Open Access
Review
Issue
Security and Safety
Volume 5, 2026
Article Number 2026001
Number of page(s) 54
Section Integrated Circuit
DOI https://doi.org/10.1051/sands/2026001
Published online 20 January 2026
  1. Kim Y, Eddins A, Anand S, et al. Evidence for the utility of quantum computin before fault tolerance. Nature 2023; 618: 500–505. [Google Scholar]
  2. Kam JF, Kang H, Hill CD, et al. Characterization of entanglement on superconducting quantum computers of up to 414 qubits. Phys Rev Res 2024; 6: 033155. [Google Scholar]
  3. Rivest RL, Shamir A and Adleman L. A method for obtaining digital signatures and public-key cryptosystems. Commun ACM 1978; 21: 120–126. [CrossRef] [Google Scholar]
  4. Rahman H and Azad S. Elliptic curve cryptography. Pract Cryptogr 2014; 147. https://csrc.nist.gov/Projects/Elliptic-Curve-Cryptography. [Google Scholar]
  5. Shor PW. Algorithms for quantum computation: Discrete logarithms and factoring. In: Proceedings 35th Annual Symposium on Foundations of Computer Science, 1994, 124–134. [Google Scholar]
  6. Mascelli J and Rodden M. Harvest now decrypt later: Examining post-quantum cryptography and the data privacy risks for distributed ledger networks. Financ Econ Discuss Ser 2025-09, 2025. https://doi.org/10.17016/FEDS.2025.093. [Google Scholar]
  7. Regev, O. (2024). On Lattices, Learning with Errors, Random Linear Codes, and Cryptography. https://arxiv.org/abs/2401.03703. [Google Scholar]
  8. Banerjee A, Peikert C and Rosen A. Pseudorandom functions and lattices. In: Advances in Cryptology – EUROCRYPT 2012. Berlin, Heidelberg: Springer, 2012, 719–737. [Google Scholar]
  9. Alekhnovich M. More on average case vs. approximation complexity. IEEE, 2003, 298–307. [Google Scholar]
  10. Ajtai M. Generating hard instances of lattice problems (extended abstract). In: Proceedings of the Twenty-Eighth Annual ACM Symposium on Theory of Computing, STOC ’96. New York, NY, USA: Association for Computing Machinery, 1996, 99–108. [Google Scholar]
  11. Boudgoust K, Jeudy C, Roux-Langlois A, et al. Towards classical hardness of module-LWE: The linear rank case. In Advances in Cryptology – ASIACRYPT 2020. Cham: Springer International Publishing, 2020, 289–317. [Google Scholar]
  12. Lyubashevsky V, Peikert C and Regev O. On ideal lattices and learning with errors over rings. In: Gilbert H, editor, Advances in Cryptology – EUROCRYPT 2010. Berlin, Heidelberg: Springer, 2010, 1–23. [Google Scholar]
  13. Alagic G, Cooper D, Dang Q, et al. Status report on the third round of the NIST post-quantum cryptography standardization process, 2022. [Google Scholar]
  14. Avanzi R, Bos J, Ducas L, et al. CRYSTALS-Kyber algorithm specifications and supporting documentation (version 3.02). US Department of Commerce, NIST, 2017. [Google Scholar]
  15. Bai S, Ducas L, Kiltz E, et al. CRYSTALS-Dilithium algorithm specifications and supporting documentation (Version 3.1). US Department of Commerce, NIST, 2021. [Google Scholar]
  16. Weger V, Gassner N and Rosenthal J. A survey on code-based cryptography. arXiv preprint arXiv: https://arxiv.org/abs/2201.07119, 2022. [Google Scholar]
  17. Aumasson J-P, Bernstein DJ, Beullens W, et al. SPHINCS+ submission to the NIST post-quantum project, v.3. US Department of Commerce, NIST, 2020. [Google Scholar]
  18. Joseph D, Misoczki R, Manzano M, et al. Transitioning organizations to post-quantum cryptography. Nature 2022; 605: 237–243. [Google Scholar]
  19. Vermeer MJD and Peet ED. Securing Communications in the Quantum Computing Age: Managing the Risks to Encryption. Santa Monica, CA: RAND Corporation, 2020. [Google Scholar]
  20. Alagic G, Alperin-Sheriff J and Apon D. Status report on the first round of the NIST post-quantum cryptography standardization process, 2019. [Google Scholar]
  21. Fouque P-A, Hoffstein J, Kirchner P, et al. Falcon: Fast-Fourier lattice-based compact signatures over NTRU specification v1.2 – 01/10/2020. US Department of Commerce, NIST, 2020. [Google Scholar]
  22. National Institute of Standards and Technology (NIST). FIPS 203: Module-lattice-based key-encapsulation mechanism standard. U.S. Department of Commerce, 2024. https://csrc.nist.gov/pubs/fips/203/final. [Google Scholar]
  23. National Institute of Standards and Technology (NIST). FIPS 204: Module-lattice-based digital signature standard. U.S. Department of Commerce, 2024. https://csrc.nist.gov/pubs/fips/204/final. [Google Scholar]
  24. National Institute of Standards and Technology (NIST). FIPS 205: Stateless hash-based digital signature standard. U.S. Department of Commerce, 2024. https://csrc.nist.gov/pubs/fips/205/final. [Google Scholar]
