Configurable ML-KEM Processor With Memory-Based NTT

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing module-lattice-based key encapsulation mechanisms (ML-KEM) for post-quantum cryptography face challenges with high computational complexity, large key and public key sizes, and resource-intensive operations, making them difficult to implement in practical cryptography systems, especially as security levels increase.

Innovation Solution

A reconfigurable ML-KEM system using memory-based numbers theoretic transform (NTT) that supports multiple security levels (1, 3, and 5) by reconfiguring internal submodules through a main controller, employing a hardware architecture that includes modules for key generation, encapsulation, and decapsulation, utilizing a configurable NTT operation to reduce resource usage and enhance processing speed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ML-KEM uses higher security levels (stages 3 and 5), then security strength is improved, but computational complexity and resource usage increase significantly

Engineering Contradiction:
Improvesecurity strengthVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The ML-KEM processor is divided into multiple independent sampling modules (hash sampler, binomial sampler, rejection sampler) that can be selectively activated based on security level requirements. Each module handles specific cryptographic operations, allowing the system to segment computational tasks and activate only necessary modules for each security level, thereby reducing overall computational complexity while maintaining security strength.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The processor employs dynamic reconfiguration capability where the main controller selectively activates or deactivates specific sampling modules based on the required security level. This dynamic adjustment allows the system to optimize resource usage by enabling only the necessary modules for the current security level (stage 1, 3, or 5), preventing unnecessary computational overhead while maintaining the required security strength.

Inventive Principle:
Principle #15Dynamics

2Reliability

If ML-KEM increases key size and public key size for higher security, then security strength is improved, but processing time increases

Engineering Contradiction:
Improvesecurity strengthVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces traditional software-based cryptographic processing with a dedicated hardware processor that implements ML-KEM operations. The hardware architecture includes specialized modules for hash sampling, binomial sampling, and rejection sampling that perform cryptographic operations in parallel and at fixed speeds, eliminating the variability and slowness of software processing. This mechanical substitution of hardware for software significantly reduces processing time while handling larger key sizes required for higher security levels.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The processor is designed to continuously process cryptographic operations without interruption once initialized. The sampling modules operate in continuous pipelines, with the hash sampler continuously generating random values, the binomial sampler continuously processing these values, and the rejection sampler continuously performing modular operations. This continuous operation minimizes idle time and maintains high processing throughput even when handling large key sizes for enhanced security.

Inventive Principle:
Principle #20Continuity of useful action

3Productivity

If ML-KEM uses traditional pipeline-based NTT, then processing speed is improved, but resource usage increases

Engineering Contradiction:
Improveprocessing speedVSAvoidresource usage
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent merges the NTT (Number Theoretic Transform) and INTT (Inverse NTT) operations into a single integrated module that shares common computational resources. The NTT/INTT module uses the same hardware components for both forward and inverse transforms, including shared multipliers, adders, and memory structures. This merging eliminates redundant resource allocation while maintaining the high processing speed of pipeline-based NTT through efficient resource sharing and parallel operation capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The NTT/INTT module is designed as a universal computational unit that can perform both forward NTT and inverse INTT operations using the same hardware infrastructure. The module accepts control signals to switch between NTT and INTT modes, utilizing the same arithmetic logic units, memory interfaces, and data pathways for both operations. This multi-functionality reduces the overall resource footprint compared to having separate dedicated pipelines for NTT and INTT, while maintaining high processing throughput through efficient resource utilization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250337567A1Configurable module-lattice post-quantum cryptography processor for key-encapsulation mechanism
Publication Date: 2025.10.30 INHA UNIV RES & BUSINESS FOUNDATION
  • US20250337567A1 patent drawing
  • US20250337567A1 patent drawing
  • US20250337567A1 patent drawing

AI summary

Disclosed is a reconfigurable module-lattice-based key encapsulation mechanism (ML-KEM) post-quantum cryptography system and method using memory-based numbers theoretic transform (NTT). A post-quantum cryptography method of a post-quantum cryptography system including a plurality of internal submodules includes reconfiguring the plurality of internal submodules by variably selecting one security level from among the plurality of security levels; reconfiguring execution of the plurality of internal submodules to be changed through a main controller; and variably processing data according to the selected security level to perform key generation, encapsulation, and decapsulation through the reconfigured plurality of internal submodules.