{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T16:02:38Z","timestamp":1780675358706,"version":"3.54.1"},"reference-count":47,"publisher":"MDPI AG","issue":"23","license":[{"start":{"date-parts":[[2023,11,25]],"date-time":"2023-11-25T00:00:00Z","timestamp":1700870400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100014188","name":"Ministry of Science and ICT","doi-asserted-by":"publisher","award":["IITP-2020-0-01847"],"award-info":[{"award-number":["IITP-2020-0-01847"]}],"id":[{"id":"10.13039\/501100014188","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100014188","name":"Ministry of Science and ICT","doi-asserted-by":"publisher","award":["2021-0-00724"],"award-info":[{"award-number":["2021-0-00724"]}],"id":[{"id":"10.13039\/501100014188","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Korea government (MSIT)","award":["IITP-2020-0-01847"],"award-info":[{"award-number":["IITP-2020-0-01847"]}]},{"name":"Korea government (MSIT)","award":["2021-0-00724"],"award-info":[{"award-number":["2021-0-00724"]}]},{"name":"IC Design Education Center (IDEC), Republic of Korea","award":["IITP-2020-0-01847"],"award-info":[{"award-number":["IITP-2020-0-01847"]}]},{"name":"IC Design Education Center (IDEC), Republic of Korea","award":["2021-0-00724"],"award-info":[{"award-number":["2021-0-00724"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The advancement of quantum computing threatens the security of conventional public-key cryptosystems. Post-quantum cryptography (PQC) was introduced to ensure data confidentiality in communication channels, and various algorithms are being developed. The National Institute of Standards and Technology (NIST) has initiated PQC standardization, and the selected algorithms for standardization and round 4 candidates were announced in 2022. Due to the large memory footprint and highly repetitive operations, there have been numerous attempts to accelerate PQC on both hardware and software. This paper introduces the RISC-V instruction set extension for NIST PQC standard algorithms and round 4 candidates. The proposed programmable crypto-processor can support a wide range of PQC algorithms with the extended RISC-V instruction set and demonstrates significant reductions in code size, the number of executed instructions, and execution cycle counts of target operations in PQC algorithms of up to 79%, 92%, and 87%, respectively, compared to RV64IM with optimization level 3 (-O3) in the GNU toolchain.<\/jats:p>","DOI":"10.3390\/s23239408","type":"journal-article","created":{"date-parts":[[2023,11,27]],"date-time":"2023-11-27T03:48:17Z","timestamp":1701056897000},"page":"9408","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":13,"title":["A Programmable Crypto-Processor for National Institute of Standards and Technology Post-Quantum Cryptography Standardization Based on the RISC-V Architecture"],"prefix":"10.3390","volume":"23","author":[{"given":"Jihye","family":"Lee","sequence":"first","affiliation":[{"name":"Department of Electronic and Electrical Engineering, Ewha Womans University, Seoul 04763, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Whijin","family":"Kim","sequence":"additional","affiliation":[{"name":"Department of Electronic and Electrical Engineering, Ewha Womans University, Seoul 04763, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ji-Hoon","family":"Kim","sequence":"additional","affiliation":[{"name":"Department of Electronic and Electrical Engineering, Ewha Womans University, Seoul 04763, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,11,25]]},"reference":[{"key":"ref_1","unstructured":"Diffie, W., and Hellman, M.E. (2019). Secure Communications and Asymmetric Cryptosystems, Routledge."},{"key":"ref_2","unstructured":"Miller, V.S. (1985, January 23\u201327). Use of elliptic curves in cryptography. Proceedings of the Conference on the Theory and Application of Cryptographic Techniques, Lyon, France."