High-speed long polynomial multiplication is important for applications in homomorphic encryption (HE) and lattice-based cryptosystems. This paper addresses low-latency hardware architectures for long polynomial modular multiplication using the number-theoretic transform (NTT) and inverse NTT (iNTT). Chinese remainder theorem (CRT) is used to decompose the modulus into multiple smaller moduli. Our proposed architecture, namely PaReNTT, makes four novel contributions. First, parallel NTT and iNTT architectures are proposed to reduce the number of clock cycles to process the polynomials. This can enable real-time processing for HE applications, as the number of clock cycles to process the polynomial is inversely proportional to the level of parallelism. Second, the proposed architecture eliminates the need for permuting the NTT outputs before their product is input to the iNTT. This reduces latency by n/4 clock cycles, where n is the length of the polynomial, and reduces buffer requirement by one delay-switch-delay circuit of size n. Third, an approach to select special moduli is presented where the moduli can be expressed in terms of a few signed power-of-two terms. Fourth, novel architectures for pre-processing for computing residual polynomials using the CRT and post-processing for combining the residual polynomials are proposed. These architectures significantly reduce the area consumption of the pre-processing and post-processing steps. The proposed long modular polynomial multiplications are ideal for applications that require low latency and high sample rate as these feed-forward architectures can be pipelined at arbitrary levels.
翻译:高速长多项式乘法在同态加密(HE)及格基密码系统中具有重要应用。本文研究了基于数论变换(NTT)及其逆变换(iNTT)的长多项式模乘的低延迟硬件架构,采用中国剩余定理(CRT)将模数分解为多个较小的模数。所提出的架构PaReNTT有以下四项创新:第一,提出并行NTT与iNTT架构以减少多项式处理的时钟周期数。由于处理多项式所需的时钟周期数与并行度成反比,该设计可实现HE应用的实时处理。第二,所提架构无需在NTT输出结果相乘并输入iNTT前执行重排列操作,从而减少n/4个时钟周期的延迟(n为多项式长度),并将缓冲区需求减少一个大小为n的延迟-开关-延迟电路。第三,提出一种特殊模数选择方法,使模数可用少量带符号二的幂次项表示。第四,提出基于CRT的残差多项式预处理架构与残差多项式合成后处理架构,显著降低了预处理与后处理步骤的面积消耗。所提出的长模多项式乘法模块因其前馈架构可进行任意级流水线处理,特别适用于需要低延迟与高采样率的应用场景。