arrow
Return

Optimizing Systolic Array-Based NTT Accelerators

delete2026-02-01
delete0
PRE
AI
S
Saleh Mulhem
E
Eike Schultz *
L
Lukas Groth
M
Mladen Bereković
R
Rainer Buchty
DOI:10.1109/LES.2025.3562707delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Lattice-based Post-quantum cryptography and Homomorphic Encryption schemes have become the key methodologies for today's and the future's secure world. This comes at the cost of a vastly increased computational load due to the multiplication of wide-integer coefficient polynomials. NIST recommends number theoretic transform (NTT) as an efficient remedy. Nevertheless, NTT strongly requires acceleration for large numbers of coefficients. This letter explores the use of systolic arrays as NTT accelerators and finds an optimal hardware architecture configuration across problem sizes. Design-space exploration is performed, resulting in a new design configuration for an efficient 2-D NTT accelerator without losing the ability to execute other workloads. Our finding indicates that for 22-nm technology, an optimal systolic array accelerator requires an area of 53.04 mm(2). The accelerator can efficiently execute and apply NTT on a polynomial with 4096 32-bit integer coefficients requiring 3296 cycles, and 1794.92 nJ.
Keywords:
Systolic arrays
Polynomials
Registers
Hardware
Computer architecture
Discrete Fourier transforms
Optimization
Transforms
NIST
Homomorphic encryption
Accelerator
homomorphic encryption (HE)
number theoretic transform (NTT)
post-quantum cryptography (PQC)

Journal

IEEE Embedded Systems Letters cover
IEEE Embedded Systems Letters
IF:
2
Papers:
101
Citations:
696

Organization

U
University of Lubeck
Scholars:
7.6K
Papers: 5.3K
Citations: 1.5W