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"120","DOI":"10.1145\/359340.359342","article-title":"A method for obtaining digital signatures and public-key cryptosystems","volume":"21","author":"Rivest","year":"1978","journal-title":"Commun. ACM"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"303","DOI":"10.1137\/S0036144598347011","article-title":"Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer","volume":"41","author":"Shor","year":"1999","journal-title":"SIAM Rev."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"100242","DOI":"10.1016\/j.array.2022.100242","article-title":"Post-quantum cryptography Algorithm\u2019s standardization and performance analysis","volume":"15","author":"Kumar","year":"2022","journal-title":"Array"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Dam, D.T., Tran, T.H., Hoang, V.P., Pham, C.K., and Hoang, T.T. (2023). A Survey of Post-Quantum Cryptography: Start of a New Race. Cryptography, 7.","DOI":"10.3390\/cryptography7030040"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"306","DOI":"10.1109\/TC.2022.3222954","article-title":"High-Speed Hardware Architectures and FPGA Benchmarking of CRYSTALS-Kyber, NTRU, and Saber","volume":"72","author":"Dang","year":"2023","journal-title":"IEEE Trans. Comput."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3292548","article-title":"Post-quantum lattice-based cryptography implementations: A survey","volume":"51","author":"Nejatollahi","year":"2019","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"ref_9","unstructured":"Choquin, L., and Piry, F. (2020). Arm Custom Instructions: Enabling Innovation and Greater Flexibility on Arm, ARM. Technical Report."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Fritzmann, T., Sharif, U., M\u00fcller-Gritschneder, D., Reinbrecht, C., Schlichtmann, U., and Sepulveda, J. (2019, January 25\u201329). Towards reliable and secure post-quantum co-processors based on RISC-V. Proceedings of the 2019 Design, Automation & Test in Europe Conference & Exhibition (DATE), Florence, Italy.","DOI":"10.23919\/DATE.2019.8715173"},{"key":"ref_11","first-page":"1140","article-title":"Sapphire: A Configurable Crypto-Processor for Post-Quantum Lattice-based Protocols","volume":"2019","author":"Banerjee","year":"2019","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"219","DOI":"10.46586\/tches.v2020.i3.219-242","article-title":"ISA extensions for finite field arithmetic: Accelerating Kyber and NewHope on RISC-V","volume":"2020","author":"Alkim","year":"2020","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"239","DOI":"10.46586\/tches.v2020.i4.239-280","article-title":"RISQ-V: Tightly coupled RISC-V accelerators for post-quantum cryptography","volume":"2020","author":"Fritzmann","year":"2020","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"150798","DOI":"10.1109\/ACCESS.2021.3126208","article-title":"A RISC-V Post Quantum Cryptography Instruction Set Extension for Number Theoretic Transform to Speed-Up CRYSTALS Algorithms","volume":"9","author":"Nannipieri","year":"2021","journal-title":"IEEE Access"},{"key":"ref_15","unstructured":"OpenHW Group (2022). CORE-V Extension Interface, OpenHW Group. Technical report."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"2672","DOI":"10.1109\/TCSI.2020.2983185","article-title":"VPQC: A domain-specific vector processor for post-quantum cryptography based on RISC-V architecture","volume":"67","author":"Xin","year":"2020","journal-title":"IEEE Trans. Circuits Syst. Regul. Pap."},{"key":"ref_17","first-page":"6457","article-title":"From pre-quantum to post-quantum IoT security: A survey on quantum-resistant cryptosystems for the Internet of Things","volume":"7","year":"2019","journal-title":"IEEE Internet Things J."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Jiang, H., Zhang, Z., and Ma, Z. (2019, January 14\u201317). Key encapsulation mechanism with explicit rejection in the quantum random oracle model. Proceedings of the Public-Key Cryptography\u2013PKC 2019: 22nd IACR International Conference on Practice and Theory of Public-Key Cryptography, Beijing, China.","DOI":"10.1007\/978-3-030-17259-6_21"},{"key":"ref_19","unstructured":"Soni, D., Basu, K., Nabeel, M., and Karri, R. (2019, January 22\u201324). A hardware evaluation study of NIST post-quantum cryptographic signature schemes. Proceedings of the Second PQC Standardization Conference, NIST, Santa Barbara, CA, USA."