Paper 2025/2337

ML-DSA-OSH: An Efficient, Open-Source Hardware Implementation of ML-DSA

Quinten Norga, COSIC, KU Leuven
Suparna Kundu, COSIC, KU Leuven
Ingrid Verbauwhede, COSIC, KU Leuven
Abstract

ML-DSA is a post-quantum lattice-based digital signature algorithm (DSA) that the National Institute of Standards and Technology (NIST) recently standardized as FIPS 204. Remarkably, there are only a handful of published hardware designs and no open-source hardware implementations of complete ML-DSA. In this work, we present an efficient open-source hardware (OSH) design of ML-DSA, based on a Dilithium implementation by Beckwith et al. (FPT 2021). We discuss the required modifications for migrating existing CRYSTALS-Dilithium implementations to match FIPS 204. In addition, we evaluate and compare the performance of our design with the prior art. Through optimized instruction scheduling in the ML-DSA rejection loop, which enables the pre-computation of critical variables, the average signing latency is improved by $16-36$ %. Finally, we extensively discuss potential applications and directions of research, further enabled through ML-DSA-OSH.

Note: This is the full version of the extended abstract published at DATE 2026.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Published elsewhere. Major revision. DATE 2026
Keywords
PQCML-DSAFPGAOpen-Source Hardware
Contact author(s)
quinten norga @ esat kuleuven be
suparna kundu @ esat kuleuven be
ingrid verbauwhede @ esat kuleuven be
History
2025-12-31: approved
2025-12-30: received
See all versions
Short URL
https://ia.cr/2025/2337
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2337,
      author = {Quinten Norga and Suparna Kundu and Ingrid Verbauwhede},
      title = {{ML}-{DSA}-{OSH}: An Efficient, Open-Source Hardware Implementation of {ML}-{DSA}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2337},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2337}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.