Unified Post-Quantum Crypto Hardware Architecture for Resource Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic algorithms, such as RSA and ECC, are vulnerable to quantum computer attacks, and there is a need for efficient and secure post-quantum cryptographic solutions, particularly for Internet of Things (IoT) devices, where a combined hardware architecture for Kyber-KEM and Dilithium-DSA algorithms does not exist.

Innovation Solution

A hardware architecture that integrates key generation, encapsulation, and decapsulation for Kyber-KEM at security levels 512, 768, and 1024, and key generation, signature generation, and verification for Dilithium-DSA at security levels 2, 3, and 5, utilizing shared resources and specific hardware modules like FIFO, SHA3 coprocessor, dual-port RAM, formatter, sampler, and operator modules, to perform algebraic operations efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If separate hardware architectures are implemented for Kyber-KEM and Dilithium-DSA algorithms, then each algorithm can be optimized independently, but the total resource consumption and device footprint increase

Engineering Contradiction:
Improvealgorithm implementation flexibilityVSAvoidhardware resource consumption
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent combines Kyber-KEM and Dilithium-DSA algorithms into a single unified hardware architecture that shares common computational resources including modular arithmetic units, polynomial multiplication engines, and memory structures. This merging approach reduces overall hardware footprint while maintaining the ability to execute both algorithms independently with their specific operational requirements

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The hardware architecture implements universal computational units that can perform multiple cryptographic operations required by both Kyber-KEM and Dilithium-DSA. The modular arithmetic units, sampling modules, and transformation engines are designed to be algorithm-agnostic, allowing the same hardware resources to serve multiple cryptographic functions across different security levels

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Quantity of substance

If a combined hardware architecture is implemented for Kyber-KEM and Dilithium-DSA, then resource consumption is reduced, but the device complexity increases

Engineering Contradiction:
Improvehardware resource consumptionVSAvoidarchitecture complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The unified architecture is segmented into distinct functional modules including key generation units, encapsulation/decapsulation engines for Kyber-KEM, and signature generation/verification engines for Dilithium-DSA. Each module is independently controllable and can be activated based on the specific algorithm being executed, managing complexity through modular design while sharing underlying computational resources

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The hardware architecture employs dynamic resource allocation and configuration mechanisms that adapt the operational mode of shared units based on which algorithm is currently executing. Control logic dynamically adjusts parameter sets, memory access patterns, and computational pathways to match the specific requirements of Kyber-KEM or Dilithium-DSA, effectively managing complexity through runtime adaptability

Inventive Principle:
Principle #15Dynamics

3Quantity of substance

If hardware resources are shared between Kyber-KEM and Dilithium-DSA, then resource efficiency improves, but the control and operation complexity increases

Engineering Contradiction:
Improveresource efficiencyVSAvoidcontrol system complexity
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The control system incorporates automated algorithm detection and configuration capabilities that automatically identify which algorithm (Kyber-KEM or Dilithium-DSA) needs to execute and configure the shared hardware resources accordingly. The system self-manages parameter loading, memory allocation, and operational sequencing without requiring external intervention for each algorithm transition, reducing control complexity while maintaining resource sharing efficiency

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11496297B1Low footprint resource sharing hardware architecture for CRYSTALS-Dilithium and CRYSTALS-Kyber
Publication Date: 2022.11.08 PQSECURE TECHNOLOGIES LLC
  • US11496297B1 patent drawing
  • US11496297B1 patent drawing
  • US11496297B1 patent drawing

AI summary

A low footprint resource sharing hardware architecture that is implemented as a co-processor and is operably configured to perform a plurality of cryptographic algorithms for Dilithium-DSA at all NIST-recommended post-quantum cryptography security levels and a plurality of cryptographic algorithms for Kyber-KEM at all NIST-recommended post-quantum cryptography security levels. The architecture also includes a singular arithmetic unit 104 operably configured perform all arithmetic operations required in the plurality of cryptographic algorithms for Kyber-KEM and the plurality of cryptographic algorithms for Dilithium-DSA and a singular sampling unit operably configured to sample all vectors and matrices required in the plurality of cryptographic algorithms for Kyber-KEM and the plurality of cryptographic algorithms for Dilithium-DSA.