International Association for Cryptologic Research

International Association
for Cryptologic Research

Transactions on Cryptographic Hardware and Embedded Systems 2026

Decomposition of Large Look-Up Tables for Fast Homomorphic Evaluation


README

This repository contains all the code required to reproduce the experiments and regenerate the tables and figures from the paper Decomposition of Large Look-Up Tables for Fast Homomorphic Evaluation, published in TCHES 2026, Volume 3. Additionally, it provides a stand-alone tool to decompose a large LUT into a circuit of smaller LUTs using the technique introduced in the paper.


Overview of this Artifact

We provide the raw data files generated by our experiments, as well as decompositions for randomly generated S-boxes. The artifact allows users to regenerate the figures from the paper using these raw data files, and to rerun the experiments to regenerate the data.

The main features of the artifact are:

Additionally, we provide a stand-alone tool that allows users to generate the decomposition of any user-provided LUT.


Installation

The only prerequisites are Python and Rust. Rust can be installed with a single command by following the instructions at:

https://rust-lang.org/tools/install/

Then run:

make install

to install all dependencies.

Alternatively, you can use the provided Docker container:

docker build -t artifact-hlut-tches .
docker run -it \
    -v "$PWD":/artifact \
    artifact-hlut-tches bash

The project directory is bind-mounted into the container, so any figures and data files generated inside the container are automatically saved on the host machine.


Quick Reproduction

Reproducing the Plots

To regenerate all figures from the paper using the provided raw data, run:

make plots MODE=paper

The generated figures will be located in figures/paper and should match those in the paper.

Full Reproduction

To reproduce all experiments, run:

make reproduce

This command:

This reproduction can take some time depending on your hardware. On our computing server, it takes approximately one hour.

Stand-alone Tool

The decomposition generation is not included in the full reproduction script, as it is computationally intensive. Instead, we provide a stand-alone tool to decompose any S-box.

Example:

make decompose S=2 P=3 N=8 GAMMA=1.05 SBOX_FILE=aes.sbox

This command generates a one-bit block decomposition of the AES S-box. The output is written to search/.

S-box file format

Provide the output values, in order, on a single line, separated by spaces. See aes.sbox for an example.


Hardware Requirements

Our experiments were run on the following hardware:


Detailed Documentation

Decompositions

We provide the decompositions and S-boxes used in our experiments in:

decompositions/paper

To regenerate the decompositions for all supported sizes, run:

make decompositions

⚠️ This operation is computationally expensive for large sizes. For targeted use, we recommend using the stand-alone tool instead.


Plots and Tables

All plots and tables from the paper can be regenerated. The available outputs include:

Plots can be generated from either:

Run:

MODE=[paper|regenerated] make plots

Benchmarks

Four benchmarks are available:

Run them individually:

make hlut-full
make tbm
make wopppbs
make cjp

Or run all benchmarks at once:

make bench

For our method, the failure probability can be selected using:

To reproduce Figure 9 (smaller output sizes), run:

make hlut-partial

Experiments

The following experiments can be reproduced. The corresponding plots can then be generated using MODE=regenerated.

Figure 5

make experiments-ranks-distribution

Figure 6

make experiments-correlation-margin-ranks

Table 1

make experiments-shapes

Table 2

make experiments-count-pbs

Table 3

make experiments-encodings

Structure of the repository