Pith. sign in

REVIEW 4 major objections 6 minor 107 references

Rudraksh: A compact and lightweight post-quantum key-encapsulation mechanism

T0 review · 4 major / 6 minor · reviewed 2026-08-10 · deepseek-v4-flash

Pith's one-line read Rudraksh, a 64-coefficient module-LWE KEM, claims level-I post-quantum security at one-third the FPGA area of compact Kyber.

desk verdict Serious hardware-driven KEM paper with a real ASCON-based design and credible area savings, but the security claim rests on a 4-bit margin from a single estimator. read the letter →

arxiv 2501.13799 v1 pith:5MFAZEO5 submitted 2025-01-23 cs.CR

classification cs.CR MSC 94A60
keywords post-quantumcryptographykey-encapsulationmechanismmodule-LWElightweightFPGAimplementationASCONnumbertheoretictransformIoTsecurity
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper sets out to establish that a key-encapsulation mechanism can be made genuinely lightweight for resource-constrained devices without sacrificing post-quantum security. It proposes Rudraksh, a module-LWE KEM built from 64-coefficient polynomials, a module rank of 9, modulus 7681, and a centered binomial error distribution, and claims more than 100 bits of Core-SVP post-quantum security with chosen-ciphertext security and failure probability below $2^{-100}$. The motivation is that current lattice KEMs, designed for security and speed, are too heavy for wireless sensors and IoT peripherals, and that earlier lightweight proposals stopped short of CCA security or fell below 100-bit security. If the claims hold, Rudraksh would be the smallest-area post-quantum KEM at its security level, roughly a threefold area reduction relative to the area-optimized Kyber implementation it compares against, while running at substantially higher clock frequency.

What carries the argument

The carrying mechanism is a hardware-driven parameter search over the module-LWE design space that fixes small power-of-two polynomial sizes ($n=32,64,128$) and searches module rank, modulus, and error width to minimize hardware resources while keeping estimated security above 100 bits and failure probability below $2^{-100}$; the chosen point is $n=64,\ell=9,q=7681,\eta=2$. Around that point the paper builds a reconfigurable single-butterfly unit that performs NTT, INTT, pointwise multiplication, compression, and encoding/decoding with a shift-and-add modular reduction tailored to $q=7681$, and an ASCON-based sponge that supplies all pseudorandom bits, hashes, and XOF functions. Synchronous scheduling lets ASCON's 64-bit squeeze output feed the NTT in lockstep, enabling runtime secret generation and reducing memory to three 18K BRAMs. The comparison metric that carries the area claims is the equivalent number of slices (ENS), a normalized gate-area estimate used to compare FPGA implementations across vendors.

What would settle it

Run the same MLWE instance through a second, independent core-SVP estimator (or a direct BKZ simulation with the same sieving cost model) and check whether the predicted bit security remains above 100; if any independent estimate falls below 100 bits, the central security claim fails. A second falsification path would be demonstrating a decryption failure rate above $2^{-100}$ on the claimed parameter set.

Watch

Extended reading notes

Core claim

On its own terms, the paper's central discovery is the parameter and hardware co-design of Rudraksh: an MLWE KEM with polynomial size $n=64$, module rank $\ell=9$, prime modulus $q=7681$, and centered binomial distribution $\eta=2$ that, according to the Leaky-LWE estimator, offers more than 100 bits of Core-SVP post-quantum security and belongs to the AES-128-equivalent level-I category while remaining CCA secure. The design replaces Keccak with the lightweight sponge ASCON for hashing and pseudorandom generation, uses complete NTT multiplication with a shift-and-add modular reduction, stores only two 18K BRAMs for NTT and one for the public key, and reports FPGA implementations on Virtex-7 and Artix-7 whose equivalent slice counts are lower than those of previously published Kyber, Saber, NewHope, Frodo, and NTRU implementations at comparable security. The paper states that Rudraksh 'currently requires the least area among the PQC KEMs of similar security,' with about a $3\times$ area reduction versus the area-optimized Kyber of [HLLM24], $63\%$-$76\%$ higher frequency than high-throughput Kyber, and roughly $2\times$ better time-area product than the compact Kyber of [ZLZ+22].

Load-bearing premise

The security claim rests entirely on what one software estimator predicts for an unusual lattice instance (64-coefficient polynomials, a 9-by-9 module structure, modulus 7681, and a narrow error distribution), with no independent check that the prediction is not optimistic.

Editorial extensions

If this is right

  • If the security estimate holds, lightweight IoT endpoints can run quantum-resistant key establishment with roughly one-third the FPGA area of the most area-optimized Kyber implementation, making the transition to post-quantum cryptography practical on sensors and peripherals.
  • Swapping Keccak for ASCON as the hash and pseudorandom source demonstrates a standardized lightweight sponge can serve a lattice KEM, reducing LUT and flip-flop counts without making the XOF the operational bottleneck.
  • The parameter choice shows the unexplored module-lattice region (small $n$, larger $\ell$) contains viable operating points, so future KEMs need not default to $n=256$ polynomials to reach level-I security.
  • CCA security with failure probability at most $2^{-100}$ and constant-time arithmetic keeps Rudraksh compatible with Fujisaki-Okamoto-style transforms and with timing side-channel resistance, which earlier lightweight lattice proposals lacked.
  • The ability to generate and transmit one polynomial at a time supports interleaved communication and computation, trading total bandwidth for a lower instantaneous bandwidth requirement in gateway-peripheral settings.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • An independent lattice-security estimate for the specific $n=64,\ell=9,q=7681,\eta=2$ instance would be the fastest check on the central claim; the paper relies on a single estimator, and small-polynomial/large-module-rank regimes are exactly where estimator optimism is most plausible.
  • The same design recipe—small polynomial size, large module rank, lightweight sponge, shift-and-add reduction—could plausibly be transplanted to NTRU-based KEMs or hybrid LWE/LWR schemes, and to lattice signatures, but those extensions are not demonstrated here.
  • Because ASCON currently offers at most 128-bit security, replacing it with Keccak for higher security levels would erase part of the area advantage; the scheme's lightweight benefit is thus specific to level-I (AES-128-equivalent) targets.
  • The paper's own side-channel discussion suggests a masked Rudraksh would likely be cheaper than masked Kyber because ASCON is cheaper to mask than Keccak, but the authors explicitly leave this claim unverified.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 6 minor

Summary. The paper proposes Rudraksh, an MLWE-based KEM with polynomial degree n=64, module rank ℓ=9, modulus q=7681, centered-binomial parameter η=2, and message encoding B=2. The parameter set is obtained from a hardware-driven exploration of polynomial size, modulus structure, polynomial multiplication, and secret/error distribution. The KEM follows a FrodoKEM-style Fujisaki–Okamoto transform and replaces Keccak with ASCON for hashing, XOF, and PRF generation. A compact FPGA implementation on Virtex-7 and Artix-7 is presented, using a single DSP and three 18K BRAMs, with claimed 2.9–3× lower area than the compact Kyber implementation of [HLLM24], higher frequency than high-throughput Kyber designs, and 104-bit quantum Core-SVP security.