  25. Melchor CA, Aragon N, Bettaieb S, et al. Hamming Quasi-Cyclic (HQC) fourth round version. US Department of Commerce, NIST, 2024. [Google Scholar]
  26. ISO/IEC. Information security – Digital signatures with appendix – Part 4: Stateful hash-based mechanisms: ISO/IEC FDIS 14888-4. International Organization for Standardization, 2023. https://www.iso.org/standard/80492.html. [Google Scholar]
  27. Buchmann J, Dahmen E and Hülsing A. XMSS-a practical forward secure signature scheme based on minimal security assumptions. Springer, 2011, 117–129. [Google Scholar]
  28. Cooper D, Apon D, Dang Q, et al. Recommendation for stateful hash-based signature schemes: 800-208. National Institute of Standards and Technology, 2020. [Google Scholar]
  29. Bernstein DJ, Chou T, Cid C, et al. Classic McEliece: Conservative code-based cryptography cryptosystem specification. US Department of Commerce, NIST, 2022. https://classic.mceliece.org/nist/mceliece-20201010.Pdf. [Google Scholar]
  30. Bos J, Costello C, Ducas L, et al. Frodo: Take off the ring! Practical, Quantum-Secure Key Exchange from LWE[EB/OL]. Cryptology ePrint Archive, Paper 2016/659, 2016. https://doi.org/10.1145/2976749.2978425. [Google Scholar]
  31. Zhu Y, Zhu W, Li C, et al. RePQC: A 3.4-μJ/Op 48-kOPS post-quantum crypto-processor for multiple-mathematical problems. IEEE J Solid-State Circuits 2022; 58: 124–140. [Google Scholar]
  32. Schöffel M, Feldmann J, Wehn N. Code-based Cryptography in IoT: A HW/SW Co-Design of HQC, in: 2022 IEEE 8th World Forum on Internet of Things (WF-IoT), Yokohama, Japan, 2022, pp. 1–7, https://doi.org/10.1109/WF-IoT54382.2022.10152031. [Google Scholar]
  33. Tian Q, Cheng H, Guo C, et al. A code-based ISE to protect Boolean masking in software. IACR Trans Cryptogr Hardw Embed Syst, 2025. [Google Scholar]
  34. Wang T, Zhang C, Zhang X, et al. Optimized hardware-software co-design for Kyber and Dilithium on RISC-V SoC FPGA. IACR Trans Cryptogr Hardw Embed Syst 2024; 2024: 99–135. [Google Scholar]
  35. Abdulrahman A, Kannwischer MJ and Lim T-H. Enabling microarchitectural agility: Taking ML-KEM & ML-DSA from Cortex-M4 to M7 with SLOTHY. In: ACM AsiaCCS 2025, 2025. [Google Scholar]
  36. Mera JMB, Turan F, Karmakar A, et al. Compact domain-specific co-processor for accelerating module lattice-based KEM. In: 2020 57th ACM/IEEE Design Automation Conference (DAC), 2020, 1–6. [Google Scholar]
  37. Wang W, Szefer J and Niederhagen R. Solving large systems of linear equations over GF(2) on FPGAs. In: 2016 International Conference on ReConFigurable Computing and FPGAs (ReConFig), 2016, 1–7. [Google Scholar]
  38. Chen P-J, Chou T, Deshpande S, et al. Complete and improved FPGA implementation of classic McEliece. Cryptology ePrint Arch 2022. [Google Scholar]
  39. Roy SS, Vercauteren F, Mentens N, et al. Compact Ring-LWE cryptoprocessor. In: Batina L and Robshaw M, editors, Cryptographic Hardware and Embedded Systems – CHES 2014. Berlin, Heidelberg: Springer, 2014, 371–391. [Google Scholar]
  40. Howe J, Oder T, Krausz M, et al. Standard lattice-based key encapsulation on embedded devices. IACR Trans Cryptogr Hardw Embed Syst 2018; 2018: 372–393. [Google Scholar]
  41. Du C and Bai G. Towards efficient polynomial multiplication for lattice-based cryptography. In: 2016 IEEE International Symposium on Circuits and Systems (ISCAS), 2016, 1178–1181. [Google Scholar]
  42. Fritzmann T, Sharif U, Müller-Gritschneder D, et al. Towards reliable and secure post-quantum co-processors based on RISC-V. In: 2019 Design, Automation Test in Europe Conference Exhibition (DATE), 2019, 1148–1153. [Google Scholar]
  43. Song S, Tang W, Chen T, et al. LEIA: A 2.05 mm2 140mW lattice encryption instruction accelerator in 40nm CMOS. In: 2018 IEEE Custom Integrated Circuits Conference (CICC). IEEE, 2018, 1–4. [Google Scholar]
  44. Banerjee U, Juvekar C, Wright A, et al. An energy-efficient reconfigurable DTLS cryptographic engine for end-to-end security in IoT applications. In: 2018 IEEE International Solid-State Circuits Conference-(ISSCC). IEEE, 2018, 42–44. [Google Scholar]
  45. Hutter M, Schilling J, Schwabe P, et al. NaCl’s crypto box in hardware, 2016. [Google Scholar]
  46. Basu K, Soni D, Nabeel M, et al. NIST post-quantum cryptography-A hardware evaluation study. IACR Cryptol ePrint Arch 2019; 2019: 47. [Google Scholar]
  47. Fritzmann T and Sepúlveda J. Efficient and flexible low-power NTT for lattice-based cryptography. In: 2019 IEEE International Symposium on Hardware Oriented Security and Trust (HOST), 2019. [Google Scholar]