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Alagic, G., Apon, D., Cooper, D., Dang, Q., Dang, T., Kelsey, J., Lichtinger, J., Liu, Y., Miller, C., and Moody, D. (2022). Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process.","DOI":"10.6028\/NIST.IR.8413"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"61478","DOI":"10.1109\/ACCESS.2018.2876401","article-title":"An efficient algorithm for the shortest vector problem","volume":"6","author":"Chuang","year":"2018","journal-title":"IEEE Access"},{"key":"ref_22","unstructured":"Regev, O. (2016, January 14\u201318). Lattice-based cryptography. Proceedings of the Annual International Cryptology Conference, Santa Barbara, CA, USA."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Khalid, A., Oder, T., Valencia, F., O\u2019Neill, M., G\u00fcneysu, T., and Regazzoni, F. (2018, January 23\u201325). Physical protection of lattice-based cryptography: Challenges and solutions. Proceedings of the 2018 on Great Lakes Symposium on VLSI, Chicago, IL, USA.","DOI":"10.1145\/3194554.3194616"},{"key":"ref_24","unstructured":"Lyubashevsky, V., Peikert, C., and Regev, O. (June, January 30). On ideal lattices and learning with errors over rings. Proceedings of the Annual International Conference on the Theory and Applications of Cryptographic Techniques, French Riviera, France."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"565","DOI":"10.1007\/s10623-014-9938-4","article-title":"Worst-case to average-case reductions for module lattices","volume":"75","author":"Langlois","year":"2015","journal-title":"Des. Codes Cryptogr."},{"key":"ref_26","unstructured":"Lamport, L. (1979). Constructing Digital Signatures from a One Way Function, SRI International. Technical Report, Technical Report CSL-98."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Buchmann, J., Dahmen, E., and H\u00fclsing, A. (2011, January 28\u201330). XMSS-a practical forward secure signature scheme based on minimal security assumptions. Proceedings of the International Workshop on Post-Quantum Cryptography, College Park, MD, USA.","DOI":"10.1007\/978-3-642-25405-5_8"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"2542","DOI":"10.1109\/TPDS.2020.2995562","article-title":"Efficient parallelism of post-quantum signature scheme SPHINCS","volume":"31","author":"Sun","year":"2020","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"ref_29","first-page":"114","article-title":"A public-key cryptosystem based on algebraic","volume":"4244","author":"McEliece","year":"1978","journal-title":"Coding Thv"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"590","DOI":"10.1109\/TIT.1973.1055088","article-title":"Goppa codes","volume":"19","author":"Berlekamp","year":"1973","journal-title":"IEEE Trans. Inf. Theory"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Dworkin, M.J. (2015). SHA-3 Standard: Permutation-Based Hash and Extendable-Output Function, National Institute of Standards and Technology. Technical report.","DOI":"10.6028\/NIST.FIPS.202"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Karabulut, E., and Aysu, A. (September, January 31). RANTT: A RISC-V architecture extension for the number theoretic transform. Proceedings of the 2020 30th International Conference on Field-Programmable Logic and Applications (FPL), Gothenburg, Sweden.","DOI":"10.1109\/FPL50879.2020.00016"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"297","DOI":"10.1090\/S0025-5718-1965-0178586-1","article-title":"An algorithm for the machine calculation of complex Fourier series","volume":"19","author":"Cooley","year":"1965","journal-title":"Math. Comput."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"519","DOI":"10.1090\/S0025-5718-1985-0777282-X","article-title":"Modular multiplication without trial division","volume":"44","author":"Montgomery","year":"1985","journal-title":"Math. Comput."