Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

Search Results (40)

Search Parameters:
Keywords = Quantum Number Theoretic Transform

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
22 pages, 1466 KB  
Article
Area–Power–Performance Trade-Offs in Lightweight Non-Pipelined and Pipelined NTT Accelerators for CRYSTALS-Dilithium
by Omar S. Sonbul, Muhammad Rashid, Khalid M. Khayyat and Hamza H. Sulimani
Electronics 2026, 15(14), 3072; https://doi.org/10.3390/electronics15143072 - 13 Jul 2026
Viewed by 262
Abstract
Number Theoretic Transform (NTT)-based polynomial multiplication is a computationally intensive operation in lattice-based post-quantum cryptography (PQC) schemes such as CRYSTALS-Dilithium. Existing hardware accelerators optimize area and timing performance, without focusing on evaluating trade-offs among hardware utilization, execution latency, operating frequency, and power consumption. [...] Read more.
Number Theoretic Transform (NTT)-based polynomial multiplication is a computationally intensive operation in lattice-based post-quantum cryptography (PQC) schemes such as CRYSTALS-Dilithium. Existing hardware accelerators optimize area and timing performance, without focusing on evaluating trade-offs among hardware utilization, execution latency, operating frequency, and power consumption. This article investigates such trade-offs through two lightweight field-programmable gate array (FPGA) implementations of an iterative NTT-based polynomial multiplication accelerator, namely non-pipelined and 4-stage pipelined architectures. Both implementations employ a single butterfly unit based on Cooley–Tukey and Gentleman–Sande configurations to compute the forward NTT (FNTT), inverse NTT (INTT), and coefficient-wise multiplication (CWM). The 4-stage pipelined architecture employs pipeline registers in the modular multiplication and Barrett reduction datapaths to maximize the operating frequency. Both architectures are implemented on an Artix-7 FPGA and evaluated across operating frequencies ranging from 10 MHz to 280 MHz. The results show that the non-pipelined architecture provides reduced hardware overhead and lower power consumption, whereas the pipelined architecture improves timing scalability and successfully operates at 280 MHz. At the maximum operating frequency, the pipelined implementation utilizes 1115 slices and achieves execution times of 4.58 μs, 0.93μs, and 4.58μs for FNTT, CWM, and INTT computations, respectively, with an average power consumption of 133 mW. The Area–Time Product (ATP) and Energy–Delay Product (EDP) evaluations demonstrate that the pipelined architecture achieves improved overall efficiency within the proposed lightweight single-butterfly-based polynomial multiplication architecture at higher operating frequencies, obtaining an ATP of 7.74×103 Slice-μs and EDP of 1501.52 nJ-μs. Full article
(This article belongs to the Special Issue Secure Hardware Architecture and Attack Resilience)
Show Figures

Figure 1

18 pages, 1546 KB  
Article
ML-KEM (CRYSTALS-Kyber) on FPGA Using the Residue Number System
by Abdullah Alhassani and Mohammed Benaissa
Cryptography 2026, 10(4), 47; https://doi.org/10.3390/cryptography10040047 - 10 Jul 2026
Viewed by 299
Abstract
The NIST standardisation process for Post-Quantum Cryptography (PQC) has nominated the CRYSTALS-Kyber Key-Encapsulation Mechanism (KEM) scheme as the primary key establishment method. The algorithm was renamed as the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM). This work proposes an efficient design for ML-KEM on FPGA with [...] Read more.
The NIST standardisation process for Post-Quantum Cryptography (PQC) has nominated the CRYSTALS-Kyber Key-Encapsulation Mechanism (KEM) scheme as the primary key establishment method. The algorithm was renamed as the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM). This work proposes an efficient design for ML-KEM on FPGA with built-in side-channel attack (SCA) protection. The design is based on combining two methodologies: the Residue Number System (RNS) arithmetic and the look-up tables implementation. At the arithmetic level in the number-theoretic transform (NTT) computation of the polynomial multiplication, the operations are spread across the RNS channels, and these computations are implemented using look-up tables. The use of look-up tables resulted in low-latency RNS implementation and higher performance. The proposed design, implemented on Xilinx Artix-7 FPGA, shows higher performance with a reasonable increase in area, whilst the experimental TVLA results demonstrate the design’s SCA protection advantages. Full article
Show Figures

Figure 1

25 pages, 4682 KB  
Article
Adaptive FPGA-Based Mixed-Radix NTT Architectures with Classical and Quantum Evaluation for CRYSTALS-Kyber
by Yaser AlKurdi, Qasem Abu Al-Haija and Ahod Alghuried
Appl. Sci. 2026, 16(12), 6183; https://doi.org/10.3390/app16126183 - 18 Jun 2026
Viewed by 493
Abstract
The imminent threat of large-scale quantum computers motivates the deployment of post-quantum cryptography (PQC). CRYSTALS-Kyber, a leading lattice-based Key Encapsulation Mechanism, relies heavily on Number Theoretic Transform (NTT) operations, which remain a major performance and resource bottleneck. This paper presents a cross-platform NTT [...] Read more.
The imminent threat of large-scale quantum computers motivates the deployment of post-quantum cryptography (PQC). CRYSTALS-Kyber, a leading lattice-based Key Encapsulation Mechanism, relies heavily on Number Theoretic Transform (NTT) operations, which remain a major performance and resource bottleneck. This paper presents a cross-platform NTT evaluation framework for CRYSTALS-Kyber, centered on an adaptive FPGA-based mixed-radix accelerator supporting radix-2, radix-4, and radix-8 configurations, together with comparative classical implementations and exploratory quantum-circuit prototypes. Classical evaluations show that an iterative Cooley–Tukey implementation outperforms a matrix-based baseline (≈3.6× faster for the forward NTT, ≈6.3× faster for the inverse NTT). Quantum prototypes implemented in Qiskit demonstrate proof-of-concept QFT-based NTT constructions under classical simulation environments, highlighting circuit-depth growth and noise sensitivity rather than practical hardware acceleration. The proposed FPGA design, based on a Xilinx Virtex UltraScale+ platform, employs an adaptive radix controller, LUT-based twiddle management, and Montgomery/Barrett modular arithmetic. Montgomery reduction provides superior timing and area trade-offs, with an estimated Fmax of up to 231.48 MHz and only 5 DSPs for radix-2. At the same time, radix-2 offers the best resource/performance balance with a latency of approximately 32,804 cycles. The hybrid approach strikes a balance between near-term FPGA practicality and long-term quantum potential while preserving Kyber’s MLWE-based security. Experimental results and comparative analysis indicate that the adaptive design substantially reduces resource usage and timing overhead compared to recent HLS-based NTT accelerators. Full article
(This article belongs to the Special Issue Recent Progress of Information Security and Cryptography)
Show Figures

Figure 1

22 pages, 2560 KB  
Article
An Open Hardware ML-KEM Polynomial Ring Accelerator on Chipyard RISC-V SoC: System-Level Integration and Evaluation
by Yi-Chang Tsai, Yu-Han Lin and Wen-Jyi Hwang
Electronics 2026, 15(12), 2511; https://doi.org/10.3390/electronics15122511 - 7 Jun 2026
Viewed by 473
Abstract
With the standardization of the Module-Lattice-Based Key Encapsulation Mechanism (ML-KEM) in NIST FIPS 203 (2024), efficient hardware support for polynomial ring operations has become critical for practical post-quantum cryptography deployment. The dominant computational workload of ML-KEM arises from matrix–vector multiplications over polynomial rings, [...] Read more.
With the standardization of the Module-Lattice-Based Key Encapsulation Mechanism (ML-KEM) in NIST FIPS 203 (2024), efficient hardware support for polynomial ring operations has become critical for practical post-quantum cryptography deployment. The dominant computational workload of ML-KEM arises from matrix–vector multiplications over polynomial rings, which involve repeated Number Theoretic Transform (NTT), pointwise multiplication, and modular addition operations. This work proposes an ML-KEM polynomial ring accelerator leveraging Open Intellectual Property (Open IP) and integrates it into an open hardware Chipyard RISC-V System on Chip (SoC) via a Memory-Mapped I/O (MMIO) interface. The design incorporates an NTT-based datapath with multiplier and adder arrays, and employs a scratchpad memory to enable intermediate data reuse and reduce memory access overhead. The proposed architecture is implemented on a Genesys 2 FPGA development board featuring a Kintex-7 XC7K325T Field Programmable Gate Array (FPGA) (Digilent Inc., Pullman, WA, USA) and evaluated at both kernel and system levels. Experimental results show that the accelerator reduces matrix–vector multiplication latency to 7372 cycles, achieving up to 40× speedup over a software baseline. At the SoC level, the complete ML-KEM implementation achieves performance improvements of 1.6× to 2.1× across different parameter sets. These results demonstrate that integrating Open IP within an open hardware SoC provides an effective and reproducible approach for accelerating ML-KEM. Full article
(This article belongs to the Special Issue New Trends in Cybersecurity and Hardware Design for IoT)
Show Figures

