PQSecure™ HW/SW Co-Design

Integrated architectures

Tightly integrated hardware and software cryptographic architectures, engineered for secure lifecycle management and long-term post-quantum migration.

Algorithm coverage

Co-designed implementations

Module Standard Status
ML-KEM FIPS 203 Available
ML-DSA FIPS 204 Available
SLH-DSA FIPS 205 Available
FN-DSA FIPS 206 Coming
XMSS, LMS Stateful hash Available
RBG / TRNG SP 800-90A and SP 800-90B CAVP A8932

Change the cryptography without changing the silicon

Crypto agility is the ability to upgrade, replace, or hybridize cryptographic algorithms without redesigning hardware.

A standalone accelerator fixes its algorithms at tape-out. A pure software stack gives up the throughput. Designing the two together is what makes the transition from RSA and ECC, through hybrid operation, to pure post-quantum possible without a silicon respin.

The migration it allows

RSA and ECC to hybrid to pure PQC, with no silicon respin at any step. Running both at once is what enables flexible acceleration paths, secure software fallback, and gradual migration strategies.

How it is built in

  • Runtime-selectable algorithms Chosen in the field, not at tape-out
  • Hybrid classical and PQC Both in operation during migration
  • Firmware-controlled dispatch Software decides which path executes
  • Modular accelerator interfaces Cores attach without redesign
  • Forward compatibility Room for NIST standards not yet published

Secure today has to mean secure in ten years

Devices shipping now will outlive the algorithms they were built with. Over-the-air modernization is how a fielded device gets the cryptography it will need later.

Post-deployment upgrades

Mechanism and purpose

OTA firmware updates

Post-quantum algorithms can be activated on a device already in the field.

Remote algorithm replacement

An algorithm can be swapped without physical access to the device.

Secure key rollover

Keys are replaced under the protection of the existing root of trust.

Algorithm deprecation

A retired algorithm can be withdrawn from service deliberately rather than left reachable.

Critical for defense systems, automotive ECUs, and IoT deployments with long field lifetimes.

Two ecosystems, one approach

The co-design pattern is the same in both: a processor doing general work beside a cryptographic core doing the part that needs to be fast and protected.

  • Architecture

    RISC-V

    Secure enclaves, sovereign silicon, and next-generation defense microelectronics

    Attachment
    Accelerators over AXI or APB
    Boot
    Secure Boot ROM integration
    Extensions
    Custom cryptographic instructions, optional
    Scaling
    Lightweight MCU up to secure SoC
  • Architecture

    ARM

    Embedded and high-performance systems migrating to post-quantum

    Cortex-M
    Secure firmware acceleration
    Cortex-A
    High-performance deployments
    TrustZone
    Secure world integration
    Keys
    Hardware-backed provisioning
Illustration of a general-purpose MCU beside a RISC-V device carrying a coprocessor and a PQSecure cryptographic core, connected by a bidirectional link
The general-purpose processor and the cryptographic core, designed as one system.

From first instruction to stored key

A typical co-designed root of trust, in the order a boot actually traverses it. The accelerator tier is chosen per design, using the same four profiles the hardware IP offers.

  1. Processor RISC-V or ARM application core
  2. Secure Boot ROM Immutable first-stage verification
  3. PQC hardware accelerator Tiny, Compact, Balanced, or High-Performance tier
  4. libpqsecure firmware stack The C and Rust libraries, in firmware
  5. Secure key storage and TRNG CAVP-validated RBG for key generation and reseeding

Entropy from source to key

Randomness is part of the security boundary. PQSecure’s hardware RBG brings the entropy source, standards-based conditioning, deterministic generation, and software interface into one validated path.

TRNG and RNG architecture

Source, conditioning, and use

TRNG and conditioning

The hardware TRNG captures physical noise inside the trust boundary, then applies an AES-CBC-MAC conditioning component validated to NIST SP 800-90B.

Deterministic generation

Conditioned entropy feeds a CTR-DRBG using AES-256, validated to NIST SP 800-90A, for controlled high-rate random-bit generation.

Validated hardware implementation

PQSecure Hardware RBG Core version 1.0 is validated under CAVP certificate A8932 on the AMD Artix-7 XC7A100T operating environment.

Hardware/software boundary

The interface defines how entropy is requested, reseeded, monitored, and isolated across the processor, secure boot firmware, key storage, and PQC accelerator.

Certification

National Institute of Standards and Technology A8932 Cryptographic Algorithm Validation Program

A validated random-bit generation path combining hardware entropy, SP 800-90B conditioning, and an SP 800-90A deterministic random bit generator.

Validated
  • AES-CBC-MAC conditioning SP 800-90B
  • CTR-DRBG AES-256 SP 800-90A
Vendor
PQSecure Technologies
View the record on NIST CSRC ↗

Validated for the AMD Artix-7 XC7A100T operating environment. First validated September 4, 2026.

NIST Cryptographic Algorithm Validation Program record for PQSecure Hardware RBG Core A8932

Protected in silicon, proven in software, checked by others

An architecture is only as sound as its weakest layer, so hardening, verification, and independent evaluation each cover a different one.

Security and assurance

Layer and measure

  • Hardware

    The accelerator and the silicon around it

    Protections

    • Side-channel-hardened accelerators
    • Masking and leakage protections
    • Fault injection mitigation
    • CAVP A8932 hardware random-bit generation
  • Software

    The firmware stack running on the core

    Protections

    • Formally verified C and Rust implementations
    • Constant-time enforcement
    • Secure update workflows
    See the software stack →
  • Independent evaluation

    Assessment by someone other than the designer

    Assessed by

    • Third-party security testing
    • Keysight DPA and CPA assessment
    • Robustness under adversarial conditions
    Hardware evaluation detail →

Where it goes

Built for programs where the silicon ships once and has to stay defensible for the whole of its service life. What ships is more than cryptographic IP: it is a migration-ready architecture.

Engineered for

  • Defense and aerospace
  • Secure boot and Root-of-Trust
  • RISC-V and ARM SoCs
  • Long-lifecycle infrastructure
  • Supply-chain-assured silicon

We combine

  • Crypto agility engineered at design time
  • OTA-ready modernization
  • RISC-V and ARM integration
  • Complete PQC coverage
  • Side-channel protected hardware
  • Formally verified software

so that today’s silicon stays secure in tomorrow’s quantum world.

Architectures that can outlive their algorithms.

Talk with our team about integrating hardware acceleration and a verified software stack into your SoC.

Contact us