Significance. If the security estimate is independently confirmed and the CCA claim is backed by a precise theorem, Rudraksh would be a useful data point for lightweight post-quantum KEMs: the hardware results show substantial LUT/FF/BRAM/DSP reductions versus prior Kyber implementations, and the use of ASCON as a lightweight hash/XOF is an interesting contribution. The paper contains a detailed hardware architecture, careful scheduling, and extensive comparisons, which are valuable. However, the paper does not ship test vectors, source code, or a machine-checked proof; the security estimate is reported as a single number from one estimator, the failure probability is stated without derivation, and the CCA-security claim is asserted by reference to existing FO constructions rather than proved for the exact scheme. These gaps are load-bearing for the headline claims and need to be addressed before the results can be fully accepted.

major comments (4)
  1. [§3.6, Table 1, Abstract] The 104-bit quantum Core-SVP estimate for KEM-poly64 has only a 4-bit margin over the claimed 100-bit NIST-level-I threshold, and it comes solely from the Leaky-LWE estimator [DSDGR20], which was also used to search the parameter space. Because the scheme operates at n=64, ℓ=9, a regime far from Kyber's n=256, ℓ=2, an estimator bias of even a few bits would invalidate the headline security claim. Please provide independent security estimates using at least one additional estimator with several attack models (e.g., the lattice-estimator), and either confirm the 104-bit number or adjust the parameter set/claim. The abstract should also distinguish the heuristic Core-SVP bound from the CCA-security property.
  2. [§2.3, Fig. 3] The CCA-security claim is asserted by stating that the KEM 'closely follows' FrodoKEM and by citing [JZC+18], but no concrete security theorem is given for the exact construction in Fig. 3. Please state the theorem, including the QROM assumptions on G and H, the correctness bound δ required by the FO variant, and the role of Arrange_msg/Original_msg encoding. Verify explicitly that the failure probability computed in §3.6 satisfies the required δ and that instantiating G and H with ASCON is compatible with the random-oracle modeling. Without this, the abstract's claim of chosen-ciphertext security is not supported by the manuscript.
  3. [§5.2, Table 5] The claim that Rudraksh 'currently requires the least area among the PQC KEMs of similar security' is based on ENS values computed across different FPGA families (Virtex-7/Artix-7 versus Kintex-7, Zynq UltraScale+, Virtex-E) and, presumably, different synthesis tool settings. Please justify the cross-platform normalization or qualify the claim to the reported boards and toolchains; as presented, the 2.9–3× area improvement over [HLLM24] is not directly supported because the two designs are measured on different FPGA families.
  4. [§3.6, §3.1] The failure probability of 2^-128 for KEM-poly64 is stated without derivation, and no script or table of decryption-noise statistics is provided. Since the FO-based CCA transform in §2.3 depends on an explicit correctness bound δ, please provide the exact computation or a reproducible script for the decryption-noise distribution of the chosen parameters, including the effect of the B=2 message encoding and the compression parameters p and t.
minor comments (6)
  1. [§4.6, §6] The statement that 'the implementation of Rudraksh is constant-time' is too broad, because the rejection sampler for the public matrix is explicitly variable time; please specify that all secret-dependent operations are constant-time and identify which operations are covered.
  2. [§4.2] There is a typo in 'Montogomery' (should be 'Montgomery'), and Algorithm 1 would benefit from a short derivation or proof of the shift-and-add reduction identities, since it is a new building block.
  3. [§2.3, Fig. 3] The KEM in Fig. 3 is called 'closely follows' FrodoKEM, but the encoding, compression, and NTT-domain operations differ; please add a precise pointer to the FrodoKEM specification and list the differences so that the claimed relationship is checkable.
  4. [§3.6, Fig. 5] Figure 5 has no visible axis labels or legend; the caption should explain what the arrows and colors represent and how the 'optimal point' is selected.
  5. [§5.1, Table 4] The ASCON-versus-Keccak comparison in Table 4 reports only LUT/FF and ENS; reporting the same comparison on the same FPGA and toolchain would strengthen the causal claim that replacing Keccak with ASCON is responsible for the area reduction.
  6. [Abstract, §5.2] The abstract's '~3× improvement' is stated for area versus [HLLM24], but Table 5 reports a 2.9× ENS reduction; the wording should be made consistent.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the security estimate comes from an external estimator, the CCA transform from the literature, and the area claims from fresh FPGA measurements.

full rationale

The paper's central claims are not derived from its own prior results. The CCA security of Rudraksh rests on the standard FO transform [HHK17] plus an MLWE hardness estimate from the external Leaky-LWE estimator [DSDGR20]; the paper explicitly reports 104-bit quantum Core-SVP for KEM-poly64 (Table 1, Section 3.6) and does not fit any parameter to a quantity that it then claims to predict. The parameter search is presented as a multi-dimensional exploration over n, ℓ, q, and CBD parameters, with the final choice (KEM-poly64) selected by the paper's own memory/area estimates and then verified by its own FPGA implementation, so the hardware-area comparisons in Section 5.2 are independent measurements rather than fitted outputs. The authors do cite their own earlier work (e.g., Scabbard [BKKV21], Scabbard hardware [KNK+24]), but these citations are used for background and for comparison baselines, not to justify the security or correctness of Rudraksh; there is no invoked uniqueness theorem, no imported ansatz, and no self-referential load-bearing step. The only notable caveat is that the 100-bit Core-SVP claim inherits the accuracy of the external estimator for an unusual (n=64, ℓ=9) parameter set, and the abstract's phrasing loosely equates a heuristic Core-SVP estimate with CCA security; that is a correctness/confidence concern, not circularity. Calling the estimate a prediction of the scheme's security would still not make it circular, since the estimator is external to the paper and not equivalent to any equation derived in it.

Assumptions & free parameters 6 free parameters · 4 assumptions · 0 invented entities

The central claims depend on the chosen scheme parameters, the MLWE hardness assumption, the FO transform, the security estimator, and the use of ASCON. No new algorithmic entities are introduced.

free parameters (6)
  • polynomial size n = 64
    Chosen by minimizing hardware memory while keeping security and failure probability in range (Section 3.1, Table 1).
  • module rank ell = 9
    Selected with n to keep lattice dimension n' = 576 for ~104-bit Core-SVP security and minimal memory (Section 3.1, Table 1).
  • prime modulus q = 7681
    Picked as an NTT-friendly 13-bit prime balancing security, failure probability, and hardware cost (Section 3.2, Table 1).
  • CBD parameter eta = 2
    Smallest centered binomial parameter that meets the security target while limiting decryption failure (Section 3.4, Table 1).
  • message encoding B = 2
    Number of message bits per coefficient, set by n=64 and lenK=128 (Section 3.1, Table 1).
  • compression modulus bits log2 p, log2 t = 10, 3
    Reconciliation parameters chosen to keep failure probability below 2^-100 (Section 3.2, Table 1).
assumptions (4)
  • domain assumption Hardness of the Module-LWE problem with the chosen parameters
    The IND-CPA security of the PKE relies on the hardness of MLWE, as stated in Section 2.1 and used in Section 3.6.
  • standard math Validity of the Fujisaki-Okamoto transform for the construction in Fig. 3
    The CCA security claim is inherited from the FO transform as in HHK17 and JZC+18; the paper says the KEM 'closely follows the FrodoKEM construction' but does not reproduce the proof.
  • ad hoc to paper Accuracy of the Leaky-LWE estimator [DSDGR20] for Core-SVP security
    The claimed bit security (104 quantum, 114 classical) comes solely from this estimator; its accuracy for small n and large ell is not independently verified.
  • domain assumption ASCON as a secure hash and XOF for this application
    ASCON is used for G, H, and PRF; the paper relies on its NIST lightweight standard status, but the specific domain separation for matrix and secret generation is a design choice.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Rudraksh: A compact and lightweight post-quantum key-encapsulation mechanism." pith.science (2026). https://pith.science/paper/5MFAZEO5

@misc{pith2026250113799,
  author       = {Pith},
  title        = {Pith review of: Rudraksh: A compact and lightweight post-quantum key-encapsulation mechanism},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/5MFAZEO5}},
  note         = {Machine review of arXiv:2501.13799}
}
abstract

