Hybrid Crypto Box IP Core with Classical and Post-Quantum Cryptography for Embedded Systems
FortifyIQ’s Hybrid Crypto Box IP core is a comprehensive, high-efficiency cryptographic solution that combines RSA, ECC, AES, and SHA-2/HMAC with a built-in accelerator for post-quantum algorithms such as ML-KEM (Kyber) and ML-DSA (Dilithium). Designed for embedded systems with balanced resource constraints, it enables secure key exchange, digital signatures, authenticated encryption, and hashing, future-proofed for the quantum era. All critical components feature robust side-channel and fault injection protections, including RTL-level, implementation-agnostic countermeasures for AES and SHA-2/HMAC. Supporting secure boot, authenticated firmware updates, and FIPS 140-3/Common Criteria certification, this Crypto Box provides a unified and scalable foundation for long-lifecycle, security-critical applications.
FortifyIQ’s Hybrid Crypto Box IP core is a unified, high-efficiency cryptographic engine that integrates classical asymmetric algorithms, symmetric cryptography, secure hashing, and post-quantum cryptographic accelerators in a compact and scalable hardware block. Designed for embedded systems requiring both long-term cryptographic agility and robust physical security, the IP enables secure key exchange, digital signatures, authenticated encryption, and data integrity in a single, certifiable package.
The classical cryptography module supports RSA-4096 and ECC operations (ECDH/ECDSA over NIST P-192 to P-521), enabling compatibility with existing PKI infrastructures. The symmetric engine provides AES-128/192/256 with support for ECB, CBC, CTR, and GCM modes. The hashing engine supports SHA-224, SHA-256, SHA-384, and SHA-512, along with HMAC for secure message authentication.
The Crypto Box also includes a dedicated post-quantum cryptography accelerator supporting: ML-KEM (Kyber) for key establishment(per FIPS 203), ML-DSA (Dilithium) for digital signatures (per FIPS 204). This enables hybrid or full-PQC deployments in secure boot, firmware authentication, and key exchange protocols. To protect against physical attacks, all sensitive blocks, such as AES, SHA-2/HMAC, ECC, RSA, ML-KEM, and ML-DSA, feature robust side-channel analysis (SCA) and fault injection (FI) countermeasures.
The Crypto Box supports secure boot and authenticated firmware updates of its internal firmware. FortifyIQ’s Hybrid Crypto Box IP core offers a future-ready security foundation for embedded systems in automotive, industrial, IoT, and edge computing applications engineered for compliance with FIPS 140-3, Common Criteria, and other high-assurance standards.