Paper 2026/1450
Optimizing Polynomial Multiplication and Fixed-Weight Sampling for HQC on ARM Cortex-M4
Abstract
In this paper, we present an optimized implementation of Hamming Quasi-Cyclic (HQC) on the ARM Cortex-M4. We optimize (i) the polynomial multiplication and (ii) the support expansion in fixed-weight sampling, and (iii) propose an optional caching strategy that reuses the public transforms and hash recomputed under a fixed key. For the polynomial multiplication, the fixed-constant multiplications in the Frobenius additive FFT (FAFFT) butterfly spend nearly half of their instructions on VMOV data movements between general-purpose and floating-point registers rather than arithmetic. Because minimizing the XOR count alone can increase the total instruction count, we propose a dirty-aware register-allocation policy and an XOR-operation reordering that reduce the VMOV count by up to $48.1\%$ while leaving the XOR count unchanged. We apply these to a multiplication that combines prior FAFFT-CRT methods, and for HQC-1 we further find a $34\%$ sparser FAFFT modulus that lowers the CRT reconstruction cost. For fixed-weight sampling, we rewrite the support expansion with predicated execution and 4-way unrolling, lowering the per-word cost of its inner loop from $22$ to $6$ cycles while remaining constant-time. On the NUCLEO-L4R5ZI board, our implementation reduces key generation, encapsulation, and decapsulation by up to $33.1\%$, $34.6\%$, and $29.8\%$ over the faster of the two prior state-of-the-art implementations, and the optional caching yields a further reduction of up to $32.7\%$ and $18.9\%$ for encapsulation and decapsulation.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- Preprint.
- Keywords
- Post-Quantum CryptographyHQCBinary polynomial multiplicationCortex-M4Additive FFT
- Contact author(s)
-
jhw1031506 @ korea ac kr
newonetiger @ korea ac kr
suhrikim @ sungshin ac kr
shhong @ smartm2m co kr
dgkwon @ kunsan ac kr - History
- 2026-07-20: approved
- 2026-07-16: received
- See all versions
- Short URL
- https://ia.cr/2026/1450
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1450,
author = {Jihoon Jang and Hanbeom Shin and Suhri Kim and Seokhie Hong and Donggeun Kwon},
title = {Optimizing Polynomial Multiplication and Fixed-Weight Sampling for {HQC} on {ARM} Cortex-M4},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1450},
year = {2026},
url = {https://eprint.iacr.org/2026/1450}
}