Resource-constrained devices such as wireless sensors and Internet of Things (IoT) devices have become ubiquitous in our digital ecosystem. These devices generate and handle a major part of our digital data. However, due to the impending threat of quantum computers on our existing public-key cryptographic schemes and the limited resources available on IoT devices, it is important to design lightweight post-quantum cryptographic (PQC) schemes suitable for these devices. In this work, we explored the design space of learning with error-based PQC schemes to design a lightweight key-encapsulation mechanism (KEM) suitable for resource-constrained devices. We have done a scrupulous and extensive analysis and evaluation of different design elements, such as polynomial size, field modulus structure, reduction algorithm, and secret and error distribution of an LWE-based KEM. Our explorations led to the proposal of a lightweight PQC-KEM, Rudraksh, without compromising security. Our scheme provides security against chosen ciphertext attacks (CCA) with more than 100 bits of Core-SVP post-quantum security and belongs to the NIST-level-I security category (provide security at least as much as AES-128). We have also shown how ASCON can be used for lightweight pseudo-random number generation and hash function in the lattice-based KEMs instead of the widely used Keccak for lightweight design. Our FPGA results show that Rudraksh currently requires the least area among the PQC KEMs of similar security. Our implementation of Rudraksh provides a $\sim3\times$ improvement in terms of the area requirement compared to the state-of-the-art area-optimized implementation of Kyber, can operate at $63\%$-$76\%$ higher frequency with respect to high-throughput Kyber, and improves time-area-product $\sim2\times$ compared to the state-of-the-art compact implementation of Kyber published in HPEC 2022.

Figures

Figures reproduced from arXiv: 2501.13799 by the authors.

Figure 1
Figure 1. An illustrative example of a typical IoT gateway architecture. [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. MLWE based IND-CPA secure PKE using NTT as Compress(x ′ )= px′+⌊q/2⌉ q mod p. Decompress:Rp −→Rq is defined as Decompress(x)= ⌊ q p ⌉x. The Encode :R2B −→Rq is defined as Encode(m) =⌊ q 2B ⌉m and the Decode :Rq −→ R2B is defined as Decode(m′′)= 2 Bm′′+⌊q/2⌉ q mod 2B. Compress, Decompress, Encode, and Decode operations are applied coefficient-wise to each polynomial and vector of polynomials. 2.3 MLWE-based Key Encap… view at source ↗
Figure 3
Figure 3. MLWE based IND-CCA secure KEM using NTT [PITH_FULL_IMAGE:figures/full_fig_p005_3.png] view at source ↗
Figures from the paper (6 more)
Figure 4
Figure 4. Figure 4: Design space of lattice-based KEMs depending on the different variations of LWE [PITH_FULL_IMAGE:figures/full_fig_p009_4.png]
Figure 5
Figure 5. Figure 5: Relation between n ′ , q, and η (η1/η2) when n = 64 is fixed (arrows indicate the direction of increase in values). The parameter set of the optimal point is selected for KEM-poly64 [PITH_FULL_IMAGE:figures/full_fig_p014_5.png]
Figure 7
Figure 7. Figure 7: Full system architecture [PITH_FULL_IMAGE:figures/full_fig_p015_7.png]
Figure 9
Figure 9. Figure 9: Structure of ASCON XOF hardware [PITH_FULL_IMAGE:figures/full_fig_p017_9.png]
Figure 10
Figure 10. Figure 10: Memory organization of the NTT module As the greatest common divisor between 13 and 64 is 1, the minimum size of the shift register needs to be 64+12= 76 to accommodate extra bits of the input stream for all possible cases. The same buffer temporarily stores the outpu…
Figure 11
Figure 11. Figure 11: Scheduling with ASCON and butterfly module [PITH_FULL_IMAGE:figures/full_fig_p019_11.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

107 extracted references · 79 canonical work pages

  1. [1]

    Cortex- M 4 optimizations for R,M LWE schemes

    Erdem Alkim, Yusuf Alper Bilgin, Murat Cenk, and François Gérard. Cortex- M 4 optimizations for R,M LWE schemes . IACR Transactions on Cryptographic Hardware and Embedded Systems , 2020(3):336–357, Jun. 2020

  2. [2]

    Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process

    Gorjan Alagic, Daniel Apon, David Cooper, Quynh Dang, Thinh Dang, John Kelsey, Jacob Lichtinger, Yi-Kai Liu, Carl Miller, Dustin Moody, Rene Peralta, Ray Perlner, Angela Robinson, and Daniel Smith-Tone. Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process . Online. Accessed 26th June, 2023, 2022. https://nvlpubs.n...

  3. [3]

    Status Report on the Second Round of the NIST Post-Quantum Cryptography Standardization Process , 2020

    Gorjan Alagic, Jacob Alperin-Sheriff, Daniel Apon, David Cooper, Quynh Dang, John Kelsey, Yi-Kai Liu, Carl Miller, Dustin Moody, Rene Peralta, Ray Perlner, Angela Robinson, and Daniel Smith-Tone. Status Report on the Second Round of the NIST Post-Quantum Cryptography Standardization Process , 2020. https://nvlpubs.nist.gov/nistpubs/ir/2020/NIST.IR.8309.pdf

  4. [4]

    Bernstein, Ward Beullens, Christoph Dobraunig, Maria Eichlseder, Scott Fluhrer, Stefan-Lukas Gazdag, Andreas H \" u lsing, Panos Kampanakis, Stefan Kölbl, Tanja Lange, Martin M

    Jean-Philippe Aumasson, Daniel J. Bernstein, Ward Beullens, Christoph Dobraunig, Maria Eichlseder, Scott Fluhrer, Stefan-Lukas Gazdag, Andreas H \" u lsing, Panos Kampanakis, Stefan Kölbl, Tanja Lange, Martin M. Lauridsen, Florian Mendel, Ruben Niederhagen, Christian Rechberger, Joost Rijneveld, Peter Schwabe, and Bas Westerbaan. SPHINCS+ Submission to th...

  5. [5]

    Schanck, Peter Schwabe, Gregor Seiler, and Damien Stehl \'e

    Roberto Avanzi, Joppe Bos, L \'e o Ducas, Eike Kiltz, Tancr \'e de Lepoint, Vadim Lyubashevsky, John M. Schanck, Peter Schwabe, Gregor Seiler, and Damien Stehl \'e . Kyber, 2020. https://github.com/pq-crystals/kyber/tree/main

  6. [6]

    Schanck, Peter Schwabe, Gregor Seiler, and Damien Stehle

    Roberto Avanzi, Joppe Bos, Leo Ducas, Eike Kiltz, Tancrede Lepoint, Vadim Lyubashevsky, John M. Schanck, Peter Schwabe, Gregor Seiler, and Damien Stehle. CRYSTALS-Kyber Algorithm Specifications And Supporting Documentation (version 3.02) , 2021. https://pq-crystals.org/kyber/data/kyber-specification-round3-20210804.pdf

  7. [7]

    Kannwischer, and Bo-Yin Yang

    Amin Abdulrahman, Jiun-Peng Chen, Yu-Jia Chen, Vincent Hwang, Matthias J. Kannwischer, and Bo-Yin Yang. Multi-moduli NTTs for Saber on Cortex-M3 and Cortex-M4 . IACR Transactions on Cryptographic Hardware and Embedded Systems , 2022(1):127–151, Nov. 2021

  8. [8]

    Post-quantum Key Exchange - A New Hope

    Erdem Alkim, L \' e o Ducas, Thomas P \" o ppelmann, and Peter Schwabe. Post-quantum Key Exchange - A New Hope . In Thorsten Holz and Stefan Savage, editors, 25th USENIX Security Symposium, USENIX Security 16, Austin, TX, USA, August 10-12, 2016 , pages 327--343. USENIX Association, 2016

Show all 107 references
  1. [9]

    Quark: A Lightweight Hash

    Jean - Philippe Aumasson, Luca Henzen, Willi Meier, and Mar \' a Naya - Plasencia. Quark: A Lightweight Hash . Journal of Cryptology , 26(2):313--339, 2013

  2. [10]

    High-Speed NTT-based Polynomial Multiplication Accelerator for Post-Quantum Cryptography

    Mojtaba Bisheh - Niasar, Reza Azarderakhsh, and Mehran Mozaffari Kermani. High-Speed NTT-based Polynomial Multiplication Accelerator for Post-Quantum Cryptography . In 28th IEEE Symposium on Computer Arithmetic, ARITH 2021, Lyngby, Denmark, June 14-16, 2021 , pages 94--101. IE...

