Vendor: CAST Category: Post Quantum

ML-KEM Key Encapsulation IP Core

The KiviPQC™-KEM is a hardware accelerator for post-quantum cryptographic operations.

CRYSTALS-Kyber (ML-KEM) View all specifications

Overview

The KiviPQC™-KEM is a hardware accelerator for post-quantum cryptographic operations. It implements the Module Lattice-based Key Encapsulation Mechanism (ML-KEM), standardized by NIST in FIPS 203. This mechanism realizes the appropriate procedures for securely exchanging a shared secret key between two parties that communicate over a public channel using a defined set of rules and parameters. The KiviPQC™-KEM supports key generation, encapsulation, and decapsulation procedures, making it suitable for both (client/server) sides of key exchange.

The engine supports all three parameter sets for ML-KEM, i.e. ML-KEM-512, ML-KEM-768, and ML-KEM-1024. It is based on a RISC-V-like SoC topology and includes a 32-bit RISC-V-based processor. The resulting shared key is of 32 bytes. Designed for straightforward integration, the communication with the host is accomplished via an AMBA® AXI4-Lite Subordinate port.

Two versions are available: a Fast (F) and a Tiny (T) version. The Fast (F) includes hardware crypto accelerators, a hardware timer module, and a crossbar interconnect module for internal data routing. The Tiny (T) version is a more compact architecture, targeting low area, with no hardware crypto accelerators. Both versions are currently offered with a software implementation of a Random Byte Generator (RBG), however, they are able to be integrated with an external (third-party) entropy source and RBG, via a fully customized interface, depending on the entropy/RBG selection.

The KiviPQC™-KEM provides hardware acceleration for computationally intensive operations while maintaining a small footprint and can be integrated into any system-on-chip (SoC) for ASIC or FPGA implementation. Beyond that, it combines a minimal attack surface with modest resource requirements for future-proof and quantum-safe systems.

Key features

NIST FIPS Compliant

  • Module Lattice-based Key Encapsulation Mechanism (ML-KEM)
    • NIST FIPS 203
  • All three ML-KEM parameter sets
  • 512 / 768 / 1024

Versions

  • Fast (F): Enhanced performance, with balanced area
  • Tiny (T): Compact architecture, targeting low area

Enhanced Security

  • Self-contained engine with a minimal attack surface
  • Protection against timing-based side channel attacks

Resource-efficient Acceleration

  • Hardware offloading and acceleration of time-consuming PQC operations
    • 600MHz, with 83k or less eq. gates in modern ASICs (F)
  • Minimal logic utilization
    • 35k or less eq. gates, at 100MHz in modern ASICs (T)

Straightforward SoC Integration

  • Lightweight, simple-control AMBA® AXI4 Interface
  • Re-usable design, LINT-clean

Block Diagram

Applications

  • The KiviPQC™-KEM realizes a quantum-safe exchange of a shared secret key between two parties (client and server) communicating over a public channel. During the key sharing, the client generates a decapsulation key and an encapsulation key, keeps the first as private and sends the second as public to the server. The server generates a copy of the shared key and an associated ciphertext using the client’s encapsulation key and sends it to the client. Finally, the client generates a copy of the same shared key using the ciphertext received from the server and the kept private decapsulation key.

  • The core offers quantum-resistant security for a wide range of applications. In public-key infrastructure and cloud security, it ensures long-term confidentiality and integrity for sensitive information. It can play a vital role in safety-critical infrastructure and networks, safeguarding communication and exchange channels from potential threats. In the realm of secure IoT device communication, the core provides strong cryptographic support to protect shared secret keys. Additionally, it is well-suited for hardware security modules (HSMs) and Trusted Platform Modules (TPMs), enhancing secure key management and cryptographic processing. Its capabilities extend to supporting MACsec key agreement (MKA) protocols for secure Ethernet communications, Internet Key Exchange (IKEv2) protocols, strengthening VPN and secure network authentication mechanisms, and edge computing.

What’s Included?

The core is available in RTL (System Verilog) source code.

Its deliverable package includes the following:

  • Self-checking HDL testbench
  • Hardware Abstraction Layer (HAL) and driver for the application processor
  • Sample simulation & synthesis scripts
  • User documentation

Specifications

Identity

Part Number
KiviPQC-KEM
Vendor
CAST
Type
Silicon IP

Security

Crypto Algorithm
CRYSTALS-Kyber (ML-KEM)

Files

Note: some files may require an NDA depending on provider policy.

Provider

HQ: USA

Learn more about Post Quantum IP core

How to design secure SoCs Part IV: Runtime Integrity Protection

In previous articles, we gave an overview about secure SoC architectures (Part I), about the importance of key management (Part II) and secure boot (Part III) - the first line of defense. Part IV of the series focuses on runtime integrity protection, a paramount, ensuring the application remains secure even during active operation.

How to design secure SoCs Part IV: Runtime Integrity Protection

SoC designers are increasingly challenged to integrate robust security measures into their designs. Modern connected devices, such as automotive Electronic Control Units (ECUs), Internet of Things (IoT) nodes, and industrial control systems, face increasing susceptibility to cyberattacks. This escalating threat landscape underscores the critical importance of mandatory security requirements.

Nine Compelling Reasons Why Menta eFPGA Is Essential for Achieving True Crypto Agility in Your ASIC or SoC

Today’s world is already overly complicated to provide robust product security, with extremely motivated hackers creating novel threats exposing new vulnerabilities every day. But considering tomorrow’s world with the looming threat of quantum computing, expanding AI possibilities and rapidly evolving regional regulations and export control risk with severe financial penalties, this is a daunting challenge.

Providing protection against EMFI attacks

This Agile Analog blog post is focused on describing the dangers of Electromagnetic Fault Injection (EMFI) attacks and outlining the importance of EMFI sensors that are designed to provide protection.

Deploying StrongSwan on an Embedded FPGA Platform, IPsec/IKEv2 on Arty Z7 with PetaLinux and PQC

The objective of this article is to present and analyze a concrete IPsec/IKEv2 deployment on an FPGA-based embedded Linux system. Using an Arty Z7 FPGA platform with PetaLinux and StrongSwan, the focus is on system-level integration rather than protocol theory: how the IPsec stack is built and deployed, how classical and post-quantum key exchange are integrated without modifying standardized protocols, and what architectural trade-offs arise when moving cryptographic operations into programmable logic.

Frequently asked questions about Post-Quantum Cryptography IP cores

What is ML-KEM Key Encapsulation IP Core?

ML-KEM Key Encapsulation IP Core is a Post Quantum IP core from CAST listed on Semi IP Hub.

How should engineers evaluate this Post Quantum?

Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this Post Quantum IP.

Can this semiconductor IP be compared with similar products?

Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.

×
Semiconductor IP