Paper 2026/2168
High-Performance Implementations of HAETAE and SMAUG-T on Arm Cortex-M55 Using MVE and Slothy
Abstract
Efficient execution of Post-Quantum Cryptography (PQC) in resource-constrained embedded environments requires the joint optimization of not only algorithm vectorization but also dataflow and instruction execution order. This paper implements the HAETAE-2/3/5 and SMAUG-T1/3/5 parameter sets of two Korean Post-Quantum Cryptography Competition (KpqC) winners using the M-profile Vector Extension (MVE) of the Arm Cortex-M55 and analyzes the contribution of each optimization stage to performance improvement. We first establish an MVE-intrinsic implementation as the baseline and then present Manually Optimized MVE Assembly that redesigns the data layout, register reuse, and memory access patterns of the principal kernels. Slothy is subsequently applied to this assembly to optimize instruction order and register allocation for the Cortex-M55 pipeline. This process is applied to the Keccak/SHAKE operations shared by the two schemes; the Number-Theoretic Transform (NTT), fixed-point Fast Fourier Transform (FFT), and Gaussian sampling of HAETAE; and the Toom-Cook/Karatsuba polynomial multiplication of SMAUG-T. Measurements on the STM32N657 show that the implementation with Slothy achieves speedups of 2.349–2.424× for the HAETAE forward NTT, 1.701–1.732× for the FFT including squared-value accumulation, and 1.322–1.350× for the SMAUG-T matrix–vector multiplication over the intrinsic implementation. At the complete-scheme level, HAETAE and SMAUG-T achieve speedups of 1.050–1.212× and 1.108–1.212×, respectively. These results demonstrate that direct dataflow redesign and automated instruction scheduling eliminate different bottlenecks and that combining the two stages can effectively improve the performance of Cortex-M55-based PQC implementations.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- Preprint.
- Keywords
- Post-Quantum CryptographyHAETAESMAUG-TCortex-M55M-profile Vector ExtensionInstruction SchedulingSlothy
- Contact author(s)
-
dkajdfhd1 @ gmail com
minjoos9797 @ gmail com
hwajeong84 @ gmail com - History
- 2026-09-26: approved
- 2026-09-23: received
- See all versions
- Short URL
- https://ia.cr/2026/2168
- License
-
CC0
BibTeX
@misc{cryptoeprint:2026/2168,
author = {Seung-Won Lee and Min-Joo Sim and Hwa-Jeong Seo},
title = {High-Performance Implementations of {HAETAE} and {SMAUG}-T on Arm Cortex-M55 Using {MVE} and Slothy},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2168},
year = {2026},
url = {https://eprint.iacr.org/2026/2168}
}