IP Library Granted Patent US 12,341,889
Granted Patent B2
US 12,341,889 · App. 18/718,645 · Granted Jun 24, 2025

Computer architecture and method for performing lattice-based cryptographic primitives with resistance to side-channel attacks

Inventors: Abubakr Abdulgadir (Reston, VA); Luke Beckwith (Sterling, VA)
Assignee: PQSecure Technologies, LLC
H04L9/3093H04L9/0618H04L9/0643
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,341,889
App. No.
18/718,645
Granted
Jun 24, 2025
Kind
B2
Abstract

A computer processing system configured to perform lattice-based cryptographic primitives with resistance to side-channel attacks with a computer processing architecture operably configured to perform at least one of key generation, key encapsulation, and key decapsulation and process security sensitive data, a sampling submodule performing hashing operations and centered binomial sampling routines, a polynomial arithmetic unit performing polynomial multiplication, polynomial addition, and polynomial subtraction by processing the security sensitive data that is divided into shares stored on a plurality of memory banks, an auxiliary submodule mathematical operations, a data interface unit operably configured to perform input and output operations and to input data and output data in shares, and de-serialize the input data into polynomial coefficients utilized by the polynomial arithmetic unit, and a controller submodule operably configured to sequence any operations needed to perform the at least one of key generation, key encapsulation, and key decapsulation.

Claims (26)

1. A computer processing system configured to perform lattice-based cryptographic primitives with resistance to side-channel attacks and comprising:

a computer processing architecture operably configured to perform at least one of key generation, key encapsulation, and key decapsulation and process security sensitive data;

a plurality of memory banks wherein the sensitive shares are mirrored such that control logic for memory address can be shared between memory banks and non-sensitive data is stored in a separate memory module;

a polynomial arithmetic unit communicatively coupled to the plurality of memory banks and operably configured to perform polynomial multiplication, polynomial addition, and polynomial subtraction by processing the security sensitive data that is divided into shares stored on the plurality of memory banks;

an auxiliary submodule;

communicatively coupled with a sampling submodule, wherein hardware resources include a share type converter module shared between a decoder and a decompressor;

communicatively coupled with the plurality of memory banks; and

operably configured to perform share conversion, message decoding, and ciphertext compression;

a data interface hardware unit having an interface configuration communicatively coupled to the plurality of memory banks, operably configured to perform input and output operations, operably configured to input data and output data in shares, and de-serialize the input data into polynomial coefficients operably configured to be utilized by the polynomial arithmetic unit; and

a controller submodule with a processor operably configured to sequence any operations needed to perform the at least one of key generation, key encapsulation, and key decapsulation.

2. The computer processing system according to claim 1 , wherein the sampling submodule is operably configured to perform a rejection sampling routine.

3. The computer processing system according to claim 1 , wherein the data interface unit is operably configured to de-serialize the input data into polynomial coefficients stored on the plurality of memory banks for utilization by the polynomial arithmetic unit.

4. The computer processing system according to claim 1 , wherein the sampling submodule further comprises:

a SHA3 unit; and

at least one sampling unit, wherein the SHA3 unit is operably configured to perform the hashing operations and operably configured to transfer sampling input data to the at least one sampling unit.

5. The computer processing system according to claim 4 , wherein the SHA3 unit is side-channel-resistant.

6. The computer processing system according to claim 4 , wherein the least one sampling unit further comprises:

a rejection sampling unit operably configured to generate a public uniform array and a central binomial sampling unit operably configured to convert the sampling input data to centered binomial sampling data and performs operation on masked data to provide side-channel resistance.

7. The computer processing system according to claim 1 , wherein the auxiliary submodule further comprises:

a share-type converter operably configured to perform the share conversion; form arithmetic to Boolean or from Boolean to arithmetic;

a message decoder operably configured to perform the message decoding; and

a ciphertext compressor operably configured to perform the ciphertext compression, the share-type converter, the message decoder, and the ciphertext compressor resistant to first-order side channel attacks.

8. The computer processing system according to claim 7 , wherein the message decoder and the ciphertext compressor share the share-type converter to reduce area consumption.

9. The computer processing system according to claim 1 , wherein the controller submodule further comprises:

a processor, control code, a configuration register, a selection register, and a status register, wherein the controller submodule is operably configured to alternatively sequence any of the operations needed to perform the least one of key generation, key encapsulation, and key decapsulation by only modifying the control code.

10. The computer processing system according to claim 1 , wherein the computer processing architecture is operably configured to perform at least one of CRYSTALS-Kyber, Saber, NTRU, and FrodoKEM.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2024
From: ABDULGADIR, ABUBAKR; BECKWITH, LUKE
To: PQSECURE TECHNOLOGIES, LLC
Reel/Frame 067732/0423 →
Continuity (1)
Related Publication 20240421993A1 · Dec 19, 2024
References Cited (22)
US 11249726B2 · Langhammer · 2022 [cited by examiner]
US 11706019B2 · Chandrakasan · 2023 [cited by examiner]
US 20190312728A1 · Poeppelmann · 2019 [cited by examiner]
US 20200259649A1 · Garcia Morchon · 2020 [cited by examiner]
US 20200265167A1 · Banerjee · 2020 [cited by examiner]
US 20200313886A1 · Poeppelmann · 2020 [cited by examiner]
US 20220171885A1 · Saarinen · 2022 [cited by examiner]
US 20220303133A1 · Pessl · 2022 [cited by applicant]
US 20220337398A1 · Schneider et al. · 2022 [cited by applicant]
US 20230030316A1 · Pessl · 2023 [cited by examiner]
US 20230254115A1 · Hamburg · 2023 [cited by examiner]
US 20230412370A1 · Meyer · 2023 [cited by examiner]
US 20240031127A1 · Basso · 2024 [cited by examiner]
US 20240031140A1 · Basso · 2024 [cited by examiner]
US 20240154718A1 · Cline · 2024 [cited by examiner]
US 20240187206A1 · Takarabt · 2024 [cited by examiner]
US 20240249768A1 · Yang · 2024 [cited by examiner]
WO WO2021032946A1 · 2021 [cited by examiner]
WO WO2021240157A1 · 2021 [cited by examiner]
WO WO2021252294A1 · 2021 [cited by examiner]
Oder T. Efficient and side-channel resistant implementation of lattice-based cryptography (Doctoral dissertation, Dissertation, Bochum, Ruhr-Universität Bochum, 2019). (Year: 2019). [cited by examiner]
Fritzmann. “Masked accelerators and Instruction Set Extensions for Post-Quantum Cryptography” 414-460. IACR Transactions on Cryptographic Hardware and Embedded Systems. [online]. Nov. 19, 2021: vol. 2022, N. 1; pp. 414-… [cited by applicant]