Figure 1

50 pages, 1251 KB  
Article
Blockchain-Enabled Lattice-Based Attribute-Based Searchable Encryption with Instant Revocation
by Zhishan Feng, Wenzhong Yang, Ying Hu, Yabo Yin, Tianqi Ma, Xiaodan Tian and Xiangxin Deng
Electronics 2026, 15(11), 2471; https://doi.org/10.3390/electronics15112471 - 4 Jun 2026
Cited by 1 | Viewed by 263
Abstract
As cloud computing proliferates, outsourced data faces severe security threats, yet existing searchable encryption (SE) schemes rely on classical hardness assumptions, centralized trust authorities, and static access control, leaving critical gaps in quantum resistance, single-point-of-failure prevention, and dynamic permission management. To address these [...] Read more.
As cloud computing proliferates, outsourced data faces severe security threats, yet existing searchable encryption (SE) schemes rely on classical hardness assumptions, centralized trust authorities, and static access control, leaving critical gaps in quantum resistance, single-point-of-failure prevention, and dynamic permission management. To address these limitations, we propose BL-ABSE, a blockchain-enhanced, lattice-based attribute-based searchable encryption framework. BL-ABSE employs the Ring Learning With Errors (RLWE) problem as its security foundation and applies the Number Theoretic Transform (NTT) to reduce polynomial multiplication from O(n2) to O(nlogn). To eliminate single-point trust risks, the framework further integrates a (t,n) threshold key protocol across an edge-node consortium governed by Practical Byzantine Fault Tolerance (PBFT) consensus. A smart-contract-maintained on-chain revocation list enables permission withdrawal via a single blockchain transaction without re-encryption. Experimental evaluation demonstrates that commitment generation requires approximately 23 ms at n=1024, search latency scales linearly at roughly 29 µs per record, and revocation completes in approximately 2 s regardless of system scale. Formal security proofs under the quantum polynomial-time (QPT) adversary model reduce six security properties—index indistinguishability, query privacy, threshold key security, Byzantine fault tolerance, audit immutability, and revocation immediacy—to the hardness of RLWE and the Short Integer Solution (SIS) problems. To the best of our knowledge, BL-ABSE is the first framework to simultaneously achieve post-quantum security, attribute-based access control, decentralized key management, instant revocation, and immutable auditing within a single unified framework. We further conduct threshold parameter verification, end-to-end revocation latency decomposition, blockchain throughput stress testing, search-pattern leakage quantification, and communication/storage overhead analysis, providing a comprehensive evaluation of both performance and security trade-offs. We explicitly characterize the search-pattern leakage inherent in the deterministic commitment design as a correctness–privacy trade-off and discuss mitigation directions. Full article
Show Figures

