Skip to content
Open access

A Unified RISC-V Vector Framework for Large-Scale NTT in FHE and ZKP

Sep 2026 · IACR Transactions on Cryptographic Hardware and Embedded Systems · 0 citations · 48 references

Abstract

Data privacy has become increasingly critical in modern society, driving significant interest from both academia and industry in privacy-preserving technologies such as fully homomorphic encryption (FHE) and zero-knowledge proofs (ZKP). More recently, emerging paradigms such as verifiable FHE require the joint support of both cryptographic techniques, significantly increasing the diversity and complexity of underlying computational workloads. Prior hardware accelerators mainly target a single application or a narrow parameter range, making them ill-suited for supporting multiple cryptographic primitives. As an emerging open platform, RISC-V combines general-purpose programmability with high-performance computation enabled by vector extensions such as RISC-V Vector Extension (RVV). In this work, we propose a unified framework to efficiently support Number Theoretic Transform (NTT) workloads in both FHE and ZKP. We observe that existing RVV-based NTT kernels fail to scale efficiently to large parameter sizes; while the four-step NTT algorithm reduces the transform size through decomposition, conventional parameter selection often leads to suboptimal performance. To address this, we introduce a model-guided decomposition strategy that automatically selects near-optimal parameters. In addition, we design limb-wise 256-bit arithmetic to efficiently support ZKP workloads using RVV. We implement our framework on a gem5-based out-of-order RISC-V core with RVV v1.0 support. Experimental results demonstrate that our approach significantly improves NTT performance across a wide range of parameters and provides an efficient execution substrate for both FHE and ZKP workloads. Specifically, our approach achieves up to 1.53x speedup over prior state-of-the-art RVV-based implementations on standalone NTTs, up to 6.15x speedup over OpenFHE on CKKS bootstrapping, and up to 1.35x speedup over libsnark on BN128-based workloads.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.