RE: [PATCH 0/5] dilithium-kyber: Optimized (i)NTT support for

Danny Tsen via Gcrypt-devel <[email protected]> Mon, 30 Mar 2026 12:28:24 +0000
Newsgroups gmane.comp.encryption.gpg.libgcrypt.devel
Message-ID <PH7PR15MB5426E94575BA2F9B11CBF6729352A@PH7PR15MB5426.namprd15.prod.outlook.com>
--===============6397590109878275716==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_PH7PR15MB5426E94575BA2F9B11CBF6729352APH7PR15MB5426namp_"

--_000_PH7PR15MB5426E94575BA2F9B11CBF6729352APH7PR15MB5426namp_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi,

That's seems like a good idea.  Let me know when you have the framework ava=
ilable.  I can follow that.

Thanks.
-Danny

________________________________
From: NIIBE Yutaka <[email protected]>
Sent: Friday, March 27, 2026 1:21 AM
To: Danny Tsen <[email protected]>; [email protected] <gcrypt-devel@gnu=
pg.org>
Subject: [EXTERNAL] Re: [PATCH 0/5] dilithium-kyber: Optimized (i)NTT suppo=
rt for

Hello,

Sorry for late reply.

Danny Tsen wrote:
> Added optimized (i)NTT algorithm support for ppc64le (Power 8 and
> above).  Defined ENABLE_PPC_DILITHIUM and ENABLE_PPC_KYBER for
> dilithium (ML-DSA) and kyber (ML-KEM) NTT and inverse NTT.

Thank you for your work.

The approach of optimizing NTT functions looks good.

Let me start a discussion about Kyber.  Then, we can apply the
result to Dilithium.


I wonder if we can do a bit more, so that we can avoid the duplication
of the ZETA constant among NTT implementation and kyber-common.c.

I'm considering about factoring following five functions from
kyber-common.c:

    void _gcry_poly_ntt(poly *r);
    void _gcry_poly_invntt_tomont(poly *r);
    void _gcry_poly_reduce(poly *r)
    void _gcry_poly_tomont(poly *r);
    void _gcry_poly_basemul_montgomery(poly *r, const poly *a, const poly *=
b);

into, say, kyber-common-generic.c.  And provide archtecture specific
kyber-common-<ARCH>-<HWACC>.S for optimized version(s).

This way, NTT functions are covered and ZETA is placed inside
kyber-common-*.

How do you think?

I'll try with the optimized implementation of AVX2 in the reference code.
https://urldefense.proofpoint.com/v2/url?u=3Dhttps-3A__www.pq-2Dcrystals.or=
g_kyber_&d=3DDwIBAg&c=3DBSDicqBQBDjDI9RkVyTcHQ&r=3DzspFcGYEyUrRywX_TdjlLwwr=
Cx0eBFnzcs6XZVVVMh0&m=3DcyhP1gGDXWh9JCIn4z5NrebvLkC7bN89aMGL_HFl26R2f9h7kqR=
DsaD6W5C2Q8tQ&s=3DguKkLMabJUVbm4bjm61GKleAAubKCEyFJJobD1MSghQ&e=3D
--

