Abstract
The transition to quantum-safe key agreement has begun: NIST has standardized ML-KEM and selected HQC for future standardization. The relative immaturity of these schemes encourages crypto-agile implementations, to facilitate resilient transitions to and between them. Intelligent crypto-agility requires efficient sharing strategies to compute operations from different cryptosystems using the same resources. This is particularly challenging for cryptosystems with distinct mathematical foundations, like lattice-based ML-KEM and code-based HQC. We introduce PHOENIX, the first crypto-agile hardware coprocessor for latticeand code-based cryptosystems—specifically, ML-KEM and HQC, at all three NIST security levels—with an effective agile sharing strategy. PHOENIX accelerates polynomial multiplication, which is the main operation in both cryptosystems, and the current bottleneck of HQC. To maximise sharing, we replace HQC’s Karatsubabased polynomial multiplication with the Frobenius Additive FFT (FAFFT), which is similar on an abstract level to ML-KEM’s Number Theoretic Transform (NTT). In hardware, our sharing strategy for the FAFFT and NTT is based on a new SuperButterfly unit that seamlessly switches between these two FFT variants over completely different rings. We have integrated PHOENIX in a real System-on-Chip FPGA scenario, where our performance measurements show that efficient cryptoagility for lattice-and code-based KEMs can be achieved with low overhead.
| Original language | English |
|---|---|
| Pages (from-to) | 1228-1255 |
| Number of pages | 28 |
| Journal | IACR Transactions on Cryptographic Hardware and Embedded Systems |
| Volume | 2026 |
| Issue number | 3 |
| DOIs | |
| Publication status | Published - 17 Jul 2026 |
Keywords
- Crypto-Agility
- FAFFT
- HQC
- ML-KEM
- NTT
- Polynomial Multiplication sharing strategy
- Post-Quantum Cryptography
- SW-HW FPGA codesign
Fingerprint
Dive into the research topics of 'PHOENIX: Crypto-Agile Hardware Sharing for ML-KEM and HQC'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver