IP Library Granted Patent US 12,388,657
Granted Patent B2
US 12,388,657 · App. 18/461,831 · Granted Aug 12, 2025

Low-memory masked Dilithium with alternative signing algorithm

Inventors: Melissa Azouaoui (Norderstedt, DE); Mohamed ElGhamrawy (Hamburg, DE); Joost Roland Renes ('s-Hertogenbosch, NL); Tobias Schneider (Graz, AT)
Assignee: NXP B.V.
H04L9/3247H04L9/088
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,388,657
App. No.
18/461,831
Granted
Aug 12, 2025
Kind
B2
Abstract

A method of performing a Dilithium signature operation on a message M using a secret key sk, including: generating a polynomial y using an ExpandMask function; calculating a polynomial z based upon y, c, and s 1 ; performing a bound check on z based upon γ 1 and β; performing a bound check on ct 0 based upon γ 2 ; calculating a polynomial {tilde over (r)} based upon A, z, c, t, α, and w 1 ; performing a bound check on {tilde over (r)} based upon γ 2 and β; calculating a hint polynomial h based on the {tilde over (r)}; and returning a digital signature of the message M where the digital signature includes z and h.

Claims (46)

1. A method of performing, using a hardware processor of a computing device, a Dilithium signature operation on a message M using a secret key sk, the method comprising:

generating a polynomial y using an ExpandMask function;

calculating a polynomial z based upon y, c, and s 1 , where s 1 is part of the secret key sk and replacing y with z in a memory;

performing a bound check on z based upon γ 1 and β, where γ 1 and β are parameters of the Dilithium signature operation;

performing a bound check on ct 0 based upon γ 2 , where γ 2 is a parameter of the Dilithium signature operation, c is based upon a hash of the message M, and polynomial t 0 is part of the secret key sk;

calculating a polynomial {tilde over (r)} based upon A, z, c, t, α, and w 1 , where A and w 1 are calculated as part of the Dilithium signature operation, α is a parameter of the Dilithium signature operation, and polynomial t is an addition of a polynomial t 1 scaled by 2 d and the polynomial t 0 where polynomial t 1 is part of a public key pk;

performing a bound check on {tilde over (r)} based upon γ 2 and β;

calculating a hint polynomial h based on the {tilde over (r)}; and

returning a digital signature of the message M where the digital signature includes z and h.

2. The method of claim 1 , wherein calculating z includes calculating z=y+cs 1 .

3. The method of claim 1 , wherein performing a bound check on z includes determining if ∥z∥ ∞ ≥γ 1 −β.

4. The method of claim 1 , wherein performing a bound check on ct 0 includes determining if ∥ct 0 ∥ ∞ ≥γ 2 .

5. The method of claim 1 , wherein calculating a polynomial {tilde over (r)} includes repeating for each polynomial vector element of the polynomial {tilde over (r)} the steps of:

calculating one polynomial vector element of the polynomial {tilde over (r)} based upon A, z, c, t, α, and w 1 ;

performing a bound check on the one polynomial vector element of {tilde over (r)} based upon γ 2 and β; and

calculating one polynomial vector element of the hint polynomial h based on the {tilde over (r)}.

6. The method of claim 1 , wherein calculating a polynomial {tilde over (r)} includes calculating {tilde over (r)}[i]=Az[i]−ct[i]−αw 1 [i] where i is an integer index specifying a polynomial of the vectors {tilde over (r)}, z, t, and w 1 .

7. The method of claim 6 , wherein performing a bound check on {tilde over (r)} includes determining if ∥{tilde over (r)}[i] ├ ┤∥_∞≥γ_2−β.

8. The method of claim 6 , wherein calculating a hint polynomial h is further based on c, t 0 , w 1 , and γ 2 , where t 0 is part of the secret key sk, where w 1 is calculated as part of the Dilithium signature operation, and where γ 2 is a parameter of the Dilithium signature operation.

9. The method of claim 1 , wherein calculating a polynomial {tilde over (r)} includes calculating {tilde over (r)}[i]=Az[i]−c(As 1 [i]+s 2 [i])−αw 1 [i] where i is an integer index specifying a polynomial of the vectors {tilde over (r)}, z, s 1 , s 2 , and w 1 .

10. The method of claim 1 , wherein calculating a polynomial {tilde over (r)} includes calculating {tilde over (r)}[i]=A(z[i]−cs 1 [i])−cs 2 [i]−αw 1 [i] where i is an integer index specifying a polynomial of the vectors {tilde over (r)}, z, s 1 , s 2 , and w 1 .

11. The method of claim 1 , further comprising determining if a number of 1's in h is greater than ω, where ω is a parameter of the Dilithium signature operation.