--_000_PH7PR15MB5426E94575BA2F9B11CBF6729352APH7PR15MB5426namp_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
Hi,</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
That's seems like a good idea.&nbsp; Let me know when you have the framewor=
k available.&nbsp; I can follow that.</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
Thanks.</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
-Danny</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div id=3D"appendonsend"></div>
<hr style=3D"display:inline-block;width:98%" tabindex=3D"-1">
<div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" st=
yle=3D"font-size:11pt" color=3D"#000000"><b>From:</b> NIIBE Yutaka &lt;gnii=
[email protected]&gt;<br>
<b>Sent:</b> Friday, March 27, 2026 1:21 AM<br>
<b>To:</b> Danny Tsen &lt;[email protected]&gt;; [email protected] &lt;=
[email protected]&gt;<br>
<b>Subject:</b> [EXTERNAL] Re: [PATCH 0/5] dilithium-kyber: Optimized (i)NT=
T support for</font>
<div>&nbsp;</div>
</div>
<div class=3D"BodyFragment"><font size=3D"2"><span style=3D"font-size:11pt;=
">
<div class=3D"PlainText">Hello,<br>
<br>
Sorry for late reply.<br>
<br>
Danny Tsen wrote:<br>
&gt; Added optimized (i)NTT algorithm support for ppc64le (Power 8 and<br>
&gt; above).&nbsp; Defined ENABLE_PPC_DILITHIUM and ENABLE_PPC_KYBER for<br=
>
&gt; dilithium (ML-DSA) and kyber (ML-KEM) NTT and inverse NTT.<br>
<br>
Thank you for your work.<br>
<br>
The approach of optimizing NTT functions looks good.<br>
<br>
Let me start a discussion about Kyber.&nbsp; Then, we can apply the<br>
result to Dilithium.<br>
<br>
<br>
I wonder if we can do a bit more, so that we can avoid the duplication<br>
of the ZETA constant among NTT implementation and kyber-common.c.<br>
<br>
I'm considering about factoring following five functions from<br>
kyber-common.c:<br>
<br>
&nbsp;&nbsp;&nbsp; void _gcry_poly_ntt(poly *r);<br>
&nbsp;&nbsp;&nbsp; void _gcry_poly_invntt_tomont(poly *r);<br>
&nbsp;&nbsp;&nbsp; void _gcry_poly_reduce(poly *r)<br>
&nbsp;&nbsp;&nbsp; void _gcry_poly_tomont(poly *r);<br>
&nbsp;&nbsp;&nbsp; void _gcry_poly_basemul_montgomery(poly *r, const poly *=
a, const poly *b);<br>
<br>
into, say, kyber-common-generic.c.&nbsp; And provide archtecture specific<b=
r>
kyber-common-&lt;ARCH&gt;-&lt;HWACC&gt;.S for optimized version(s).<br>
<br>
This way, NTT functions are covered and ZETA is placed inside<br>
kyber-common-*.<br>
<br>
How do you think?<br>
<br>
I'll try with the optimized implementation of AVX2 in the reference code.<b=
r>
<a href=3D"https://urldefense.proofpoint.com/v2/url?u=3Dhttps-3A__www.pq-2D=
crystals.org_kyber_&amp;d=3DDwIBAg&amp;c=3DBSDicqBQBDjDI9RkVyTcHQ&amp;r=3Dz=
spFcGYEyUrRywX_TdjlLwwrCx0eBFnzcs6XZVVVMh0&amp;m=3DcyhP1gGDXWh9JCIn4z5Nrebv=
LkC7bN89aMGL_HFl26R2f9h7kqRDsaD6W5C2Q8tQ&amp;s=3DguKkLMabJUVbm4bjm61GKleAAu=
bKCEyFJJobD1MSghQ&amp;e=3D">https://urldefense.proofpoint.com/v2/url?u=3Dht=
tps-3A__www.pq-2Dcrystals.org_kyber_&amp;d=3DDwIBAg&amp;c=3DBSDicqBQBDjDI9R=
kVyTcHQ&amp;r=3DzspFcGYEyUrRywX_TdjlLwwrCx0eBFnzcs6XZVVVMh0&amp;m=3DcyhP1gG=
DXWh9JCIn4z5NrebvLkC7bN89aMGL_HFl26R2f9h7kqRDsaD6W5C2Q8tQ&amp;s=3DguKkLMabJ=
UVbm4bjm61GKleAAubKCEyFJJobD1MSghQ&amp;e=3D</a>
<br>
-- <br>
</div>
</span></font></div>
</body>
</html>

--_000_PH7PR15MB5426E94575BA2F9B11CBF6729352APH7PR15MB5426namp_--


--===============6397590109878275716==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Gcrypt-devel mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gcrypt-devel

--===============6397590109878275716==--