Back to Search View Original Cite This Article

Abstract

<title>Abstract</title> <p>The NIST standardisation of ML-KEM-512 (FIPS 203) and ML-DSA-44 (FIPS 204) creates an immediate mandate to deploy quantum-resistant protocols on resource-constrained embedded processors, yet Correlation Power Analysis (CPA) simultaneously threatens the symmetric layer protecting the same platforms. This work presents PQ-SEAL (Post-Quantum Secure Embedded Architecture with Leakage-Resilient AES), the first end-to-end integration of a post-quantum TLS-style handshake with a provably leakage-resilient (LR4) AES-128 rekeying scheme on a bare-metal RISC-V softcore [12]. The system executes on an Ibex RV32IMC softcore at 50 MHz on a Xilinx Artix-7 FPGA within a 64 KB SRAM budget without an operating system, heap allocator, or external cryptographic library. The five-step PQ handshake – comprising ML-KEM-512 key encapsulation, ML-DSA-44 mutual authentication, and SHAKE-128 session-key derivation – completes in 0.9 s. Post-handshake symmetric communication employs AES-128-CTR with LR4 rekeying (Ki+1=AESKi (Ki), m=10 blocks). A software CPA evaluation over N =300 plaintext–ciphertext pairs collected from running hardware demonstrates that fixed-key AES-128 reaches key rank 4 at 300 traces, whereas the LR4 rekeying scheme sustains rank 124 – a 31× improvement in attacker uncertainty at zero additional hardware cost. A real-time role- based encrypted messaging platform built atop the secure channel validates the system in a practical multi-user deployment. All results are obtained from physical FPGA hardware. Index Terms—Post-quantum cryptography, ML-KEM, ML-DSA, RISC-V, FPGA, side-channel analysis, LR4 rekeying, AES-128, Ibex, Correlation Power Analysis, FIPS 203, FIPS 204, bare-metal.</p>

Show More

Keywords

fips rekeying analysis aes128 system

Related Articles

PORE

About

Connect