{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T06:26:12Z","timestamp":1785306372214,"version":"3.55.0"},"reference-count":37,"publisher":"Association for Computing Machinery (ACM)","issue":"1","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2026,1,31]]},"abstract":"<jats:p>\n                    Modular Inversion (MI) is one of the fundamental arithmetic operations in the finite field, which plays an essential role in various cryptographic applications and requires high performance and security. Unfortunately, the simple MI algorithm is vulnerable to side-channel attacks, such as the timing attack, which can compromise the cryptographic system by analyzing the time taken to execute cryptographic algorithms. Attackers may recover the initial data since the time can differ based on the input. Besides, the low complexity and low resource consumption of hardware implementations in MI are also challenging. In this article, we propose two novel modular inversion algorithms, named Constant-Time Integer Modular Inversion (CT-IMI) and Constant-Time Complementary Montgomery Modular Inversion (CT-CMMI). They both consist of constant iteration rounds to resist the timing attack. CT-IMI processes the data in the integer field, which is designed for common scenarios. CT-CMMI is suitable for the cross-domain case, which can directly use data in the Montgomery domain and avoid the conversion steps for some specific applications, e.g., scalar multiplication in Elliptic Curve Cryptography (ECC). In software simulations, we measure the average clock cycles for a single inversion and illustrate the relationship between various bit lengths and the latency. The significant differences between constant and non-constant algorithms demonstrate the vulnerability of modular inversion to timing attacks. In addition, we design two efficient hardware architectures on FPGA. Experimental results show that our CT-IMI can finish a single inversion in 2.56\n                    <jats:inline-formula content-type=\"math\/tex\">\n                      <jats:tex-math notation=\"LaTeX\" version=\"MathJax\">\\(\\mu\\)<\/jats:tex-math>\n                    <\/jats:inline-formula>\n                    s with 4.2k LUTs, 1.8k FFs, and our CT-CMMI requires 2.45\n                    <jats:inline-formula content-type=\"math\/tex\">\n                      <jats:tex-math notation=\"LaTeX\" version=\"MathJax\">\\(\\mu\\)<\/jats:tex-math>\n                    <\/jats:inline-formula>\n                    s with 2.7k LUTs, 1.6k FFs. The product of area and latency of our CT-IMI and CT-CMMI can reach 10.50 and 6.62, respectively, which shows optimal performance compared with all the results in the existing literature.\n                  <\/jats:p>","DOI":"10.1145\/3777365","type":"journal-article","created":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T11:20:26Z","timestamp":1763119226000},"page":"1-26","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["High-Performance Accelerator for Constant-Time Cross-Domain Integer and Montgomery Inversion on FPGA"],"prefix":"10.1145","volume":"25","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-0122-8379","authenticated-orcid":false,"given":"Xiaoyu","family":"Ji","sequence":"first","affiliation":[{"name":"Shandong University","place":["Qingdao, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5733-4528","authenticated-orcid":false,"given":"Cheng","family":"Chen","sequence":"additional","affiliation":[{"name":"Shandong University","place":["Qingdao, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4829-8753","authenticated-orcid":false,"given":"Gangqiang","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Information Science and Engineering, Shandong University","place":["Qingdao, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9322-0808","authenticated-orcid":false,"given":"Hongchao","family":"Zhou","sequence":"additional","affiliation":[{"name":"Shandong University","place":["Qingdao, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6489-9495","authenticated-orcid":false,"given":"Hailiang","family":"Xiong","sequence":"additional","affiliation":[{"name":"Shandong