International Association for Cryptologic Research

International Association
for Cryptologic Research

Transactions on Cryptographic Hardware and Embedded Systems 2026

Breaking the Myth of MPCitH Inefficiency:

Optimizing MQOM for Embedded Platforms


Ryad Benadjila
CryptoExperts, Paris, France

Thibauld Feneuil
CryptoExperts, Paris, France


Keywords: Post-quantum signatures, MPC-in-the-head, MQOM, Embedded


Abstract

Signature schemes based on the MPC-in-the-Head (MPCitH) paradigm play an important role in enabling cryptosystems founded on a wide diversity of hardness assumptions. While the design of such schemes is currently stabilizing, providing efficient implementations on embedded devices remains a critical challenge, as MPCitH frameworks are known to manipulate large data structures and to rely heavily on symmetric primitives.In this work, we present a highly optimized implementation of the NIST candidate MQOM (version 2) targeting embedded microcontrollers. Our implementation significantly outperforms existing MPCitH implementations on such platforms, both in terms of memory footprint and execution time. In particular, for the L1 parameter set, we can achieve an SRAM usage below 10 KB, including the key and signature buffers, while preserving practical signing and verification performance (on the order of a few hundred megacycles). We further explore time-memory trade-offs, achieving execution times below 100 Mc for certain variants at the cost of an additional 5-10 KB of memory.We also provide the first memory-friendly implementation of the one-tree technique, which is used to reduce signature sizes in several MPCitH-based schemes. This enables a comparative analysis of the implementation costs of correlated trees (used in MQOM) versus the one-tree technique (used in other candidates). We then demonstrate how streaming and precomputation techniques can further mitigate the impact of the running time and the signature size. For instance, these approaches enable overlapping computation with data reception, for example by starting computations before all inputs are available, thereby reducing overall latency.

Publication

IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 3

Paper

Artifact

Artifact number
tches/2026/a33

Artifact published
September 21, 2026

Badge
✅ IACR CHES Artifacts Functional

README

ZIP (82556400 Bytes)  

View on Github

License
This work is licensed under the MIT License.

Note that license information is supplied by the authors and has not been confirmed by the IACR.


BibTeX How to cite

Ryad Benadjila, Thibauld Feneuil. (2026). Breaking the Myth of MPCitH Inefficiency: Optimizing MQOM for Embedded Platforms. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(3), 279–305. https://doi.org/10.46586/tches.v2026.i3.279-305. Artifact at https://artifacts.iacr.org/tches/2026/a33.