{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,26]],"date-time":"2026-03-26T15:18:06Z","timestamp":1774538286430,"version":"3.50.1"},"reference-count":27,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2022,11,17]],"date-time":"2022-11-17T00:00:00Z","timestamp":1668643200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,11,17]],"date-time":"2022-11-17T00:00:00Z","timestamp":1668643200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100004663","name":"Ministry of Science and Technology, Taiwan","doi-asserted-by":"publisher","award":["109-2221-E-001-009- MY3"],"award-info":[{"award-number":["109-2221-E-001-009- MY3"]}],"id":[{"id":"10.13039\/501100004663","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001869","name":"Academia Sinica","doi-asserted-by":"publisher","award":["AS-IA-109-M01"],"award-info":[{"award-number":["AS-IA-109-M01"]}],"id":[{"id":"10.13039\/501100001869","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Executive Yuan","award":["AS-KPQ-109-DSTCP"],"award-info":[{"award-number":["AS-KPQ-109-DSTCP"]}]},{"name":"EUREKA cluster PENTA","award":["PENTA-2018e-17004-SunRISE"],"award-info":[{"award-number":["PENTA-2018e-17004-SunRISE"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptogr Eng"],"published-print":{"date-parts":[[2023,6]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>We present a novel full hardware implementation of Streamlined NTRU Prime, with two variants: a high-speed, high-area implementation and a slower, low-area implementation. We introduce several new techniques that improve performance, including a batch inversion for key generation, a high-speed schoolbook polynomial multiplier, an NTT polynomial multiplier combined with a CRT map, a new DSP-free modular reduction method, a high-speed radix sorting module, and new encoders and decoders. With the high-speed design, we achieve the to-date fastest speeds for Streamlined NTRU Prime, with speeds of 5007, 10,989, and 64,026 cycles for encapsulation, decapsulation, and key generation, respectively, while running at 285 MHz on a Xilinx Zynq Ultrascale+. The entire design uses 40,060 LUT, 26,384 flip-flops, 36.5 Bram, and 31 DSP.<\/jats:p>","DOI":"10.1007\/s13389-022-00303-z","type":"journal-article","created":{"date-parts":[[2022,11,17]],"date-time":"2022-11-17T10:04:06Z","timestamp":1668679446000},"page":"167-186","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Streamlined NTRU Prime on FPGA"],"prefix":"10.1007","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8187-7554","authenticated-orcid":false,"given":"Bo-Yuan","family":"Peng","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5253-881X","authenticated-orcid":false,"given":"Adrian","family":"Marotzke","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ming-Han","family":"Tsai","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9362-5282","authenticated-orcid":false,"given":"Bo-Yin","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ho-Lin","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,11,17]]},"reference":[{"key":"303_CR1","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2021.i1.217-238","author":"E Alkim","year":"2021","unstructured":"Alkim, E., Cheng, D.Y.L., Chung, C.M.M., Evkan, H., Huang, L.W.L., Hwang, V., Li, C.L.T., Niederhagen, R., Shih, C.J., W\u00e4lde, J., Yang, B.Y.: Polynomial multiplication in NTRU prime. IACR Trans. Cryptogr. Hardw. Embed. Syst. (2021). https:\/\/doi.org\/10.46586\/tches.v2021.i1.217-238","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"303_CR2","unstructured":"Apon, D.: NIST assignments of platforms on implementation efforts to PQC teams (online) https:\/\/groups.google.com\/a\/list.nist.gov\/g\/pqc-forum\/c\/cJxMq0_90gU\/m\/qbGEs3TXGwAJ. 