Figure 1

40 pages, 892 KB  
Article
IoT-Oriented Digital Signature Defense Against Single-Trace Belief Propagation Attacks in Post-Quantum Cryptography
by Maksim Iavich and Nursulu Kapalova
J. Cybersecur. Priv. 2026, 6(3), 77; https://doi.org/10.3390/jcp6030077 - 27 Apr 2026
Viewed by 1480
Abstract
Post-quantum cryptographic implementations in Internet-of-Things (IoT) devices are significantly threatened by physical side-channel attacks, where practical attack risks are increased by physical accessibility and resource limitations. In particular, recent work has shown that belief propagation-based attacks can recover secret keys from lattice-based digital [...] Read more.
Post-quantum cryptographic implementations in Internet-of-Things (IoT) devices are significantly threatened by physical side-channel attacks, where practical attack risks are increased by physical accessibility and resource limitations. In particular, recent work has shown that belief propagation-based attacks can recover secret keys from lattice-based digital signatures using only a single side-channel trace of the Number Theoretic Transform (NTT). This work introduces the Quantum-Randomized Number Theoretic Transform (QR-NTT), an implementation-level defense mechanism that integrates quantum-derived entropy directly into the execution flow of lattice-based signature algorithms. Rather than treating randomness as a static input, QR-NTT uses quantum entropy to introduce controlled variability in execution ordering, arithmetic factor usage, and memory access behavior while preserving mathematical correctness and constant-time execution. The proposed framework is designed for embedded platforms and remains compatible with existing post-quantum cryptographic standards and IoT communication protocols. A complete implementation on an ARM Cortex-M4 platform, coupled with commercial quantum random number generator (QRNG) hardware, demonstrates that QR-NTT significantly degrades the effectiveness of template matching and belief propagation attacks. Experimental evaluation shows a reduction in single-trace attack success rates from over 90% to below 3% and an increase of approximately two orders of magnitude in the number of traces required for successful key recovery. These security gains are achieved with moderate overheads of 18.3% in execution time and 1.8 KB of additional memory while remaining well within practical IoT constraints. The results indicate that quantum-derived entropy can be leveraged as a practical implementation-level defense against physical attacks, complementing algorithmic post-quantum security. QR-NTT demonstrates a viable path toward strengthening the real-world resilience of post-quantum IoT systems without sacrificing deployability. Full article
(This article belongs to the Section Cryptography and Cryptology)
Show Figures

Figure 1

26 pages, 1413 KB  
Article
A Novel Hybrid Quantum Circuit for Integer Factorization: End-to-End Evaluation in Simulation and Real Quantum Hardware
by Jesse Van Griensven Thé, Victor Oliveira Santos and Bahram Gharabaghi
J. Cybersecur. Priv. 2026, 6(2), 71; https://doi.org/10.3390/jcp6020071 - 10 Apr 2026
Viewed by 1325
Abstract
The literature indicates that the qubit requirements for factoring RSA-2048 remain on the order of 1 million, under commonly assumed architectures and error-correction models, leaving a substantial gap between current resource estimates and near-term practical feasibility. Reducing this requirement to the low-thousand-qubit regime [...] Read more.
The literature indicates that the qubit requirements for factoring RSA-2048 remain on the order of 1 million, under commonly assumed architectures and error-correction models, leaving a substantial gap between current resource estimates and near-term practical feasibility. Reducing this requirement to the low-thousand-qubit regime therefore remains an important open research objective. This work proposes a hybrid classical–quantum algorithm that uses a classical modular exponentiation subroutine with a Quantum Number Theoretic Transform (QNTT) circuit to increase the speed and reduce the required quantum resources relative to Shor’s algorithm for integer factorization, which underpins cryptographic systems like RSA and ECC. We evaluate multiple coprime numbers, the result of multiplication of two primes, in both simulation and real quantum hardware, using IBM’s reference Shor implementation as the baseline. Because Shor and proposed Jesse–Victor–Gharabaghi (JVG) use different register sizes for the same coprime N, the reported gate/depth reductions should be interpreted as end-to-end quantum-resource budgets for factoring the same N, rather than a per-qubit or transform-only efficiency claim. In simulation, the JVG algorithm achieved substantial practical reductions in computational resources, decreasing runtime from 174.1 s to 5.4 s, memory usage from 12.5 GB to 0.27 GB, and quantum gate counts by approximately 99%. On quantum hardware, JVG reduced the required runtime from 67.8 s to 2 s, and the quantum gate counts by over 98%. We showed that the proposed algorithm can address the relevant RSA-1024 case scenario, establishing that this method can provide validation for large-scale situations. Furthermore, extrapolation to RSA-2048 indicates that the JVG algorithm significantly outperforms Shor’s approach, requiring a projected quantum runtime of 29 h for ten thousand runs for factorization under identical scaling assumptions. Overall, these results support JVG as a more hardware-compatible and robust noise-tolerant substitute for Shor’s framework, offering a viable research direction toward practical quantum integer factorization on near-term Noisy Intermediate-Scale Quantum (NISQ) devices. Full article
(This article belongs to the Section Cryptography and Cryptology)
Show Figures