12. The method of claim 1 , wherein {tilde over (r)}, z, and y are masked using a plurality of shares.

13. A data processing system comprising instructions embodied in a non-transitory computer readable medium, the instructions for a method of performing a Dilithium signature operation on a message M using a secret key sk, the instructions, comprising:

generating a polynomial y using an ExpandMask function;

calculating a polynomial z based upon y, c, and s 1 , where s 1 is part of the secret key sk and replacing y with z in a memory;

performing a bound check on z based upon γ 1 and β, where γ 1 and β are parameters of the Dilithium signature operation;

performing a bound check on ct 0 based upon γ 2 , where γ 2 is a parameter of the Dilithium signature operation, c is based upon a hash of the message M, and polynomial t 0 is part of the secret key sk;

calculating a polynomial {tilde over (r)} based upon A, z, c, t, α, and w 1 , where A and w 1 are calculated as part of the Dilithium signature operation, α is a parameter of the Dilithium signature operation, and polynomial t is an addition of a polynomial t 1 scaled by 2 d and the polynomial t 0 where polynomial t 1 is part of a public key pk;

performing a bound check on {tilde over (r)} based upon γ 2 and β;

calculating a hint polynomial h based on the {tilde over (r)}; and

returning a digital signature of the message M where the digital signature includes z and h.

14. The data processing system of claim 13 , wherein calculating z includes calculating z=y+cs 1 .

15. The data processing system of claim 13 , wherein performing a bound check on z includes determining if ∥z∥ ∞ ≥γ 1 −β.

16. The data processing system of claim 13 , wherein performing a bound check on ct 0 includes determining if ∥ct 0 ∥ ∞ ≥γ 2 .

17. The data processing system of claim 13 , wherein calculating a polynomial {tilde over (r)} includes repeating for each polynomial vector element of the polynomial {tilde over (r)} the steps of:

calculating one polynomial vector element of the polynomial {tilde over (r)} based upon A, z, c, t, α, and w 1 ;

performing a bound check on the one polynomial vector element of {tilde over (r)} based upon γ 2 and β; and

calculating one polynomial vector element of the hint polynomial h based on the {tilde over (r)}.

18. The data processing system of claim 13 , wherein calculating a polynomial {tilde over (r)} includes calculating {tilde over (r)}[i]=Az[i]−ct[i]−αw 1 [i] where i is an integer index specifying a polynomial of the vectors {tilde over (r)}, z, t, and w 1 .

19. The data processing system of claim 18 , wherein performing a bound check on {tilde over (r)} includes determining if ∥{tilde over (r)}[i] ├ ┤∥_∞≥γ_2−β.

20. The data processing system of claim 18 , wherein calculating a hint polynomial h is further based on c, t 0 , w 1 , and γ 2 , where t 0 is part of the secret key sk, where w 1 is calculated as part of the Dilithium signature operation, and where γ 2 is a parameter of the Dilithium signature operation.

21. The data processing system of claim 13 , wherein calculating a polynomial {tilde over (r)} includes calculating {tilde over (r)}[i]=Az[i]−c(As 1 [i]+s 2 [i])−αw 1 [i] where i is an integer index specifying a polynomial of the vectors {tilde over (r)}, z, s 1 , s 2 , and w 1 .

22. The data processing system of claim 13 , wherein calculating a polynomial {tilde over (r)} includes calculating {tilde over (r)}[i]=A(z[i]−cs 1 [i])−cs 2 [i]−αw 1 [i] where i is an integer index specifying a polynomial of the vectors {tilde over (r)}, z, s 1 , s 2 , and w 1 .

23. The data processing system of claim 13 , further comprising determining if a number of 1's in h is greater than ω, where ω is a parameter of the Dilithium signature operation.