  3. [11]

    SABER: Mod-LWR based KEM (Round 3 Submission) , 2021

    Andrea Basso, Jose Maria Bermudo Mera , Jan-Pieter D’Anvers, Angshuman Karmakar, Sujoy Sinha Roy, Michiel Van Beirendonck, and Frederik Vercauteren. SABER: Mod-LWR based KEM (Round 3 Submission) , 2021. https://www.esat.kuleuven.be/cosic/pqcrypto/saber/files/saberspecround3.pdf

  4. [12]

    Fluhrer, \' O scar Garc \' a - Morch \' o n, Thijs Laarhoven, Ronald Rietman, Markku - Juhani O

    Hayo Baan, Sauvik Bhattacharya, Scott R. Fluhrer, \' O scar Garc \' a - Morch \' o n, Thijs Laarhoven, Ronald Rietman, Markku - Juhani O. Saarinen, Ludo Tolhuizen, and Zhenfei Zhang. Round5: Compact and Fast Post-quantum Public-Key Encryption . In Jintai Ding and Rainer Steinw...

  5. [13]

    Bos, Craig Costello, L \' e o Ducas, Ilya Mironov, Michael Naehrig, Valeria Nikolaenko, Ananth Raghunathan, and Douglas Stebila

    Joppe W. Bos, Craig Costello, L \' e o Ducas, Ilya Mironov, Michael Naehrig, Valeria Nikolaenko, Ananth Raghunathan, and Douglas Stebila. Frodo: Take off the Ring! Practical, Quantum-Secure Key Exchange from LWE . In Edgar R. Weippl, Stefan Katzenbeisser, Christopher Kruegel, ...

  6. [14]

    TurboSHAKE

    Guido Bertoni, Joan Daemen, Seth Hoffert, Michaël Peeters, Gilles Van Assche, Ronny Van Keer, and Benoît Viguier. TurboSHAKE . Cryptology ePrint Archive, Paper 2023/342, 2023. https://eprint.iacr.org/2023/342

  7. [15]

    Schanck, Peter Schwabe, Gregor Seiler, and Damien Stehle

    Joppe Bos, Leo Ducas, Eike Kiltz, Tancrede Lepoint, Vadim Lyubashevsky, John M. Schanck, Peter Schwabe, Gregor Seiler, and Damien Stehle. CRYSTALS - Kyber: A CCA-Secure Module-Lattice-Based KEM . In 2018 IEEE European Symposium on Security and Privacy (EuroS & P) , pages 353--...

  8. [16]

    Cryptographic sponge functions , 2011

    Guido Bertoni, Joan Daemen, Micha \" e l Peeters, and Gilles Van Assche . Cryptographic sponge functions , 2011. https://keccak.team/files/CSF-0.1.pdf

  9. [17]

    Guido Bertoni, Joan Daemen, Micha \" e l Peeters, and Gilles Van Assche . Keccak. In Thomas Johansson and Phong Q. Nguyen, editors, Advances in Cryptology - EUROCRYPT 2013, 32nd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Athens,...

  10. [18]

    o pfert, Tim G \

    Johannes Buchmann, Florian G \" o pfert, Tim G \" u neysu, Tobias Oder, and Thomas P \" o ppelmann. High-Performance and Lightweight Lattice-Based Public-Key Encryption . In Richard Chow and G \" o kay Saldamli, editors, Proceedings of the 2nd ACM International Workshop on IoT...

  11. [19]

    An Elliptic Curve Processor Suitable For RFID -Tags

    Lejla Batina, Jorge Guajardo, Tim Kerins, Nele Mentens, Pim Tuyls, and Ingrid Verbauwhede. An Elliptic Curve Processor Suitable For RFID -Tags . Cryptology ePrint Archive, Paper 2006/227, 2006. https://eprint.iacr.org/2006/227

  12. [20]

    Scabbard: a suite of efficient learning with rounding key-encapsulation mechanisms

    Jose Maria Bermudo Mera , Angshuman Karmakar, Suparna Kundu, and Ingrid Verbauwhede. Scabbard: a suite of efficient learning with rounding key-encapsulation mechanisms . IACR Trans. Cryptogr. Hardw. Embed. Syst. , 2021(4):474--509, 2021

  13. [21]

    Kannwischer, and Peter Schwabe

    Leon Botros, Matthias J. Kannwischer, and Peter Schwabe. Memory-Efficient High-Speed Implementation of Kyber on Cortex-M4 . In Johannes Buchmann, Abderrahmane Nitaj, and Tajje - eddine Rachidi, editors, Progress in Cryptology - AFRICACRYPT 2019 - 11th International Conference ...

  14. [22]

    Time-memory trade-off in Toom-Cook multiplication: an application to module-lattice based cryptography

    Jose Maria Bermudo Mera , Angshuman Karmakar, and Ingrid Verbauwhede. Time-memory trade-off in Toom-Cook multiplication: an application to module-lattice based cryptography . IACR Trans. Cryptogr. Hardw. Embed. Syst. , 2020(2):222--244, 2020

  15. [23]

    ALE: AES-Based Lightweight Authenticated Encryption

    Andrey Bogdanov, Florian Mendel, Francesco Regazzoni, Vincent Rijmen, and Elmar Tischhauser. ALE: AES-Based Lightweight Authenticated Encryption . In FSE , volume 8424 of Lecture Notes in Computer Science , pages 447--466. Springer, 2013

  16. [24]

    Low-cost elliptic curve cryptography for wireless sensor networks

    Lejla Batina, Nele Mentens, Kazuo Sakiyama, Bart Preneel, and Ingrid Verbauwhede. Low-cost elliptic curve cryptography for wireless sensor networks. In ESAS , volume 4357 of Lecture Notes in Computer Science , pages 6--17. Springer, 2006

  17. [25]

    Pseudorandom Functions and Lattices

    Abhishek Banerjee, Chris Peikert, and Alon Rosen. Pseudorandom Functions and Lattices . In Advances in Cryptology - EUROCRYPT 2012 , volume 7237 of Lecture Notes in Computer Science , pages 719--737. Springer, 2012

  18. [26]

    NIST post-quantum cryptography- a hardware evaluation study

    Kanad Basu, Deepraj Soni, Mohammed Nabeel, and Ramesh Karri. NIST post-quantum cryptography- a hardware evaluation study. Cryptology ePrint Archive, Paper 2019/047, 2019. https://eprint.iacr.org/2019/047

  19. [27]

    Compact domain-specific co-processor for accelerating module lattice-based KEM

    Jose Maria Bermudo Mera , Furkan Turan, Angshuman Karmakar, Sujoy Sinha Roy, and Ingrid Verbauwhede. Compact domain-specific co-processor for accelerating module lattice-based KEM . In 57th ACM/IEEE Design Automation Conference, DAC 2020, San Francisco, CA, USA, July 20-24, 20...

