Skip to main navigation Skip to search Skip to main content

A Framework for designing High-Order Side-Channel Protected Hardware Implementations of ML-KEM

Research output: Contribution to journalArticleScientificpeer-review

49 Downloads (Pure)

Abstract

ML-KEM (formerly Kyber) has recently been adopted as FIPS 203 in the NIST Post-Quantum Cryptography standardization process. While existing hardware implementations primarily optimize for performance, they often lack protections against side-channel attacks. We introduce HOPE-MLKEM, a framework that includes the first configurable, open, and full-hardware implementation of ML-KEM with integrated high-order protection against timing and power side-channel attacks. Our modular architecture supports all security levels and operations, incorporating optimized building blocks for polynomial arithmetic, modular multiplication, and programmable control logic. At the same time, this methodology enables the seamless integration of masking countermeasures up to high orders. We evaluated HOPE-MLKEM on FPGA and ASIC platforms, achieving competitive results compared to state-of-the-art unprotected designs while providing resistance against high-order side-channel attacks. Beyond its technical contributions, HOPE-MLKEM is released as an open-source framework to foster community-driven exploration of design choices, leakage evaluation, and hardware optimizations.

Original languageEnglish
Pages (from-to)272-295
JournalIACR Transactions on Cryptographic Hardware and Embedded Systems
Volume2026
Issue number2
DOIs
Publication statusPublished - 23 Apr 2026
Publication typeA1 Journal article-refereed

Keywords

  • Countermeasures
  • Hardware
  • ML-KEM
  • Open-source
  • PQC

Publication forum classification

  • Publication forum level 1

ASJC Scopus subject areas

  • Software
  • Signal Processing
  • Hardware and Architecture
  • Computer Networks and Communications
  • Computer Graphics and Computer-Aided Design
  • Artificial Intelligence

Fingerprint

Dive into the research topics of 'A Framework for designing High-Order Side-Channel Protected Hardware Implementations of ML-KEM'. Together they form a unique fingerprint.

Cite this