  48. Nejatollahi H, Dutt ND, Banerjee I, et al. Domain-specific accelerators for ideal lattice-based public key protocols. IACR Cryptol ePrint Arch 2018; 2018: 608. [Google Scholar]
  49. Farahmand F. Implementing and benchmarking seven Round 2 lattice-based key encapsulation mechanisms using a software/hardware codesign approach, 2019. [Google Scholar]
  50. Zhu Y, Zhu W, Ouyang Y, et al. A 28nm 69.4kOPS 4.4μJ/Op versatile post-quantum crypto-processor across multiple mathematical problems. In: 2024 IEEE International Solid-State Circuits Conference (ISSCC), Vol. 67, 2024, 298–300. [Google Scholar]
  51. Zhu Y, Zhu W, Ouyang Y, et al. PQPU: A 4.4-μJ/Op 69.4-kOPS agile post-quantum crypto-processor across multiple mathematical problems. IEEE J Solid-State Circuits 2025; 60: 2261–2275. [Google Scholar]
  52. ElGhamrawy M, Azouaoui M, Bronchain O, et al. From MLWE to RLWE: A differential fault attack on randomized & deterministic dilithium. IACR Trans Cryptogr Hardw Embed Syst 2023; 2023: 565–594. [Google Scholar]
  53. Berzati A, Calle Viera A, Chartouny M, et al. Exploiting Intermediate Value Leakage in Dilithium: A Template-Based Approach[EB/OL]. Cryptology ePrint Archive, Paper 2023/050, 2023. https://eprint.iacr.org/2023/050. [Google Scholar]
  54. Dong H and Guo Q. Multi-value plaintext-checking and full-decryption oracle-based attacks on HQC from offline templates. IACR Trans Cryptogr Hardw Embed Syst 2025. https://ches.iacr.org/2025/acceptedpapers.php. [Google Scholar]
  55. Uhle F, Müller N and Moradi A. Fault injection evaluation with statistical analysis – How to deal with nearly fabricated large circuits. IACR Trans Cryptogr Hardw Embed Syst, 2025. https://ches.iacr.org/2025/acceptedpapers.php. [Google Scholar]
  56. D’Anvers J-P, Karmakar A, Roy SS, et al. Saber: Module-LWR based key exchange, CPA-secure encryption and CCA-secure KEM. In: Progress in Cryptology – AFRICACRYPT 2018. Springer, 2018, 282–305. [Google Scholar]
  57. D’Anvers J-P, Vercauteren F and Verbauwhede I. The impact of error dependencies on Ring/Mod-LWE/LWR based schemes. IACR Cryptol ePrint Arch 2018, Report 2018/1172. [Google Scholar]
  58. McEliece RJ. A public-key cryptosystem based on algebraic coding theory. Deep Space Netw Prog Rep 1978; 44: 114–116. [Google Scholar]
  59. Aragon N. BIKE:BIKE_Spec. US Department of Commerce, NIST, 2022. https://bikesuite.org/ [Google Scholar]
  60. Merkle RC. A digital signature based on a conventional encryption function. In: Advances in Cryptology – CRYPTO ’87. Lecture Notes in Computer Science, Vol. 293. Springer, 1987, 369–378. [Google Scholar]
  61. Huelsing A, Butin D, Gazdag S, et al. XMSS: EXtended Merkle signature scheme. RFC Editor, 2018. [Google Scholar]
  62. Liu G, Liu G, Jiang K, et al. Improving MPCitH with preprocessing: Mask is all you need. IACR Trans Cryptogr Hardw Embed Syst, 2025. https://ches.iacr.org/2025/acceptedpapers.php. [Google Scholar]
  63. Chen M-S, Petzoldt A, Schmidt D, et al. Rainbow-Round 2. US Department of Commerce, NIST, 2019. https://csrc.nist.gov/CSRC/media/Presentations/rainbow-round-2-presentation/images-media/rainbow-ding.pdf [Google Scholar]
  64. Ding J and Schmidt D. Rainbow, a new multivariable polynomial signature scheme. In: Applied Cryptography and Network Security (ACNS 2005). Lecture Notes in Computer Science, Vol. 3531. Springer, 2005, 164–175. [Google Scholar]
  65. Kipnis A, Patarin J and Goubin L. Unbalanced oil and vinegar signature schemes. In: Advances in Cryptology – EUROCRYPT ’99. Lecture Notes in Computer Science, Vol. 1592. Springer, 1999, 206–222. [Google Scholar]
  66. Jao D and De Feo L. Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies. In: Proceedings of the 4th International Conference on Post-Quantum Cryptography (PQCrypto 2011). Springer, 2011, 19–34. [Google Scholar]
  67. Jao D, Azarderakhsh R, De Feo L, et al. Supersingular isogeny key encapsulation. In: Submission to the NIST Post-Quantum Cryptography Standardization Project, 2017. [Google Scholar]
  68. Jao D, Azarderakhsh R and Campagna M. SIKE: Supersingular isogeny key encapsulation Round 3. US Department of Commerce, NIST, 2020. https://csrc.nist.gov/csrc/media/Projects/post-quantum-cryptography/documents/round-4/submissions/SIKE-spec.pdf [Google Scholar]
  69. De Feo L, Kohel DR, Leroux A, et al. SQISign: Compact post-quantum signatures from quaternions and isogenies. In: Advances in Cryptology–ASIACRYPT 2020. Springer, 2020, 64–93. [Google Scholar]
  70. Castryck W and Decru T. An efficient key recovery attack on SIDH. In: Hazay C and Stam M, editors. Cham, 2023, 423–447. [Google Scholar]
  71. Castryck W, Lange T, Martindale C, et al. CSIDH: An efficient post-quantum commutative group action. In: Galbraith S and Peyrin T, editors, Advances in Cryptology – ASIACRYPT 2018. Cham: Springer International Publishing, 2018, 395–427. [Google Scholar]
  72. Bruun NM. Z-transform DFT filters and FFT’s. IEEE Trans Acoust Speech Signal Process 1978; 26: 56–63. [Google Scholar]
  73. Karatsuba, A.A., & Ofman, Y. Multiplication of Multidigit Numbers on Automata. Soviet physics. Doklady, 1963; 7: 595–596. [Google Scholar]
  74. Sikeridis D, Kampanakis P and Devetsikiotis M. Assessing the overhead of post-quantum cryptography in TLS 1.3 and SSH. In: Proceedings of the 16th International Conference on Emerging Networking EXperiments and Technologies (CoNEXT ’20). ACM, 2020, 149–156. [Google Scholar]
  75. Sikeridis D, Kampanakis P and Devetsikiotis M. Post-quantum authentication in TLS 1.3: A performance study. In: NDSS Symposium 2020, 2020. [Google Scholar]
  76. Kampanakis P and Childs-Klein W. The impact of data-heavy, post-quantum TLS 1.3 on the Time-To-Last-Byte of real-world connections. In: Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb) 2024, 2024. [Google Scholar]
  77. Sosnowski M, Wiedner F, Hauser E, et al. The performance of post-quantum TLS 1.3. In: Companion of the 19th International Conference on Emerging Networking EXperiments and Technologies (CoNEXT Companion) 2023, 2023. [Google Scholar]
  78. Campbell D, Rafferty C, Khalid A, et al. Acceleration of post quantum digital signature scheme crystals-dilithium on reconfigurable hardware. In: 2022 32nd International Conference on Field-Programmable Logic and Applications (FPL), 2022, 462–463. [Google Scholar]
  79. Malal A. Designing efficient and flexible NTT accelerators, 2023. https://eprint.iacr.org/2023/1617. [Google Scholar]
  80. Longa, P., Naehrig, M. (2016). Speeding up the Number Theoretic Transform for Faster Ideal Lattice-Based Cryptography. In: Foresti, S., Persiano, G. (eds) Cryptology and Network Security. CANS 2016. Lecture Notes in Computer Science, vol 10052. Springer, Cham. https://doi.org/10.1007/978-3-319-48965-0_8. [Google Scholar]
  81. Maeder RE. Storage allocation for the Karatsuba integer multiplication algorithm. In: Miola A, editor, Design and Implementation of Symbolic Computation Systems. Berlin, Heidelberg: Springer, 1993, 59–65. [Google Scholar]
  82. Wu Y, Bai G and Wu X. A Karatsuba algorithm based accelerator for pairing computation. In: 2019 IEEE International Conference on Electron Devices and Solid-State Circuits (EDSSC), 2019, 1–3. [Google Scholar]
  83. Pöppelmann T, Oder T, Güneysu T. High-performance ideal lattice-based cryptography on 8-Bit ATxmega microcontrollers. In: Lauter K and Rodríguez-Henríquez F, editors, Progress in Cryptology – LATINCRYPT 2015. Cham: Springer International Publishing, 2015, 346–365. [Google Scholar]
  84. Zhang N, Yang B, Chen C, et al. Highly efficient architecture of NewHope-NIST on FPGA using low-complexity NTT/INTT. IACR Trans Cryptogr Hardw Embed Syst 2020; 2020: 49–72. [Google Scholar]
  85. Zhu Y, Zhu W, Zhu M, et al. A 28nm 48KOPS 3.4μJ/Op agile crypto-processor for post-quantum cryptography on multi-mathematical problems. In: 2022 IEEE International Solid-State Circuits Conference (ISSCC), Vol. 65, 2022, 514–516. [Google Scholar]
  86. Li A, Lu J, Liu D, et al. A 40nm 2.76 μ J/O p energy-efficient secure post-quantum crypto-processor for Crystals-Kyber on module-LWE. In: 2023 IEEE Asian Solid-State Circuits Conference (A-SSCC), 2023, 1–3. [Google Scholar]
  87. Jung H, Dang Truong Q and Lee H. Highly-efficient hardware architecture for ML-KEM PQC standard. IEEE Open J Circuits Syst 2025; 6: 356–369. [Google Scholar]
  88. Zhu Y, Wang H, Zhu W, et al. High-speed hardware implementation of NTT/INTT-optimized LAC cryptosystem. Microelectron Comput 2025; 42: 187–195. [Google Scholar]
  89. Banerjee U, Pathak A and Chandrakasan AP. 2.3 an energy-efficient configurable lattice cryptography processor for the quantum-secure Internet of Things. In: 2019 IEEE International Solid-State Circuits Conference – (ISSCC), 2019, 46–48. [Google Scholar]
  90. Xin G, Han J, Yin T, et al. VPQC: A domain-specific vector processor for post-quantum cryptography based on RISC-V architecture. IEEE Trans Circuits Syst I: Regul Pap 2020; 67: 2672–2684. [Google Scholar]
  91. Zhao C, Zhang N, Wang H, et al. A compact and high-performance hardware architecture for CRYSTALS-Dilithium. IACR Trans Cryptogr Hardw Embed Syst 2021; 2022: 270–295. [Google Scholar]
