Unified Hardware IP for Post-Quantum Cryptography based on Kyber and Dilithium
Turn-key implementations of the NIST FIPS recommended CRYSTALS post-quantum for key encapsulation (KEM) and digital signature algorithm (DSA)
Overview
PQSecure™-CRYSTALS from PQSecure Technologies, LLC. is a set of hardware IP cores designed for various target applications of digital signatures and key encapsulation based on Dilithium and Kyber algorithms. PQSecure™-CRYSTALS supports parameters for all three FIPS recommended security levels with countermeasures (optional) against various side-channel and known fault attacks. It can be used in various security protocols to replace or augment the traditional elliptic curve based key exchange and digital signatures (ECDH and ECDSA) such as TLS, which are potentially compromised by quantum computing.
PQSecure™-CRYSTALS has several variations that operate at different levels of performance and security levels. The lowest area (tiny) design is PQSecure™-CRYSTALS-1000T, the compact design is designated PQSecure™-CRYSTALS-1000C, the balanced-performance design is PQSecure™-CRYSTALS1000B, and the highest-performance design is PQSecure™- CRYSTALS-1000H.
PQSecure™-CRYSTALS-1000 series have been designed in a flexible manner to be platform independent and is available to be integrated to both FPGA- and ASIC-based solutions without relying on specific embedded resources of the platforms.
PQSecure™-CRYSTALS-1000 series are secure against timing attacks and can optionally provide power side-channel countermeasures (to address FIPS 140-3 non-invasive attack requirements) for all three security levels. For instance, PQSecure™-CRYSTALS-1000B-SCA-FI is a balanced performance implementation that provides basic fault injection (FI) countermeasures and uses masking, shuffling, and other techniques to protect against Simple Power Analysis (SPA) attacks as well as first order Differential Power Analysis (DPA) attacks for all NIST/FIPS security levels.
Key features
- Turn-key implementations of the NIST FIPS recommended CRYSTALS post-quantum for key encapsulation (KEM) and digital signature algorithm (DSA)
- Complete CPU offload of cryptographic operations
- Highly silicon customizable design with optional hash accelerator, memory, and control unit to support customer’s requirements.
- Ease of integration into various RISC-V, SoC, and FPGA architectures and development flow
Block Diagram
Benefits
- Support for multiple interface standards including AXI, APB, and AHB.
- Choice of several performance grades versus silicon footprint trade-offs
- Substantial power reductions in comparison to software implementations
- Optional and secure-by-design support for side-channel attack countermeasures
- Protection against known fault injection attacks
Applications
- Microcontroller and Microprocessor acceleration for IoTs
- Secure networking protocols such as SSL/TLS, and IPSec
- Secure car-to-car communications
- Secure boot and root of trust for HSMs
What’s Included?
- PQS-CRYSTALS-1000 is available in several formats including netlist, source code (plain and encrypted) with a complete testbench in SystemVerilog with known answer tests (KATs) for verification, with UVM testbenches, as well as integration data, simulation results and synthesis scripts.
Specifications
Identity
Security
Files
Note: some files may require an NDA depending on provider policy.
Provider
Learn more about Post Quantum IP core
How to design secure SoCs Part IV: Runtime Integrity Protection
How to design secure SoCs Part IV: Runtime Integrity Protection
Nine Compelling Reasons Why Menta eFPGA Is Essential for Achieving True Crypto Agility in Your ASIC or SoC
Providing protection against EMFI attacks
Deploying StrongSwan on an Embedded FPGA Platform, IPsec/IKEv2 on Arty Z7 with PetaLinux and PQC
Frequently asked questions about Post-Quantum Cryptography IP cores
What is Unified Hardware IP for Post-Quantum Cryptography based on Kyber and Dilithium?
Unified Hardware IP for Post-Quantum Cryptography based on Kyber and Dilithium is a Post Quantum IP core from PQSecure Technologies listed on Semi IP Hub.
How should engineers evaluate this Post Quantum?
Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this Post Quantum IP.
Can this semiconductor IP be compared with similar products?
Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.