Lattice-Based Cryptography Coprocessor Area Optimization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic solutions for lattice-based cryptographic primitives like Kyber-KEM and Dilithium-DSA face inefficiencies in area footprint and resource utilization, lacking a unified architecture to support all security levels and operations required for both algorithms, leading to suboptimal performance and increased resource consumption.
Innovation Solution
A specialized coprocessor with a polynomial arithmetic submodule, hash submodule, and control unit is designed to efficiently perform polynomial arithmetic and hash operations, supporting all security levels for Kyber-KEM and Dilithium-DSA, featuring a compact architecture with shared modules to reduce resource usage and enhance performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If separate NTT and matrix multiplication modules are used, then operational functionality is improved, but area footprint increases
Solution Approach 1:
The patent combines NTT and matrix multiplication operations into a unified architecture using shared butterfly units and modular multiplication components. This merging eliminates the need for separate dedicated modules, reducing overall area footprint while maintaining full operational functionality for both Kyber-KEM and Dilithium-DSA algorithms.
Solution Approach 2:
The architecture implements universal butterfly units that can perform multiple functions including NTT, inverse NTT, and matrix multiplication operations. These multi-functional units replace separate dedicated modules, enabling a single architecture to support all required cryptographic operations across different security levels without increasing area requirements.
2Adaptability or versatility
If a general purpose coprocessor is used, then versatility is improved, but area efficiency deteriorates
Solution Approach 1:
The patent applies local quality by implementing specialized control units and optimized data paths tailored specifically for lattice-based cryptographic operations. Rather than using a generic coprocessor architecture, the design incorporates domain-specific optimizations for polynomial arithmetic, modular operations, and memory access patterns, achieving both versatility and area efficiency.
3Productivity
If both butterflies are used for Karatsuba multiplication, then computational performance is improved, but area footprint increases
Solution Approach 1:
The architecture implements dynamic resource allocation where butterfly units can be configured to perform different operations based on computational needs. The system dynamically switches between using one or both butterflies depending on the specific cryptographic operation, allowing optimal computational performance while minimizing area utilization when full Karatsuba multiplication is not required.
Data Source
AI summary
An area efficient architecture for lattice based key encapsulation and digital signature generation having a co-processor with a polynomial arithmetic submodule configured to process polynomial arithmetic and generate integer values representing polynomial coefficients, a hash submodule operably configured to perform hash operations and to generate pseudorandom numbers, a polynomial format submodule communicatively coupled to the polynomial arithmetic submodule and the hash submodule and operably configured to encode polynomials and decode polynomials, a memory bank communicatively coupled with and operably configured to receive and store temporary values from the polynomial arithmetic submodule, the hash submodule, the polynomial format submodule, and a data interface, and with a control unit operably configured to manage the data interface at selectively controlled time intervals and to utilize the polynomial arithmetic submodule, the hash submodule, and the polynomial format submodule to perform the plurality of cryptographic algorithms for Dilithium-DSA and for Kyber-KEM with the temporary values.