  92. Ouyang Y, Zhu Y, Zhu W, et al. FalconSign: An efficient and high-throughput hardware architecture for Falcon signature generation. IACR Trans Cryptogr Hardw Embed Syst 2024; 2025: 203–226. [Google Scholar]
  93. Banerjee U, Ukyab TS and Chandrakasan AP. Sapphire: A configurable crypto-processor for post-quantum lattice-based protocols. IACR Trans Cryptogr Hardw Embed Syst 2019; 2019: 17–61. [Google Scholar]
  94. Zhu Y, Zhu M, Yang B, et al. LWRpro: An energy-efficient configurable crypto-processor for module-LWR. IEEE Trans Circuits Syst I: Regul Pap 2021; 68: 1146–1159. [Google Scholar]
  95. Hülsing A, Rijneveld J, Schanck J, et al. High-speed key encapsulation from NTRU. In: Fischer W and Homma N, editors. Cham: Springer International Publishing, 2017, 232–252. [Google Scholar]
  96. Ghosh A, Mera JMB, Karmakar A, et al. A 334 μW 0.158 mm2 ASIC for post-quantum key-encapsulation mechanism Saber with low-latency striding Toom–Cook multiplication. IEEE J Solid-State Circuits 2023; 58: 2383–2398. [Google Scholar]
  97. Wong Z-Y, Wong DC-K, Lee W-K, et al. KaratSaber: New speed records for Saber polynomial multiplication using efficient Karatsuba FPGA architecture. IEEE Trans Comput 2023; 72: 1830–1842. [Google Scholar]
  98. Deshpande S, Xu C, Nawan M, et al. Fast and efficient hardware implementation of HQC, 2022. https://eprint.iacr.org/2022/1183. [Google Scholar]
  99. Antognazza F, Barenghi A and Pelosi G. An efficient and unified RTL accelerator design for HQC-128, HQC-192, and HQC-256. IEEE Trans Comput 2025. [Google Scholar]
  100. Ras A, Loiseau A, Carmona M, et al. PHOENIX: Crypto-agile hardware sharing for ML-KEM and HQC. In: SecuElec Seminar/Cryptology ePrint Archive (presented May 2025), 2025. [Google Scholar]
  101. Antognazza F, Barenghi A, Pelosi G, et al. A high efficiency hardware design for the post-quantum KEM HQC. In: IEEE Symposium on Hardware Oriented Security and Trust (HOST) 2024, 2024. [Google Scholar]
  102. Antognazza F, Barenghi A, Pelosi G, et al. A versatile and unified HQC hardware accelerator. In: Applied Cryptography and Network Security Workshops (ACNS Workshops).Lecture Notes in Computer Science, Vol. 14587. Springer, 2024, 214–219. [Google Scholar]
  103. Galimberti A, Goli A, Sforza M, et al. FPGA-based design and implementation of a code-based post-quantum KEM. In: Applied Cryptography and Network Security Workshops (ACNS Workshops). Lecture Notes in Computer Science, Vol. 14587. Springer, 2024, 38–46. [Google Scholar]
  104. Reinders A H, Misoczki R, Ghosh S, et al. Efficient BIKE Hardware Design with Constant-Time Decoder[C]//2020 IEEE International Conference on Quantum Computing and Engineering (QCE). [S.l.]: IEEE, 2020: 197–204. https://doi.org/10.1109/QCE49297.2020.00033. [Google Scholar]
  105. Montanaro G., Galimberti A., Colizzi E. and Zoni D., “Hardware-Software Co-Design of BIKE with HLS-Generated Accelerators,” 2022 29th IEEE International Conference on Electronics, Circuits and Systems (ICECS), Glasgow, United Kingdom, 2022, pp. 1–4, https://doi.org/10.1109/ICECS202256217.2022.9970992 [Google Scholar]
  106. Bernstein DJ, Chou T and Schwabe P. McBits: Fast constant-time code-based cryptography. In: Bertoni G and Coron J-S, editors, Cryptographic Hardware and Embedded Systems – CHES 2013. Berlin, Heidelberg: Springer, 2013, 250–272. [Google Scholar]
  107. Chou T. Mcbits revisited. In: Fischer W and Homma N, editors, Cryptographic Hardware and Embedded Systems – CHES 2017. Cham: Springer International Publishing, 2017, 213–231. [Google Scholar]
  108. Dang VB, Mohajerani K and Gaj K. High-speed hardware architectures and FPGA benchmarking of CRYSTALS-Kyber, NTRU, and Saber. IEEE Trans Comput 2023; 72: 306–320. [Google Scholar]
  109. Silverman JH. Almost inverses and fast NTRU key creation, 1999. [Google Scholar]
  110. Bernstein DJ and Yang B-Y. Fast constant-time GCD computation and modular inversion. IACR Trans Cryptogr Hardw Embed Syst 2019; 2019: 340–398. [Google Scholar]
  111. Sreedhar K, Nyengele G, Horowitz M, et al. A 3.25 GHz large-integer extended GCD accelerator in 12 nm. In: 2024 IEEE European Solid-State Electronics Research Conference (ESSERC), 2024, 476–479. [Google Scholar]
  112. Sreedhar K, Horowitz M and Torng C. A fast large-integer extended GCD algorithm and hardware design for verifiable delay functions and modular inversion, 2021. https://eprint.iacr.org/2021/1292. DOI: https://doi.org/10.46586/tches.v2022.i4.163-187. [Google Scholar]