  20. [28]

    Ukyab, and Anantha P

    Utsav Banerjee, Tenzin S. Ukyab, and Anantha P. Chandrakasan. Sapphire: A configurable crypto-processor for post-quantum lattice-based protocols (extended version). Cryptology ePrint Archive, Paper 2019/1140, 2019. https://eprint.iacr.org/2019/1140

  21. [29]

    The Competition for Authenticated Encryption: Security, Applicability, and Robustness , 2019

    CAESAR. The Competition for Authenticated Encryption: Security, Applicability, and Robustness , 2019. https://competitions.cr.yp.to/caesar-submissions.html

  22. [30]

    A Very Compact S-Box for AES

    David Canright. A Very Compact S-Box for AES . In Josyula R. Rao and Berk Sunar, editors, Cryptographic Hardware and Embedded Systems - CHES 2005, 7th International Workshop, Edinburgh, UK, August 29 - September 1, 2005, Proceedings , volume 3659 of Lecture Notes in Computer S...

  23. [31]

    SMAUG : Pushing lattice-based key encapsulation mechanisms to the limits

    Jung Hee Cheon, Hyeongmin Choe, Dongyeon Hong, and MinJune Yi. SMAUG : Pushing lattice-based key encapsulation mechanisms to the limits. Cryptology ePrint Archive, Paper 2023/739, 2023. https://eprint.iacr.org/2023/739

  24. [32]

    Schanck, Peter Schwabe, William Whyte, and Zhenfei Zhang

    Cong Chen, Oussama Danba, Jeffrey Hoffstein, Andreas Hülsing, Joost Rijneveld, John M. Schanck, Peter Schwabe, William Whyte, and Zhenfei Zhang. NTRU Algorithm Specifications And Supporting Documentation , 2019. https://ntru.org/f/ntru-20190330.pdf

  25. [33]

    Kannwischer, Gregor Seiler, Cheng - Jhih Shih, and Bo - Yin Yang

    Chi - Ming Marvin Chung, Vincent Hwang, Matthias J. Kannwischer, Gregor Seiler, Cheng - Jhih Shih, and Bo - Yin Yang. NTT Multiplication for NTT-unfriendly Rings New Speed Records for Saber and NTRU on Cortex-M4 and AVX2 . IACR Trans. Cryptogr. Hardw. Embed. Syst. , 2021(2):15...

  26. [34]

    Lizard: Cut Off the Tail! A Practical Post-quantum Public-Key Encryption from LWE and LWR

    Jung Hee Cheon, Duhyeong Kim, Joohee Lee, and Yongsoo Song. Lizard: Cut Off the Tail! A Practical Post-quantum Public-Key Encryption from LWE and LWR . In Dario Catalano and Roberto De Prisco, editors, Security and Cryptography for Networks - 11th International Conference, SCN...

  27. [35]

    Post-Quantum Cryptography: Digital Signature Schemes

    Lily Chen, Dustin Moody, and Yi-Kai Liu. Post-Quantum Cryptography: Digital Signature Schemes. Round 1 Additional Signatures , 2023. https://csrc.nist.gov/Projects/pqc-dig-sig/round-1-additional-signatures

  28. [36]

    Yuanmi Chen and Phong Q. Nguyen. BKZ 2.0: Better Lattice Security Estimates . In Dong Hoon Lee and Xiaoyun Wang, editors, Advances in Cryptology - ASIACRYPT 2011 - 17th International Conference on the Theory and Application of Cryptology and Information Security, Seoul, South ...

  29. [37]

    Stephen A. Cook. On the Minimum Computation Time of Functions . PhD thesis, Harvard University, 1966. pp. 51-77

  30. [38]

    ASCON: Lightweight Authenticated Encryption & Hashing , 2012

    Christoph Dobraunig, Maria Eichlseder, Florian Mendel, and Martin Schläffer. ASCON: Lightweight Authenticated Encryption & Hashing , 2012. https://ascon.iaik.tugraz.at/files/asconv12-nist.pdf

  31. [39]

    Implementation and benchmarking of round 2 candidates in the NIST post-quantum cryptography standardization process using hardware and software/hardware co-design approaches

    Viet Ba Dang, Farnoud Farahmand, Michal Andrzejczak, Kamyar Mohajerani, Duc Tri Nguyen, and Kris Gaj. Implementation and benchmarking of round 2 candidates in the NIST post-quantum cryptography standardization process using hardware and software/hardware co-design approaches. ...

  32. [40]

    Decryption Failure Attacks on IND-CCA Secure Lattice-Based Schemes

    Jan-Pieter D’Anvers, Qian Guo, Thomas Johansson, Alexander Nilsson, Frederik Vercauteren, and Ingrid Verbauwhede. Decryption Failure Attacks on IND-CCA Secure Lattice-Based Schemes . In Public-Key Cryptography – PKC 2019 , volume 11443 of Lecture Notes in Computer Science , pa...

  33. [41]

    CRYSTALS-Dilithium: A Lattice-Based Digital Signature Scheme

    Léo Ducas, Eike Kiltz, Tancrède Lepoint, Vadim Lyubashevsky, Peter Schwabe, Gregor Seiler, and Damien Stehlé. CRYSTALS-Dilithium: A Lattice-Based Digital Signature Scheme . IACR Transactions on Cryptographic Hardware and Embedded Systems , 2018(1):238–268, Feb. 2018

  34. [42]

    Saber: Module-LWR Based Key Exchange, CPA-Secure Encryption and CCA-Secure KEM

    Jan - Pieter D'Anvers, Angshuman Karmakar, Sujoy Sinha Roy, and Frederik Vercauteren. Saber: Module-LWR Based Key Exchange, CPA-Secure Encryption and CCA-Secure KEM . In AFRICACRYPT , volume 10831 of Lecture Notes in Computer Science , pages 282--305. Springer, 2018

  35. [43]

    High-Speed Hardware Architectures and FPGA Benchmarking of CRYSTALS-Kyber, NTRU, and Saber

    Viet Ba Dang, Kamyar Mohajerani, and Kris Gaj. High-Speed Hardware Architectures and FPGA Benchmarking of CRYSTALS-Kyber, NTRU, and Saber . IEEE Trans. Computers , 72(2):306--320, 2023

  36. [44]

    LWE with Side Information: Attacks and Concrete Security Estimation

    Dana Dachman-Soled, Léo Ducas, Huijing Gong, and Mélissa Rossi. LWE with Side Information: Attacks and Concrete Security Estimation . Cryptology ePrint Archive, Report 2020/292, 2020. https://eprint.iacr.org/2020/292

  37. [45]

    Lightweight and Fault-Resilient Implementations of Binary Ring-LWE for IoT Devices

    Shahriar Ebrahimi and Siavash Bayat-Sarmadi. Lightweight and Fault-Resilient Implementations of Binary Ring-LWE for IoT Devices . IEEE Internet of Things Journal , 7(8):6970--6978, 2020

  38. [46]

    Post-Quantum Cryptoprocessors Optimized for Edge and Resource-Constrained Devices in IoT

    Shahriar Ebrahimi, Siavash Bayat-Sarmadi, and Hatameh Mosanaei-Boorani. Post-Quantum Cryptoprocessors Optimized for Edge and Resource-Constrained Devices in IoT . IEEE Internet of Things Journal , 6(3):5500--5507, 2019

  39. [47]

    Falcon: Fast-Fourier Lattice-based Compact Signatures over NTRU , 2018

    Pierre-Alain Fouque, Jeffrey Hoffstein, Paul Kirchner, Vadim Lyubashevsky, Thomas Pornin, Thomas Prest, Thomas Ricosset, Gregor Seiler, William Whyte, and Zhenfei Zhang. Falcon: Fast-Fourier Lattice-based Compact Signatures over NTRU , 2018. https://falcon-sign.info/

  40. [48]

    A 334 \( \) W 0.158 mm\( ^ 2 \) Saber Learning with Rounding based Post-Quantum Crypto Accelerator

    Archisman Ghosh, Jose Maria Bermudo Mera , Angshuman Karmakar, Debayan Das, Santosh Ghosh, Ingrid Verbauwhede, and Shreyas Sen. A 334 \( \) W 0.158 mm\( ^ 2 \) Saber Learning with Rounding based Post-Quantum Crypto Accelerator . In IEEE Custom Integrated Circuits Conference, C...