University","place":["Qingdao, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9516-9583","authenticated-orcid":false,"given":"Xianye","family":"Ben","sequence":"additional","affiliation":[{"name":"Shandong University","place":["Qingdao, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1319-1224","authenticated-orcid":false,"given":"Zhiguo","family":"Wan","sequence":"additional","affiliation":[{"name":"Zhejiang Lab","place":["Hangzhou, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,1,8]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"crossref","unstructured":"Daniel J. Bernstein and Bo-Yin Yang. 2019. Fast Constant-time GCD computation and modular inversion. IACR Transactions on Cryptographic Hardware and Embedded Systems 2019 3 (2019) 340\u2013398.","DOI":"10.46586\/tches.v2019.i3.340-398"},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40349-1_14"},{"key":"e_1_3_1_4_2","doi-asserted-by":"crossref","unstructured":"Karim Bigou and Arnaud Tisserand. 2016. Binary-Ternary plus-minus modular inversion in RNS. IEEE Transactions on Computers 65 11 (2016) 3495\u20133501.","DOI":"10.1109\/TC.2016.2529625"},{"key":"e_1_3_1_5_2","doi-asserted-by":"crossref","unstructured":"Joppe W. Bos. 2014. Constant time modular inversion. Journal of Cryptographic Engineering 4 (2014) 275\u2013281.","DOI":"10.1007\/s13389-014-0084-8"},{"key":"e_1_3_1_6_2","volume-title":"Recommendations for Discrete Logarithm-based Cryptography: Elliptic Curve Domain Parameters","author":"Chen Lily","year":"2019","unstructured":"Lily Chen, Dustin Moody, Andrew Regenscheid, and Karen Randall. 2019. Recommendations for Discrete Logarithm-based Cryptography: Elliptic Curve Domain Parameters. Technical Report. National Institute of Standards and Technology."},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISOCC.2015.7401713"},{"key":"e_1_3_1_8_2","unstructured":"Richard E. Crandall. 1992. Method and Apparatus for Public Key Exchange in a Cryptographic System. US Patent 5 159 632."},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/FPL53798.2021.00028"},{"key":"e_1_3_1_10_2","doi-asserted-by":"crossref","unstructured":"W. Diffie and M. Hellman. 1976. New directions in cryptography. IEEE Transactions on Information Theory 22 6 (1976) 644\u2013654.","DOI":"10.1109\/TIT.1976.1055638"},{"key":"e_1_3_1_11_2","doi-asserted-by":"crossref","unstructured":"Laszlo Hars. 2006. Modular inverse algorithms without multiplications for cryptographic applications. EURASIP Journal on Embedded Systems 2006 1 (2006) 1\u201313.","DOI":"10.1155\/ES\/2006\/32192"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSDIS.2015.47"},{"key":"e_1_3_1_13_2","unstructured":"Jin Hu and Yongbin Li. 2022. An improved modular inversion algorithm and its hardware implementation. Journal of Hunan University (Natural Sciences) 49 02 (2022) 101\u2013105."},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-25319-5_5"},{"key":"e_1_3_1_15_2","doi-asserted-by":"crossref","unstructured":"B. S. Kaliski. 1995. The montgomery inverse and its applications. IEEE Transactions on Computers 44 8 (1995) 1064\u20131065.","DOI":"10.1109\/12.403725"},{"key":"e_1_3_1_16_2","volume-title":"The Art of Computer Programming: Seminumerical Algorithms (3rd ed.)","author":"Knuth Donald E.","year":"1998","unstructured":"Donald E. Knuth. 1998. The Art of Computer Programming: Seminumerical Algorithms (3rd ed.). Addison-Wesley Publishing Company, Massachusetts."},{"key":"e_1_3_1_17_2","doi-asserted-by":"crossref","unstructured":"Neal Koblitz. 1987. Elliptic curve cryptosystems. Mathematics of Computation 48 177 (1987) 203\u2013209.","DOI":"10.1090\/S0025-5718-1987-0866109-5"},{"key":"e_1_3_1_18_2","volume-title":"Elementary Number Theory (2nd. ed.)","author":"Landau Edmund","year":"1999","unstructured":"Edmund Landau. 1999. Elementary Number Theory (2nd. ed.). AMS Chelsea Pub., Providence, R.I."},{"key":"e_1_3_1_19_2","unstructured":"The GNU Multiple Precision Arithmetic Library. 