  113. Chen M-S and Chou T. Classic McEliece on the ARM Cortex-M4, 2021. https://eprint.iacr.org/2021/492. [Google Scholar]
  114. Roth J, Karatsiolis E and Krämer J. Classic McEliece implementation with low memory footprint. In: Liardet P-Y and Mentens N, editors, Smart Card Research and Advanced Applications. Cham: Springer International Publishing, 2021, 34–49. [Google Scholar]
  115. Zhu Y, Zhu W, Chen C, et al. Mckeycutter: A high-throughput key generator of classic McEliece on hardware. In: 2023 60th ACM/IEEE Design Automation Conference (DAC), 2023, 1–6. [Google Scholar]
  116. Wang W, Szefer J and Niederhagen R. FPGA-based key generator for the Niederreiter cryptosystem using binary Goppa codes. In: Cryptographic Hardware and Embedded Systems (CHES). Springer International Publishing, 2017, 253–274. [Google Scholar]
  117. Zhang H, Qiao X, Tian J, et al. Fast hardware architecture with efficient matrix computations for the key generation of classic McEliece. IEEE Trans Circuits Syst I: Regul Pap 2025; 72: 1321–1331. [Google Scholar]
  118. Richter-Brockmann J, Mono J and Güneysu T. Folding BIKE: Scalable hardware implementation for reconfigurable devices. IEEE Trans Comput 2022; 71: 1204–1215. [Google Scholar]
  119. Richter-Brockmann J, Chen M-S, Ghosh S, et al. Racing BIKE: Improved polynomial multiplication and inversion in hardware, 2021. [Google Scholar]
  120. Bernstein DJ, Hopwood D, Hülsing A, et al. SPHINCS: Practical stateless hash-based signatures. Springer, 2015, 368–397. [Google Scholar]
  121. Bernstein DJ, Hülsing A, Kölbl S, et al. The SPHINCS+ signature framework, 2019, 2129–2146. [Google Scholar]
  122. Zhang K, Cui H and Yu Y. SPHINCS-α: A compact stateless hash-based signature scheme. Cryptol ePrint Arch 2022. [Google Scholar]
  123. Amiet D, Curiger A and Zbinden P. FPGA-based accelerator for post-quantum signature scheme SPHINCS-256. IACR Trans Cryptogr Hardw Embed Syst 2018; 2018: 18–39. [Google Scholar]
  124. Berthet Q, Upegui A, Gantel L, et al. An area-efficient SPHINCS+ post-quantum signature coprocessor. In: 2021 IEEE International Parallel and Distributed Processing Symposium Workshops (IPDPSW), 2021, 180–187. [Google Scholar]
  125. Amiet D, Leuenberger L, Curiger A, et al. FPGA-based SPHINCS+ implementations: Mind the glitch. In: 2020 23rd Euromicro Conference on Digital System Design (DSD), 2020, 229–237. [Google Scholar]
  126. Mohan P, Wang W, Jungk B, et al. ASIC accelerator in 28 nm for the post-quantum digital signature scheme XMSS. In: 2020 IEEE 38th International Conference on Computer Design (ICCD), 2020, 656–662. [Google Scholar]
  127. Tang S, Yi H, Ding J, et al. High-speed hardware implementation of rainbow signature on FPGAs. In: Proceedings of the 4th International Conference on Post-Quantum Cryptography, PQCrypto’11. Berlin, Heidelberg: Springer-Verlag, 2011, 228–243. [Google Scholar]
  128. Ferozpuri A and Gaj K. High-speed FPGA implementation of the NIST Round 1 rainbow signature scheme. In: 2018 International Conference on ReConFigurable Computing and FPGAs (ReConFig), 2018, 1–8. [Google Scholar]
  129. Balasubramanian S, Bogdanov A, Rupp A, et al. Fast multivariate signature generation in hardware: The case of rainbow. In: 2008 16th International Symposium on Field-Programmable Custom Computing Machines, 2008, 281–282. [Google Scholar]
  130. Yeh L-Y, Chen P-J, Pai C-C, et al. An energy-efficient dual-field elliptic curve cryptography processor for Internet of Things applications. IEEE Trans Circuits Syst II: Express Briefs 2020; 67: 1614–1618. [Google Scholar]
  131. Lee C-Y, Horng J-S, Jou I-C, et al. Low-complexity bit-parallel systolic Montgomery multipliers for special classes of GF(2m). IEEE Trans Comput 2005; 54: 1061–1070. [Google Scholar]
  132. Meher PK. Systolic and super-systolic multipliers for finite field GF(2m) based on irreducible trinomials. IEEE Trans Circuits Syst I: Regul Pap 2008; 55: 1031–1040. [Google Scholar]
  133. Xie J, Jun He J and Meher PK. Low latency systolic Montgomery multiplier for finite field GF(2m) based on pentanomials. IEEE Trans Very Large Scale Integr (VLSI) Syst 2012; 21: 385–389. [Google Scholar]
  134. Xie J, Meher PK and Mao Z-H. Low-latency high-throughput systolic multipliers over GF(2m) for NIST recommended pentanomials. IEEE Trans Circuits Syst I: Regul Pap 2015; 62: 881–890. [Google Scholar]
  135. Bagheri S, Kaveh M, Hernando-Gallego F, et al. A constant-time hardware architecture for the CSIDH key-exchange protocol. arXiv preprint arXiv: https://arxiv.org/abs/2508.11082, 2025. [Google Scholar]
