Transactions on Cryptographic Hardware and Embedded Systems 2026
Breaking the Myth of MPCitH Inefficiency:
Optimizing MQOM for Embedded Platforms
Ryad Benadjila
CryptoExperts, Paris, France
Thibauld Feneuil
CryptoExperts, Paris, France
Keywords: Post-quantum signatures, MPC-in-the-head, MQOM, Embedded
Abstract
Signature schemes based on the MPC-in-the-Head (MPCitH) paradigm play an important role in enabling cryptosystems founded on a wide diversity of hardness assumptions. While the design of such schemes is currently stabilizing, providing efficient implementations on embedded devices remains a critical challenge, as MPCitH frameworks are known to manipulate large data structures and to rely heavily on symmetric primitives.In this work, we present a highly optimized implementation of the NIST candidate MQOM (version 2) targeting embedded microcontrollers. Our implementation significantly outperforms existing MPCitH implementations on such platforms, both in terms of memory footprint and execution time. In particular, for the L1 parameter set, we can achieve an SRAM usage below 10 KB, including the key and signature buffers, while preserving practical signing and verification performance (on the order of a few hundred megacycles). We further explore time-memory trade-offs, achieving execution times below 100 Mc for certain variants at the cost of an additional 5-10 KB of memory.We also provide the first memory-friendly implementation of the one-tree technique, which is used to reduce signature sizes in several MPCitH-based schemes. This enables a comparative analysis of the implementation costs of correlated trees (used in MQOM) versus the one-tree technique (used in other candidates). We then demonstrate how streaming and precomputation techniques can further mitigate the impact of the running time and the signature size. For instance, these approaches enable overlapping computation with data reception, for example by starting computations before all inputs are available, thereby reducing overall latency.
Publication
IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 3
PaperArtifact
Artifact number
tches/2026/a33
Artifact published
September 21, 2026
Badge
✅ IACR CHES Artifacts Functional
License
This work is licensed under the MIT License.
Note that license information is supplied by the authors and has not been confirmed by the IACR.
BibTeX How to cite
Ryad Benadjila, Thibauld Feneuil. (2026). Breaking the Myth of MPCitH Inefficiency: Optimizing MQOM for Embedded Platforms. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(3), 279–305. https://doi.org/10.46586/tches.v2026.i3.279-305. Artifact at https://artifacts.iacr.org/tches/2026/a33.