International Association for Cryptologic Research

International Association
for Cryptologic Research

Transactions on Cryptographic Hardware and Embedded Systems 2026

High-Performance FPGA Accelerator for the Post-quantum Signature Scheme CROSS


Patrick Karl
TUM School of Computation, Information and Technology, Technical University of Munich, Munich, Germany

Francesco Antognazza
Politecnico di Milano, Department of Electronics, Information and Bioengineering (DEIB), Milan, Italy

Alessandro Barenghi
Politecnico di Milano, Department of Electronics, Information and Bioengineering (DEIB), Milan, Italy

Gerardo Pelosi
Politecnico di Milano, Department of Electronics, Information and Bioengineering (DEIB), Milan, Italy

Georg Sigl
TUM School of Computation, Information and Technology, Technical University of Munich, Munich, Germany; Fraunhofer Institute for Applied and Integrated Security, Garching, Germany


Keywords: Hardware Accelerator, CROSS, Post-quantum Digital Signature, Restricted Syndrome Decoding Problem, FPGA


Abstract

In October 2024, the National Institute of Standards and Technology announced the second round candidates of its standardization effort for additional post-quantum signatures. One of these candidates is CROSS, a code-based scheme relying on the restricted syndrome decoding problem. In this work, we present the first hardware design of CROSS, delineating efficient implementation strategies for the critical components of the cryptographic scheme. Our architecture parallelizes rejection sampling in two dimensions, enabling to simultaneously generate multiple vectors, as well as multiple entries of these vectors. We implement hardware friendly modular reduction circuits requiring only shifts and additions to obtain a DSPfree design, and carefully schedule operations enabling to hide them behind more computationally intensive tasks. Depending on the chosen security level, our design generates a key pair in 8 to 148 μs, signs a message in 338 μs to 4.62 ms, and verifies a signature in 303 μs to 3.27 ms on an AMD Artix-7 device. We show that our design is among the fastest and smallest when compared with other on-ramp candidates, namely LESS, MEDS, MAYO, Raccoon and SDitH, and comparable to current standard-selected ML-DSA, FN-DSA, and SLH-DSA in terms of efficiency.

Publication

IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 3

Paper

Artifact

Artifact number
tches/2026/a44

Artifact published
September 21, 2026

Badge
✅ IACR CHES Artifacts Functional

README

ZIP (1177700 Bytes)  

View on Github

License

Some files in this archive are licensed under a different license. See the contents of this archive for more information.

Note that license information is supplied by the authors and has not been confirmed by the IACR.


BibTeX How to cite

Patrick Karl, Francesco Antognazza, Alessandro Barenghi, Gerardo Pelosi, Georg Sigl. (2026). High-Performance FPGA Accelerator for the Post-quantum Signature Scheme CROSS. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(3), 98–121. https://doi.org/10.46586/tches.v2026.i3.98-121. Artifact at https://artifacts.iacr.org/tches/2026/a44.