Number theoretic transform (NTT) has been a very useful tool in computations for number theory, algebra and cryptography. Its performance affects some post-quantum cryptosystems. In this paper, we discuss the butterfly operation of NTT. This basic module of NTT requires heavy modular arithmetics. Montgomery reduction is commonly used in this setting. Recently several variants of Montgomery algorithm have been proposed for the purpose of speeding up NTT. We observe that the Chinese remainder theorem (CRT) can be involved in this type of algorithms in natural and transparent ways. In the first part of the paper, a framework of using CRT to model Montgomery type algorithms is described. The derivation of these algorithms as well as their correctness are all treated in the CRT framework. Under our approach, some problems of a modular reduction algorithm (published in IACR Transactions on Cryptographic Hardware and Embedded Systems, doi:10.46586/tches.v2022.i4.614-636 ) are identified, and a counterexample is generated to show that the algorithm is incorrect. In the second part of the paper, we modify a modular multiplication algorithm of Plantard to suite the butterfly structure by Scott, an improved computation of the butterfly module for NTT is obtained. Experiments show that the method performs better compared to NTT implementations using previous popular methods.
翻译:数论变换(NTT)已成为数论、代数和密码学计算中非常有用的工具。其性能影响部分后量子密码系统。本文讨论了NTT的蝶形运算,该基本模块需要大量的模算术运算。在此场景中,蒙哥马利归约(Montgomery reduction)被广泛使用。近期,为加速NTT提出了几种蒙哥马利算法的变体。我们观察到,中国剩余定理(CRT)可以自然且透明地融入此类算法。论文第一部分描述了使用CRT建模蒙哥马利类型算法的框架。这些算法的推导及其正确性均在CRT框架下处理。在我们的方法中,发现了一个模归约算法(发表于IACR Transactions on Cryptographic Hardware and Embedded Systems, doi:10.46586/tches.v2022.i4.614-636)存在的问题,并构造了反例证明该算法不正确。论文第二部分,我们修改了Plantard的模乘算法以适配Scott的蝶形结构,从而得到了改进的NTT蝶形模块计算方法。实验表明,与使用先前流行方法实现的NTT相比,该方法性能更优。