7 Feb. 2019; Accessed 15 Oct. 2021"},{"key":"303_CR3","unstructured":"Bernstein, D.J., Brumley, B.B., Chen, M-S., Tuveri, N.: OpenSSLNTRU: faster post-quantum TLS key exchange. In: 31st USENIX Security Symposium (USENIX Security 22). pp. 845\u2013862. Boston, MA (2022). https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/bernstein"},{"key":"303_CR4","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Chuengsatiansup, C., Lange, T., van Vredendaal, C.: NTRU prime: reducing attack surface at low cost. In: International Conference on Selected Areas in Cryptography. pp. 235\u2013260. Springer, Berlin (2017)","DOI":"10.1007\/978-3-319-72565-9_12"},{"key":"303_CR5","unstructured":"Bernstein, D.J., Lange, T.: SUPERCOP, the system for unified performance evaluation related to cryptographic operations and primitive. https:\/\/bench.cr.yp.to\/supercop.html (2021). Accessed 07 Sept 2021"},{"key":"303_CR6","doi-asserted-by":"publisher","DOI":"10.13154\/tches.v2019.i3.340-398","author":"DJ Bernstein","year":"2019","unstructured":"Bernstein, D.J., Yang, B.Y.: Fast constant-time GCD computation and modular inversion. IACR Trans. Cryptogr. Hardw. Embed. Syst. (2019). https:\/\/doi.org\/10.13154\/tches.v2019.i3.340-398","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"303_CR7","unstructured":"Brumley, B.B., Chen, M.S., Chuengsatiansup, C., Lange, T., Marotzke, A., Tuveri, N., van Vredendaal, C., Yang, B.Y.: NTRU prime: round 3. In: Post-Quantum Cryptography Standardization Project. NIST (2020)"},{"key":"303_CR8","doi-asserted-by":"publisher","unstructured":"Chung, C-M.M., Hwang, V., Kannwischer, M.J., Seiler, G., Shih, C-J., Yang, B-Y.: NTT Multiplication for NTT-unfriendly Rings: New Speed Records for Saber and NTRU on Cortex-M4 and AVX2. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2021:159\u2013188 (2021). https:\/\/tches.iacr.org\/index.php\/TCHES\/article\/view\/879. https:\/\/doi.org\/10.46586\/tches.v2021.i2.159-188","DOI":"10.46586\/tches.v2021.i2.159-188"},{"key":"303_CR9","unstructured":"Dang, V.B., Farahmand, F., Andrzejczak, M., Mohajerani, K., Nguyen, D.T., Gaj, K.: Implementation and Benchmarking of Round 2 Candidates in the NIST Post-Quantum Cryptography Standardization Process Using Hardware and Software\/Hardware Co-design Approaches. Cryptology ePrint Archive, Report 2020\/795 (2020), https:\/\/eprint.iacr.org\/2020\/795"},{"key":"303_CR10","unstructured":"Dang, V.B., Mohajerani, K., Gaj, K.: High-Speed Hardware Architectures and Fair FPGA Benchmarking of CRYSTALS-Kyber, NTRU, and Saber. Cryptology ePrint Archive, Report 2021\/1508 (2021). https:\/\/eprint.iacr.org\/2021\/1508"},{"key":"303_CR11","doi-asserted-by":"crossref","unstructured":"Good, I.J.: Random motion on a finite abelian group. In: Mathematical Proceedings of the Cambridge Philosophical Society, vol.\u00a047, pp. 756\u2013762. Cambridge University Press, Cambridge (1951)","DOI":"10.1017\/S0305004100027201"},{"key":"303_CR12","unstructured":"Knuth, D.E.: The Art of Computer Programming: Volume 3: Sorting and Searching. Addison-Wesley Professional, Boston (1998)"},{"key":"303_CR13","doi-asserted-by":"publisher","first-page":"210","DOI":"10.1007\/978-3-030-97348-3_12","volume-title":"Smart Card Research and Advanced Applications","author":"G Land","year":"2022","unstructured":"Land, G., Sasdrich, P., G\u00fcneysu, T.: A hard crystal\u2014implementing dilithium on reconfigurable hardware. In: Grosso, V., P\u00f6ppelmann, T. (eds.) Smart Card Research and Advanced Applications, pp. 210\u2013230. Springer, Cham (2022)"},{"key":"303_CR14","doi-asserted-by":"publisher","unstructured":"Lo, H.F., Shieh, M.D., Wu, C.M.: Design of an efficient FFT processor for DAB system. In: ISCAS 2001. The 2001 IEEE International Symposium on Circuits and Systems (Cat. No. 01CH37196). vol.