Figure 1

11 pages, 237 KB  
Article
Classical Correspondence of Squeezing Operators and the Extension of Bohr’s Correspondence Principle
by Ke Zhang and Hongyi Fan
Photonics 2026, 13(4), 359; https://doi.org/10.3390/photonics13040359 - 9 Apr 2026
Viewed by 448
Abstract
Bohr’s correspondence principle acts as a link between quantum physics and classical physics theory, while squeezed light, as a special nonclassical quantum state in quantum physics, achieves precision measurements and gravitational wave detection by minimizing quantum noise in one quadrature component of the [...] Read more.
Bohr’s correspondence principle acts as a link between quantum physics and classical physics theory, while squeezed light, as a special nonclassical quantum state in quantum physics, achieves precision measurements and gravitational wave detection by minimizing quantum noise in one quadrature component of the optical field. Consequently, determining whether the classical counterpart of the squeezing operator reflects classical spatial scaling transformations is of significant theoretical importance. This paper establishes a universal integral formula that transforms any operator into its Weyl ordering form using the method of integration within the ordered product of operators, combined with the coherent state representation and integration theory within Weyl ordering. By transforming both single-mode and two-mode squeezing operators into their corresponding Weyl ordering forms, their classical counterpart functions are derived. This elucidates the classical correspondence of the squeezed light field density operator and demonstrates that this correspondence fundamentally represents a classical scaling transformation. As a practical application of the classical counterpart of the single-mode squeezing operator, the photon number distribution characteristics in a single-mode squeezed light field are obtained, confirming its noise-squeezing effect. This study not only deepens the theoretical implications of Bohr’s correspondence principle from the perspective of “transformation correspondence” but also introduces novel insights into the establishment of the mathematical foundations of quantum optics and quantum statistical theory. Full article
22 pages, 568 KB  
Article
Application of Extended Dirac Equation to Photon–Electron Interactions and Electron–Positron Collision Processes: A Quantum Theoretical Approach Using a 256 × 256 Matrix Representation
by Hirokazu Maruyama
Atoms 2026, 14(2), 14; https://doi.org/10.3390/atoms14020014 - 19 Feb 2026
Viewed by 1324
Abstract
We propose a novel theoretical framework for describing photon–electron interactions and electron collision processes in a unified manner within quantum electrodynamics. Specifically, we develop a method to construct the Dirac operator in curved spacetime using only matrix representations rooted in the basis structure [...] Read more.
We propose a novel theoretical framework for describing photon–electron interactions and electron collision processes in a unified manner within quantum electrodynamics. Specifically, we develop a method to construct the Dirac operator in curved spacetime using only matrix representations rooted in the basis structure of four-dimensional gamma matrix algebra, without introducing vierbeins (tetrads) or independent spin connections. We realize 16 gamma matrices with two indices as 256×256 matrices and embed the spacetime metric directly into the matrix elements. This reduces geometric operations such as covariantization, connection-like operations, and basis transformations to matrix products and trace calculations, yielding a unified and transparent computational scheme. The spacetime dimension remains as four, and the number “16” represents the number of basis elements of four-dimensional gamma matrix algebra (24=16). Based on the extended QED Lagrangian, vertex rules, propagators, spin sums, and traces can be handled uniformly, making it suitable for automation. As validation of this method, we analyzed four fundamental scattering processes in atomic and particle physics: (i) Compton scattering (photon–electron scattering), (ii) muon pair production (e+eμ+μ), (iii) Møller scattering (electron–electron collision), and (iv) Bhabha scattering (electron–positron collision). In the flat spacetime limit, we confirmed the exact reproduction of standard quantum electrodynamics (QED) results including the Klein–Nishina formula. Furthermore, trial calculations using a metric with off-diagonal components show systematic deviations from flat results near scattering angle θ90, suggesting that metric-induced angular dependence could in principle serve as an observable signature. The matrix representation developed in this work enables unified pipeline execution of theoretical calculations for photon interactions and charged particle collision processes, with expected applications to precision calculations in atomic and particle physics. Full article
(This article belongs to the Section Atomic, Molecular and Nuclear Spectroscopy and Collisions)
Show Figures

