Optimized implementation of SMAUG-T on resource-constrained 16-bit MSP430 MCU
Mingi Kim, DongHyun Shin, WooHyung Ko, YoungBeom Kim, Seog Chung Seo · ICT Express · 2025
In this paper, we present an optimized implementation of SMAUG-T, one of Round 2 Key Encapsulation Mechanism algorithms in Korean Post-quantum Cryptography Competition, on a widely used 16-bit MSP430 MCU. To achieve performance efficiency of polynomial multiplication, one of the most time-consuming operations in SMAUG-T, we find the optimal method by investigating several latest algorithms such as the Toom–Cook method and the Number-Theoretic Transform (NTT)-based methods (32-bit single moduli version and 16-bit multi-moduli version). Through the investigation, we found that 32-bit single moduli version is the best approach for polynomial multiplication in SMAUG-T on 16-bit MSP430 MCU. To enhance the performance of NTT-based polynomial multiplication, we proposed an improved 32-bit signed Montgomery multiplication method with a newly found Montgomery prime (0x250001) and the intrinsic hardware multiplier. We also apply the state-of-the-art techniques for NTT and inverse NTT (iNTT) such as the layer merging, CT butterfly by tuning them proper to the target device. As a result, our NTT implementation achieves around 35% of improved performance compared to the previous best result of 32-bit single moduli version implementation proposed for Dilithium on 16-bit MSP430 MCU. Finally, our SMAUG-T implementation with the proposed NTT implementation provides 43%–63%, 92%–99%, and 85%–95% of improved performance for key generation, encapsulation, and decapsulation compared to the reference implementation, respectively.