2021. GMP library. Retrieved February 18 2023 from https:\/\/gmplib.org\/"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/TENCON.2009.5396175"},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICNISC57059.2022.00016"},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-36400-5_6"},{"key":"e_1_3_1_23_2","doi-asserted-by":"crossref","unstructured":"M. Donald MacLaren. 1970. The art of computer programming. volume 2: Seminumerical algorithms (Donald E. Knuth). SIAM Review 12 2 (1970) 306\u2013308.","DOI":"10.1137\/1012065"},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-39799-X_31"},{"key":"e_1_3_1_25_2","doi-asserted-by":"crossref","unstructured":"Peter L. Montgomery. 1985. Modular multiplication without trial division. Mathematics of Computation 44 170 (1985) 519\u2013521.","DOI":"10.1090\/S0025-5718-1985-0777282-X"},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICEMIS.2017.8272995"},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/LightSec.2011.14"},{"key":"e_1_3_1_28_2","unstructured":"National Standardization Technical Committee of Information Security of China. 2017. Information Technology - SM2 Elliptic Curve Public Key Cryptographic Algorithm - Part 5: Parameter Definition. GB\/T 32918.5-2017."},{"key":"e_1_3_1_29_2","unstructured":"William M. Daley and Raymond G. Kammer. 2000. Digital signature standard (DSS). National Institute of Standards. 1\u201374. Retrieved from https:\/\/apps.dtic.mil\/sti\/html\/tr\/ADA399987\/"},{"key":"e_1_3_1_30_2","doi-asserted-by":"crossref","unstructured":"Pascal Sasdrich and Tim G\u00fcneysu. 2015. Implementing curve25519 for side-channel\u2013protected elliptic curve cryptography. ACM Transactions on Reconfigurable Technology and Systems 9 1 (2015) 1\u201315.","DOI":"10.1145\/2700834"},{"key":"e_1_3_1_31_2","doi-asserted-by":"crossref","unstructured":"E. Savas and C. K. Koc. 2000. The montgomery modular inverse-revisited. IEEE Transactions on Computers 49 7 (2000) 763\u2013766.","DOI":"10.1109\/12.863048"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-5906-5_32"},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/UBMK.2019.8907211"},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISECS.2009.7"},{"key":"e_1_3_1_35_2","unstructured":"P. Wuille and G. Maxwell. 2021. Roconnor-Blockstream: Safegcd-Bounds. Retrieved from https:\/\/github.com\/sipa\/safegcd-bounds"},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/CIS.2017.00122"},{"key":"e_1_3_1_37_2","doi-asserted-by":"crossref","first-page":"90","DOI":"10.1109\/ICASIC.2007.4415574","volume-title":"Proceedings of the 2007 7th International Conference on ASIC.","author":"Yan Xiaodong","year":"2007","unstructured":"Xiaodong Yan and Shuguo Li. 2007. Modified modular inversion algorithm for VLSI implementation. In Proceedings of the 2007 7th International Conference on ASIC.90\u201393."},{"key":"e_1_3_1_38_2","first-page":"1491","volume-title":"Proceedings of the IEEE 2002 International Conference on Communications, Circuits and Systems and West Sino Expositions.","author":"Zhou Tao","year":"2002","unstructured":"Tao Zhou, Xingjun Wu, Guoqiang Bai, and Hongyi Chen. 2002. New algorithm and fast VLSI implementation for modular inversion in galois field GF(p). In Proceedings of the IEEE 2002 International Conference on Communications, Circuits and Systems and West Sino Expositions.1491\u20131495."}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3777365","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,8]],"date-time":"2026-01-08T16:53:44Z","timestamp":1767891224000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3777365"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1,8]]},"references-count":37,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,1,31]]}},"alternative-id":["10.1145\/3777365"],"URL":"https:\/\/doi.org\/10.1145\/3777365","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"value":"1539-9087","type":"print"},{"value":"1558-3465","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1,8]]},"assertion":[{"value":"2023-08-31","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-10-04","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-01-08","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}