PIP-NTT:迈向用于基于格的后量子密码术中迭代数论变换的可扩展内存并行加速器
PIP-NTT: Towards a Scalable Memory-Parallelized Accelerator for Iterative NTT in PQC
浏览论文内容
中文总结 AI 辅助
研究基于格的后量子密码术中迭代NTT的高效实现,提出用四个较小内存的内存并行化策略及无乘法重缩放架构,经设计空间探索优化蝶形单元,构建PIP-NTT加速器,实验表明其在FPGA平台上效率显著提升,且可扩展、适用多种PQC方案。
中文摘要 AI 辅助
迭代正向和反向数论变换(NTT)是基于格的后量子密码学(PQC)中的关键组件,通常使用库利-图基和绅士-桑德蝶形单元实现。现有迭代NTT加速器常依赖乒乓内存方案和与分圆环相关的大内存块,限制了整体效率。为此,我们提出一种内存并行化策略,用四个较小的n/4大小的内存,保持传统设计的总内存占用。还引入了用于逆NTT的无乘法重缩放架构。在此基础上,对统一的库利-图基和绅士-桑德蝶形单元进行基于硬件的全面设计空间探索,评估粗粒度和细粒度流水线策略。优化后的蝶形单元构成了我们提出的流水线和内存并行化NTT加速器“PIP-NTT”的核心。它在紧密的面积约束下集成了两个这样的单元和内存并行化方案以提高计算吞吐量。FPGA平台实验结果表明,与文献中面积最优化和高速的NTT加速器相比,PIP-NTT在平均面积-时间积方面效率分别提高了2.67倍和1.48倍。该设计可跨蝶形基数扩展,适用于其他PQC方案,是未来加密硬件的通用解决方案。
英文摘要
The iterative forward and inverse number theoretic transform (NTT) is a key component in lattice-based post-quantum cryptography (PQC), typically implemented using Cooley-Tukey and Gentleman-Sande butterfly units. Existing iterative NTT accelerators often rely on ping-pong memory schemes and large memory blocks tied to the cyclotomic ring, which limits overall efficiency. To overcome this, we propose a memory-parallelization strategy using four smaller n/4-sized memories for ring size n, preserving the total memory footprint of conventional designs. We also introduce a multiplication-free rescaling architecture for the inverse NTT. Building on these innovations, we perform a comprehensive hardware-based design space exploration of unified Cooley-Tukey and Gentleman-Sande butterfly units, evaluating both coarse- and fine-grained pipelining strategies. The resulting optimized butterfly unit forms the core of our proposed pipelined and memory-parallelized NTT accelerator, "PIP-NTT". It integrates two such units alongside the memory-parallelization scheme to boost computational throughput under tight area constraints. Experimental results on FPGA platforms show that PIP-NTT achieves 2.67x and 1.48x higher efficiency in average Area-Time Product compared to the most area-optimized and high-speed NTT accelerators in the literature. The design is scalable across butterfly radices and adaptable to other PQC schemes, making it a versatile solution for future cryptographic hardware