  136. Su G and Bai G. Towards high-performance supersingular isogeny cryptographic hardware accelerator design. Electronics 2023; 12. [Google Scholar]
  137. Elkhatib R, Koziel B, Azarderakhsh R, et al. Cryptographic engineering a fast and efficient SIKE in FPGA. ACM Trans Embed Comput Syst (TECS) 2024; 23: 1–25. [Google Scholar]
  138. Koziel B, Azarderakhsh R and Kermani MM. Fast hardware architectures for supersingular isogeny Diffie-Hellman key exchange on FPGA, 2016. https://eprint.iacr.org/2016/1044. [Google Scholar]
  139. Khadra SA, Ismail NA, Attiya GM, et al. Accelerating supersingular isogeny Diffie-Hellman (SIDH) cryptosystem for the security of resource-constrained IoT devices with FPGA. In: 2023 3rd International Conference on Electronic Engineering (ICEEM), 2023, 1–7. [Google Scholar]
  140. Elkhatib R, Azarderakhsh R and Mozaffari-Kermani M. High-performance FPGA accelerator for SIKE. IEEE Trans Comput 2022; 71: 1237–1248. [Google Scholar]
  141. Fritzmann T, Sigl G and Sepúlveda MJ. RISQ-V: Tightly coupled RISC-V accelerators for post-quantum cryptography. IACR Cryptol ePrint Arch 2020; 2020: 446. [Google Scholar]
  142. Wan L, Zheng F, Fan G, et al. A novel high-performance implementation of CRYSTALS-Kyber with AI accelerator. In: Atluri V, Di Pietro R, Jensen CD, et al., editors, Computer Security – ESORICS 2022. Cham: Springer Nature Switzerland, 2022, 514–534. [Google Scholar]
  143. Lee W-K, Seo H, Zhang Z, et al. TensorCrypto: High throughput acceleration of lattice-based cryptography using tensor core on GPU. IEEE Access 2022; 10: 20616–20632. [Google Scholar]
  144. Nguyen H, Cambou B and Nguyen TT. A GPU-accelerated high-performance design for crystals-dilithium digital signature. In: 2025 IEEE International Conference on Consumer Electronics (ICCE), 2025, 1–4. [Google Scholar]
  145. Dong J, Fu Y, Qin X, et al. Eco-bike: Bridging the gap between PQC bike and GPU acceleration. IEEE Trans Inf Forensics Secur 2024; 19: 8952–8965. [Google Scholar]
  146. Li W, Wei H, Ying Shen S, et al. cuFalcon: An adaptive parallel GPU implementation for high-performance Falcon acceleration. IACR Cryptol ePrint Arch 2025; 2025: 249. [Google Scholar]
  147. Dai R, Dong J, Qiu M, et al. Golf: Unleashing GPU-driven acceleration for falcon post-quantum cryptography. IEEE Trans Inf Forensics Secur 2025; 20: 9441–9453. [Google Scholar]
  148. Soni D, Basu K, Nabeel M, et al. A hardware evaluation study of NIST post-quantum cryptographic signature schemes on FPGA. In: Second PQC Standardization Conference, 2020. [Google Scholar]
  149. Kieu-Do-Nguyen B, The Binh N, Pham-Quoc C, et al. Compact and low-latency FPGA-based number theoretic transform architecture for CRYSTALS Kyber postquantum cryptography scheme. Information 2024; 15. [Google Scholar]
  150. Xilinx Inc. 7 Series FPGAs Overview (DS180), 2020. https://docs.xilinx.com/v/u/en-US/ds180_7Series_Overview. [Google Scholar]
  151. Xilinx Inc. Vitis Unified Software Platform Documentation: Application Acceleration Development. AMD Xilinx, 2023. https://docs.xilinx.com/r/en-US/ug1393-vitis-application-acceleration. [Google Scholar]
  152. Intel Corporation. Intel Quartus Prime Design Software User Guide: Design Compilation. Intel FPGA Software Documentation, 2023. https://www.intel.com/content/www/us/en/docs/programmable/683682/current/overview.html. [Google Scholar]
  153. Kuon I and Rose J. Measuring the gap between FPGAs and ASICs. IEEE Trans Comput-Aided Des Integr Circuits Syst 2007; 26: 203–215. [Google Scholar]
  154. Ibro M and Marinova G. FPGA power consumption optimization methods analysis. In: 2023 International Conference on Electromechanical and Energy Systems (SIELMEN), 2023, 1–4. [Google Scholar]
  155. Ibanez S, Brebner G, McKeown N, et al. The P4-> NetFPGA workflow for line-rate packet processing. In: Proceedings of the 2019 ACM/SIGDA International Symposium on Field-Programmable Gate Arrays, FPGA ’19. New York, NY, USA: Association for Computing Machinery, 2019, 1–9. [Google Scholar]
  156. Chirkov G and Wentzlaff D. SMAPPIC: Scalable multi-FPGA architecture prototype platform in the cloud. In: Proceedings of the 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, ASPLOS 2023, Vol. 2. New York, NY, USA: Association for Computing Machinery, 2023, 733–746. [Google Scholar]
  157. Monmasson E and Cirstea MN. FPGA design methodology for industrial control systems–A review. IEEE Trans Ind Electron 2007; 54: 1824–1842. [Google Scholar]
  158. Kermiche A, Saoudi M and Drouiche A. High throughput pipelined implementation of SHA3 hash algorithm on FPGA. J Cryptogr Eng 2025; 15: 15. [Google Scholar]
