[PDF][PDF] CRYSTALS-Kyber algorithm specifications and supporting documentation

R Avanzi, J Bos, L Ducas, E Kiltz, T Lepoint… - NIST PQC …, 2019 - pq-crystals.org
• Increase noise parameter for Kyber512 In the round-2 submission of Kyber, the decryption
error for Kyber512 was rather conservative, while at the same time, there were requests to …

NTT multiplication for NTT-unfriendly rings: New speed records for Saber and NTRU on Cortex-M4 and AVX2

CMM Chung, V Hwang, MJ Kannwischer… - IACR Transactions on …, 2021 - tches.iacr.org
In this paper, we show how multiplication for polynomial rings used in the NIST PQC finalists
Saber and NTRU can be efficiently implemented using the Number-theoretic transform …

High-speed NTT-based polynomial multiplication accelerator for post-quantum cryptography

M Bisheh-Niasar, R Azarderakhsh… - 2021 IEEE 28th …, 2021 - ieeexplore.ieee.org
This paper demonstrates an architecture for accelerating the polynomial multiplication using
number theoretic transform (NTT). Kyber is one of the finalists in the third round of the NIST …

RISQ-V: Tightly coupled RISC-V accelerators for post-quantum cryptography

T Fritzmann, G Sigl, J Sepúlveda - IACR Transactions on …, 2020 - tches.iacr.org
Empowering electronic devices to support Post-Quantum Cryptography (PQC) is a
challenging task. PQC introduces new mathematical elements and operations which are …

Masked accelerators and instruction set extensions for post-quantum cryptography

T Fritzmann, M Van Beirendonck… - IACR …, 2022 - philosophymindscience.org
Side-channel attacks can break mathematically secure cryptographic systems leading to a
major concern in applied cryptography. While the cryptanalysis and security evaluation of …

Compact dilithium implementations on Cortex-M3 and Cortex-M4

DOC Greconici, MJ Kannwischer… - IACR Transactions on …, 2021 - tches.iacr.org
We present implementations of the lattice-based digital signature scheme Dilithium for ARM
Cortex-M3 and ARM Cortex-M4. Dilithium is one of the three signature finalists of the NIST …

Neon ntt: Faster dilithium, kyber, and saber on cortex-a72 and apple m1

H Becker, V Hwang, MJ Kannwischer… - Cryptology ePrint …, 2021 - eprint.iacr.org
We present new speed records on the Armv8-A architecture for the lattice-based schemes
Dilithium, Kyber, and Saber. The core novelty in this paper is the combination of …

Faster kyber and dilithium on the cortex-m4

A Abdulrahman, V Hwang, MJ Kannwischer… - … Conference on Applied …, 2022 - Springer
This paper presents faster implementations of the lattice-based schemes Dilithium and
Kyber on the Cortex-M4. Dilithium is one of three signature finalists in the NIST post …

Kyber on ARM64: Compact implementations of Kyber on 64-bit ARM Cortex-A processors

P Sanal, E Karagoz, H Seo, R Azarderakhsh… - … Conference on Security …, 2021 - Springer
Public-key cryptography based on the lattice problem is efficient and believed to be secure
in a post-quantum era. In this paper, we introduce carefully-optimized implementations of …

A high-performance domain-specific processor with matrix extension of RISC-V for module-LWE applications

Y Zhao, R **e, G **n, J Han - IEEE Transactions on Circuits and …, 2022 - ieeexplore.ieee.org
The 5G edge computing infrastructure should be empowered with quantum attack resistance
by implementing post-quantum cryptography (PQC). Among various PQC schemes, lattice …