Résumé
The transition to quantum-safe key agreement has begun: NIST has standardized ML-KEM and selected HQC for future standardization. The relative immaturity of these schemes encourages crypto-agile implementations, to facilitate resilient transitions to and between them. Intelligent crypto-agility requires efficient sharing strategies to compute operations from different cryptosystems using the same resources. This is particularly challenging for cryptosystems with distinct mathematical foundations, like lattice-based ML-KEM and code-based HQC. We introduce PHOENIX, the first crypto-agile hardware coprocessor for latticeand code-based cryptosystems—specifically, ML-KEM and HQC, at all three NIST security levels—with an effective agile sharing strategy. PHOENIX accelerates polynomial multiplication, which is the main operation in both cryptosystems, and the current bottleneck of HQC. To maximise sharing, we replace HQC’s Karatsubabased polynomial multiplication with the Frobenius Additive FFT (FAFFT), which is similar on an abstract level to ML-KEM’s Number Theoretic Transform (NTT). In hardware, our sharing strategy for the FAFFT and NTT is based on a new SuperButterfly unit that seamlessly switches between these two FFT variants over completely different rings. We have integrated PHOENIX in a real System-on-Chip FPGA scenario, where our performance measurements show that efficient cryptoagility for lattice-and code-based KEMs can be achieved with low overhead.
| langue originale | Anglais |
|---|---|
| Pages (de - à) | 1228-1255 |
| Nombre de pages | 28 |
| journal | IACR Transactions on Cryptographic Hardware and Embedded Systems |
| Volume | 2026 |
| Numéro de publication | 3 |
| Les DOIs | |
| état | Publié - 17 juil. 2026 |
Empreinte digitale
Examiner les sujets de recherche de « PHOENIX: Crypto-Agile Hardware Sharing for ML-KEM and HQC ». Ensemble, ils forment une empreinte digitale unique.Contient cette citation
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver