Paper 2025/1763

A High Throughput Kyber NTT

Jonas Bertels, KU Leuven
Ingrid Verbauwhede, KU Leuven
Abstract

NIST recently selected Kyber as a standard for key encapsulation and decapsulation. As such, servers will soon need dedicated hardware for these encapsulation protocols. The computationally critical operation of Kyber is its Number Theoretic Transform, which is commonly accelerated by dedicated hardware such as FPGAs. This work presents an extremely high-throughput design for the Kyber NTT. By utilizing the LUT-based modular multiplication technique used by us in CHES 2025, its area delay product is generally between one and two orders of magnitude better than similar designs in literature. For instance, where Yaman et al. with 16 Processing Elements requires 9500 LUTs and 16 DSPs to perform an NTT in 69 clock cycles, our design requires 67210 LUTs and no DSPs to perform an NTT every clock cycle.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Preprint.
Keywords
KyberNTTFPGA
Contact author(s)
jonas bertels @ esat kuleuven be
ingrid verbauwhede @ esat kuleuven be
History
2025-09-29: approved
2025-09-26: received
See all versions
Short URL
https://ia.cr/2025/1763
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1763,
      author = {Jonas Bertels and Ingrid Verbauwhede},
      title = {A High Throughput Kyber {NTT}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1763},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1763}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.