Paper 2026/2329
What Makes Lattice Key Generation Expensive? Controlled Cost Attribution with Structured LWR, ML-KEM, and HAETAE on Cortex-M4
Abstract
End-to-end cycle counts quantify lattice key-generation time on a microcontroller, but not which implementation decisions create that cost. We develop a controlled attribution method for public structure, candidate admission, and transform lifetime: how public data are organised, when candidate acceptance is checked, and whether transformed secret state is retained or reconstructed. On a fixed STM32L476RG Cortex-M4 target, paired runs within one executable keep the relevant secret, accepted candidate, or output key unchanged; separate measurements record resource effects. In our Bos-based structured-LWR implementation, reorganising public data exposes expansion and multiplication cost, and same-key, first-attempt comparisons show nearly additive admission and lifetime effects. We then test whether these explanations transfer across algorithms and rejection structures. In ML-KEM-512, whose KeyGen has no candidate rejection, retaining the secret's NTT-domain representation reduces cycles; a pre-specified ML-KEM-768 test preserves this direction but shows that the saving does not scale with module rank alone. HAETAE-5 tests both decisions inside a retrying KeyGen. Early checking stops rejected candidates before matrix computation, whereas deferred checking repeats matrix work across attempts and, under recomputation, rebuilds transformed secret state. The interaction grows with the retry count, while retention saves cycles at the cost of a larger KeyGen frame. Together, these experiments establish a compositional account of KeyGen cost: public structure defines the downstream computation for each candidate, while candidate admission and transform lifetime determine how many candidates execute it and how often reusable transformed representations are rebuilt. These relations yield directional predictions across the tested KeyGen structures, with paired measurements quantifying their cycle and storage consequences.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- Preprint.
- Keywords
- lattice cryptographyCortex-M4key generationcost attribution
- Contact author(s)
-
yan zhang ece @ outlook com
20251393014 @ stu sicnu edu cn
jkxy_tl @ sicnu edu cn - History
- 2026-10-05: approved
- 2026-10-04: received
- See all versions
- Short URL
- https://ia.cr/2026/2329
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2329,
author = {Yan Zhang and Meizi Li and Liang Tan},
title = {What Makes Lattice Key Generation Expensive? Controlled Cost Attribution with Structured {LWR}, {ML}-{KEM}, and {HAETAE} on Cortex-M4},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2329},
year = {2026},
url = {https://eprint.iacr.org/2026/2329}
}