Figure 1

23 pages, 1194 KB  
Article
Deeply Pipelined NTT Accelerator with Ping-Pong Memory and LUT-Only Barrett Reduction for Post-Quantum Cryptography
by Omar S. Sonbul, Muhammad Rashid, Muhammad I. Masud, Mohammed Aman and Amar Y. Jaffar
Electronics 2026, 15(3), 513; https://doi.org/10.3390/electronics15030513 - 25 Jan 2026
Cited by 3 | Viewed by 1310 | Correction
Abstract
Lattice-based post-quantum cryptography relies on fast polynomial multiplication. The Number-Theoretic Transform (NTT) is the key operation that enables this acceleration. To provide high throughput and low latency while keeping the area overhead small, hardware implementations of the NTT is essential. This is particularly [...] Read more.
Lattice-based post-quantum cryptography relies on fast polynomial multiplication. The Number-Theoretic Transform (NTT) is the key operation that enables this acceleration. To provide high throughput and low latency while keeping the area overhead small, hardware implementations of the NTT is essential. This is particularly true for resource-constrained devices. However, existing NTT accelerators either achieve high throughput at the cost of large area overhead or provide compact designs with limited pipelining and low operating frequency. Therefore, this article presents a compact, seven-stage pipelined NTT accelerator architecture for post-quantum cryptography, using the CRYSTALS–Kyber algorithm as a case study. The CRYSTALS–Kyber algorithm is selected due to its NIST standardization, strong security guarantees, and suitability for hardware acceleration. Specifically, a unified three-stage pipelined butterfly unit is designed using a single DSP48E1 block for the required integer multiplication. In contrast, the modular reduction stage is implemented using a four-stage pipelined, lookup-table (LUT)-only Barrett reduction unit. The term “LUT-only” refers strictly to the reduction logic and not to the butterfly multiplication. Furthermore, two dual-port BRAM18 blocks are used in a ping-pong manner to hold intermediate and final coefficients. In addition, a simple finite-state machine controller is implemented, which manages all forward NTT (FNTT) and inverse NTT (INTT) stages. For validation, the proposed design is realized on a Xilinx Artix-7 FPGA. It uses only 503 LUTs, 545 flip-flops, 1 DSP48E1 block, and 2 BRAM18 blocks. The complete FNTT and INTT with final rescaling require 1029 and 1285 clock cycles, respectively. At 200 MHz, these correspond to execution times of 5.14 µs for the FNTT and 6.42 µs for the INTT. Full article
(This article belongs to the Section Computer Science & Engineering)
Show Figures

