FIQ-PQC04-SW Hardened ML‑KEM (FIPS 203) + ML‑DSA (FIPS 204)

Secure Post‑Quantum Cryptographic Library

FortifyIQ’s FIQ‑PQC04‑SW provides a unified, hardened implementation of both ML‑KEM (Key Encapsulation Mechanism, FIPS 203) and ML‑DSA (Digital Signature Algorithm, FIPS 204), enabling secure key establishment and authentication in a single integrated software package.

The crypto-agile library supports all key sizes of both algorithms and incorporates comprehensive protections against Side‑Channel Attacks (SCA) and Fault Injection Attacks (FIA). The implementation is engineered to meet or exceed rigorous certification standards, including all levels of FIPS 140‑3 and SESIP, and Common Criteria AVA_VAN.5.

Features

Efficient Performance

  • Hybrid PQC Ready: Native support for dual-scheme execution, combining classical algorithms (ECC/RSA) with ML-KEM/ML-DSA for secure, compliant migration.
  • Future-Proof Agility: Software-upgradable architecture allows updating algorithms, key sizes, and protections as standards evolve without rewriting the application.
  • Target-Optimized Footprint: Configurable builds for memory-constrained targets or high-throughput environments.
  • Complies with FIPS 203 (ML‑KEM) and FIPS 204 (ML‑DSA) – NIST ACVP/CAVP certified.

Integrated SCA & FIA Protections

  • Validated algorithmic protection based on a novel mathematical approach
  • Hardened implementations of sensitive operations
  • Significantly lower overhead than the common alternative (e.g. share-based)
  • Security Certification Readiness for all levels of FIPS 140‑3 and SESIP, and Common Criteria AVA_VAN.5.
Applications
  • IoT Devices
  • Automotive Systems
  • Embedded & Industrial Control
  • Authentication Tokens
  • Payment Systems
  • Secure Communications
  • Network Devices
  • Secure Boot & Firmware Signing
  • Hardware Security Modules (HSMs)
  • PQC‑ready SoCs and microcontrollers
Technical Overview

FIQ‑PQC04‑SW integrates FortifyIQ’s hardened implementations of both ML‑KEM and ML‑DSA:

ML‑KEM Module

  • Implements the standardized ML‑KEM key encapsulation algorithm (FIPS 203).
  • Protected against SCA and FIA with minimal performance overhead.

ML‑DSA Module

  • Implements the standardized ML‑DSA digital signature algorithm (FIPS 204).
  • Strong SCA and FIA protection with minimal performance overhead.

The library is NIST ACVP/CAVP certified.

Supported Algorithms & Key Sizes

ML‑KEM (FIPS 203) – CRYSTALS‑Kyber Based

  • ML‑KEM‑512
  • ML‑KEM‑768<
  • ML‑KEM‑1024<

ML‑DSA (FIPS 204) – CRYSTALS‑Dilithium Based

  • ML‑DSA‑44
  • ML‑DSA‑65
  • ML‑DSA‑87

FIQ‑PQC04‑SW is FortifyIQ’s unified, hardened, security-certification‑ready post‑quantum cryptographic software library, combining ML‑KEM and ML‑DSA into a single compact solution. It is engineered for quantum‑resistant key establishment and authentication with minimal resource usage. Its strong side‑channel and fault injection protections ensure a truly safe quantum transition.

External Dependencies
  • Requires a good entropy source, such as TRNG; Can reuse the PQC entropy source.
  • No additional dependencies
Deliverables
  • Full software library (ML‑KEM + ML‑DSA)
  • Integration documentation
  • API reference
  • Test vectors
SGS certification logo
FortifyIQ AES Algorithm
AVA_VAN.5 Evaluation & Validation Summary
SGS Brightsight Common Criteria Laboratory
“Summary. The leakage analysis (Welch t-test) on over 30 million traces did not show statistically significant first- and second-order differences between trace sets with fixed and random inputs. The template-based DPA analysis, on the pseudo-random trace set for the profiling phase (15 million traces) and on a sub-set of 300k fix input traces for matching phase targeting the first-round S-box output, and template attack on ciphertext, did not indicate any potential information leakage.”
“The results for the soft IP presented in the report were obtained on the TOE which is the basic hardware implementation of the soft IP without additional levels of security (e.g. that are present in a secure silicon layout). Therefore the internal strength of the soft IP itself was evaluated. This indicates that the investigated features and parameters of the soft IP implementation should be robust against SCA and fault injection attacks in different implementations including ASIC. Nevertheless, according to the Common Criteria rules, the strength of the final composite product must be evaluated on its own”
Request Technical Details