Cryptographic hardware IP
Silicon-ready cryptographic cores for FPGA, ASIC, and SoC integration, with post-quantum and classical algorithms in one portfolio.
Post-quantum coverage
| Algorithm | L1 | L2 | L3 | L5 | Standard |
|---|---|---|---|---|---|
| ML-KEM | FIPS 203 | ||||
| ML-DSA | FIPS 204 | ||||
| SLH-DSA | FIPS 205 | ||||
| FN-DSA | FIPS 206 |
Available Coming Not defined at this level
Levels reflect the parameter sets defined in each standard. Stateful hash-based signatures (XMSS, LMS/HSS) are specified separately under NIST SP 800-208 and are listed in the full coverage index below.
Algorithm coverage
One IP portfolio spanning the post-quantum standards and the classical, symmetric, lightweight, and entropy functions that stay essential to the platform.
Complete portfolio
Post-quantum standards
- ML-KEM FIPS 203
- ML-DSA FIPS 204
- SLH-DSA FIPS 205
- FN-DSA / Falcon FIPS 206, coming soon
Hash-based signatures
- XMSS RFC 8391
- LMS / HSS RFC 8554
- Stateful guidance NIST SP 800-208
Classical public-key
- ECDSA / ECDH NIST curves
- Curve25519 / Ed25519 RFC 7748, RFC 8032
- Curve448 / Ed448 RFC 7748, RFC 8032
- RSA 2048 / 3072 / 4096 CRT acceleration
Symmetric and hashing
- AES GCM, CTR, CBC
- SHA-2 FIPS 180
- SHA-3 FIPS 202
- HMAC FIPS 198
Lightweight and entropy
- ASCON AEAD, hash, XOF
- Trivium Stream cipher
- TRNG SP 800-90B, 90C
- DRBG SP 800-90A
Post-quantum cores support NIST security levels 1, 3, and 5. Side-channel protection is optional on the classical public-key cores.
Where it goes
The same cores ship into FPGA prototyping, ASIC production, and SoC integration, presenting interfaces that fit trust boundaries already in your design.
| Item | Coverage | Delivery and integration |
|---|---|---|
| FPGA | AMD / Xilinx (Artix, Kintex, UltraScale+, Versal), Intel / Altera, Microchip, Menta eFPGA, Analog Devices / Flex-Logix eFPGA | FPGA-proven and side-channel evaluated |
| ASIC | Technology-node portable | Synthesizable Verilog and SystemVerilog, optimized for area, timing, and power, EDA-flow compatible |
| SoC | RISC-V co-design ready | AXI, APB, and TileLink interfaces, Secure Boot integration, key provisioning interfaces |
Applications
- Secure boot and Root-of-Trust
- Secure enclaves and hardware security modules
- Defense and aerospace platforms
- 5G and edge infrastructure
- IoT and constrained devices
- Supply-chain-assured silicon programs
Protection, and how it is proven
Countermeasures are part of the microarchitecture rather than a layer added afterwards. They are measured internally with TVLA and independently by Keysight.
| Threat class | Response in the microarchitecture |
|---|---|
| Differential Power Analysis (DPA) | Resistance, with first-order masking and shuffling |
| Correlation Power Analysis (CPA) | Mitigation, with first-order masking and shuffling |
| Timing analysis | Constant-time hardware datapaths |
| Fault injection | Fault injection countermeasures |
| Glitch and electromagnetic | Glitch and EM-aware design |
Ready for FIPS 140-3 non-invasive attacks, level 3 and above.
Verification
- In-house verification
-
- UVM-based verification environments
- RTL regression and constrained testing
- FPGA validation platforms
- TVLA-oriented leakage evaluation
- ACVP and CAVP algorithm compliance
- NIST known-answer test vectors
- Independent evaluation
-
Keysight evaluates the cores for functional correctness, DPA and CPA leakage, electromagnetic side channels, fault injection susceptibility, and robustness under adversarial conditions.
- Software pairing
-
The cores integrate with libpqsecure-C and libpqsecure-rs for hardware acceleration with secure software fallback, unified Root-of-Trust architectures, and hybrid classical plus post-quantum deployments.
Architecture profiles
Every profile presents the same integration interface, so area, power, and throughput can change without reworking how the core connects.
Smallest area Highest throughput
-
Tiny
Ultra-low area, constrained devices
- Smallest silicon area
- Reduced memory usage
- IoT endpoints
-
Compact
Low area, efficient embedded
- Area-optimized
- Moderate throughput
- Power-sensitive designs
-
Balanced
Area and performance optimized
- Optimized tradeoff
- Secure gateways
- Defense platforms
-
High-performance
Maximum throughput, SoC optimized
- Parallel engines
- Deep pipelining
- Data center and cloud
Certification
pqsecure-hw-core, version 1.0, validated as HARDWARE.
- Validated
-
- ML-KEM FIPS 203
- ML-DSA FIPS 204
- SLH-DSA FIPS 205
- Vendor
- PQSecure Technologies
Put protected cryptography inside your silicon.
Talk with our hardware team about core selection, profile sizing, integration, and licensing.
Contact us