  41. [49]

    A 334 \( \) W 0.158 mm\( ^ 2 \) ASIC for Post-Quantum Key-Encapsulation Mechanism Saber With Low-Latency Striding Toom-Cook Multiplication

    Archisman Ghosh, Jose Maria Bermudo Mera , Angshuman Karmakar, Debayan Das, Santosh Ghosh, Ingrid Verbauwhede, and Shreyas Sen. A 334 \( \) W 0.158 mm\( ^ 2 \) ASIC for Post-Quantum Key-Encapsulation Mechanism Saber With Low-Latency Striding Toom-Cook Multiplication . IEEE J. ...

  42. [50]

    Archisman Ghosh, Debayan Das, Josef Danial, Vivek De, Santosh Ghosh, and Shreyas Sen. 36.2 An EM/power SCA-resilient AES-256 with synthesizable signature attenuation using digital-friendly current source and RO-bleed-based integrated local feedback and global switched-mode con...

  43. [51]

    Syn-STELLAR: An EM/power SCA-resilient AES-256 with synthesis-friendly signature attenuation

    Archisman Ghosh, Debayan Das, Josef Danial, Vivek De, Santosh Ghosh, and Shreyas Sen. Syn-STELLAR: An EM/power SCA-resilient AES-256 with synthesis-friendly signature attenuation . IEEE Journal of Solid-State Circuits , 57(1):167--181, 2021

  44. [52]

    Denisa O. C. Greconici, Matthias J. Kannwischer, and Amber Sprenkels. Compact Dilithium Implementations on Cortex-M3 and Cortex-M4 . IACR Transactions on Cryptographic Hardware and Embedded Systems , 2021(1):1–24, Dec. 2020

  45. [53]

    Power and EM SCA resilience in 65nm AES-256 exploiting clock-slew dependent variability in CMOS digital circuits

    Archisman Ghosh, Md Abdur Rahman, Debayan Das, Santosh Ghosh, and Shreyas Sen. Power and EM SCA resilience in 65nm AES-256 exploiting clock-slew dependent variability in CMOS digital circuits . In 2023 IEEE Custom Integrated Circuits Conference (CICC) , pages 1--2. IEEE, 2023

  46. [54]

    Abdur Rahman, Debayan Das, Santosh Ghosh, and Shreyas Sen

    Archisman Ghosh, Md. Abdur Rahman, Debayan Das, Santosh Ghosh, and Shreyas Sen. Exploiting clock-slew dependent variability in CMOS digital circuits towards power and EM SCA resilience. Cryptology ePrint Archive, Paper 2024/1019, 2024. https://eprint.iacr.org/2024/1019

  47. [55]

    A Digital Cascoded Signature Attenuation Countermeasure with Intelligent Malicious Voltage Drop Attack Detector for EM/Power SCA Resilient Parallel AES-256

    Archisman Ghosh, Dong-Hyun Seo, Debayan Das, Santosh Ghosh, and Shreyas Sen. A Digital Cascoded Signature Attenuation Countermeasure with Intelligent Malicious Voltage Drop Attack Detector for EM/Power SCA Resilient Parallel AES-256 . In 2022 IEEE Custom Integrated Circuits Co...

  48. [56]

    Hassan and Mohammed Benaissa

    Mohamed N. Hassan and Mohammed Benaissa. A scalable hardware/software co-design for elliptic curve cryptography on PicoBlaze microcontroller . In Proceedings of 2010 IEEE International Symposium on Circuits and Systems , pages 2111--2114, 2010

  49. [57]

    Novel Low-Complexity Polynomial Multiplication Over Hybrid Fields for Efficient Implementation of Binary Ring-LWE Post-Quantum Cryptography

    Pengzhou He, Ujjwal Guin, and Jiafeng Xie. Novel Low-Complexity Polynomial Multiplication Over Hybrid Fields for Efficient Implementation of Binary Ring-LWE Post-Quantum Cryptography . IEEE Journal on Emerging and Selected Topics in Circuits and Systems , 11(2):383--394, 2021

  50. [58]

    A Modular Analysis of the Fujisaki-Okamoto Transformation

    Dennis Hofheinz, Kathrin H \" o velmanns, and Eike Kiltz. A Modular Analysis of the Fujisaki-Okamoto Transformation . In Yael Kalai and Leonid Reyzin, editors, Theory of Cryptography - 15th International Conference, TCC 2017, Baltimore, MD, USA, November 12-15, 2017, Proceedin...

  51. [59]

    A pure hardware implementation of CRYSTALS-KYBER PQC algorithm through resource reuse

    Yiming Huang, Miaoqing Huang, Zhongkui Lei, and Jiaxuan Wu. A pure hardware implementation of CRYSTALS-KYBER PQC algorithm through resource reuse. IEICE Electron. Express , 17(17):20200234, 2020

  52. [60]

    Kannwischer, Georg Land, Thomas Pöppelmann, Peter Schwabe, and Amber Sprenkels

    Daniel Heinz, Matthias J. Kannwischer, Georg Land, Thomas Pöppelmann, Peter Schwabe, and Amber Sprenkels. First-Order Masked Kyber on ARM Cortex-M4 . Cryptology ePrint Archive, Paper 2022/058, 2022. https://eprint.iacr.org/2022/058

  53. [61]

    A lightweight hardware implementation of CRYSTALS-Kyber

    Shiyang He, Hui Li, Fenghua Li, and Ruhui Ma. A lightweight hardware implementation of CRYSTALS-Kyber . Journal of Information and Intelligence , 2(2):167--176, 2024

  54. [62]

    Standard Lattice-Based Key Encapsulation on Embedded Devices

    James Howe, Tobias Oder, Markus Krausz, and Tim G \" u neysu. Standard Lattice-Based Key Encapsulation on Embedded Devices . IACR Trans. Cryptogr. Hardw. Embed. Syst. , 2018(3):372--393, 2018

  55. [63]

    Silverman

    Jeffrey Hoffstein, Jill Pipher, and Joseph H. Silverman. NTRU: A R ing- B ased P ublic K ey C ryptosystem . In Joe Buhler, editor, Algorithmic Number Theory, Third International Symposium, ANTS-III, Portland, Oregon, USA, June 21-25, 1998, Proceedings , volume 1423 of Lecture ...

  56. [64]

    A New RFID Privacy Model

    Jens Hermans, Andreas Pashalidis, Frederik Vercauteren, and Bart Preneel. A New RFID Privacy Model . In Vijay Atluri and Claudia D \' az, editors, Computer Security - ESORICS 2011 - 16th European Symposium on Research in Computer Security, Leuven, Belgium, September 12-14, 201...

  57. [65]

    Hein, Johannes Wolkerstorfer, and Norbert Felber

    Daniel M. Hein, Johannes Wolkerstorfer, and Norbert Felber. ECC Is Ready for RFID - A Proof in Silicon . In Roberto Maria Avanzi, Liam Keliher, and Francesco Sica, editors, Selected Areas in Cryptography, 15th International Workshop, SAC 2008, Sackville, New Brunswick, Canada,...

