Skip to Main content Skip to Navigation
Conference papers

Fast Lattice-Based Encryption: Stretching Spring

Abstract : The SPRING pseudo-random function (PRF) has been described by Banerjee, Brenner, Leurent, Peikert and Rosen at FSE 2014. It is quite fast, only 4.5 times slower than the AES (without hardware acceleration) when used in counter mode. SPRING is similar to the PRF of Banerjee, Peikert and Rosen from EUROCRYPT 2012, whose security relies on the hardness of the Learning With Rounding (LWR) problem, which can itself be reduced to hard lattice problems. However, there is no such chain of reductions relating SPRING to lattice problems, because it uses small parameters for efficiency reasons. Consequently, the heuristic security of SPRING is evaluated using known attacks and the complexity of the best known algorithms for breaking the underlying hard problem. In this paper, we revisit the efficiency and security of SPRING when used as a pseudo-random generator. We propose a new variant which is competitive with the AES in counter mode without hardware AES acceleration, and about four times slower than AES with hardware acceleration. In terms of security, we improve some previous analysis of SPRING and we estimate the security of our variant against classical algorithms and attacks. Finally, we implement our variant using AVX2 instructions, resulting in high performances on high-end desktop computers .
Document type :
Conference papers
Complete list of metadata

Cited literature [8 references]  Display  Hide  Download
Contributor : Charles Bouillaguet Connect in order to contact the contributor
Submitted on : Sunday, December 3, 2017 - 10:44:37 PM
Last modification on : Friday, January 7, 2022 - 3:43:51 AM


Files produced by the author(s)


  • HAL Id : hal-01654408, version 1


Charles Bouillaguet, Claire Delaplace, Pierre-Alain Fouque, Paul Kirchner. Fast Lattice-Based Encryption: Stretching Spring. International Workshop on Post-Quantum Cryptography, Jun 2017, Utrecht, Netherlands. ⟨hal-01654408⟩



Les métriques sont temporairement indisponibles