Skip to main navigation Skip to search Skip to main content

PHOENIX: Crypto-Agile Hardware Sharing for ML-KEM and HQC

  • Antonio Ras
  • , Antoine Loiseau
  • , Mikael Carmona
  • , Simon Pontié
  • , Guénaël Renault
  • , Benjamin Smith
  • , Emanuele Valea
  • LTHE (UMR 5564 CNRS/IRD/Université de Grenoble)
  • Ecole des Mines de Saint Etienne
  • ANSSI

Research output: Contribution to journalArticlepeer-review

Abstract

The transition to quantum-safe key agreement has begun: NIST has standardized ML-KEM and selected HQC for future standardization. The relative immaturity of these schemes encourages crypto-agile implementations, to facilitate resilient transitions to and between them. Intelligent crypto-agility requires efficient sharing strategies to compute operations from different cryptosystems using the same resources. This is particularly challenging for cryptosystems with distinct mathematical foundations, like lattice-based ML-KEM and code-based HQC. We introduce PHOENIX, the first crypto-agile hardware coprocessor for latticeand code-based cryptosystems—specifically, ML-KEM and HQC, at all three NIST security levels—with an effective agile sharing strategy. PHOENIX accelerates polynomial multiplication, which is the main operation in both cryptosystems, and the current bottleneck of HQC. To maximise sharing, we replace HQC’s Karatsubabased polynomial multiplication with the Frobenius Additive FFT (FAFFT), which is similar on an abstract level to ML-KEM’s Number Theoretic Transform (NTT). In hardware, our sharing strategy for the FAFFT and NTT is based on a new SuperButterfly unit that seamlessly switches between these two FFT variants over completely different rings. We have integrated PHOENIX in a real System-on-Chip FPGA scenario, where our performance measurements show that efficient cryptoagility for lattice-and code-based KEMs can be achieved with low overhead.

Original languageEnglish
Pages (from-to)1228-1255
Number of pages28
JournalIACR Transactions on Cryptographic Hardware and Embedded Systems
Volume2026
Issue number3
DOIs
Publication statusPublished - 17 Jul 2026

Keywords

  • Crypto-Agility
  • FAFFT
  • HQC
  • ML-KEM
  • NTT
  • Polynomial Multiplication sharing strategy
  • Post-Quantum Cryptography
  • SW-HW FPGA codesign

Fingerprint

Dive into the research topics of 'PHOENIX: Crypto-Agile Hardware Sharing for ML-KEM and HQC'. Together they form a unique fingerprint.

Cite this