  58. [66]

    IND-CCA-Secure Key Encapsulation Mechanism in the Quantum Random Oracle Model, Revisited

    Haodong Jiang, Zhenfeng Zhang, Long Chen, Hong Wang, and Zhi Ma. IND-CCA-Secure Key Encapsulation Mechanism in the Quantum Random Oracle Model, Revisited . In Hovav Shacham and Alexandra Boldyreva, editors, Advances in Cryptology - CRYPTO 2018 - 38th Annual International Crypt...

  59. [67]

    Saber on ARM CCA -secure module lattice-based key encapsulation on ARM

    Angshuman Karmakar, Jose Maria Bermudo Mera , Sujoy Sinha Roy, and Ingrid Verbauwhede. Saber on ARM CCA -secure module lattice-based key encapsulation on ARM . IACR Trans. Cryptogr. Hardw. Embed. Syst. , 2018(3):243--266, 2018

  60. [68]

    Higher-Order Masked Saber

    Suparna Kundu, Jan - Pieter D'Anvers, Michiel Van Beirendonck , Angshuman Karmakar, and Ingrid Verbauwhede. Higher-Order Masked Saber . In Clemente Galdi and Stanislaw Jarecki, editors, Security and Cryptography for Networks - 13th International Conference, SCN 2022, Amalfi, I...

  61. [69]

    On the Masking-Friendly Designs for Post-quantum Cryptography

    Suparna Kundu, Angshuman Karmakar, and Ingrid Verbauwhede. On the Masking-Friendly Designs for Post-quantum Cryptography . In Francesco Regazzoni, Bodhisatwa Mazumdar, and Sri Parameswaran, editors, Security, Privacy, and Applied Cryptography Engineering - 13th International C...

  62. [70]

    Scabbard: An Exploratory Study on Hardware Aware Design Choices of Learning with Rounding-based Key Encapsulation Mechanisms

    Suparna Kundu, Quinten Norga, Angshuman Karmakar, Shreya Gangopadhyay, Jose Maria Bermudo Mera, and Ingrid Verbauwhede. Scabbard: An Exploratory Study on Hardware Aware Design Choices of Learning with Rounding-based Key Encapsulation Mechanisms . ACM Trans. Embed. Comput. Syst...

  63. [71]

    Korean pqc competition

    KpqC. Korean pqc competition. https://www.kpqc.or.kr/competition.html

  64. [72]

    Kannwischer, Joost Rijneveld, and Peter Schwabe

    Matthias J. Kannwischer, Joost Rijneveld, and Peter Schwabe. Faster Multiplication in Z _ 2^m [x] on Cortex-M4 to Speed up NIST PQC Candidates . In Robert H. Deng, Val \' e rie Gauthier - Uma \ n a, Mart \' n Ochoa, and Moti Yung, editors, Applied Cryptography and Network Secu...

  65. [73]

    Abdel Alim Kamal and Amr M. Youssef. An FPGA implementation of the NTRUEncrypt cryptosystem . In 2009 International Conference on Microelectronics - ICM , pages 209--212, 2009

  66. [74]

    A Lightweight Implementation of Keccak Hash Function for Radio-Frequency Identification Applications

    Elif Bilge Kavun and Tolga Yal c in. A Lightweight Implementation of Keccak Hash Function for Radio-Frequency Identification Applications . In Siddika Berna \" O rs Yal c in, editor, Radio Frequency Identification: Security and Privacy Issues - 6th International Workshop, RFID...

  67. [75]

    Lightweight Implementations of SHA-3 Candidates on FPGAs

    Jens - Peter Kaps, Panasayya Yalla, Kishore Kumar Surapathi, Bilal Habib, Susheel Vadlamudi, Smriti Gurung, and John Pham. Lightweight Implementations of SHA-3 Candidates on FPGAs . In Daniel J. Bernstein and Sanjit Chatterjee, editors, Progress in Cryptology - INDOCRYPT 2011 ...

  68. [76]

    Lucas, Ali Alwan, Marion Murzello, Yazheng Tu, Pengzhou He, Andrew J

    Benjamin J. Lucas, Ali Alwan, Marion Murzello, Yazheng Tu, Pengzhou He, Andrew J. Schwartz, David Guevara, Ujjwal Guin, Kyle Juretus, and Jiafeng Xie. Lightweight Hardware Implementation of Binary Ring-LWE PQC Accelerator . IEEE Computer Architecture Letters , 21(1):17--20, 2022

  69. [77]

    LAC : Practical ring- LWE based public-key encryption with byte-level modulus

    Xianhui Lu, Yamin Liu, Zhenfei Zhang, Dingding Jia, Haiyang Xue, Jingnan He, Bao Li, and Kunpeng Wang. LAC : Practical ring- LWE based public-key encryption with byte-level modulus. Cryptology ePrint Archive, Paper 2018/1009, 2018. https://eprint.iacr.org/2018/1009

  70. [78]

    Speeding up the Number Theoretic Transform for Faster Ideal Lattice-Based Cryptography

    Patrick Longa and Michael Naehrig. Speeding up the Number Theoretic Transform for Faster Ideal Lattice-Based Cryptography . In Sara Foresti and Giuseppe Persiano, editors, Cryptology and Network Security - 15th International Conference, CANS 2016, Milan, Italy, November 14-16,...

  71. [79]

    Better Key Sizes (and Attacks) for LWE-Based Encryption

    Richard Lindner and Chris Peikert. Better Key Sizes (and Attacks) for LWE-Based Encryption . In Aggelos Kiayias, editor, Topics in Cryptology - CT-RSA 2011 - The Cryptographers' Track at the RSA Conference 2011, San Francisco, CA, USA, February 14-18, 2011. Proceedings , volum...

  72. [80]

    On Ideal Lattices and Learning with Errors over Rings

    Vadim Lyubashevsky, Chris Peikert, and Oded Regev. On Ideal Lattices and Learning with Errors over Rings . In Henri Gilbert, editor, Advances in Cryptology - EUROCRYPT 2010, 29th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Monaco...

  73. [81]

    Worst-case to average-case reductions for module lattices

    Adeline Langlois and Damien Stehl \' e . Worst-case to average-case reductions for module lattices . Designs, Codes and Cryptography , 75(3):565--599, 2015

  74. [82]

    u neysu. A Hard Crystal - Implementing Dilithium on Reconfigurable Hardware . In Vincent Grosso and Thomas P \

    Georg Land, Pascal Sasdrich, and Tim G \" u neysu. A Hard Crystal - Implementing Dilithium on Reconfigurable Hardware . In Vincent Grosso and Thomas P \" o ppelmann, editors, Smart Card Research and Advanced Applications - 20th International Conference, CARDIS 2021, L \" u bec...

  75. [83]

    Victor S. Miller. Use of Elliptic Curves in Cryptography . In Hugh C. Williams, editor, Advances in Cryptology - CRYPTO '85, Santa Barbara, California, USA, August 18-22, 1985, Proceedings , volume 218 of Lecture Notes in Computer Science , pages 417--426. Springer, 1985

  76. [84]

    Lightweight Cryptography Project , 2023

    NIST. Lightweight Cryptography Project , 2023. https://csrc.nist.gov/projects/lightweight-cryptography

  77. [85]

    Module-Lattice-based Key-Encapsulation Mechanism Standard , 2023

    NIST. Module-Lattice-based Key-Encapsulation Mechanism Standard , 2023. https://doi.org/10.6028/NIST.FIPS.203.ipd

  78. [86]

    Towards a Lightweight CRYSTALS-Kyber in FPGAs: an Ultra-lightweight BRAM-free NTT Core

    Ziying Ni, Ayesha Khalid, Weiqiang Liu, and M \' a ire O'Neill. Towards a Lightweight CRYSTALS-Kyber in FPGAs: an Ultra-lightweight BRAM-free NTT Core . In IEEE International Symposium on Circuits and Systems, ISCAS 2023, Monterey, CA, USA, May 21-25, 2023 , pages 1--5. IEEE , 2023

  79. [87]

    Public-key cryptosystems from the worst-case shortest vector problem: extended abstract

    Chris Peikert. Public-key cryptosystems from the worst-case shortest vector problem: extended abstract . In Michael Mitzenmacher, editor, Proceedings of the 41st Annual ACM Symposium on Theory of Computing, STOC 2009, Bethesda, MD, USA, May 31 - June 2, 2009 , pages 333--342. ...