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"336","DOI":"10.46586\/tches.v2020.i3.336-357","article-title":"Cortex-M4 optimizations for {R, M} LWE schemes","volume":"2020","author":"Alkim","year":"2020","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Chen, M.S., G\u00fcneysu, T., Krausz, M., and Thoma, J.P. (2022, January 20\u201323). Carry-less to bike faster. Proceedings of the Applied Cryptography and Network Security: 20th International Conference, ACNS 2022, Rome, Italy.","DOI":"10.1007\/978-3-031-09234-3_41"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Sch\u00f6ffel, M., Feldmann, J., and Wehn, N. (2023). Code-based Cryptography in IoT: A HW\/SW Co-Design of HQC. arXiv.","DOI":"10.1109\/WF-IoT54382.2022.10152031"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Waterman, A., Lee, Y., Patterson, D.A., and Asanovi, K. (2014). The Risc-v Instruction Set Manual. Volume 1: User-Level Isa, Version 2.0, Department of Electrical Engineering and Computer Sciences, California University. Technical report.","DOI":"10.21236\/ADA605735"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Oder, T., Speith, J., H\u00f6ltgen, K., and G\u00fcneysu, T. (2019, January 8\u201310). Towards practical microcontroller implementation of the signature scheme Falcon. Proceedings of the International Conference on Post-Quantum Cryptography, Chongqing, China.","DOI":"10.1007\/978-3-030-25510-7_4"},{"key":"ref_40","unstructured":"Marshall, B. (2021). RISC-V Cryptographic Extension Proposals. Volume I: Scalar &amp, RISC-V International. Entropy Source Instructions."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Banerjee, U., Das, S., and Chandrakasan, A.P. (2020, January 12\u201314). Accelerating post-quantum cryptography using an energy-efficient tls crypto-processor. Proceedings of the 2020 IEEE International Symposium on Circuits and Systems (ISCAS), Seville, Spain.","DOI":"10.1109\/ISCAS45731.2020.9180550"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Soni, D., and Karri, R. (2021, January 7\u20139). Efficient hardware implementation of pqc primitives and pqc algorithms using high-level synthesis. Proceedings of the 2021 IEEE Computer Society Annual Symposium on VLSI (ISVLSI), Tampa, FL, USA.","DOI":"10.1109\/ISVLSI51109.2021.00061"},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"2629","DOI":"10.1109\/TVLSI.2019.2926114","article-title":"The Cost of Application-Class Processing: Energy and Performance Analysis of a Linux-Ready 1.7-GHz 64-Bit RISC-V Core in 22-nm FDSOI Technology","volume":"27","author":"Zaruba","year":"2019","journal-title":"IEEE Trans. Very Large Scale Integr. (VLSI) Syst."},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Stoffelen, K. (2019, January 2\u20134). Efficient cryptography on the RISC-V architecture. Proceedings of the International Conference on Cryptology and Information Security in Latin America, Santiago de, Chile, Chile.","DOI":"10.1007\/978-3-030-30530-7_16"},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Li, H., Mentens, N., and Picek, S. (2023, January 17\u201319). Maximizing the Potential of Custom RISC-V Vector Extensions for Speeding up SHA-3 Hash Functions. Proceedings of the 2023 Design, Automation & Test in Europe Conference & Exhibition (DATE), Antwerp, Belgium.","DOI":"10.23919\/DATE56975.2023.10137009"},{"key":"ref_46","unstructured":"Kannwischer, M.J., Rijneveld, J., Schwabe, P., and Stoffelen, K. (2019). PQM4: Post-Quantum Crypto Library for the ARM Cortex-M4, GitHub."},{"key":"ref_47","unstructured":"(2023, November 15). GF2X\/GF2X \u00b7 GITLAB. Available online: https:\/\/gitlab.inria.fr\/gf2x\/gf2x."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/23\/9408\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T21:30:24Z","timestamp":1760131824000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/23\/9408"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,25]]},"references-count":47,"journal-issue":{"issue":"23","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["s23239408"],"URL":"https:\/\/doi.org\/10.3390\/s23239408","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,11,25]]}}}