Skip to content

HORCRUX: A Complete PQC RISC-V eXtension Architecture

Jul 2026 · arXiv.org · Vol abs/2607.13939 · 1 citation · 47 references
Computer Science

TL;DR

HORCRUX addresses the difficult trade-off between crypto-agility, high performance, and low resource consumption in constrained environments, a balance typically missing in hardware extensions that focus on limited PQC subsets.

Abstract

This work presents a compact RISC-V extension for Post-Quantum Cryptography (PQC) called HORCRUX, which provides a unified Instruction-Set Extension (ISE) supporting all NIST-approved PQC algorithms. HORCRUX addresses the difficult trade-off between crypto-agility, high performance, and low resource consumption in constrained environments, a balance typically missing in hardware extensions that focus on limited PQC subsets. By targeting shared kernels across ML-KEM, MLDSA, SLH-DSA, HQC, and Falcon, the extension introduces new RISC-V instructions executed by a resource-efficient, tightly coupled coprocessor. This architecture is specifically optimized for embedded systems with strict energy budgets and limited area. Experimental evaluation on a Zynq UltraScale+ FPGA demonstrates speedups of up to 129x for hash-based, 9x for lattice-based, and 27x for code-based schemes, while adding fewer than 21k LUTs and 4.4k FFs. ASIC results from postsynthesis characterization in 65 nm CMOS are also reported, alongside a rigorous power characterization to validate the architecture's energy efficiency. The extension's modular structure maintains backward compatibility with standard RISC-V cores, offering a scalable solution for deploying PQC on constrained embedded systems.

View source

Similar papers

Open access Sep 2026

SHARMONY

This work composes SHA-2 and SHA-3 into a unified hardware architecture, bringing them together as a single, efficient cryptographic ensemble. This need is driven in particular by Post-Quantum Cryptography (PQC), where different standardized schemes rely on either SHA-2 or SHA-3/SHAKE primitives. Rather than enforcing...

Liga Anwar, Carlos Andres Lara-Nino, Jong-Yeon Park et al. · 0 citations
Open access Aug 2026

Design and Implementation of a High-Performance RISC-V CPU IP Core for Multiple Cryptographic Algorithms

A hierarchical multiplier architecture consisting of partial-product generation, 4–2 compressor-tree reduction, and a look-ahead adder is developed to improve multiplication throughput and reduce latency compared with conventional Wallace-tree implementations.

Y.-J. Cheng, Cheng-Rui Yin, K.-X. Tang et al. · 0 citations
Conference Aug 2026

Hardware Implementation of a Secure Pipelined RISC-V Core with Boolean Masking and Efficient Arithmetic Units on FPGA

Edge devices are performing more sensitive work under loads, e.g., sensor fusion and embedded cryptography, with tight power constraints, and hence their processors are appealing targets. and is also requiring efficient arithmetic as well as sidechannel attacks. This is an improved 32-bit RISC-V soft core based on the...

Shivarudraiah B, S. B, Laxmisagar H. S. · 0 citations
Preprint Sep 2026

Implementation and Evaluation of NTT Arithmetic for ML-KEM on a CGLA

FIPS 203 standardizes ML-KEM for post-quantum key establishment. Its polynomial multiplication relies on NTT butterflies with exact modular arithmetic over q = 3329. Dedicated NTT accelerators minimize latency with fixed modular arithmetic and stage schedules. A CPU-Grounded Linear Array (CGLA) reuses one programmable...

Takuto Ando, Yasuhiko Nakashima · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.