A Framework for designing High-Order Side-Channel Protected Hardware Implementations of ML-KEM
Camacho-Ruiz, Eros; Navarro-Torrero, Pablo; Aldaya, Alejandro Cabrera (2026-04-23)
Camacho-Ruiz, Eros
Navarro-Torrero, Pablo
Aldaya, Alejandro Cabrera
23.04.2026
IACR Transactions on Cryptographic Hardware and Embedded Systems
Julkaisun pysyvä osoite on
https://urn.fi/URN:NBN:fi:tuni-202605125429
https://urn.fi/URN:NBN:fi:tuni-202605125429
Kuvaus
Peer reviewed
Tiivistelmä
ML-KEM (formerly Kyber) has recently been adopted as FIPS 203 in the NIST Post-Quantum Cryptography standardization process. While existing hardware implementations primarily optimize for performance, they often lack protections against side-channel attacks. We introduce HOPE-MLKEM, a framework that includes the first configurable, open, and full-hardware implementation of ML-KEM with integrated high-order protection against timing and power side-channel attacks. Our modular architecture supports all security levels and operations, incorporating optimized building blocks for polynomial arithmetic, modular multiplication, and programmable control logic. At the same time, this methodology enables the seamless integration of masking countermeasures up to high orders. We evaluated HOPE-MLKEM on FPGA and ASIC platforms, achieving competitive results compared to state-of-the-art unprotected designs while providing resistance against high-order side-channel attacks. Beyond its technical contributions, HOPE-MLKEM is released as an open-source framework to foster community-driven exploration of design choices, leakage evaluation, and hardware optimizations.
Kokoelmat
- TUNICRIS-julkaisut [25386]
