Vendor: Secure-IC Category: Post Quantum

XMSS Post-Quantum Cryptography IP

XMSS is a Post-Quantum Cryptographic (PQC) algorithm, meaning it is mathematically designed to be robust against a cryptanalytic …

Overview

XMSS is a Post-Quantum Cryptographic (PQC) algorithm, meaning it is mathematically designed to be robust against a cryptanalytic attack using a quantum computer. XMSS is a stateful Hash-Based Signature Scheme that has been recommended by NIST in 2020.

The XMSS IP is a software IP that may run on the Host CPU. It uses HASH IP resources, which may be implemented either in software (for a full software XMSS implementation) or in Hardware, to a mixed Hardware/Software implementation. The figure below shows the IP block diagram in its system environment, in case of an implementation using a Hardware HASH IP: the hardware SHA-2 IP, and a portable software library.

Secure-IC TRNG IP for XMSS keys generation and SDMAC IP are also used. The interconnection is ensured by an AMBA bus.

Standards

  • XMSS is standardized by IRTF in RFC8391: XMSS: eXtended Merkle Signature Scheme
  • It has been recommended as ‘Stateful Hash-Based Signature Scheme’ in SP 800-208
  • The XMSS function has been implemented using only RFC8391
  • The variants XMSS-SHA2_10_256 and XMSS-SHA2_16_256 have been implemented, for hybrid hardware/ software implementation based on Secure-IC HASH IP
  • Key generation, Signature and Verification operations are supported. Performance depends on the system resources, in particular for Key generation and Signature

Key features

ML-KEM and ML-DSA have been selected by the NIST post-quantum cryptography project.
The US National Security Agency also recommends to implement those algorithms in its Commercial National Security Algorithm Suite 2.0 (CNSA 2.0).
The present product is based on the version of ML-KEM and ML-DSA selected by the NIST at the end of round 3 and is aligned with NIST reference implementation.

Security features

  • ML-KEM-512, ML-KEM-768, ML-KEM-1024.
  • ML-DSA-II, ML-DSA-III, ML-DSA-V.
  • Implementation protected against Side-Channel Attack (Key Generation and Key Decapsulation operations are sensitive):
  • Simple Power Analysis (SPA)
  • Differential Power Analysis (DPA)
  • Differential Electromagnetic Analysis (DEMA)
  • Correlation Power Analysis (CPA)
  • Correlation Electromagnetic Analysis (CEMA)
  • Optional: health tests for integrity verification.

Other features

  • Hybrid hardware-software solution.
  • Optimized in performance or power/area.
  • Performs Key Generation, Key Encapsulation and Key Decapsulation functions
  • Performs Key generation, Signature and Verification.
  • Memory can be shared or dedicated.
  • Easy to integrate into the system thanks to AMBA AXI wrapper.
  • The control interface of the hardware accelerator is the AMBA AXI interface

Block Diagram

Applications

  • XMSS is designed to resist cryptanalysis using either classical or quantum computers, in applications such as:
    • Secure communications systems
    • Secure Boot
  • For Signature, XMSS IP ensures:
    • Key Generation
    • Signature
    • Signature verification
  • XMSS is recommended for Post-Quantum Firmware signature in the US National Security Agency’s Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) document.

What’s Included?

  • Specifications
  • User guide
  • Test report documentation
  • XMSS software library

Specifications

Identity

Part Number
SCZ_IP_PQC_XMSS
Vendor
Secure-IC
Type
Silicon IP

Videos

Video 1

Files

Note: some files may require an NDA depending on provider policy.

Provider

HQ: France

Learn more about Post Quantum IP core

How to design secure SoCs Part IV: Runtime Integrity Protection

In previous articles, we gave an overview about secure SoC architectures (Part I), about the importance of key management (Part II) and secure boot (Part III) - the first line of defense. Part IV of the series focuses on runtime integrity protection, a paramount, ensuring the application remains secure even during active operation.

How to design secure SoCs Part IV: Runtime Integrity Protection

SoC designers are increasingly challenged to integrate robust security measures into their designs. Modern connected devices, such as automotive Electronic Control Units (ECUs), Internet of Things (IoT) nodes, and industrial control systems, face increasing susceptibility to cyberattacks. This escalating threat landscape underscores the critical importance of mandatory security requirements.

Nine Compelling Reasons Why Menta eFPGA Is Essential for Achieving True Crypto Agility in Your ASIC or SoC

Today’s world is already overly complicated to provide robust product security, with extremely motivated hackers creating novel threats exposing new vulnerabilities every day. But considering tomorrow’s world with the looming threat of quantum computing, expanding AI possibilities and rapidly evolving regional regulations and export control risk with severe financial penalties, this is a daunting challenge.

Providing protection against EMFI attacks

This Agile Analog blog post is focused on describing the dangers of Electromagnetic Fault Injection (EMFI) attacks and outlining the importance of EMFI sensors that are designed to provide protection.

Deploying StrongSwan on an Embedded FPGA Platform, IPsec/IKEv2 on Arty Z7 with PetaLinux and PQC

The objective of this article is to present and analyze a concrete IPsec/IKEv2 deployment on an FPGA-based embedded Linux system. Using an Arty Z7 FPGA platform with PetaLinux and StrongSwan, the focus is on system-level integration rather than protocol theory: how the IPsec stack is built and deployed, how classical and post-quantum key exchange are integrated without modifying standardized protocols, and what architectural trade-offs arise when moving cryptographic operations into programmable logic.

Frequently asked questions about Post-Quantum Cryptography IP cores

What is XMSS Post-Quantum Cryptography IP?

XMSS Post-Quantum Cryptography IP is a Post Quantum IP core from Secure-IC listed on Semi IP Hub.

How should engineers evaluate this Post Quantum?

Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this Post Quantum IP.

Can this semiconductor IP be compared with similar products?

Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.

×
Semiconductor IP