Modulus Multiplier for Post-Quantum Cryptography KEMs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hardware solutions for key encapsulation mechanisms (KEMs) are not versatile and do not support multiple lattice-based KEMs due to different parameter choices and implementations, limiting their applicability across various cryptographic systems.

Innovation Solution

An optimized hardware accelerator is developed that supports multiple lattice-based KEMs using Secure Hash Algorithm-3 (SHA-3) for pseudo-random number generation, Random Oracles, and Centered Binomial Distributions for secret generation, incorporating a modulus multiplier for efficient polynomial multiplication across different coefficient definitions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a hardware solution is designed for providing one specific KEM, then the implementation can be optimized for that specific algorithm, but the solution cannot work for other KEMs with different parameters and implementations

Engineering Contradiction:
Improvecomputational efficiencyVSAvoidsupport for multiple KEM schemes
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal hardware accelerator that can execute multiple lattice-based KEM schemes (Kyber, Dilithium, Falcon, SPHINCS+) through a common architecture. The system uses configurable parameters and modular design to adapt to different cryptographic algorithms without requiring separate dedicated hardware for each scheme, thereby achieving both efficiency and versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If different parameter choices and implementations are used for different KEMs, then each KEM can be optimized for its specific security requirements, but a common hardware platform cannot be used

Engineering Contradiction:
Improvesecurity assuranceVSAvoidhardware architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hardware accelerator employs dynamic configuration capabilities that allow parameters such as polynomial degrees, modulus values, and cryptographic constants to be adjusted based on the selected KEM scheme. This dynamic adaptability enables the system to maintain optimal security parameters for each algorithm while using a single flexible hardware platform, avoiding the need for multiple fixed-architecture devices.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11569994B2Accelerating multiple post-quantum cryptograhy key encapsulation mechanisms
Publication Date: 2023.01.31 INTEL CORP
  • US11569994B2 patent drawing
  • US11569994B2 patent drawing
  • US11569994B2 patent drawing

AI summary

An accelerator includes polynomial multiplier circuitry including at least one modulus multiplier operating according to a mode. The at least one modulus multiplier include a multiplier to multiply two polynomial coefficients to generate a multiplication result, a power of two reducer to reduce the multiplication result to a reduced multiplication result when the mode is a power of two mode, and a prime modulus reducer to reduce the multiplication result to the reduced multiplication result when the mode is a prime modulus mode.