provide":[131],"experimental":[132],"evidence":[133],"that":[134,172],"overall":[136],"performance":[137],"signing":[140],"degrades":[142],"by":[143],"at":[144],"most":[145],"33%":[146],"only":[147],"due":[148],"additional":[151],"overhead":[152,159],"'constant-time'":[154],"sampling,":[155],"including":[156],"60%":[158],"number":[162],"generation.":[163],"Breaking":[164],"general":[166],"belief,":[167],"indirectly":[170],"show":[171],"use":[174],"algorithms":[182],"would":[183],"beneficial.":[185]},"abstract_inverted_index_v3":null,"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W2944971662","counts_by_year":[{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":6},{"year":2021,"cited_by_count":1},{"year":2020,"cited_by_count":8},{"year":2019,"cited_by_count":1}],"updated_date":"2025-02-25T11:28:09.958430","created_date":"2019-05-29"}