{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T17:26:48Z","timestamp":1783099608073,"version":"3.54.6"},"reference-count":21,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2024,1,20]],"date-time":"2024-01-20T00:00:00Z","timestamp":1705708800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,1,20]],"date-time":"2024-01-20T00:00:00Z","timestamp":1705708800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100006690","name":"Politecnico di Milano","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100006690","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["SN COMPUT. SCI."],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The significant effort in the research and design of large-scale quantum computers has spurred a transition to post-quantum cryptographic primitives worldwide. The post-quantum cryptographic primitive standardization effort led by the US NIST has recently selected the asymmetric encryption primitive Kyber as its candidate for standardization and indicated NTRU, as a valid alternative if intellectual property issues are not solved. Finally, a more conservative alternative to NTRU, NTRUPrime was also considered as an alternate candidate, due to its design choices that remove the possibility for a large set of attacks preemptively. All the aforementioned asymmetric primitives provide good performances, and are prime choices to provide IoT devices with post-quantum confidentiality services. In this work, we present a comprehensive exploration of hardware designs for the computation of polynomial multiplications, the workhorse operation in all the aforementioned cryptosystems, with a thorough analysis of performance, compactness and efficiency. The presented designs cope with the differences in the arithmetics of polynomial rings employed by distinct cryptosystems, benefiting from configurations and optimizations that are applicable at synthesis time and\/or run time. In this context, we target a use case scenario where long-term key pairs are used, such as the ones for VPNs (e.g., over IPSec), secure shell protocols and instant messaging applications. Our high-performance design variants exhibit figures of latency comparable to the ones needed for the execution of the symmetric cryptographic primitives also included in the Post-Quantum schemes. Notably, the performance figures of the designs proposed for NTRU and NTRU Prime surpass the ones described in the related literature.<\/jats:p>","DOI":"10.1007\/s42979-023-02547-w","type":"journal-article","created":{"date-parts":[[2024,1,20]],"date-time":"2024-01-20T10:02:03Z","timestamp":1705744923000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Performance and Efficiency Exploration of Hardware Polynomial Multipliers for Post-Quantum Lattice-Based Cryptosystems"],"prefix":"10.1007","volume":"5","author":[{"given":"Francesco","family":"Antognazza","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0840-6358","authenticated-orcid":false,"given":"Alessandro","family":"Barenghi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gerardo","family":"Pelosi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ruggero","family":"Susella","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,1,20]]},"reference":[{"key":"2547_CR1","unstructured":"NIST PQC Team: PQC standardization process: announcing four candidates to be standardized, plus fourth round candidates. 2022. https:\/\/csrc.nist.gov\/news\/2022\/pqc-candidates-to-be-standardized-and-round-4."},{"key":"2547_CR2","unstructured":"The CRYSTALS-Kyber Team: CRYSTALS-cryptographic suite for algebraic lattices-Kyber 2020. https:\/\/pq-crystals.org\/kyber\/."},{"key":"2547_CR3","unstructured":"The NTRU Team: NTRU\u2013a submission to the NIST post-quantum standardization effort 2020. https:\/\/www.ntru.org\/."},{"key":"2547_CR4","unstructured":"The NTRU Prime Team: NTRU Prime. 2022. https:\/\/ntruprime.cr.yp.to\/."},{"key":"2547_CR5","unstructured":"The SABER Team: SABER\u2013MLWR-Based KEM 2019. https:\/\/www.esat.kuleuven.be\/cosic\/pqcrypto\/saber\/."},{"key":"2547_CR6","doi-asserted-by":"crossref","unstructured":"Alagic G, Apon D, Cooper D, Dang Q, Dang T, Kelsey J, Lichtinger J, Miller C, Moody D, Peralta R, Perlner R, Robinson A, Smith-Tone D, Liu Y-K. Status report on the third round of the NIST post-quantum cryptography standardization process. 2022. https:\/\/doi.org\/10.6028\/NIST.IR.8413-upd1.","DOI":"10.6028\/NIST.IR.8413"},{"key":"2547_CR7","unstructured":"ISE Crypto PQC working group: Securing tomorrow today: Why Google now protects its internal communications from quantum threats. https:\/\/cloud.google.com\/blog\/products\/identity-security\/why-google-now-uses-post-quantum-cryptography-for-internal-comms."},{"key":"2547_CR8","unstructured":"Schmieg S. PQC at Google. Invited talk at The 14th International Conference on Post-Quantum Cryptography, PQCrypto 2023. https:\/\/pqcrypto2023.umiacs.io\/slides\/Invited.3.pdf."},{"key":"2547_CR9","unstructured":"The OpenSSH Team: OpenSSH Changelog for version 9.0 2022. https:\/\/www.openssh.com\/txt\/release-9.0."},{"issue":"4","key":"2547_CR10","doi-asserted-by":"publisher","first-page":"526","DOI":"10.1147\/sj.294.0526","volume":"29","author":"PG Comba","year":"1990","unstructured":"Comba PG. Exponentiation cryptosystems on the IBM PC. IBM Syst J. 1990;29(4):526\u201338. https:\/\/doi.org\/10.1147\/sj.294.0526.","journal-title":"IBM Syst J"},{"key":"2547_CR11","first-page":"595","volume":"7","author":"A Karatsuba","year":"1963","unstructured":"Karatsuba A. Multiplication of multidigit numbers on automata. Soviet Phys Doklady. 