  159. Xilinx Inc. UltraScale+ Architecture and Product Overview (DS890), 2022. https://docs.xilinx.com/v/u/en-US/ds890-ultrascale-overview. [Google Scholar]
  160. Intel Corporation. Intel Agilex 7 Device Overview. Intel FPGA Documentation, 2023. https://www.intel.com/content/www/us/en/docs/programmable/683563/current/overview.html. [Google Scholar]
  161. Kim B, Park J, Moon S, et al. Configurable energy-efficient lattice-based post-quantum cryptography processor for IoT devices. In: ESSCIRC 2022- IEEE 48th European Solid State Circuits Conference (ESSCIRC), 2022, 525–528. [Google Scholar]
  162. Li A, Lu J, Liu D, et al. A 40nm 1.26μ/Op energy-efficient CRYSTALS-KYBER post-quantum cryptoprocessor with comprehensive side channel security analysis and countermeasures. In: 2024 IEEE Custom Integrated Circuits Conference (CICC), 2024, 1–2. [Google Scholar]
  163. Lu J, Liu D, Zhang J, et al. A 28nm 84.9KOPS 1.82μJ/op RISC-V Crypto-SoC with primitive-based deep-coupling unified post-quantum engine. In: 2025 Symposium on VLSI Technology and Circuits (VLSI Technology and Circuits), 2025, 1–3. [Google Scholar]
  164. Zhu J, Yuan Y, Nie L, et al. A 28 nm 75.6 KOPS 13 nJ computing-in-memory pipeline number theoretic transform accelerator for PQC. IEEE Trans Circuits Syst II: Express Briefs 2025; 72: 273–277. [Google Scholar]
  165. Beullens W. Breaking rainbow takes a weekend on a laptop. In: Dodis Y and Shrimpton T, editors, Advances in Cryptology – CRYPTO 2022. Cham: Springer Nature Switzerland, 2022, 464–479. [Google Scholar]
  166. Albrecht MR, Curtis BR, Deo A, et al. Estimate all the {LWE, NTRU} schemes! In: Security and Cryptography for Networks. Cham: Springer International Publishing, 2018, 351–367. [Google Scholar]
  167. Wu H and Xu G. Enhancing the dual attack against MLWE: Constructing more short vectors using its algebraic structure, 2022. https://eprint.iacr.org/2022/1661. [Google Scholar]
  168. Chen Y. Quantum algorithms for lattice problems, 2024. https://eprint.iacr.org/2024/555. [Google Scholar]
  169. Feneuil T, Joux A and Rivain M. Syndrome decoding in the head: Shorter signatures from zero-knowledge proofs, 2022. https://eprint.iacr.org/2022/188. DOI: https://doi.org/10.1007/978-3-031-15979-4 19. [Google Scholar]
  170. DESHPANDE S, LEE Y, KARAKUZU C, et al. Sphincslet: An area-efficient accelerator for the full sphincs+digital signature algorithm[J/OL]. ACM Trans. Embed. Comput. Syst., 2025, 24(5). https://doi.org/10.1145/3728469. [Google Scholar]
  171. Deshpande S, Howe J, Szefer J, et al. SDitH in hardware. IACR Trans Cryptogr Hardw Embed Syst 2024; 2024: 215–251. [Google Scholar]
  172. Schöffel M, Tomasi H and Wehn N. HW/SW implementation of MiRitH on embedded platforms, 2024. [Google Scholar]
  173. Hagerstrand B. Infosec Global and Marvell partner to provide crypto agility in the cloud, 2024. [Google Scholar]
  174. Jung H and Oh H. Designing a scalable and area-efficient hardware accelerator supporting multiple PQC schemes. Electronics 2024; 13: 3360. [Google Scholar]
  175. Coron J-S, Gérard F, Trannoy M, et al. Improved gadgets for the high-order masking of dilithium. IACR Trans Cryptogr Hardw Embed Syst 2023; 2023: 484–508. [Google Scholar]
  176. Heinz D, Kannwischer MJ, Land G, et al. First-order masked Kyber on ARM Cortex-M4. IACR Trans Cryptogr Hardw Embed Syst 2022; 2022: 149–172. [Google Scholar]
  177. Fritzmann T, Van Beirendonck M, Roy D, et al. Masked accelerators and instruction set extensions for post-quantum cryptography. IACR Trans Cryptogr Hardw Embed Syst 2021; 2022: 414–460. [Google Scholar]
  178. Norga Q, Kundu S, Ojha UK, et al. Masking gaussian elimination at arbitrary order, with application to multivariate- and code-based PQC. arXiv:2411.00067, 2025. [Google Scholar]
  179. Hülsing A, et al. SPHINCS+ submission to the NIST post-quantum project, 2019. [Google Scholar]
  180. Kundu S, Ghosh A, Karmakar A, et al. Rudraksh: A compact and lightweight post-quantum keyencapsulation mechanism. IACR Trans Cryptographic Hardware Embedded Syst 2025; 2: 647–680. [Google Scholar]

Current usage metrics show cumulative count of Article Views (full-text article views including HTML views, PDF and ePub downloads, according to the available data) and Abstracts Views on Vision4Press platform.

Data correspond to usage on the plateform after 2015. The current usage metrics is available 48-96 hours after online publication and is updated daily on week days.

Initial download of the metrics may take a while.