Figure 1

37 pages, 483 KB  
Review
Lattice-Based Cryptographic Accelerators for the Post-Quantum Era: Architectures, Optimizations, and Implementation Challenges
by Hua Yan, Lei Wu, Qiming Sun and Pengzhou He
Electronics 2026, 15(2), 475; https://doi.org/10.3390/electronics15020475 - 22 Jan 2026
Cited by 1 | Viewed by 4155
Abstract
The imminent threat of large-scale quantum computers to modern public-key cryptographic devices has led to extensive research into post-quantum cryptography (PQC). Lattice-based schemes have proven to be the top candidate among existing PQC schemes due to their strong security guarantees, versatility, and relatively [...] Read more.
The imminent threat of large-scale quantum computers to modern public-key cryptographic devices has led to extensive research into post-quantum cryptography (PQC). Lattice-based schemes have proven to be the top candidate among existing PQC schemes due to their strong security guarantees, versatility, and relatively efficient operations. However, the computational cost of lattice-based algorithms—including various arithmetic operations such as Number Theoretic Transform (NTT), polynomial multiplication, and sampling—poses considerable performance challenges in practice. This survey offers a comprehensive review of hardware acceleration for lattice-based cryptographic schemes—specifically both the architectural and implementation details of the standardized algorithms in the category CRYSTALS-Kyber, CRYSTALS-Dilithium, and FALCON (Fast Fourier Lattice-Based Compact Signatures over NTRU). It examines optimization measures at various levels, such as algorithmic optimization, arithmetic unit design, memory hierarchy management, and system integration. The paper compares the various performance measures (throughput, latency, area, and power) of Field-Programmable Gate Array (FPGA) and Application-Specific Integrated Circuit (ASIC) implementations. We also address major issues related to implementation, side-channel resistance, resource constraints within IoT (Internet of Things) devices, and the trade-offs between performance and security. Finally, we point out new research opportunities and existing challenges, with implications for hardware accelerator design in the post-quantum cryptographic environment. Full article
14 pages, 2142 KB  
Article
Accelerating Post-Quantum Cryptography: A High-Efficiency NTT for ML-KEM on RISC-V
by Duc-Thuan Dam, Khai-Duy Nguyen, Duc-Hung Le and Cong-Kha Pham
Electronics 2026, 15(1), 100; https://doi.org/10.3390/electronics15010100 - 24 Dec 2025
Cited by 1 | Viewed by 1812
Abstract
Post-quantum cryptography (PQC) is rapidly being standardized, with key primitives such as Key Encapsulation Mechanisms (KEMs) and Digital Signature Algorithms (DSAs) moving into practical applications. While initial research focused on pure software and hardware implementations, the focus is shifting toward flexible, high-efficiency solutions [...] Read more.
Post-quantum cryptography (PQC) is rapidly being standardized, with key primitives such as Key Encapsulation Mechanisms (KEMs) and Digital Signature Algorithms (DSAs) moving into practical applications. While initial research focused on pure software and hardware implementations, the focus is shifting toward flexible, high-efficiency solutions suitable for widespread deployment. A system-on-chip is a viable option with the ability to coordinate between hardware and software flexibly. However, the main drawback of this system is the latency in exchanging data during computation. Currently, most SoCs are implemented on FPGAs, and there is a lack of SoCs realized on ASICs. This paper introduces a complete RISC-V SoC design in an ASIC for Module Lattice-based KEM. Our system features a RISC-V processor tightly integrated with a high-efficiency Number Theoretic Transform (NTT) accelerator. This accelerator leverages custom instructions to accelerate cryptographic operations. Our research has achieved the following results: (1) The accelerator provides a speedup of up to 14.51× for NTT and 16.75× for inverse NTT operations compared to other RISC-V platforms; (2) This leads to end-to-end performance improvements for ML-KEM of up to 56.5% for security level I, 50.9% for level III, and 45.4% for level V; (3) The ASIC design is fabricated using a 180 nm CMOS process at a maximum operating frequency of 118 MHz with an area overhead of 8.7%. The chip achieved a minimum power consumption of 5.913 μW at 10 kHz and 0.9 V of supply voltage. Full article
(This article belongs to the Special Issue Recent Advances in Quantum Information)
Show Figures

Figure 1

18 pages, 484 KB  
Article
A High-Throughput, BRAM-Efficient NTT/INTT Accelerator for ML-KEM
by Xianwei Gao, Yitong Li, Tianyao Li, Xuemei Li and Jianxin Wang
Electronics 2025, 14(24), 4868; https://doi.org/10.3390/electronics14244868 - 10 Dec 2025
Cited by 2 | Viewed by 965
Abstract
The Number-Theoretic Transform is the primary performance bottleneck in hardware accelerators for post-quantum cryptography schemes like the Module-Lattice-based Key-Encapsulation Mechanism. A key design challenge is the trade-off between the massive parallelism required for low-latency computation and the prohibitive on-chip Block RAM consumption this [...] Read more.
The Number-Theoretic Transform is the primary performance bottleneck in hardware accelerators for post-quantum cryptography schemes like the Module-Lattice-based Key-Encapsulation Mechanism. A key design challenge is the trade-off between the massive parallelism required for low-latency computation and the prohibitive on-chip Block RAM consumption this typically entails. This paper introduces an NTT/INTT accelerator architecture that resolves this conflict, achieving a state-of-the-art latency of 40 clock cycles for a 256-point transform while utilizing only 5 BRAM blocks. Our architecture achieves this by pairing a 32-way parallel streaming datapath with a hybrid memory subsystem that strategically allocates on-chip storage resources. The core innovation is the use of distributed RAM instead of BRAM for high-bandwidth buffering of intermediate data between pipeline stages. This reserves the scarce BRAM resources for storing static twiddle factors and for system-level FIFO interfaces. By deliberately trading abundant logic fabric and dedicated DSP slices for BRAM efficiency, our work demonstrates a design point optimized for high-speed, BRAM-constrained System-on-Chip environments, proving that a focus on memory hierarchy is critical to developing PQC solutions that are both fast and practical for real-world integration. Full article
(This article belongs to the Section Electronic Materials, Devices and Applications)
Show Figures

