Quantum computers will solve some of the most complex problems in minutes versus the potentially thousands of years that classical computers and supercomputers would require. Because they will rapidly break current ECC and RSA cryptography, placing sensitive data and systems at risk, it's important to consider post-quantum cryptography in today's SoC designs, not a future upgrade. With the NIST PQC standards finalized, migration planning is underway across the industry, and long-lived platforms need crypto agility built into the silicon.

Synopsys Agile Post Quantum Cryptography (PQC) Public Key Accelerators (PKAs) are quantum-safe IP solutions that offload the computationally intensive operations required for asymmetric cryptography, including the latest NIST-selected quantum-resistant algorithms.

Synopsys Agile PQC PKAs comply with the latest NIST PQC digital signature, key encapsulation and encryption algorithms, including:

  • ML-KEM (FIPS 203, formerly CRYSTALS-Kyber): This algorithm is based on lattice problems and offers a balance of security, efficiency, and ease of implementation, making it a suitable choice for general encryption tasks.
  • ML-DSA (FIPS 204, formerly CRYSTALS-Dilithium): This algorithm is also based on lattice problems but is specifically designed for digital signatures, offering strong security guarantees and efficient performance.
  • SLH-DSA (FIPS 205, formerly SPHINCS+): This algorithm employs a stateless hash-based approach, offering a different set of security assurances compared to lattice-based methods.
  • XMSS & LMS (SP 800-208): These algorithms are from the NIST standard SP 800-208, which was released in 2020. Both XMSS and LMS rely on the Merkle tree structure, which provides a secure and efficient way to manage and verify many signatures.
  • FN-DSA (Falcon) and HQC are on the roadmap.

Synopsys Agile PQC PKAs can adapt to the standards' evolutions by efficiently incorporating hardware and embedded firmware, where the hardware accelerates the main cryptographic primitives for performance and power benefits, but the higher-level algorithms are implemented in firmware to provide flexibility for future algorithm updates. The traditional ECC and RSA algorithms as well as hybrid schemes are also supported. 

Synopsys Agile PKAs are highly configurable and scalable and can be tuned for most optimal performance, area, power, and latency.

 

Key Benefits, Specifications and Target Applications

Key Benefits

  • Crypto-Agile IP — HW/FW/SW, adaptable to future standards’ evolution, with filed-updatable algorithms
  • Tuned to your design —highly configurable IP can be tuned for specific applications with most optimal PPA
  • Certified — NIST CAVP certified PQC algorithms, including the first CAVP certification for SLH-DSA, plus FIPS 140-3 certification support
  • Hardened against physical attacks: Option for DPA/TA and fault injection countermeasures, with a secure key interface

Specifications

  • Scalable PQC PKA IP complies with latest NIST PQC algorithms
    • ML-KEM (FIPS 203)
    • ML-DSA (FIPS 204)
    • SLH-DSA (FIPS 205)
    • XMSS and LMS (SP 800-208)
    • RSA (up to 8192-bit)
    • ECC (up to 1024-bit; NIST, Brainpool, Montgomery, Edwards, SM2, generic Weierstrass)
    • Full PQC digital signatures, key encapsulation, key exchange, and encrypt/decrypt functions

Target Applications

  • Data centers 
  • Networking infrastructure 
  • Automotive 
  • Industrial control
  • Aerospace and defense
  • Storage 
  • Consumer and IoT 
  • Payment card industry 
  • Secure manufacturing
  • NSA CNSA 2.0 quantum-resistant deployments

Product Details

Resources

Find Your IP

Search for IP

Quickly identify and access the right IP solutions for your project needs.


Foundation IP Selector

Find embedded memory and logic IP for your SoC design.

Non-Volatile Memory IP Selector

Find silicon-proven NVM IP for your SoC design needs.

Ask BETA This experience is in beta mode. Please double check responses for accuracy.

End Chat

Closing this window clears your chat history and ends your session. Are you sure you want to end this chat?