NTT Precomputation Table for Lattice Cryptography Speed

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Lattice-based cryptography, which relies on computations over a polynomial ring, faces inefficiencies in number-theoretic transform processing, particularly in multiplications, which are essential for key generation, encryption, and decryption, limiting the speed and security of quantum computer-resistant cryptography.

Innovation Solution

A number-theoretic transform processing apparatus and method that utilize a precomputation table to reduce the number of Zq multiplications required for noise processing in lattice-based cryptography, employing techniques such as high-speed computing methods and precomputing powers of number-theoretic transform constants to achieve O(n*log(n)) time complexity, thereby speeding up the transformation process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional number-theoretic transform processing is used in lattice-based cryptography, then the cryptographic operations can be performed, but the execution cycles for key generation, encryption, decryption, and encapsulation are excessive, limiting processing speed

Engineering Contradiction:
Improveprocessing speedVSAvoidexecution cycles
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent precomputes powers of number-theoretic transform constants and stores them in a lookup table before performing the actual number-theoretic transform. This preliminary computation eliminates the need for repeated expensive multiplications during the transform process, significantly reducing execution cycles for key generation, encryption, decryption, and encapsulation operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces repeated multiplication operations with a combination of table lookup and addition operations. By substituting the mechanical multiplication process with a lookup table approach, the system achieves O(n log n) time complexity instead of O(n²), dramatically improving processing speed for lattice-based cryptographic operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If the number of Zq multiplications is reduced through precomputation, then processing speed improves, but the complexity of the processing apparatus increases due to precomputation table management

Engineering Contradiction:
Improveprocessing speedVSAvoidprecomputation table management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent performs precomputation of powers of number-theoretic transform constants during system initialization and stores them in a lookup table. This one-time preliminary action significantly reduces the complexity of repeated cryptographic operations, as the table lookup and addition operations are much simpler than repeated multiplications.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent computes and stores only the necessary powers of number-theoretic transform constants that will be needed during cryptographic operations. By computing only the required portion of the precomputation table rather than all possible values, the system manages memory usage efficiently while still achieving significant speed improvements for the actual cryptographic processing.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11922135B2Number-theoretic transform processing apparatus, number-theoretic transform processing method, and computer program product
Publication Date: 2024.03.05 KK TOSHIBA
  • US11922135B2 patent drawing
  • US11922135B2 patent drawing
  • US11922135B2 patent drawing

AI summary

According to an embodiment, a number-theoretic transform processing apparatus for a noise in lattice-based cryptography includes a processor configured to perform number-theoretic transform of the noise using a precomputation table including a combination of products of one or more elements that belong to a subspace of a finite field Zq and indicate coefficients of the noise, with one or more number-theoretic transform constants.