Paper 2026/2168

High-Performance Implementations of HAETAE and SMAUG-T on Arm Cortex-M55 Using MVE and Slothy

Seung-Won Lee, Hansung University
Min-Joo Sim, Hansung University
Hwa-Jeong Seo, Hansung University
Abstract

Efficient execution of Post-Quantum Cryptography (PQC) in resource-constrained embedded environments requires the joint optimization of not only algorithm vectorization but also dataflow and instruction execution order. This paper implements the HAETAE-2/3/5 and SMAUG-T1/3/5 parameter sets of two Korean Post-Quantum Cryptography Competition (KpqC) winners using the M-profile Vector Extension (MVE) of the Arm Cortex-M55 and analyzes the contribution of each optimization stage to performance improvement. We first establish an MVE-intrinsic implementation as the baseline and then present Manually Optimized MVE Assembly that redesigns the data layout, register reuse, and memory access patterns of the principal kernels. Slothy is subsequently applied to this assembly to optimize instruction order and register allocation for the Cortex-M55 pipeline. This process is applied to the Keccak/SHAKE operations shared by the two schemes; the Number-Theoretic Transform (NTT), fixed-point Fast Fourier Transform (FFT), and Gaussian sampling of HAETAE; and the Toom-Cook/Karatsuba polynomial multiplication of SMAUG-T. Measurements on the STM32N657 show that the implementation with Slothy achieves speedups of 2.349–2.424× for the HAETAE forward NTT, 1.701–1.732× for the FFT including squared-value accumulation, and 1.322–1.350× for the SMAUG-T matrix–vector multiplication over the intrinsic implementation. At the complete-scheme level, HAETAE and SMAUG-T achieve speedups of 1.050–1.212× and 1.108–1.212×, respectively. These results demonstrate that direct dataflow redesign and automated instruction scheduling eliminate different bottlenecks and that combining the two stages can effectively improve the performance of Cortex-M55-based PQC implementations.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Preprint.
Keywords
Post-Quantum CryptographyHAETAESMAUG-TCortex-M55M-profile Vector ExtensionInstruction SchedulingSlothy
Contact author(s)
dkajdfhd1 @ gmail com
minjoos9797 @ gmail com
hwajeong84 @ gmail com
History
2026-09-26: approved
2026-09-23: received
See all versions
Short URL
https://ia.cr/2026/2168
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2026/2168,
      author = {Seung-Won Lee and Min-Joo Sim and Hwa-Jeong Seo},
      title = {High-Performance Implementations of {HAETAE} and {SMAUG}-T on Arm Cortex-M55 Using {MVE} and Slothy},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2168},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2168}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.