24. The data processing system of claim 13 , wherein {tilde over (r)}, z, and y are masked using a plurality of shares.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2023
From: AZOUAOUI, MELISSA; ELGHAMRAWY, MOHAMED; RENES, JOOST ROLAND; SCHNEIDER, TOBIAS
To: NXP B.V.
Reel/Frame 064813/0671 →
Continuity (1)
Related Publication 20250080342A1 · Mar 6, 2025
References Cited (30)
US 11416638B2 · Banerjee · 2022 [cited by applicant]
US 11496297B1 · Beckwith · 2022 [cited by applicant]
US 20220012334A1 · Ghosh · 2022 [cited by applicant]
US 20230030316A1 · Pessl · 2023 [cited by examiner]
US 20240031164A1 · Ghosh · 2024 [cited by examiner]
US 20240119359A1 · Arbajian · 2024 [cited by examiner]
CN 112910649A · 2021 [cited by applicant]
KR 102462395B1 · 2022 [cited by applicant]
WO 2021240157A1 · 2021 [cited by applicant]
Aikata, Ahmet Can Mert, Malik Imran, Samuel Pagliarini, and Sujoy Sinha Roy, Kali: A crystal for post-quantum security using kyber and dilithium, IEEE Trans. CircuitsSyst. I Regul. Pap. 70 (2023), No. 2, 747-758. [cited by applicant]
Aikata Aikata, Ahmet Can Mert, David Jacquemin, Amitabh Das, Donald Matthews, Santosh Ghosh, and Sujoy Sinha Roy, A unified cryptoprocessor for lattice-based signature and key-exchange, IACR Cryptol. ePrint Arch. (2021)… [cited by applicant]
Melissa Azouaoui, Olivier Bronchain, Gaëtan Cassiers, Clément Hoffmann, Yulia Kuzovkova, Joost Renes, Markus Schönauer, Tobias Schneider, François-Xavier Standaert, and Christine van Vredendaal, Leveling dilithium again… [cited by applicant]
Luke Beckwith, Abubakr Abdulgadir, and Reza Azarderakhsh, A flexible shared hardware accelerator for nist-recommended algorithms crystals-kyber and crystalsdilithium with sca protection, NIST Fourth PQC Standardization … [cited by applicant]
Joppe W. Bos, Joost Renes, and Amber Sprenkels, Dilithium for memory constrained devices, IACR Cryptol. ePrint Arch. (2022), 323. [cited by applicant]
Julien Devevey, Pouria Fallahpour, Alain Passelègue, and Damien Stehlé, A detailed analysis of fiat-shamir with aborts, IACR Cryptol. ePrint Arch. (2023), 245. [cited by applicant]
Léo Ducas, Eike Kiltz, Tancrède Lepoint, Vadim Lyubashevsky, Peter Schwabe, Gregor Seiler, and Damien Stehlé, Crystals-dilithium algorithm specifications and supporting documentation (version 3.1), 2021. [cited by applicant]
Denisa O. C. Greconici, Matthias J. Kannwischer, and Amber Sprenkels, Compact dilithium implementations on cortex-m3 and cortex-m4, IACR Cryptol. ePrint Arch.(2020), 1278. [cited by applicant]
Matthias J. Kannwischer, Joost Rijneveld, Peter Schwabe, and Ko Stoffelen, pqm4: Testing and benchmarking NIST PQC on ARM cortex-m4, IACR Cryptol. ePrint Arch. (2019), 844. [cited by applicant]
Georg Land, Pascal Sasdrich, and Tim Güneysu, A hard crystal—implementing dilithium on reconfigurable hardware, IACR Cryptol. ePrint Arch. (2021), 355. [cited by applicant]
Yuejun Liu, Yongbin Zhou, Shuo Sun, Tianyu Wang, Rui Zhang, and Jingdian Ming, On the security of lattice-based fiat-shamir signatures in the presence of randomness leakage, IEEE Trans. Inf. Forensics Secur. 16 (2021), … [cited by applicant]
Soundes Marzougui, Vincent Ulitzsch, Mehdi Tibouchi, and Jean-Pierre Seifert, Profiling side-channel attacks on dilithium: A small bit-fiddling leak breaks it all, IACR Cryptol. ePrint Arch. (2022), 106. [cited by applicant]
Vincent Migliore, Benoît Gérard, Mehdi Tibouchi, and Pierre-Alain Fouque, Masking dilithium: Efficient implementation and side-channel evaluation, IACR Cryptol. ePrint Arch. (2019), 394. [cited by applicant]
National Institute of Standards and Technology, Post-quantum cryptography standardization, https://csrc.nist.gov/Projects/Post-Quantum-Cryptography/Post-Quantum-Cryptography-Standardization. [cited by applicant]
Hauke Malte Steffen, Georg Land, Lucie Johanna Kogelheide, and Tim Güneysu, Breaking and protecting the crystal: Side-channel analysis of dilithium in hardware, IACR Cryptol. ePrint Arch. (2022), 1410. [cited by applicant]
Cankun Zhao, Neng Zhang, Hanning Wang, Bohan Yang, Wenping Zhu, Zhengdong Li, Min Zhu, Shouyi Yin, Shaojun Wei, and Leibo Liu, A compact and high-performance hardware architecture for crystals-dilithium, IACR Trans. Cry… [cited by applicant]
Improved Gadgets for the High-Order Masking of Dilithium. Anonymous submission to TCHES issue 4. [cited by applicant]
U.S. Appl. No. 18/366,384, filed Aug. 7, 2023. [cited by applicant]
U.S. Appl. No. 17/935,550, filed Sep. 26, 2022. [cited by applicant]
U.S. Appl. No. 18/320,028, filed May 18, 2023. [cited by applicant]
U.S. Appl. No. 17/835,898, filed Jun. 8, 2022. [cited by applicant]