\u00a04, pp. 654\u2013657 (2001). https:\/\/doi.org\/10.1109\/ISCAS.2001.922322","DOI":"10.1109\/ISCAS.2001.922322"},{"key":"303_CR15","doi-asserted-by":"crossref","unstructured":"Marotzke, A.: A constant time full hardware implementation of streamlined NTRU prime. In: International Conference on Smart Card Research and Advanced Applications, pp. 3\u201317. Springer, Berlin (2020)","DOI":"10.1007\/978-3-030-68487-7_1"},{"key":"303_CR16","doi-asserted-by":"crossref","unstructured":"Mishra, P.K., Sarkar, P.: Application of Montgomery\u2019s trick to scalar multiplication for elliptic and hyperelliptic curves using a fixed base point. In: International Workshop on Public Key Cryptography. pp. 41\u201354. Springer, Heidelberg (2004)","DOI":"10.1007\/978-3-540-24632-9_4"},{"key":"303_CR17","unstructured":"NIST: Nist post-quantum cryptography standardization (online). https:\/\/csrc.nist.gov\/Projects\/Post-Quantum-Cryptography\/Post-Quantum-Cryptography-Standardization . Accessed 11 June 2020"},{"key":"303_CR18","doi-asserted-by":"publisher","DOI":"10.13154\/tches.v2020.i4.443-466","author":"SS Roy","year":"2020","unstructured":"Roy, S.S., Basso, A.: High-speed instruction-set coprocessor for lattice-based key encapsulation mechanism: Saber in hardware. IACR Trans. Cryptogr. Hardw. Embed. Syst. (2020). https:\/\/doi.org\/10.13154\/tches.v2020.i4.443-466","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"303_CR19","unstructured":"Savory, D.: SHA-512 hardware implementation in VHDL. Based on NIST FIPS 180-4 (online). https:\/\/github.com\/dsaves\/SHA-512. Accessed 11 June 2020"},{"key":"303_CR20","doi-asserted-by":"crossref","unstructured":"Wang, W., Szefer, J., Niederhagen, R.: FPGA-based Niederreiter cryptosystem using binary Goppa codes. In: International Conference on Post-Quantum Cryptography, pp. 77\u201398. Springer, Cham (2018)","DOI":"10.1007\/978-3-319-79063-3_4"},{"key":"303_CR21","doi-asserted-by":"crossref","unstructured":"Xilinx, Inc.: UG474: 7 Series FPGAs Configurable Logic Block, 1.8 edn. Sept. 2016","DOI":"10.23919\/AE.2017.8053605"},{"key":"303_CR22","unstructured":"Xilinx, Inc.: UG574: UltraScale Architecture Configurable Logic Block, 1.5 edn. Feb. 2017"},{"key":"303_CR23","unstructured":"Xilinx, Inc.: UG479: 7 Series DSP48E1 Slice, 1.10 edn. Mar. 2018"},{"key":"303_CR24","unstructured":"Xilinx, Inc.: UG473: 7 Series FPGAs Memory Resources, 1.14 edn. July 2019"},{"key":"303_CR25","unstructured":"Xilinx, Inc.: UG573: UltraScale Architecture Memory Resources, 1.13 edn. Sept. 2021"},{"key":"303_CR26","unstructured":"Xilinx, Inc.: UG579: UltraScale Architecture DSP Slice, 1.11 edn. Aug. 2021"},{"key":"303_CR27","doi-asserted-by":"publisher","DOI":"10.13154\/tches.v2020.i2.49-72","author":"N Zhang","year":"2020","unstructured":"Zhang, N., Yang, B., Chen, C., Yin, S., Wei, S., Liu, L.: Highly efficient architecture of NewHope-NIST on FPGA using low-complexity NTT\/INTT. IACR Trans. Cryptogr. Hardw. Embed. Syst. (2020). https:\/\/doi.org\/10.13154\/tches.v2020.i2.49-72","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."}],"container-title":["Journal of Cryptographic Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-022-00303-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s13389-022-00303-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-022-00303-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,8]],"date-time":"2024-10-08T23:25:03Z","timestamp":1728429903000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s13389-022-00303-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,17]]},"references-count":27,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2023,6]]}},"alternative-id":["303"],"URL":"https:\/\/doi.org\/10.1007\/s13389-022-00303-z","relation":{},"ISSN":["2190-8508","2190-8516"],"issn-type":[{"value":"2190-8508","type":"print"},{"value":"2190-8516","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,17]]},"assertion":[{"value":"28 October 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 October 2022","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 November 2022","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}