  80. [88]

    o ppelmann and Tim G \

    Thomas P \" o ppelmann and Tim G \" u neysu. Towards Practical Lattice-Based Public-Key Encryption on Reconfigurable Hardware . In Tanja Lange, Kristin E. Lauter, and Petr Lisonek, editors, Selected Areas in Cryptography - SAC 2013 - 20th International Conference, Burnaby, BC,...

  81. [89]

    TiGER: Tiny bandwidth key encapsulation mechanism for easy miGration based on RLWE(R)

    Seunghwan Park, Chi-Gon Jung, Aesun Park, Joongeun Choi, and Honggoo Kang. TiGER: Tiny bandwidth key encapsulation mechanism for easy miGration based on RLWE(R) . Cryptology ePrint Archive, Paper 2022/1651, 2022. https://eprint.iacr.org/2022/1651

  82. [90]

    John M. Pollard. The Fast Fourier Transform in a Finite Field . Mathematics of Computation , 25:365--374, 1971

  83. [91]

    Reduced-round Keccak for PQ schemes , 2022 (accessed 11-October-2024)

    pqc - forum. Reduced-round Keccak for PQ schemes , 2022 (accessed 11-October-2024). https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/t95kZqnbS4Q/m/zZwWaYxoBAAJ?utm_medium=email&utm_source=footer&pli=1

  84. [92]

    High-speed Instruction-set Coprocessor for Lattice-based Key Encapsulation Mechanism: Saber in Hardware

    Sujoy Sinha Roy and Andrea Basso. High-speed Instruction-set Coprocessor for Lattice-based Key Encapsulation Mechanism: Saber in Hardware . IACR Transactions on Cryptographic Hardware and Embedded Systems , 2020(4):443--466, 2020

  85. [93]

    On lattices, learning with errors, random linear codes, and cryptography

    Oded Regev. On lattices, learning with errors, random linear codes, and cryptography. J. ACM , 56(6):34:1--34:40, 2009

  86. [94]

    Rivest, Adi Shamir, and Leonard M

    Ronald L. Rivest, Adi Shamir, and Leonard M. Adleman. A Method for Obtaining Digital Signatures and Public-Key Cryptosystems . Commun. ACM , 21(2):120--126, 1978

  87. [95]

    Compact Ring-LWE Cryptoprocessor

    Sujoy Sinha Roy, Frederik Vercauteren, Nele Mentens, Donald Donglong Chen, and Ingrid Verbauwhede. Compact Ring-LWE Cryptoprocessor . In Lejla Batina and Matthew Robshaw, editors, Cryptographic Hardware and Embedded Systems - CHES 2014 - 16th International Workshop, Busan, Sou...

  88. [96]

    Lattice basis reduction: Improved practical algorithms and solving subset sum problems

    Claus - Peter Schnorr and Martin Euchner. Lattice basis reduction: Improved practical algorithms and solving subset sum problems. Math. Program. , 66:181--199, 1994

  89. [97]

    Circuit-Level Techniques for Side-Channel Attack Resilience: A tutorial

    Shreyas Sen and Archisman Ghosh. Circuit-Level Techniques for Side-Channel Attack Resilience: A tutorial . IEEE Solid-State Circuits Magazine , 16(4):96--108, 2024

  90. [98]

    Assessing the overhead of post-quantum cryptography in TLS 1.3 and SSH

    Dimitrios Sikeridis, Panos Kampanakis, and Michael Devetsikiotis. Assessing the overhead of post-quantum cryptography in TLS 1.3 and SSH . In Proceedings of the 16th International Conference on Emerging Networking EXperiments and Technologies , CoNEXT '20, page 149–156, New Yo...

  91. [99]

    Post-Quantum TLS Without Handshake Signatures

    Peter Schwabe, Douglas Stebila, and Thom Wiggers. Post-Quantum TLS Without Handshake Signatures . In Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security , CCS '20, page 1461–1480, New York, NY, USA, 2020. Association for Computing Machinery

  92. [100]

    More Efficient Post-quantum KEMTLS with Pre-distributed Public Keys

    Peter Schwabe, Douglas Stebila, and Thom Wiggers. More Efficient Post-quantum KEMTLS with Pre-distributed Public Keys . In Elisa Bertino, Haya Schulmann, and Michael Waidner, editors, Computer Security - ESORICS 2021 - 26th European Symposium on Research in Computer Security, ...

  93. [101]

    Andrei L. Toom. The Complexity of a Scheme of Functional Elements Realizing the Multiplication of Integers . In Soviet Mathematics-Doklady , volume 7, pages 714--716, 1963

  94. [102]

    A Side-Channel-Resistant Implementation of SABER

    Michiel Van Beirendonck , Jan - Pieter D'Anvers, Angshuman Karmakar, Josep Balasch, and Ingrid Verbauwhede. A Side-Channel-Resistant Implementation of SABER . ACM J. Emerg. Technol. Comput. Syst. , 17(2):10:1--10:26, 2021

  95. [103]

    Efficient Implementation of Finite Field Arithmetic for Binary Ring-LWE Post-Quantum Cryptography Through a Novel Lookup-Table-Like Method

    Jiafeng Xie, Pengzhou He, and Wujie Wen. Efficient Implementation of Finite Field Arithmetic for Binary Ring-LWE Post-Quantum Cryptography Through a Novel Lookup-Table-Like Method . In 2021 58th ACM/IEEE Design Automation Conference (DAC) , pages 1279--1284, 2021

  96. [104]

    A Compact Hardware Implementation of CCA-Secure Key Exchange Mechanism CRYSTALS-KYBER on FPGA

    Yufei Xing and Shuguo Li. A Compact Hardware Implementation of CCA-Secure Key Exchange Mechanism CRYSTALS-KYBER on FPGA . IACR Transactions on Cryptographic Hardware and Embedded Systems , 2021(2):328--356, 2021

  97. [105]

    Hardware Design and Implementation of Post-Quantum Cryptography Kyber

    Qingru Zeng, Quanxin Li, Baoze Zhao, Han Jiao, and Yihua Huang. Hardware Design and Implementation of Post-Quantum Cryptography Kyber . In 2022 IEEE High Performance Extreme Computing Conference (HPEC) , pages 1--6, 2022

  98. [106]

    Highly Efficient Architecture of NewHope-NIST on FPGA using Low-Complexity NTT/INTT

    Neng Zhang, Bohan Yang, Chen Chen, Shouyi Yin, Shaojun Wei, and Leibo Liu. Highly Efficient Architecture of NewHope-NIST on FPGA using Low-Complexity NTT/INTT . IACR Trans. Cryptogr. Hardw. Embed. Syst. , 2020(2):49--72, 2020

  99. [107]

    A Compact and High-Performance Hardware Architecture for CRYSTALS-Dilithium

    Cankun Zhao, Neng Zhang, Hanning Wang, Bohan Yang, Wenping Zhu, Zhengdong Li, Min Zhu, Shouyi Yin, Shaojun Wei, and Leibo Liu. A Compact and High-Performance Hardware Architecture for CRYSTALS-Dilithium . IACR Transactions on Cryptographic Hardware and Embedded Systems , 2022(...

Pith tools

Reviewed August 10, 2026 · model on record in the stance chip above.