Figure 1

36 pages, 2534 KB  
Article
A Lightweight Key Agreement Protocol for V2X Communications Based on Kyber and Saber
by Yinfei Dai, Qi Wang, Xiao Song and Shaoqiang Wang
Sensors 2025, 25(22), 6938; https://doi.org/10.3390/s25226938 - 13 Nov 2025
Cited by 4 | Viewed by 1821
Abstract
This paper proposes a post-quantum secure key agreement protocol tailored for vehicular networks (V2X), addressing the dual challenges of quantum resistance and lightweight deployment. The hybrid scheme integrates two lattice-based Key Encapsulation Mechanisms (KEMs)—Kyber and Saber—to construct a dual-path handshake framework that enhances [...] Read more.
This paper proposes a post-quantum secure key agreement protocol tailored for vehicular networks (V2X), addressing the dual challenges of quantum resistance and lightweight deployment. The hybrid scheme integrates two lattice-based Key Encapsulation Mechanisms (KEMs)—Kyber and Saber—to construct a dual-path handshake framework that enhances cryptographic redundancy and ensures robustness against quantum attacks. The protocol achieves secure and authenticated key exchange through RSU public-key broadcasting, OBU dual-path encapsulation, and session-key derivation using HMAC and timestamps. To support efficient execution in embedded vehicular environments, several algorithm-level optimizations are incorporated, including Number Theoretic Transform (NTT) acceleration for Kyber, AVX2-based parallelism for Saber, and integer inner-product techniques to minimize computational overhead. Experimental validation on a Veins + SUMO vehicular simulation platform demonstrates that the proposed protocol reduces handshake latency by nearly 60% compared with RSA, achieves delay performance comparable to ECDH, and lowers total resource consumption by around 40%. These results confirm that the Kyber + Saber hybrid protocol provides a practical, scalable, and quantum-resistant solution for secure V2X communication in dynamic, resource-constrained, and latency-sensitive environments. Full article
(This article belongs to the Section Vehicular Sensing)
Show Figures

Figure 1

27 pages, 341 KB  
Article
Four-Dimensional Spaces of Complex Numbers and Unitary States of Two-Qubit Quantum Systems
by Mars B. Gabbassov, Tolybay Z. Kuanov, Turganbay K. Yermagambetov and Berik I. Tuleuov
Symmetry 2025, 17(11), 1789; https://doi.org/10.3390/sym17111789 - 22 Oct 2025
Viewed by 900
Abstract
The pure states of two-qubit quantum systems are described by a four-dimensional vector of complex numbers, and unitary operators transferring a two-qubit quantum system from one state to another have the form of a 4×4 matrix with complex elements. This fact [...] Read more.
The pure states of two-qubit quantum systems are described by a four-dimensional vector of complex numbers, and unitary operators transferring a two-qubit quantum system from one state to another have the form of a 4×4 matrix with complex elements. This fact brings to mind the idea of studying the spaces of four-dimensional numbers with complex components. Moreover, the results obtained by the authors for four-dimensional numbers with real components inspire some optimism. In this paper we construct four-dimensional spaces of complex numbers by analogy with four-dimensional spaces of real numbers. Each four-dimensional number is mapped to a matrix formed from its components and it is proved that the constructed mapping is a bijection and a homomorphism. In the space of four-dimensional numbers of the eight basis elements, half are real and half are imaginary. The presence of such symmetry distinguishes these spaces from the space of quaternions, in which one basis element is real and the rest are imaginary. The symmetry of the basis numbers makes these spaces a natural generalization of one-dimensional and two-dimensional (complex) algebra. The conditions under which the corresponding matrices are gates for two-qubit quantum systems are defined. The notion of a unitary state of a two-qubit quantum system is introduced, to which various gates from commutative groups of gates correspond. It is shown that any gate of a unitary state transforms a unitary state into a unitary state and a non-unitary state into a non-unitary state. Almost all gates used in the construction of quantum circuits, in particular H, SWAP, CX, CY, and CZ, have the same properties. The problem of searching for a gate that transfers a quantum system from one unitary state to another unitary state has been solved. Thus, with the help of four-dimensional spaces of complex numbers it was possible to construct whole classes of two-qubit gates, which opens new possibilities for the construction of quantum algorithms. The results obtained have important theoretical and practical implications for quantum computing. Full article
(This article belongs to the Section C: Physics)
Back to TopTop