Vendor: PQSecure Technologies Category: Post Quantum

Unified Hardware IP for Post-Quantum Cryptography based on Kyber and Dilithium

Turn-key implementations of the NIST FIPS recommended CRYSTALS post-quantum for key encapsulation (KEM) and digital signature algorithm (DSA)

CRYSTALS-Kyber (ML-KEM) View all specifications

Overview

PQSecure™-CRYSTALS from PQSecure Technologies, LLC. is a set of hardware IP cores designed for various target applications of digital signatures and key encapsulation based on Dilithium and Kyber algorithms. PQSecure™-CRYSTALS supports parameters for all three FIPS recommended security levels with countermeasures (optional) against various side-channel and known fault attacks. It can be used in various security protocols to replace or augment the traditional elliptic curve based key exchange and digital signatures (ECDH and ECDSA) such as TLS, which are potentially compromised by quantum computing.

PQSecure™-CRYSTALS has several variations that operate at different levels of performance and security levels. The lowest area (tiny) design is PQSecure™-CRYSTALS-1000T, the compact design is designated PQSecure™-CRYSTALS-1000C, the balanced-performance design is PQSecure™-CRYSTALS1000B, and the highest-performance design is PQSecure™- CRYSTALS-1000H.

PQSecure™-CRYSTALS-1000 series have been designed in a flexible manner to be platform independent and is available to be integrated to both FPGA- and ASIC-based solutions without relying on specific embedded resources of the platforms.

PQSecure™-CRYSTALS-1000 series are secure against timing attacks and can optionally provide power side-channel countermeasures (to address FIPS 140-3 non-invasive attack requirements) for all three security levels. For instance, PQSecure™-CRYSTALS-1000B-SCA-FI is a balanced performance implementation that provides basic fault injection (FI) countermeasures and uses masking, shuffling, and other techniques to protect against Simple Power Analysis (SPA) attacks as well as first order Differential Power Analysis (DPA) attacks for all NIST/FIPS security levels.

Key features

  • Turn-key implementations of the NIST FIPS recommended CRYSTALS post-quantum for key encapsulation (KEM) and digital signature algorithm (DSA)
  • Complete CPU offload of cryptographic operations
  • Highly silicon customizable design with optional hash accelerator, memory, and control unit to support customer’s requirements.
  • Ease of integration into various RISC-V, SoC, and FPGA architectures and development flow

Block Diagram

Benefits

  • Support for multiple interface standards including AXI, APB, and AHB.
  • Choice of several performance grades versus silicon footprint trade-offs
  • Substantial power reductions in comparison to software implementations
  • Optional and secure-by-design support for side-channel attack countermeasures
  • Protection against known fault injection attacks

Applications

  • Microcontroller and Microprocessor acceleration for IoTs
  • Secure networking protocols such as SSL/TLS, and IPSec
  • Secure car-to-car communications
  • Secure boot and root of trust for HSMs

What’s Included?

  • PQS-CRYSTALS-1000 is available in several formats including netlist, source code (plain and encrypted) with a complete testbench in SystemVerilog with known answer tests (KATs) for verification, with UVM testbenches, as well as integration data, simulation results and synthesis scripts.

Specifications

Identity

Part Number
PQSecure™-CRYSTALS-1000
Vendor
PQSecure Technologies
Type
Silicon IP

Security

Crypto Algorithm
CRYSTALS-Kyber (ML-KEM)

Files

Note: some files may require an NDA depending on provider policy.

Provider

Learn more about Post Quantum IP core

How to design secure SoCs Part IV: Runtime Integrity Protection

In previous articles, we gave an overview about secure SoC architectures (Part I), about the importance of key management (Part II) and secure boot (Part III) - the first line of defense. Part IV of the series focuses on runtime integrity protection, a paramount, ensuring the application remains secure even during active operation.

How to design secure SoCs Part IV: Runtime Integrity Protection

SoC designers are increasingly challenged to integrate robust security measures into their designs. Modern connected devices, such as automotive Electronic Control Units (ECUs), Internet of Things (IoT) nodes, and industrial control systems, face increasing susceptibility to cyberattacks. This escalating threat landscape underscores the critical importance of mandatory security requirements.

Nine Compelling Reasons Why Menta eFPGA Is Essential for Achieving True Crypto Agility in Your ASIC or SoC

Today’s world is already overly complicated to provide robust product security, with extremely motivated hackers creating novel threats exposing new vulnerabilities every day. But considering tomorrow’s world with the looming threat of quantum computing, expanding AI possibilities and rapidly evolving regional regulations and export control risk with severe financial penalties, this is a daunting challenge.

Providing protection against EMFI attacks

This Agile Analog blog post is focused on describing the dangers of Electromagnetic Fault Injection (EMFI) attacks and outlining the importance of EMFI sensors that are designed to provide protection.

Deploying StrongSwan on an Embedded FPGA Platform, IPsec/IKEv2 on Arty Z7 with PetaLinux and PQC

The objective of this article is to present and analyze a concrete IPsec/IKEv2 deployment on an FPGA-based embedded Linux system. Using an Arty Z7 FPGA platform with PetaLinux and StrongSwan, the focus is on system-level integration rather than protocol theory: how the IPsec stack is built and deployed, how classical and post-quantum key exchange are integrated without modifying standardized protocols, and what architectural trade-offs arise when moving cryptographic operations into programmable logic.

Frequently asked questions about Post-Quantum Cryptography IP cores

What is Unified Hardware IP for Post-Quantum Cryptography based on Kyber and Dilithium?

Unified Hardware IP for Post-Quantum Cryptography based on Kyber and Dilithium is a Post Quantum IP core from PQSecure Technologies listed on Semi IP Hub.

How should engineers evaluate this Post Quantum?

Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this Post Quantum IP.

Can this semiconductor IP be compared with similar products?

Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.

×
Semiconductor IP