Today’s cryptographic standards are threatened by the rapid advancement in the research and development of quantum computers. To address this problem, the National Institute of Standards and Technologies (NIST) is working for the development and implementation of cryptographic schemes that are resistant to quantum computing. For this reason, NIST has launched multiple competitions, aiming to standardize post-quantum cryptography (PQC), by gathering and evaluating schemes developed by industry, governments and academic institutions. A fundamental requirement for all proposed digital signature algorithms is the generation of secure pseudo-random objects. This thesis presents the RandShaper library, a framework designed to support these schemes in the generation and shaping of such objects, including modular numbers, fixed-weight strings and permutations. RandShaper starts from binary strings generated by various PRNGs, and implements efficient and, when possible, side-channel-resistant (constant-time) techniques to obtain the target pseudo-random objects. Finally, performance assessments are conducted by benchmarking all the methods implemented within the library, using the parameters of the NIST digital signature candidates to evaluate both computational efficiency and entropy consumption.

Gli attuali standard crittografici sono minacciati dai rapidi progressi nella ricerca e nello sviluppo dei computer quantistici. Per far fronte a questo problema, il National Institute of Standards and Technologies (NIST) sta lavorando allo sviluppo e all’implementazione di schemi crittografici resistenti al calcolo quantistico. Per questa ragione, il NIST ha indetto diverse competizioni con l’obiettivo di standardizzare la crittografia post-quantum (PQC), raccogliendo e valutando algoritmi proposti dall’industria, dai governi e dalle istituzioni accademiche. Un requisito fondamentale per tutti gli algoritmi di firma digitale proposti è la generazione sicura di oggetti pseudo-casuali. Questa tesi presenta la libreria RandShaper, un framework progettato per supportare tali schemi nella generazione e strutturazione (shaping) di questi oggetti, tra cui numeri modulari, stringhe a peso fisso e permutazioni. RandShaper parte da stringhe binarie generate da vari PRNG e implementa tecniche efficienti e, quando possibile, resistenti agli attacchi side-channel (a tempo costante) per ottenere gli oggetti pseudo-casuali desiderati. Infine, sono state condotte delle valutazioni prestazionali testando tutti i metodi implementati all’interno della libreria, utilizzando i parametri dei candidati per le firme digitali del NIST per valutarne sia l’efficienza computazionale sia il consumo di entropia.

RandShaper: a library for the secure shaping of pseudo-random objects for post-quantum cryptography

Pozzi, Marco
2025/2026

Abstract

Today’s cryptographic standards are threatened by the rapid advancement in the research and development of quantum computers. To address this problem, the National Institute of Standards and Technologies (NIST) is working for the development and implementation of cryptographic schemes that are resistant to quantum computing. For this reason, NIST has launched multiple competitions, aiming to standardize post-quantum cryptography (PQC), by gathering and evaluating schemes developed by industry, governments and academic institutions. A fundamental requirement for all proposed digital signature algorithms is the generation of secure pseudo-random objects. This thesis presents the RandShaper library, a framework designed to support these schemes in the generation and shaping of such objects, including modular numbers, fixed-weight strings and permutations. RandShaper starts from binary strings generated by various PRNGs, and implements efficient and, when possible, side-channel-resistant (constant-time) techniques to obtain the target pseudo-random objects. Finally, performance assessments are conducted by benchmarking all the methods implemented within the library, using the parameters of the NIST digital signature candidates to evaluate both computational efficiency and entropy consumption.
ING - Scuola di Ingegneria Industriale e dell'Informazione
22-lug-2026
2025/2026
Gli attuali standard crittografici sono minacciati dai rapidi progressi nella ricerca e nello sviluppo dei computer quantistici. Per far fronte a questo problema, il National Institute of Standards and Technologies (NIST) sta lavorando allo sviluppo e all’implementazione di schemi crittografici resistenti al calcolo quantistico. Per questa ragione, il NIST ha indetto diverse competizioni con l’obiettivo di standardizzare la crittografia post-quantum (PQC), raccogliendo e valutando algoritmi proposti dall’industria, dai governi e dalle istituzioni accademiche. Un requisito fondamentale per tutti gli algoritmi di firma digitale proposti è la generazione sicura di oggetti pseudo-casuali. Questa tesi presenta la libreria RandShaper, un framework progettato per supportare tali schemi nella generazione e strutturazione (shaping) di questi oggetti, tra cui numeri modulari, stringhe a peso fisso e permutazioni. RandShaper parte da stringhe binarie generate da vari PRNG e implementa tecniche efficienti e, quando possibile, resistenti agli attacchi side-channel (a tempo costante) per ottenere gli oggetti pseudo-casuali desiderati. Infine, sono state condotte delle valutazioni prestazionali testando tutti i metodi implementati all’interno della libreria, utilizzando i parametri dei candidati per le firme digitali del NIST per valutarne sia l’efficienza computazionale sia il consumo di entropia.
File allegati
File Dimensione Formato  
2026_07_Pozzi_Tesi.pdf

accessibile in internet per tutti

Descrizione: Tesi
Dimensione 1.04 MB
Formato Adobe PDF
1.04 MB Adobe PDF Visualizza/Apri
2026_07_Pozzi_Executive Summary.pdf

accessibile in internet per tutti

Descrizione: Executive Summary
Dimensione 512.45 kB
Formato Adobe PDF
512.45 kB Adobe PDF Visualizza/Apri

I documenti in POLITesi sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10589/260696