Paper 2025/1322
Generation of Fast Finite Field Arithmetic for Cortex-M4 with ECDH and SQIsign Applications
Abstract
Finite field arithmetic is central to several cryptographic algorithms on embedded devices like the ARM Cortex-M4, particularly for elliptic curve and isogeny-based cryptography. However, rapid algorithm evolution, driven by initiatives such as NIST’s post-quantum standardization, might frequently render hand-optimized implementations obsolete. We address this challenge with m4-modarith, a library generating C code with inline assembly for the Cortex-M4 that rivals custom-tuned assembly, enabling agile development in this ever-changing landscape. Our generated modular multiplications obtains fast performances, competitive with hand-optimized assembly implementations published in the literature, even outperforming some of them for Curve25519. Two contributions are pivotal to this success. First, we introduce a novel multiplication strategy that matches the memory access complexity of the operand caching method while being applicable to a larger cache size for Cortex-M4 implementations. Second, we generalize an efficient pseudo-Mersenne reduction strategy, and formally prove its correctness and applicability for most primes of cryptographic interest. Our generator allowed agile optimization of SQIsign’s NIST PQC Round 2 submission, improving level 1 verification from 123 Mcycles to only 54 Mcycles, a $2.3\times$ speedup. As an additional case study, we use our generator to improve performance of portable implementations of RFC~7748 by up to $2.2\times$.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- Published by the IACR in TCHES 2025
- Keywords
- Finite Field ArithmeticRFC7748PQCSQIsignCortex-M4.
- Contact author(s)
-
felix rodrigues @ ic unicamp br
decio gazzoni @ ic unicamp br
gora adj @ tii ae
isaac canales @ tii ae
jorge saab @ tii ae
jlopez @ ic unicamp br
michael scott @ tii ae
francisco rodriguez @ tii ae - History
- 2025-07-19: approved
- 2025-07-18: received
- See all versions
- Short URL
- https://ia.cr/2025/1322
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1322,
author = {Felix Carvalho Rodrigues and Décio Gazzoni Filho and Gora Adj and Isaac A. Canales-Martínez and Jorge Chávez-Saab and Julio López and Michael Scott and Francisco Rodríguez-Henríquez},
title = {Generation of Fast Finite Field Arithmetic for Cortex-M4 with {ECDH} and {SQIsign} Applications},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1322},
year = {2025},
url = {https://eprint.iacr.org/2025/1322}
}