Return
Optimizing Systolic Array-Based NTT Accelerators
DOI:10.1109/LES.2025.3562707.png)
Abstract
En 中文
Lattice-based Post-quantum cryptography and Homomorphic Encryption schemes have become the key methodologies for today's and the future's secure world. This comes at the cost of a vastly increased computational load due to the multiplication of wide-integer coefficient polynomials. NIST recommends number theoretic transform (NTT) as an efficient remedy. Nevertheless, NTT strongly requires acceleration for large numbers of coefficients. This letter explores the use of systolic arrays as NTT accelerators and finds an optimal hardware architecture configuration across problem sizes. Design-space exploration is performed, resulting in a new design configuration for an efficient 2-D NTT accelerator without losing the ability to execute other workloads. Our finding indicates that for 22-nm technology, an optimal systolic array accelerator requires an area of 53.04 mm(2). The accelerator can efficiently execute and apply NTT on a polynomial with 4096 32-bit integer coefficients requiring 3296 cycles, and 1794.92 nJ.
Keywords:
Systolic arrays
Polynomials
Registers
Hardware
Computer architecture
Discrete Fourier transforms
Optimization
Transforms
NIST
Homomorphic encryption
Accelerator
homomorphic encryption (HE)
number theoretic transform (NTT)
post-quantum cryptography (PQC)

