Paper 2026/2329

What Makes Lattice Key Generation Expensive? Controlled Cost Attribution with Structured LWR, ML-KEM, and HAETAE on Cortex-M4

Yan Zhang, Southwest Jiaotong University
Meizi Li, Sichuan Normal University
Liang Tan, Sichuan Normal University
Abstract

End-to-end cycle counts quantify lattice key-generation time on a microcontroller, but not which implementation decisions create that cost. We develop a controlled attribution method for public structure, candidate admission, and transform lifetime: how public data are organised, when candidate acceptance is checked, and whether transformed secret state is retained or reconstructed. On a fixed STM32L476RG Cortex-M4 target, paired runs within one executable keep the relevant secret, accepted candidate, or output key unchanged; separate measurements record resource effects. In our Bos-based structured-LWR implementation, reorganising public data exposes expansion and multiplication cost, and same-key, first-attempt comparisons show nearly additive admission and lifetime effects. We then test whether these explanations transfer across algorithms and rejection structures. In ML-KEM-512, whose KeyGen has no candidate rejection, retaining the secret's NTT-domain representation reduces cycles; a pre-specified ML-KEM-768 test preserves this direction but shows that the saving does not scale with module rank alone. HAETAE-5 tests both decisions inside a retrying KeyGen. Early checking stops rejected candidates before matrix computation, whereas deferred checking repeats matrix work across attempts and, under recomputation, rebuilds transformed secret state. The interaction grows with the retry count, while retention saves cycles at the cost of a larger KeyGen frame. Together, these experiments establish a compositional account of KeyGen cost: public structure defines the downstream computation for each candidate, while candidate admission and transform lifetime determine how many candidates execute it and how often reusable transformed representations are rebuilt. These relations yield directional predictions across the tested KeyGen structures, with paired measurements quantifying their cycle and storage consequences.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Preprint.
Keywords
lattice cryptographyCortex-M4key generationcost attribution
Contact author(s)
yan zhang ece @ outlook com
20251393014 @ stu sicnu edu cn
jkxy_tl @ sicnu edu cn
History
2026-10-05: approved
2026-10-04: received
See all versions
Short URL
https://ia.cr/2026/2329
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2329,
      author = {Yan Zhang and Meizi Li and Liang Tan},
      title = {What Makes Lattice Key Generation Expensive? Controlled Cost Attribution with Structured {LWR}, {ML}-{KEM}, and {HAETAE} on Cortex-M4},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2329},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2329}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.