1963;7:595\u20136.","journal-title":"Soviet Phys Doklady"},{"key":"2547_CR12","doi-asserted-by":"publisher","unstructured":"Bodrato M. Towards optimal toom-cook multiplication for univariate and multivariate polynomials in characteristic 2 and 0. In: Carlet C, Sunar B (eds) Arithmetic of finite fields, first international workshop, WAIFI 2007, Madrid, Spain, June 21-22, 2007. In: Proceedings. Lecture Notes in Computer Science, vol. 4547, pp. 116\u2013133. Springer 2007. https:\/\/doi.org\/10.1007\/978-3-540-73074-3_10.","DOI":"10.1007\/978-3-540-73074-3_10"},{"key":"2547_CR13","doi-asserted-by":"crossref","unstructured":"Ylonen T. IETF RFC 4252\u2014The secure shell (SSH) Authentication protocol. 2006. https:\/\/www.rfc-editor.org\/rfc\/rfc4252.","DOI":"10.17487\/rfc4252"},{"key":"2547_CR14","doi-asserted-by":"publisher","unstructured":"Antognazza F, Barenghi A, Pelosi G, Susella R. An efficient unified architecture for polynomial multiplications in lattice-based cryptoschemes. In: Mori P, Lenzini G, Furnell S (eds) Proceedings of the 9th International Conference on Information Systems Security and Privacy, ICISSP 2023, Lisbon, Portugal, February 22-24, 2023, pp. 81\u201388. SciTePress 2023. https:\/\/doi.org\/10.5220\/0011654200003405.","DOI":"10.5220\/0011654200003405"},{"key":"2547_CR15","doi-asserted-by":"publisher","unstructured":"Marotzke A. A constant time full hardware implementation of streamlined NTRU prime. In: Liardet P, Mentens N (eds) Smart card research and advanced applications-19th international conference, CARDIS 2020, virtual event, november 18\u201319, 2020, Revised Selected Papers. Lecture Notes in Computer Science, vol. 12609, pp. 3\u201317. Springer 2020. https:\/\/doi.org\/10.1007\/978-3-030-68487-7_1.","DOI":"10.1007\/978-3-030-68487-7_1"},{"key":"2547_CR16","unstructured":"Dang VB, Mohajerani K, Gaj K. High-speed hardware architectures and FPGA benchmarking of CRYSTALS-Kyber, NTRU, and Saber 2021. https:\/\/eprint.iacr.org\/2021\/1508."},{"key":"2547_CR17","doi-asserted-by":"publisher","unstructured":"Liu B, Wu H. Efficient architecture and implementation for NTRUEncrypt system. In: IEEE 58th International Midwest Symposium on Circuits and Systems, MWSCAS 2015, Fort Collins, CO, USA, August 2-5, 2015, pp. 1\u20134. IEEE 2015. https:\/\/doi.org\/10.1109\/MWSCAS.2015.7282143.","DOI":"10.1109\/MWSCAS.2015.7282143"},{"key":"2547_CR18","doi-asserted-by":"publisher","unstructured":"Basso A, Roy SS. Optimized polynomial multiplier architectures for post-quantum KEM Saber. In: 58th ACM\/IEEE Design Automation Conference, DAC 2021, San Francisco, CA, USA, December 5-9, 2021, pp. 1285\u20131290. IEEE 2021. https:\/\/doi.org\/10.1109\/DAC18074.2021.9586219.","DOI":"10.1109\/DAC18074.2021.9586219"},{"key":"2547_CR19","doi-asserted-by":"publisher","unstructured":"Farahmand F, Dang VB, Nguyen DT, Gaj K. Evaluating the Potential for Hardware Acceleration of four NTRU-based key encapsulation mechanisms using software\/hardware codesign. In: Ding J, Steinwandt R (eds) Post-quantum cryptography-10th International Conference, PQCrypto 2019, Chongqing, China, May 8-10, 2019 Revised Selected Papers. Lecture Notes in Computer Science, vol. 11505, pp. 23\u201343. Springer 2019. https:\/\/doi.org\/10.1007\/978-3-030-25510-7_2.","DOI":"10.1007\/978-3-030-25510-7_2"},{"key":"2547_CR20","unstructured":"Peng B, Marotzke A, Tsai M, Yang B, Chen H. Streamlined NTRU prime on FPGA 2021. https:\/\/eprint.iacr.org\/2021\/1444."},{"key":"2547_CR21","unstructured":"Carter E, He P, Xie J. High-performance polynomial multiplication hardware accelerators for KEM Saber and NTRU 2022. https:\/\/eprint.iacr.org\/2022\/628."}],"container-title":["SN Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-023-02547-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s42979-023-02547-w\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-023-02547-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,20]],"date-time":"2024-01-20T10:11:24Z","timestamp":1705745484000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s42979-023-02547-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,1,20]]},"references-count":21,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2024,2]]}},"alternative-id":["2547"],"URL":"https:\/\/doi.org\/10.1007\/s42979-023-02547-w","relation":{},"ISSN":["2661-8907"],"issn-type":[{"value":"2661-8907","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,1,20]]},"assertion":[{"value":"8 June 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 December 2023","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 January 2024","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"On behalf of all authors, the corresponding author states that there is no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of Interest"}},{"value":"No research involving humans and animals was performed, nor personal data being collected.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Human and animal rights"}},{"value":"There was no need to ask for informed consent.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Informed consent"}}],"article-number":"212"}}