DocumentCode
1519550
Title
Packed AES-GCM Algorithm Suitable for AES/PCLMULQDQ Instructions
Author
Jankowski, Krzysztof ; Laurent, Pierre
Author_Institution
Intel, Shannon, Ireland
Volume
60
Issue
1
fYear
2011
Firstpage
135
Lastpage
138
Abstract
The level of interest in Galois Counter Mode (GCM) Authenticated Encryption rose significantly within the last few years. GCM is interesting because it is the only authenticated encryption standard that can be implemented in a fully pipelined or parallelized way and it is the most appropriate for encrypting packetized data. McGrew and Viega [CHECK END OF SENTENCE] described (but did not detail) how GHASH can be implemented with more than one multiplier operating in parallel. This paper details how that can be done and shows that, when N multipliers are used, and the multipliers use the approach of multiplying polynomials then applying a modular reduction, a single modular reduction can be used instead on N separate operations. This optimization can be used even when there is a single multiplier, which makes this implementation strategy have a broader appeal. Recently Intel has introduced new ISA instructions into the next generation CPU core, namely: AES family and PCLMULQDQ operating in XMM registers domain. In this paper, we discuss the example implementation of proposed GHASH modifications using above instructions.
Keywords
cryptography; polynomials; AES-PCLMULQDQ instructions; GHASH; Galois counter mode authenticated encryption standard; Intel; XMM registers domain; modular reduction; packed AES-GCM algorithm; polynomial multiplication; Authentication; Counting circuits; Cryptography; Data processing; Instruction sets; Payloads; Polynomials; Registers; Software algorithms; Software performance; AES; GCM; Software; data encryption; performance evaluation of algorithms.;
fLanguage
English
Journal_Title
Computers, IEEE Transactions on
Publisher
ieee
ISSN
0018-9340
Type
jour
DOI
10.1109/TC.2010.147
Filename
5487510
Link To Document