EDBT 2026 Demo / reviewers in the wild / expert
Phuc-Phan Duong
dblp:374/9772
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2025
0009-0004-4534-9879ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 1 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A Low-Latency Polynomial Arithmetic Unit for ML-KEM and ML-DSA StandardsabstractExisting communication protocols based on public key cryptography (PKC) functions will no longer be secure in the quantum era. NIST has released standards for key encapsulation and digital signature mechanisms based on module lattice (ML-KEM and ML-DSA) to address this challenge. In this paper, we propose a unique, high-performance arithmetic unit capable of performing all the polynomial operations needed for ML-KEM and ML-DSA (KDA). The proposed KDA architecture includes a computational unit that supports one 4×1 NTT configuration for ML-DSA and double 4×1 NTT configurations for ML-KEM. A two-step NTT data flow and configurable memory unit are introduced to reorder and store coefficients for all operations. Moreover, we propose the re-used twiddle factor method for NTT and point-wise multiplication. We have implemented three design versions, ML-KEM standalone, ML-DSA standalone, and KDA, and compared them to the existing studies. The comparison shows that our KDA achieves superior ATP performance, improving ×1.1-×3.6. Trong-Hung Nguyen, Duc-Thuan Dam, Phuc-Phan Duong, Trong-Thuc Hoang, Cong-Kha Pham |
ISCAS | 3 |
| 2025 | A Timing-Constrained Design Methodology for Radix- 2k NTT in Polynomial ArithmeticabstractPolynomial modular multiplication is the most complex and costly operation in homomorphic encryption (HE) and post-quantum cryptography (PQC). Using the Number Theoretic Transform (NTT) helps reduce the complexity of multiplication to quasi-linear O($N\,\textup{log}_{2}N$). Although NTT significantly impacts the performance of HE and PQC, existing NTT-based multipliers often fall short due to inefficient data movement and large memory overhead. Notably, deploying low-latency cryptosystems incurs more significant costs with reduced acceleration gains. To overcome these constraints, we introduce a pioneering methodology called timing-constrained NTT (TCO-NTT). We propose an innovative time-controlled memory (TCM) structure that re-orders and stores coefficients within each stage of the NTT. Then, we employ the divide-and-conquer strategy, allowing freely configurable parallelism levels. Besides, our proposed methodology can generalize to radix-2kNTT and supports any arbitrary polynomial degreeNand scale factorpvalues. We evaluate the proposed TCO-NTT on typical HE and PQC parameter sets across multiple levels of parallelism and radix-2kNTT configurations. FPGA implementation results demonstrate that our TCO-NTT achieves minimal hardware cost while consistently executing the NTT in a near-theoretical execution time. Our area-time product (ATP) reports about LUT-ATP (LATP), FF-ATP (FATP), and BRAM-ATP (BATP) surpass the reported-to-date NTT designs by up to 10.2×, 17.8× and 47.2×. The proposed TCO-NTT sets new records for NTT-based multiplier efficiency, laying the foundation for implementing HE and PQC in real-time applications. Trong-Hung Nguyen, Duc-Thuan Dam, Phuc-Phan Duong, Tuan-Kiet Dang, Trong-Thuc Hoang, Cong-Kha Pham |
IEEE Trans. Circuits Syst. I Regul. Pap. | 3 |
| 2025 | Efficient Hardware Implementation of the Lightweight CRYSTALS-KyberabstractQuantum computing raises questions about the security of data encrypted using modern methods. Hence, the National Institute of Standards and Technology (NIST) has undertaken standardization of post-quantum cryptography (PQC) algorithms to defend against attacks from both classical and quantum computers. Following four rounds of evaluation, CRYSTALS-Kyber has been selected for standardization. In this paper, we present an efficient hardware architecture of CRYSTALS-Kyber for resource-constrained IoT devices. Firstly, we propose a compact hash module for CRYSTALS-Kyber. A single buffer is designed to perform padding, hashing, and holding data. Hence, using large FIFOs for data input/output is eliminated. Then, we propose a novel non-memory-based iterative number theoretic transform (NMI-NTT) architecture. Finally, the data flow between modules is optimized to improve parallelization and execution time. Implementation results on an Artix-7 FPGA show that our design consumes minimal hardware resources compared to the designs reported to date, corresponding to 5487 LUTs, 3426 FFs, 1548 SLICEs, 3.5 BRAMs, and 2 DSPs. Our design computes key generation, encapsulation, and decapsulation phases in 3.3/4.5/6.1 K-cycles for Kyber512, 5.6/7.1/9.2 K-cycles for Kyber768, and 8.5/10.1/12.9 K-cycles for Kyber1024, with 185MHz operating frequency. Our area-time-product (ATP) performance outperforms other designs. Trong-Hung Nguyen, Duc-Thuan Dam, Phuc-Phan Duong, Binh Kieu-Do-Nguyen, Cong-Kha Pham, Trong-Thuc Hoang |
IEEE Trans. Circuits Syst. I Regul. Pap. | 3 |
| 2024 | A Strong 4 × 4 S-Box Using an Enhanced Tent MapabstractSubstitution boxes (S-Boxes) are essential nonlinear components in order to be resistant to the cryptanalytic analysis of modern block ciphers. Given their significance, there is a wide range of S-Box construction techniques. Chaos systems are candidates for constructing S-boxes, with properties characterized by uncertainty, irregularity, and unpredictability. This paper proposes an effective method to create a 4 × 4 S-Box with strong cryptographic properties based on a one-dimensional chaotic map, which is the enhanced tent map. The algorithm used to create S-Boxes uses parameters based on the fundamental characteristics of an S-Box. The cryptanalysis results show that the created S-Box satisfies high-security properties. The output Bit Independence Criterion (BIC) and Strict Avalanche Criterion (SAC) simultaneously reach the ideal value, which no other S-Boxes have ever achieved. Additionally, the other evaluation criteria are comparable to most existing S-Boxes. Owing to these characteristics, the S-Box is appropriate for developing lightweight block ciphers. Phuc-Phan Duong, Trong-Thuc Hoang, Cong-Kha Pham |
ISCAS | 1 |